3 ms·
Interesting, I would also look into if the usemode-helper function can maybe used to re-map syscalls and proxy them through a wrapper library just like LD_PRE
by badrabbit 6y ago
Interesting, I would also look into if the usemode-helper function can maybe used to re-map syscalls and proxy them through a wrapper library just like LD_PRELOAD but done at the kernel level after this, every process will load the wrapper lib (not just every glibc process) much like windows programs load user32/kernel32.dll.
Is this feasible or am I misunderstandig the feature?:
https://kernelnewbies.org/KernelProjects/usermode-helper-enhancements https://kernelnewbies.org/KernelProjects/usermode-helper-enh...
https://elixir.bootlin.com/linux/latest/source/security/Kconfig#L198 https://elixir.bootlin.com/linux/latest/source/security/Kcon...
- cryptonector 6y agoOh, nice, so start an app that doesn't use libc (e.g., a golang app) using ptrace(2) to control it, inject code to intercept system calls, mark the app's text as requiring syscall dispatch, then stop ptracing. Presto: LD_PRELOAD for libc-non-using apps. Granted, to make this easy to use the interceptor should be able to use normal LD_PRELOAD objects, which means bootstrapping ld.so and libc, which is going to be very difficult to do.
- monocasa 6y agoThis is how User Mode Linux and gvisor work more or less (albeit with the 'injected' code running in another process entirely). It's also how a kernel I'm writing works in a port that works like user mode linux (in addition to the ports on native hardware). The issue is that ptrace is unreasonably slow (orders of magnitude slower than just regular syscalls), so they'd want the fast normal path to not go through ptrace. But they don't have a way to communicate that to the kernel at the moment.
- cryptonector 6y agoAnd this scheme gets you a fast path.