Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interface for onaccess scanning

From: tvrtko . ursulin
Date: Wed Aug 06 2008 - 05:29:34 EST


Eric Paris wrote on 05/08/2008 20:46:03:

> On Mon, 2008-08-04 at 17:51 -0700, Greg KH wrote:
> > On Mon, Aug 04, 2008 at 08:32:54PM -0400, Eric Paris wrote:
>
> > Oh, and after that, not using a binary interface, have we not learned
> > from the ioctl mess? I sure thought we had...
>
> I don't see a reason why we can't use strings and key=value pairs for
> any metadata being sent back and forth. That seem more reasonable?

Should be OK from my point of view assuming we keep cache and basic
filesystem exclusions in kernel. Otherwise it would be too much work (I am
talking about CPU time) to do with each and every interception.

Tvrtko


Sophos Plc, The Pentagon, Abingdon Science Park, Abingdon,
OX14 3YP, United Kingdom.

Company Reg No 2096520. VAT Reg No GB 348 3873 20.

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/