• [^] # Re: Dommage

    Posté par . En réponse à la dépêche Sandboxing fin dans le noyau linux : la saga des filtres seccomp. Évalué à 5.

    Dans son premier mail BPF, Will Drewry explique longuement pourquoi il pense que ftrace/perf n'est pas l'endroit adapté. Je t'invite à aller lire son explication qui est très complète. Sa conclusion :

    At every turn, it appears that the tracing infrastructure was unsuited
    for being used for attack surface reduction or as a larger security
    subsystem on its own. [...] It doesn't mean that it has security problems, just that
    there will be a continued struggle between having a really good perf
    system and and really good kernel attack surface reduction system if
    they were merged.