4 ms·
Further on in that same thread, Bob Beck just asked about adding minherit() functionality[1] to Linux as well. LibreSSL might end up adding some very useful sys
by jeffmcjunkin 12y ago
Further on in that same thread, Bob Beck just asked about adding minherit() functionality[1] to Linux as well. LibreSSL might end up adding some very useful syscalls to Linux, which helps with their portability and helps future Linux userland programs in the same situation. Win-win!
[1] http://lists.openwall.net/linux-kernel/2014/07/17/707 http://lists.openwall.net/linux-kernel/2014/07/17/707
- sarciszewski 12y agoThat is really awesome. Though it will be 2 more years before an Ubuntu LTS will support these features :(
- kwijibob 12y agoNot necessarily. Ubuntu have "enablement stacks" kernel updates for the LTS releases. These are more than just upstream patches. For example, 12.04 LTS release had 12.04.4 with a backported kernel as a standard update. https://wiki.ubuntu.com/PrecisePangolin/ReleaseNotes/ChangeSummary/12.04.4 https://wiki.ubuntu.com/PrecisePangolin/ReleaseNotes/ChangeS...
- sarciszewski 12y agoOh, and here I thought they just patched security holes but kept the same old kernel for 2 years. [insert "the more you know" graphic here]
- tcoppi 12y agoSeems like that functionality would better be included as separate madvise() advice than a new syscall, but probably a good addition either way.
- ramidarigaz 12y agoThe next email in that thread suggests using madvise() as well.
- panzi 12y agoI'm a noob concerning all of this, but how would it be different to MADV_DONTFORK? Or why can't MADV_DONTFORK be used for the same task?
- simcop2387 12y agoMADV_DONTFORK ends up working a bit different, when the forked process tries to read the page it ends up as a segmentation fault because the page wasn't carried over. It can be made to work but that ends up more difficult since you have to trap that signal and be able to prove you aren't going to catch a real one. Adding something like INHERITZERO would end up giving you a new blank page which would be much nicer to deal with in the userspace.
- JoshTriplett 12y ago> MADV_DONTFORK ends up working a bit different, when the forked process tries to read the page it ends up as a segmentation fault because the page wasn't carried over. It can be made to work but that ends up more difficult since you have to trap that signal and be able to prove you aren't going to catch a real one. Doubly difficult from within library code that needs to work in arbitrary programs, and thus cannot mess with signal handling.