Re: [RFC 0/5] [TALPA] Intro to a linux interface for on access scanning

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Eric Paris <eparis@...>
Cc: <malware-list@...>, <linux-kernel@...>
Date: Tuesday, August 5, 2008 - 10:35 pm

Eric Paris <eparis@redhat.com> writes:


Actually local disk file systems can be changed invisibly to the VFS too by 
directly writing to the block device. This does not change the
page cache, but the on disk copy and when a page is pruned from
RAM and reloaded VFS will see the new contents without knowing
about any change. How would you stop that in your
proposal? I assume you could always require a special LKM that
forbids block writes for anything mounted, but that has other problems 
too and one wuld need to be extremly careful of holes in
such a protection scheme (e.g. overlapping partitions) 

[haven't read the rest of the proposal]

-Andi

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [RFC 0/5] [TALPA] Intro to a linux interface for on acce..., Andi Kleen, (Tue Aug 5, 10:35 pm)
Sidebar to [malware-list] [RFC 0/5] [TALPA] Intro to a linux..., David Collier-Brown, (Wed Aug 6, 7:40 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., David Collier-Brown, (Mon Aug 11, 12:11 pm)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., Arjan van de Ven, (Wed Aug 13, 10:28 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interf..., David Collier-Brown, (Wed Aug 6, 7:31 am)