On Fri, May 12, 2017 at 09:43:40AM +0200, Arnd Bergmann wrote: > How realistic and how useful would it be to first completely eliminate > the ones that are in loadable modules and then wrapping the definition > in #ifndef MODULE (or even make it an extern function)?
Should be fairly doable and might be a nice step towards cleaning the mess up. In fact with my seres a large part of those are gone, and most of the remaining handler are ioctl handlers or what seems like opencoded versions of probe_kernel_read. But it won't help against exploits modifying addr_limit manually.