Email lists > FreeBSD current version > Re: cpuctl(formely devcpu) patch test request > Re: cpuctl(formely devcpu) patch test request

Re: cpuctl(formely devcpu) patch test request




This post if a part of  this thread

2008-06-16 13:42:41
Re: cpuctl(formely devcpu) patch test request
On Mon, 2008-06-16 at 22:27 +0400, Stanislav Sedov wrote:
> On Mon, 16 Jun 2008 19:10:17 +0100
> "Rui Paulo" <rpauloFreeBSD.org> mentioned:
> 
> > There's no security issue here.
> > If the system administrator is concerned about
"security" of cpuctl,
> > he/she just has to compile-out cpuctl or remove
the module from the
> > file system.
> > 
> 
> Well, in this case it would be possible to load that
again. Setting
> a non-zero securelevel or implementing a specific MAC
policy might
> be a more correct solution. cpuctl(4) won't allow any
MSR operations
> if securelevel is above zero.
> 

Is it potentially "unsafe" to use RDMSR?

-- 
Coleman Kane

about | contact  Other archives ( Real Estate discussion Medical topics )