Re: [PATCH] proc: Disable /proc/$pid/wchan

From: Kees Cook
Date: Thu Sep 23 2021 - 21:16:21 EST


On Thu, Sep 23, 2021 at 05:22:30PM -0700, Vito Caputo wrote:
> Instead of unwinding stacks maybe the kernel should be sticking an
> entrypoint address in the current task struct for get_wchan() to
> access, whenever userspace enters the kernel?

wchan is supposed to show where the kernel is at the instant the
get_wchan() happens. (i.e. recording it at syscall entry would just
always show syscall entry.)

--
Kees Cook