On 2020-07-08, Theo de Raadt wrote: > I think we need something like this. > > Documenting it will be a challenge. > > I really don't like the name as is too generic, when the control is only > for a narrow set of "current time" system calls.
I thought I'd start with something, but lots of questions. Should it be per wrapper? I know in the past we've had some similar conversations about eliminating syscalls (open/openat) and I imagine there will be future instances. Initial thought is it's easier to make one button, and then document it in ktrace perhaps? But we can also add per function options, and document them in the appropriate pages.
