re: [filemon] CVS commit: htdocs/support/security

2019-12-18 Thread matthew green
> As far as I can tell, there are many races caused by autoloading. i have long advocated that we should turn off both module autoload and autounload, as they're security and reliability nightmares. *perhaps* autoload, for a specific list of known OK modules would be OK in the default for me,

Re: [filemon] CVS commit: htdocs/support/security

2019-12-18 Thread David Holland
On Tue, Dec 17, 2019 at 02:19:01PM +0100, Maxime Villard wrote: > Typically with a character device, the kmod can get unloaded while an ioctl > is being executed on it. When it comes to syscalls, I haven't looked > closely, but the issue is likely the same. > > You can use tricks to "narrow