From: Andi Kleen <andi@firstfloor.org>
To: Arjan van de Ven <arjan@infradead.org>
Cc: Greg KH <greg@kroah.com>, Rusty Russell <rusty@rustcorp.com.au>,
Ingo Molnar <mingo@elte.hu>,
Siarhei Liakh <sliakh.lkml@gmail.com>,
linux-kernel@vger.kernel.org,
linux-security-module@vger.kernel.org,
James Morris <jmorris@namei.org>,
Andrew Morton <akpm@linux-foundation.org>, Andi Kleen <ak@muc.de>,
Thomas Gleixner <tglx@linutronix.de>,
"H. Peter Anvin" <hpa@zytor.com>,
linux-cris-kernel@axis.com
Subject: Re: [PATCH v5] RO/NX protection for loadable kernel modules
Date: Mon, 13 Jul 2009 11:02:14 +0200 [thread overview]
Message-ID: <87k52d9crt.fsf@basil.nowhere.org> (raw)
In-Reply-To: <20090712145804.2f1fce98@infradead.org> (Arjan van de Ven's message of "Sun, 12 Jul 2009 14:58:04 -0700")
Arjan van de Ven <arjan@infradead.org> writes:
> I've seen some of these case, where the distro kernel has something as
> a module, but the other parts of the distro the unconditionally load
> that module always. That makes no sense.
One good reason for this is that if something goes wrong with
the module you can still remove/blacklist the module. This can
be very useful in distro deployment, where telling users
"please set flag xyz" is much easier than asking them to get
a special kernel build. It also helps debugging when you're
trying to narrow down where a problem is.
But you can't do that with built-in drivers.
One way to avoid this would be to have a standard way to turn off
drivers/subsystems that are built in on the command line. Right
now that's difficult because the linked kernel doesn't even know
the driver names anymore.
Perhaps we should keep the module names/metadata even in static
kernel? (and make CONFIG_MODULE on the subsystem level disappear?).
IMHO that would be a great cleanup anyways, avoiding one special
case in the driver build testing.
It would be also nice if you could cat some file in sys and it gave
you the module descriptions for example.
-Andi
--
ak@linux.intel.com -- Speaking for myself only.
next prev parent reply other threads:[~2009-07-13 9:02 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-07-08 23:10 [PATCH v5] RO/NX protection for loadable kernel modules Siarhei Liakh
[not found] ` <20090710112403.GC3760@elte.hu>
[not found] ` <200907111537.03191.rusty@rustcorp.com.au>
2009-07-11 7:30 ` Ingo Molnar
2009-07-11 11:22 ` Rusty Russell
2009-07-11 8:51 ` Rusty Russell
2009-07-11 15:49 ` Arjan van de Ven
2009-07-12 4:40 ` Rusty Russell
2009-07-12 4:45 ` H. Peter Anvin
2009-07-12 7:45 ` Arjan van de Ven
2009-07-12 9:25 ` Andi Kleen
2009-07-12 9:58 ` Rusty Russell
2009-07-12 15:32 ` Arjan van de Ven
2009-07-12 17:33 ` Greg KH
2009-07-12 21:58 ` Arjan van de Ven
2009-07-12 22:14 ` Greg KH
2009-07-13 9:02 ` Andi Kleen [this message]
2009-07-12 23:21 ` Rusty Russell
2009-07-13 3:11 ` Arjan van de Ven
2009-07-12 9:24 ` Andi Kleen
2009-07-13 16:59 ` Roland Dreier
2009-07-13 10:59 ` Jesper Nilsson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87k52d9crt.fsf@basil.nowhere.org \
--to=andi@firstfloor.org \
--cc=ak@muc.de \
--cc=akpm@linux-foundation.org \
--cc=arjan@infradead.org \
--cc=greg@kroah.com \
--cc=hpa@zytor.com \
--cc=jmorris@namei.org \
--cc=linux-cris-kernel@axis.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=mingo@elte.hu \
--cc=rusty@rustcorp.com.au \
--cc=sliakh.lkml@gmail.com \
--cc=tglx@linutronix.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox