[d-kernel] [PATCH] UBUNTU: SAUCE: security, perf: Allow further restriction of perf_event_open

Dmitry V. Levin ldv на altlinux.org
Вс Июн 5 10:59:11 MSK 2022


Hi,

On Sun, Jun 05, 2022 at 11:48:06AM +0400, Alexey Sheplyakov wrote:
> Hello,
> 
> On Thu, Jun 02, 2022 at 07:39:14PM +0300, Dmitry V. Levin wrote:
> > > No, thanks. Profiling on Linux is already more diffucult than it should be
> > > Making things even more complicated is not appreciated at all.
> > 
> > Since the kernel we are talking about is a universal kernel, it has to
> > suit needs of both those who care about basic security and those who do
> > profiling.
> 
> Breaking a basic system functionality (such as debugging and profiling)
> has nothing to do with security.

Whatever you might consider a basic system functionality is your point of
view, other people are likely to have different use cases where some of
things your treat as basic are redundant or even dangerous.

With regards to debugging and profiling, I do have installs where neither
debugging nor profiling should be allowed, and we have a universal kernel
to achieve that.


-- 
ldv


Подробная информация о списке рассылки devel-kernel