Re: [kernel-hardening] [PATCH 0/2] introduce post-init read-only memory

From: H. Peter Anvin
Date: Wed Nov 25 2015 - 14:07:40 EST


On 11/25/2015 10:54 AM, Kees Cook wrote:
>>
>> We should not wait for compile-time support, that doesn't make any
>> sense. What would be useful would be a way to override this on the
>> command line -- that way, if disabling RO or RO-after-init memory makes
>> something work, we have an instant diagnosis.
>
> Seems easiest to have an arg just skip calling mark_rodata_ro(). I can add that.
>

Exactly.

-hpa


--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/