Re: Reducing runtime complexity
Pawan Gupta <[email protected]>
| Newsgroups | com.openwall.lists.kernel-hardening,org.kernel.vger.linux-hardening |
|---|---|
| Message-ID | <20221201211429.venqtlzegdbdc7et@desk> |
On Thu, Dec 01, 2022 at 09:09:04PM +0100, Stefan Bavendiek wrote: >Some time ago I wrote a thesis about complexity in the Linux kernel and >how to reduce it in order to limit the attack surface[1]. While the >results are unlikely to bring news to the audience here, it did >indicate some possible ways to avoid exposing optional kernel features >when they are not needed. The basic idea would be to either build or >configure parts of the kernel after or during the installation on a >specific host. Distributions are commonly shipping the kernel as one >large binary that includes support for nearly every hardware driver and >optional feature Is this really true? Most drivers are built as loadable modules and are only loaded when the hardware is present. Are you suggesting to configure-out the modules that are always static? This sounds like an embedded system build.
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEhLB5DdoLvdxF3TZu/KkigcHMTKMFAmOJGTUACgkQ/KkigcHM TKO8Hg/7BtJQa0gxh2s6wp8eQu0bVFa6vPEf4jHnO27WARZRidGnlg9WzOqxF4Pq BTrdHlRsmrNbW0dl2T2ke2s5bs5YBIb1j/6nAVEiHy58yS89r80AXxIrPuQU6h/u IeebBtst8mvgj/cOUnguiE191ZmBizyGcgiRDVHTXFOFWBhNBe3dmSUNefgiUpr0 BWKticd6Dm0EeKyOE3xR+gvsdz9kbmw2nE6KXpdwnjcu0VH7tMJx4v/jmzb+EUV4 i/c9p3DmPR6HSBQM3OzMozFt55ttlw+P9R14PHt2oNJWNbgVvdkr8kq6Am4QUn0M q7QyD6nennNS2Gq5NsOlF6CR3xt1YLGZJjglpOuGGLwF0kNO1JTjlVKdKe3AjkjB 9KS+QVLIcm/KaT8wJaTKZc+AvlHQBRaXgY+X6IwLAPDHkISEqRHjESmDhI4KYSLo qEhLbVBu+2dnSbn7PAF3dIbqP9Sa3y6ioieRBjBZW6if2IkNHwSxfV1pq6WtkvQ6 3pGbCVu1Ah4LWIqRbfXFkX6VEt9V+A4kiytqNXnBdodZjCeOTNIr6rmbRMH18Z8d F/4xyh7kNqrbFn68K0mMloR3Oc0eWzdcTtBXjwoNyJ2nuq6i3CEYx+d5QBijCUgf GDENGYW15VujEs5jfdN+UDdv8xpJFJECs1pdf+WQfKMpyyM+J1I= =NnWb -----END PGP SIGNATURE-----