4 ms·
I got to the twentieth slide, and I still wonder: What does tame() itself DO?
by chipuni 11y ago
I got to the twentieth slide, and I still wonder:
What does tame() itself DO?
- kuschku 11y agoInstantly kill your process if it tries to use any syscall but the ones you have requested.
- fidget 11y agoThe ones _it_ has requested.
- masklinn 11y agohttp://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/tame.2 http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/... Whitelist syscalls. Any non-whitelisted syscall being invoked causes the process to be terminated with SIGKILL (or a non-blockable SIGABRT if `abort` it set). Further tame(2) calls can only further restrict the whitelist. The whitelisting can get down to just _exit(2).
- mmastrac 11y agoI was wondering why you'd ever want to just limit yourself to _exit, but the man page answers that: A request value of "" restricts the process to the _exit(2) system call. This can be used for pure computation operating on memory shared with another process.
- 0xcde4c3db 11y ago"The man page answers that" could probably be the OpenBSD motto.
- xiaq 11y agoIt was the Unix motto. Before GNU ruined man pages...