On Tue, 2008-08-05 at 10:41 -0400, Press, Jonathan wrote:You aren't doing write time scanning anyway. This exclusion means that an 'excluded' process can OPEN things that would normally be called malware. The model here doesn't talk about adding files with bad information to the system it talks about stopping that bad information from being opened and propagated further. Thread exclusions as they are written in the patch only weaken security to those processes which actively choose to read malware, it in no way weakens the security of the system as a whole... Wait wit, you'd rather have a 'privileged' process be allowed to exclude every other process on a system than have a it only be allowed to exclude itself? and somehow that is safer? "by name" is right out the window. You are never going to win 'by name' on anything to do with the kernel :) Maybe you can get me to eventually buy into 'by pid' or something like that, but setting flags on other running processes is always going to be racy and scary for me. Can you show me some code on how to do this cleanly? And why it needs to be done in kernel? What is the goal you are trying to achieve? A performance win for the application in question or is this a security aware application that needs to be able to access 'sensitive' data? -Eric --
| Ingo Molnar | Re: x86: 4kstacks default |
| Stephen Rothwell | Re: Announce: Linux-next (Or Andrew's dream :-)) |
| Trent Piepho | [PATCH] [POWERPC] Improve (in|out)_beXX() asm code |
| Rafael J. Wysocki | [Bug #10919] [regression] display dimming is slow and laggy - Acer Travelmate 661lci |
git: | |
| Linus Torvalds | Re: iptables very slow after commit 784544739a25c30637397ace5489eeb6e15d7d49 |
| Andrew Morton | Re: [BUG] New Kernel Bugs |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
