Messages in this thread |  | | Subject | Re: secure computing for 2.6.7 | | From | Alan Cox <> | | Date | Sun, 01 Aug 2004 21:45:14 +0100 |
| |
On Sul, 2004-08-01 at 18:29, chris@scary.beasts.org wrote: > How hard would it be to have a per-task bitmap of syscalls allowed? This > way, a task could restrict to the exact subset of syscalls required for > maximum security.
Very easy indeed, although you might have to do a tiny bit of tweaking for kernel made syscalls (eg hotplug triggers).
You can already do all of this using several user space applications that manage it via ptrace. They do have a performance hit however.
- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
|  |