3 ms·
you give process direct access to a piece of kernel memory. its a reason why there is separation. thats all.
by sim7c00 1y ago
you give process direct access to a piece of kernel memory.
its a reason why there is separation. thats all.
- wtallis 1y agoMost of the security concerns with io_uring that I've seen aren't related to the shared buffers at all but simply stem from the fact that io_uring is a mechanism to instruct the kernel to do stuff without making system calls, so security measures that focus on what system calls a process is allowed to do are ineffective.
- loeg 1y agoThis isn't the issue; it's relatively easy to safely share some ring buffers. The issue was/is that io_uring is rapidly growing the equivalent of ~all historical Linux syscall interfaces and sometimes comparable security measures were missed on the new interfaces. (Also, stuff like seccomp filters on syscalls are kind of meaningless for io_uring.)
- duped 1y ago...don't you supply the memory in the submission queue? or do you mean the queues themselves?
- LAC-Tech 1y agoThe memory for the submission queue is mmapd into user space. Easiest implementation to read is the Zig stdlib: https://github.com/ziglang/zig/blob/69cf40da600224734d39c6f64fb2e0905e42d54a/lib/std/os/linux/IoUring.zig#L1511 https://github.com/ziglang/zig/blob/69cf40da600224734d39c6f6...