Cc: Press, Jonathan <Jonathan.Press@...>, Arjan van de Ven <arjan@...>, Eric Paris <eparis@...>, <linux-kernel@...>, <malware-list@...>, <linux-security-module@...>
> > However, I want to point out that scanning on close is still an integral
kill -9
deferred close via mmap
etc etc etc
You can't just armwave it into glibc, that doesn't hold water. You also
have shared state between processes (index on last close of a handle
shared by several threads or processes).
Same problem you have in the indexing business (which also wants the
close hook) - aside from all the practical issues that LD_PRELOAD tends
to turn up.
I'm not actually interested in the AV stuff, but content indexing I do
care about and we do need a way to get notification up to user space.
Alan
--