Re: Reducing runtime complexity

Pawan Gupta <[email protected]>
Newsgroups com.openwall.lists.kernel-hardening,org.kernel.vger.linux-hardening
Message-ID <20221201211429.venqtlzegdbdc7et@desk>
On Thu, Dec 01, 2022 at 09:09:04PM +0100, Stefan Bavendiek wrote:
>Some time ago I wrote a thesis about complexity in the Linux kernel and
>how to reduce it in order to limit the attack surface[1]. While the
>results are unlikely to bring news to the audience here, it did
>indicate some possible ways to avoid exposing optional kernel features
>when they are not needed. The basic idea would be to either build or
>configure parts of the kernel after or during the installation on a
>specific host. Distributions are commonly shipping the kernel as one
>large binary that includes support for nearly every hardware driver and
>optional feature

Is this really true? Most drivers are built as loadable modules and are
only loaded when the hardware is present.

Are you suggesting to configure-out the modules that are always static?
This sounds like an embedded system build.
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEhLB5DdoLvdxF3TZu/KkigcHMTKMFAmOJGTUACgkQ/KkigcHM
TKO8Hg/7BtJQa0gxh2s6wp8eQu0bVFa6vPEf4jHnO27WARZRidGnlg9WzOqxF4Pq
BTrdHlRsmrNbW0dl2T2ke2s5bs5YBIb1j/6nAVEiHy58yS89r80AXxIrPuQU6h/u
IeebBtst8mvgj/cOUnguiE191ZmBizyGcgiRDVHTXFOFWBhNBe3dmSUNefgiUpr0
BWKticd6Dm0EeKyOE3xR+gvsdz9kbmw2nE6KXpdwnjcu0VH7tMJx4v/jmzb+EUV4
i/c9p3DmPR6HSBQM3OzMozFt55ttlw+P9R14PHt2oNJWNbgVvdkr8kq6Am4QUn0M
q7QyD6nennNS2Gq5NsOlF6CR3xt1YLGZJjglpOuGGLwF0kNO1JTjlVKdKe3AjkjB
9KS+QVLIcm/KaT8wJaTKZc+AvlHQBRaXgY+X6IwLAPDHkISEqRHjESmDhI4KYSLo
qEhLbVBu+2dnSbn7PAF3dIbqP9Sa3y6ioieRBjBZW6if2IkNHwSxfV1pq6WtkvQ6
3pGbCVu1Ah4LWIqRbfXFkX6VEt9V+A4kiytqNXnBdodZjCeOTNIr6rmbRMH18Z8d
F/4xyh7kNqrbFn68K0mMloR3Oc0eWzdcTtBXjwoNyJ2nuq6i3CEYx+d5QBijCUgf
GDENGYW15VujEs5jfdN+UDdv8xpJFJECs1pdf+WQfKMpyyM+J1I=
=NnWb
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.