Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The OS can scan the program for instructions that access these bits. If necessary on a per-basic-block basis.


Of course, this only works if you can't introduce new code without the kernel noticing.


Yes, you can introduce new code but the kernel should also watch for that (JIT compilation etc.) and check the resulting code. It's quite involved, and the whole process looks more like a sandbox or emulator, but it's possible.


Doing this performantly is going to be very prohibitive.


Perhaps (depends also on CPU support), but on the other hand: in today's world with untrusted apps, the kernel will have to do some sandboxing anyway.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: