Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1704659

Re: [PATCH 0/2] mm,fork,security: introduce MADV_WIPEONFORK

Path csiph.com!goblin2!goblin3!goblin.stu.neva.ru!news.redatomik.org!aioe.org!bofh.it!news.nic.it!robomod
From Rik van Riel <riel@redhat.com>
Newsgroups linux.kernel
Subject Re: [PATCH 0/2] mm,fork,security: introduce MADV_WIPEONFORK
Date Sat, 05 Aug 2017 17:30:02 +0200
Message-ID <ub9bA-6KA-7@gated-at.bofh.it> (permalink)
References <uaQ8W-2CK-17@gated-at.bofh.it> <uaUvW-5hz-63@gated-at.bofh.it>
Dmarc-Filter OpenDMARC Filter v1.3.2 mx1.redhat.com 94B1B883C1
Authentication-Results ext-mx02.extmail.prod.ext.phx2.redhat.com; dmarc=none (p=none dis=none) header.from=redhat.com
Authentication-Results ext-mx02.extmail.prod.ext.phx2.redhat.com; spf=fail smtp.mailfrom=riel@redhat.com
Organization Red Hat, Inc
Content-Type text/plain; charset="UTF-8"
MIME-Version 1.0
Content-Transfer-Encoding 7bit
X-Scanned-By MIMEDefang 2.79 on 10.5.11.13
X-Greylist Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.26]); Sat, 05 Aug 2017 15:21:46 +0000 (UTC)
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 23
X-Original-Cc linux-kernel@vger.kernel.org, linux-mm@kvack.org, fweimer@redhat.com, colm@allcosts.net, akpm@linux-foundation.org, rppt@linux.vnet.ibm.com, keescook@chromium.org, luto@amacapital.net, wad@chromium.org, mingo@kernel.org
X-Original-Date Sat, 05 Aug 2017 11:21:44 -0400
X-Original-Message-ID <1501946504.6577.9.camel@redhat.com>
X-Original-References <20170804190730.17858-1-riel@redhat.com> <20170804234435.lkblljl3f3ud2spm@node.shutemov.name>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1704659

Show key headers only | View raw


On Sat, 2017-08-05 at 02:44 +0300, Kirill A. Shutemov wrote:
> On Fri, Aug 04, 2017 at 03:07:28PM -0400, riel@redhat.com wrote:
> > [resend because half the recipients got dropped due to IPv6
> > firewall issues]
> > 
> > Introduce MADV_WIPEONFORK semantics, which result in a VMA being
> > empty in the child process after fork. This differs from
> > MADV_DONTFORK
> > in one important way.
> > 
> > If a child process accesses memory that was MADV_WIPEONFORK, it
> > will get zeroes. The address ranges are still valid, they are just
> > empty.
> 
> I feel like we are repeating mistake we made with MADV_DONTNEED.
> 
> MADV_WIPEONFORK would require a specific action from kernel, ignoring
> the /advise/ would likely lead to application misbehaviour.
> 
> Is it something we really want to see from madvise()?

We already have various mandatory madvise behaviors in Linux,
including MADV_REMOVE, MADV_DONTFORK, and MADV_DONTDUMP.

Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

[PATCH 0/2] mm,fork,security: introduce MADV_WIPEONFORK riel@redhat.com - 2017-08-04 21:10 +0200
  Re: [PATCH 0/2] mm,fork,security: introduce MADV_WIPEONFORK "Kirill A. Shutemov" <kirill@shutemov.name> - 2017-08-05 01:50 +0200
    Re: [PATCH 0/2] mm,fork,security: introduce MADV_WIPEONFORK Rik van Riel <riel@redhat.com> - 2017-08-05 17:30 +0200

csiph-web