mirror of
https://github.com/opnsense/src.git
synced 2026-03-12 05:32:15 -04:00
Previously, we tried to allow this only for root. However, we were calling suser() on the *target* process rather than the current process. This means that if you can ptrace() a process running as root you can set a hardware watch point in the kernel. In practice I think you probably have to be root in order to pass the p_candebug() checks in ptrace() to attach to a process running as root anyway. Rather than fix the suser(), I just axed the entire idea, as I can't think of any good reason _at all_ for userland to set hardware watch points for KVM. MFC after: 3 days Also thinks hardware watch points on KVM from userland are bad: bde, rwatson |
||
|---|---|---|
| .. | ||
| apm | ||
| cbus | ||
| compile | ||
| conf | ||
| include | ||
| linux | ||
| pc98 | ||