New "scallhook" feature. Is is OK to create a proposal?

Alexander Churanov alexanderchuranov at gmail.com
Tue Apr 6 13:51:33 UTC 2010


Folks,

My friend, Vladislav Soldatov, and I are going to propose and implement a
new "scallhook" feature: the generic modular solution to monitoring,
filtering and translating system calls.

The feature differs from OpenBSD systrace: it is much more general, going to
be modular and have strong foundation for security application.

The project includes implementing the kernel-side code, the userland
configuration utility, some of most required filtering/translating modules
as well as a new handbook (otherbooks) section on configuration and
extending, plus articles on the web. The future additions to the project may
be a system for sandboxing application every time it is started and an
extension to ports system which would automatically sandbox application when
it is being installed.

About me:

I am software engineer, currently working in Cisco Systems, specializing in
C/C++/UNIX. My additional interests are software quality and security. I am
a port maintainer for devel/boost-* and was participating in extending
syscons driver, until the project was superseded by syscons rewrite by Ed
Schouten.

About Vladislav:
Vladislav is a PhD of computer science, has experience with developing in C
and C++ for FreeBSD.

Before writing the full proposal on the wiki, I'd like to receive the first
approval.

What do you think of this?
Will be the feature accepted?

Alexander Churanov


More information about the freebsd-arch mailing list