Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 3 Dec 2001 09:34:47 -0800
From:      "Zachary M. Smith" <spader@arbornet.org>
To:        freebsd-security@FreeBSD.ORG
Subject:   Re: philosophical question...
Message-ID:  <20011203093447.E32204@arbornet.org>
In-Reply-To: <Pine.NEB.3.96L.1011203074251.94074Q-100000@fledge.watson.org>; from rwatson@FreeBSD.ORG on Mon, Dec 03, 2001 at 07:44:24AM -0500
References:  <20011203032305.K92148@elvis.mu.org> <Pine.NEB.3.96L.1011203074251.94074Q-100000@fledge.watson.org>

next in thread | previous in thread | raw e-mail | index | archive | help

--8P1HSweYDcXXzwPJ
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

If we're talking about a userland.<applicationname> and having
applications decide wether or not they want to use the new random
malloc, maybe looking into setting up something like Darwin's
'defaults' would be a good way to go.

-zach

On Mon, Dec 03, 2001 at 07:44:24AM -0500, Robert Watson wrote:
>=20
> On Mon, 3 Dec 2001, Alfred Perlstein wrote:
>=20
> > * Oleg Cherkasov <Oleg.Cherkasov@mail.com> [011203 03:16] wrote:
> > >=20
> > > Think a new key 'malloc.random' for sysctl could be more useful, prot=
ected=20
> > > with 'kern.securelevel' > 1.
> >=20
> > However, malloc(3) has nothing to do with the kernel.
>=20
> Yeah, I'm not sure why it would be keyed off of 'securelevel'.  Seems to
> me that we should avoid any more userland cruft being associated
> unnecessarily with securelevels, actually :-).=20
>=20
> And if we do stuff this in a securelevel, it sounds like we need a
> userland.<applicationname> sysctl namespace.  More likely, we just need
> this to be a flag on /etc/malloc.conf.=20
>=20
> Robert N M Watson             FreeBSD Core Team, TrustedBSD Project
> robert@fledge.watson.org      NAI Labs, Safeport Network Services
>=20
>=20
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-security" in the body of the message

--=20

--8P1HSweYDcXXzwPJ
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (FreeBSD)
Comment: For info see http://www.gnupg.org

iD8DBQE8C7e3M6FaXlC3H6ARApJPAJ9nixMqxizD8dLQpykXhlVt+XVJ5QCfScJ5
rFoPNK3UiADaAUPNHI17kbk=
=g+Dv
-----END PGP SIGNATURE-----

--8P1HSweYDcXXzwPJ--

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20011203093447.E32204>