lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Sun, 30 Nov 2008 21:22:17 -0800 (PST) From: david@...g.hm To: Enrico Weigelt <weigelt@...ux.de> cc: linux kernel list <linux-kernel@...r.kernel.org> Subject: Re: scanner interface proposal was: [TALPA] Intro to a linux interface for on access scanning (fwd) On Mon, 1 Dec 2008, Enrico Weigelt wrote: > * Alan Cox <alan@...rguk.ukuu.org.uk> wrote: >>> Fine. Why not just putting this into a userland filesystem ? >> >> 1. Performance > > Does it really hurt so bad, compared with all actual AV stuff ? > It has to go to userland anyway, in case you don't intend to > put the scanner into the kernel ;-o if you have to scan every file then you are right, the userland overhead would be swamped by the scanner overhead. but much of the time you will be accessing files that are already scanned or that you aren't going to scan, but you would still be paying the userland penalty for the filesystem. David Lang >> 2. Networked file systems > > What's the problem ? > (btw: 9P already *IS* an network filesystem ;-P) > >> 3. Ioctls > > Ah, just forgot a while that this crap still exists ;-o > > BUT: do the affected dirs have to contain devices ? > Is there any point for pulling /dev through the AV scanner ? > > > cu > -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@...r.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists