The other thing to consider is if you return time as accurate as the CPU
cycle counter, you have just created a mechanism for a covert information
channel. One of the things that surprised me was that the higher security
levels do not want a process to be able to get a highly accurate time.
If processes can get a highly accurate time value from some sort of global
clock, it allows a pair of processes to create a covert channel for passing
information. The less secure program monitors the time variences of the
high-security program in order to get information about or from them.
-Bret
-------------------------------------------------------------
SBS Technologies, Connectivity Products
... solutions for real-time connectivity
Bret Indrelee, Engineer
SBS Technologies, Inc., Connectivity Products
1284 Corporate Center Drive, St. Paul MN 55121
Direct: (651) 905-4731
Main: (651) 905-4700 Fax: (651) 905-4701
E-mail: bindrelee@sbs-cp.com http://www.sbs.com
-------------------------------------------------------------
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/