4 ms·
> to be secure against actively hostile code Was that a requirement for the predecessor of eBPF: Custom kernel modules?
by DelightOne 3y ago
> to be secure against actively hostile code
Was that a requirement for the predecessor of eBPF: Custom kernel modules?
- insanitybit 3y agoKernel modules require root privileges to load and the Linux kernel's philosophy (pre user namespaces lollllll) was that root -> kernel privesc didn't matter.
- DelightOne 3y agoOf course it would be nice if every app can load up its own untrusted eBPF code and for the kernel to not be compromised. But why such high standards, where else is that the standard to go for? Seems perfect is the enemy of good.
- insanitybit 3y agoI don't think "standard" is the point. It's about unlocking new features and capabilities.
- tptacek 3y agoeBPF is not a replacement for the general concept of custom kernel modules.