Performance improvements to chroot restrictions
Posted: Tue Jun 29, 2010 8:04 pm
I've just uploaded a patch to:
http://grsecurity.net/~spender/new_chroot.patch
Based on some feedback I received from a user on IRC about reduced interactivity during heavy activity within chroots, I've written the chroot detection/root comparison code to eliminate any such performance hit. I've tested it locally here and ran it through all the chroot regression tests successfully, but I'd like it to receive more widespread testing before I put it in the stable tree. Especially if you've noticed the aforementioned performance hit, I'd like to hear your feedback on the patch. The patch at the address above applies on top of the latest 2.6.32.15 grsecurity patch.
-Brad
http://grsecurity.net/~spender/new_chroot.patch
Based on some feedback I received from a user on IRC about reduced interactivity during heavy activity within chroots, I've written the chroot detection/root comparison code to eliminate any such performance hit. I've tested it locally here and ran it through all the chroot regression tests successfully, but I'd like it to receive more widespread testing before I put it in the stable tree. Especially if you've noticed the aforementioned performance hit, I'd like to hear your feedback on the patch. The patch at the address above applies on top of the latest 2.6.32.15 grsecurity patch.
-Brad