Re: [announce] procps 2.0.13 with NPTL enhancements

Adrian Bunk (bunk@fs.tum.de)
Fri, 30 May 2003 08:26:36 +0200


On Fri, May 30, 2003 at 01:00:54AM -0400, Albert Cahalan wrote:
> Robert Love writes:
> On Thu, 2003-05-29 at 18:08, Adrian Bunk wrote:
>
> >> Well, since I read Albert Cahalan's comment in
> >> Debian bug #172735 [1] I understand the people
> >> maintaining a different branch...
> >
> > Exactly.
> >
> > That bug is fixed in the official tree, fyi.
> > A segfault, as you said, is always a bug.
> > An error message is displayed.
>
> You asked for it...
>
> Nice cheapshot there. So, if I remove some
> critical kernel interfaces from your system,
> nothing should crash? How about I take out
> a few choice system calls or a chunk of libc?
>
> (note: the "bug" is not exploitable)
>
> Face it. For nearly a decade, /proc has been
> a critical kernel interface. This isn't 1991.
> (embedded systems excepted; they don't use procps)
>
> That said, I may do something about the issue
> simply to please users with messed-up systems.
>...

Disabling the proc filesystem is simple by unchecking one item in the
kernel config menu and different from taking out "a chunk of libc" it's
more or less supported.

I don't say #172735 is exploitable. An error message "Error: /proc isn't
mounted" tells you what is wrong, a segmentation fault tells you
_nothing_.

I've seen at several occasions that several man days were lost trying to
find problems in other programs that caused segmentation faults. In the
end things like diff'ing strace files give you important hints after
hours of clueless searching. Error messages instead of segmentation
faults would have prevented several fruitless hours in my live.

After reading the last sentence you might perhaps understand my opinion
about the quality of a software whose maintainer says about a
segmentation fault "Crashing is kind of a good thing even. ... In error
checking, there is a certain balance to achieve." .

cu
Adrian

-- 

"Is there not promise of rain?" Ling Tan asked suddenly out of the darkness. There had been need of rain for many days. "Only a promise," Lao Er said. Pearl S. Buck - Dragon Seed

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/