3 ms·
> Cannot call abort() because some systems have unsafe corefiles. Huh, FreeBSD has MAP_NOCORE which allows the program to map pages that will explicitly not be
by lcampbell 12y ago
> Cannot call abort() because some systems have unsafe corefiles.
Huh, FreeBSD has MAP_NOCORE which allows the program to map pages that will explicitly not be included in the core file. I never realized that this was FreeBSD-specific extension (added in 2007?).
I'm really surprised other platforms haven't adopted it, though I surmise there's a good technical reason or two. (EDIT: or maybe there's similar functionality via another API? I haven't been able to turn up anything).
- tcoppi 12y agoLinux since 3.4 has MADV_DONTDUMP [1], and there also appears to be a /proc filter file you can use to exclude general segments of memory from being dumped [2]. 1. http://man7.org/linux/man-pages/man2/madvise.2.html http://man7.org/linux/man-pages/man2/madvise.2.html 2. http://man7.org/linux/man-pages/man5/core.5.html http://man7.org/linux/man-pages/man5/core.5.html
- quotemstr 12y agoIt's hard to blacklist every piece of memory that might be sensitive. It's a much better idea, IMHO, to just put corefiles in a location accessible only to root. That's how Windows, OS X, Ubuntu, Android, and lots of other commercial systems work.
- xorcist 12y ago.. which you need to do anyway. The SSL library, and the program linked against it, can fail in a thousand more ways that generate them.
- floatboth 12y agoWell, there is a way to disable core dumps entirely: setrlimit RLIMIT_CORE to 0