看板FB_security
標 題Re: [patch] unprivileged mlock(2)
發信站NCTU CS FreeBSD Server (Thu Oct 4 23:01:42 2012)
轉信站ptt!csnews.cs.nctu!news.cs.nctu!FreeBSD.cs.nctu!freebsd.org!owner-free
This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig1006662FCC9A90D3E8FF85E7
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
On 9/28/12 5:24 PM, Andrey Zonov wrote:
> On 9/27/12 7:25 PM, Simon L. B. Nielsen wrote:
>> On Tue, Sep 25, 2012 at 1:06 PM, Andrey Zonov <
[email protected]> wrote=
:
>>> Hi,
>>>
>>> Please review this patch [1] which allows unprivileged users call
>>> mlock()/munlock() and mlockall()/munlockall().
>>>
>>> AFAIK, these calls were not allowed for every-one because accounting =
for
>>> mlockall(MCL_FUTURE) was not implemented.
>>
>> I can't comment on the implementation details (don't know much about
>> VM system), but do you have tests to show that the new code actually
>> works in preventing users from mlocking more than 8MB by default?
>>
>=20
> Sure, test is attached.
>=20
Hi Simon,
Have you got a chance to look at that?
--=20
Andrey Zonov
--------------enig1006662FCC9A90D3E8FF85E7
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.18 (Darwin)
Comment: GPGTools -
http://gpgtools.org
iQEcBAEBAgAGBQJQbWyZAAoJEBWLemxX/CvTV1cH/izvL+mEhRdtJPyk/diGngl9
j6wancGIRKfQxKjrmBLrUsZiPKbpb6R/bIghJd/1U0NJuF4ZGgDX4DfoZW4H4wGQ
K34v8F7GEaA9V42x7zKSdv6gfdcbGZzTDWCqRjiaLVHHYh3OHvlguD5/gHIUTDmm
tYihcSTtAIvj05Og1ZarZQSezYU5LKbGo920JgZH0AC3EnM9GcH6UmJXQ/g0nLNf
GjECDASPnrYB87me/loToQxzOz+NfoY4pbZ0JTpd2zWsu/hRA2A1NthbMrD27hMR
slB8saA3Ybhx0QkLnr4ixx1rInmx27dWua4vqZVtfUrOp73huBINMxGQPmZXP9o=
=p1Qk
-----END PGP SIGNATURE-----
--------------enig1006662FCC9A90D3E8FF85E7--