logoalt Hacker News

Killswitch: Per-function short-circuit mitigation primitive

61 pointsby signa11today at 9:14 AM13 commentsview on HN

Comments

logdahltoday at 2:13 PM

Super cool. Also, love reading high quality linux patches. I think many, myself previously included, are afraid to even read the kernel source as one thinks it must be super complex. Of course some parts really are. However, the code is honestly of such high quality. I also highly value that feeling of realizing something once thought 'arcane' was actually only made by other humans, and it is legal to go read it and learn from it.

Phelinofisttoday at 5:16 PM

Could something like this also be done via BPF?

PeterWhittakertoday at 12:08 PM

Clever! I know some will say it's like closing the barn door after the horse left, but having this in place to mitigate future vulnerabilities will be handy.

show 1 reply
luka598today at 4:38 PM

>Assisted-by: Claude:claude-opus-4-7

show 1 reply
tostitoday at 1:47 PM

Better tooling for kpatch would be nice tho

IIRC canonical makes patches for official ubuntu kernels but acts like a Chinese restaurant (closed kitchen, orders come in through a small hatch behind the counter)

frumiousirctoday at 12:47 PM

If I'm a malicious actor that gets root, can I killswitch the killswitch?

show 2 replies