Performance impact
Performance impact
Posted Jul 30, 2022 10:14 UTC (Sat) by Wol (subscriber, #4433)In reply to: Performance impact by mathstuf
Parent article: Security requirements for new kernel features
That way, people who don't want the hassle/overhead just don't bother registering god with io_uring. People who are paranoid, or need accounting, or whatever, configure god to reject calls it doesn't know about (and the writers of said calls will quickly get bug reports saying "your io_uring call doesn't work - missing security module").
And if this is added *quickly*, before io_uring gets too embedded, it means that "no security module no run" is a realistic option. The later it gets left, the harder it gets to turn that on without all hell breaking loose ...
Cheers,
Wol