Re: [PATCH 3/5] v2 seccomp_filters: Enable ftrace-based system callfiltering

From: Ingo Molnar
Date: Wed May 25 2011 - 15:06:25 EST



* Linus Torvalds <torvalds@xxxxxxxxxxxxxxxxxxxx> wrote:

> And per-system-call permissions are very dubious. What system calls
> don't you want to succeed? That ioctl? You just made it impossible
> to do a modern graphical application. Yet the kind of thing where
> we would _want_ to help users is in making it easier to sandbox
> something like the adobe flash player. But without accelerated
> direct rendering, that's not going to fly, is it?

I was under the impression that Will had a very specific application
in mind which actually works today and uses the inferior version of
seccomp.

Will, mind filling us in on that?

I'd agree that adding any of this without a real serious app making
real use of it would be pointless. I discussed this under the
impression that the app existed :-)

I also got the very distinct impression from the various iterations
that a real usecase existed behind it - all the fixes and
considerations looked very realistic, not designed up for security's
sake.

> So I'm sorry for throwing cold water on you guys, but the whole
> "let's come up with a new security gadget" thing just makes me go
> "oh no, not again".

Fair enough :-)

Thanks,

Ingo
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/