From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756894Ab1GAOmU (ORCPT ); Fri, 1 Jul 2011 10:42:20 -0400 Received: from 173-166-109-252-newengland.hfc.comcastbusiness.net ([173.166.109.252]:53908 "EHLO bombadil.infradead.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1756689Ab1GAOmR (ORCPT ); Fri, 1 Jul 2011 10:42:17 -0400 Date: Fri, 1 Jul 2011 10:41:29 -0400 From: Christoph Hellwig To: Ingo Molnar Cc: Christoph Hellwig , Petr Tesarik , Andrew Morton , Fenghua Yu , "H. Peter Anvin" , Ingo Molnar , Paul Mundt , Russell King , Thomas Gleixner , Tony Luck , x86@kernel.org, linux-arm-kernel@lists.infradead.org, linux-ia64@vger.kernel.org, linux-sh@vger.kernel.org, linux-kernel@vger.kernel.org, Arjan van de Ven , Dave Jones , Linus Torvalds Subject: Re: [PATCH 00/10] Enhance /dev/mem to allow read/write of arbitrary physical addresses Message-ID: <20110701144129.GA10052@infradead.org> References: <201106171038.25988.ptesarik@suse.cz> <20110617093032.GA19235@elte.hu> <201106291106.00070.ptesarik@suse.cz> <20110701125802.GE12605@elte.hu> <20110701134705.GA6175@infradead.org> <20110701143735.GA21367@elte.hu> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20110701143735.GA21367@elte.hu> User-Agent: Mutt/1.5.21 (2010-09-15) X-SRS-Rewrite: SMTP reverse-path rewritten from by bombadil.infradead.org See http://www.infradead.org/rpr.html Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Jul 01, 2011 at 04:37:35PM +0200, Ingo Molnar wrote: > After initial modules have loaded i essentially disable crash.ko via > /proc/sys/kernel/modules_disabled so rootkits have to work a bit > harder than that. Not sure for fedora as I don'[t have a kernel tree at hand right now, but for x86 systems at least RHEL6 has the module built in. Either way we'll need some way to support crash properly in mainline, preferably in a boot-time opt-in way. I'd tend slightly toward optionally enabling /dev/mem for it instead of a separate driver, but if people prefer a different route I'm fine, too. Note that for normal crash usage read only access is just fine.