Meta tags:
Headings (most frequently used words):
linux, macos, solaris, loadable, kernel, module, contents, advantages, disadvantages, implementations, in, different, operating, systems, binary, compatibility, security, see, also, references, freebsd, netware, vxworks, license, issues, linuxant, controversy,
Text of the page (most frequently used words):
#kernel (105), the (103), modules (43), and (33), module (32), #system (32), linux (32), loadable (23), operating (22), edit (22), with (20), can (20), freebsd (19), are (19), from (17), for (17), that (17), retrieved (13), this (11), file (11), loaded (11), extension (11), macos (10), memory (10), command (10), may (9), other (9), library (9), systems (9), boot (9), not (9), they (9), september (8), 2012 (8), device (8), archived (8), running (8), code (7), wikipedia (7), license (7), scheduler (7), user (7), only (7), original (7), netware (7), page (6), articles (6), drivers (6), proprietary (6), version (6), time (6), api (6), base (6), gpl (6), apple (6), 2011 (6), when (6), have (6), load (6), solaris (6), any (6), will (6), search (5), using (5), use (5), was (5), unsourced (5), statements (5), history (5), list (5), security (5), support (5), protection (5), extensions (5), developer (5), 2013 (5), also (5), which (5), loading (5), versions (5), needed (5), hide (5), different (5), toggle (4), contents (4), inc (4), short (4), link (4), real (4), initramfs (4), virtual (4), process (4), network (4), driver (4), new (4), abi (4), computer (4), general (4), space (4), windows (4), kext (4), such (4), binary (4), lkm (4), compatibility (4), unloaded (4), into (4), used (4), citation (4), functionality (4), move (4), sidebar (4), view (3), policy (3), non (3), foundation (3), pages (3), deprecated (3), links (3), org (3), playstation (3), switch (3), gnu (3), open (3), storage (3), virtualization (3), documentation (3), free (3), software (3), portal (3), read (3), interface (3), linus (3), torvalds (3), users (3), group (3), programming (3), live (3), loader (3), control (3), comparison (3), net (3), machine (3), being (3), module_license (3), section (3), microsoft (3), compatible (3), set (3), trusted (3), path (3), enabled (3), bundle (3), files (3), releases (3), has (3), automatically (3), called (3), then (3), lkms (3), most (3), example (3), without (3), within (3), means (3), problems (3), but (3), usr (3), downloadable (3), vxworks (3), once (3), linuxant (3), maintainers (3), menu (3), implementations (3), would (3), tools (3), main (3), add (2), languages (2), table (2), mobile (2), developers (2), contact (2), about (2), privacy (2), available (2), under (2), terms (2), organization (2), categories (2), displaying (2), descriptions (2), redirect (2), targets (2), via (2), cs1 (2), maint (2), archival (2), service (2), wayback (2), april (2), 2015 (2), 2007 (2), all (2), description (2), wikidata (2), kernels (2), darwin (2), source (2), robert (2), matthew (2), people (2), kld (2), bpf (2), altq (2), 802 (2), scheduling (2), ports (2), project (2), adopters (2), server (2), embedded (2), mode (2), less (2), computing (2), performance (2), mainline (2), variants (2), drm (2), components (2), standard (2), userspace (2), oops (2), criticism (2), architectures (2), concepts (2), fault (2), management (2), preemptive (2), thread (2), block (2), monolithic (2), object (2), just (2), distributed (2), kextload (2), 2016 (2), 2020 (2), disabling (2), cite (2), sysctl (2), txt (2), jonathan (2), corbet (2), 2004 (2), lwn (2), november (2), novell (2), tainted (2), guide (2), march (2), what (2), references (2), shared (2), see (2), elf (2), verified (2), signed (2), certificates (2), some (2), possible (2), feature (2), signing (2), disabled (2), root (2), property (2), however (2), executable (2), attempt (2), later (2), certificate (2), provided (2), part (2), specific (2), attacker (2), change (2), modifying (2), their (2), over (2), make (2), way (2), help (2), privilege (2), required (2), stable (2), thus (2), compiled (2), cause (2), those (2), versioning (2), data (2), information (2), before (2), start (2), always (2), unload (2), platform (2), name (2), dkm (2), nlm (2), nlms (2), inserted (2), lists (2), reside (2), listed (2), located (2), supplied (2), stored (2), directory (2), third (2), usually (2), null (2), its (2), controversy (2), bugs (2), likely (2), investigated (2), become (2), issues (2), grub (2), lib (2), minor (2), fragmented (2), penalty (2), more (2), tlb (2), filesystems (2), disadvantages (2), require (2), advantages (2), current (2), dynamically (2), extends (2), appearance (2), upload (2), changes (2), article (2), subsection (2), log (2), create (2), account (2), donate (2), topic, cookie, statement, statistics, conduct, legal, safety, contacts, disclaimers, text, additional, apply, site, you, agree, registered, trademark, profit, wikimedia, creative, commons, attribution, sharealike, rendered, parsoid, last, edited, 2025, utc, hidden, annotated, webarchive, template, february, 2024, matches, https, index, php, title, loadable_kernel_module, oldid, 1310102974, vita, openserver, nintendo, watchos, tvos, ios, junos, xigmanas, gentoo, kfreebsd, trueos, pfsense, opnsense, m0n0wall, midnightbsd, ghostbsd, freesbie, freenas, dragonfly, bsd, desktopbsd, xnu, chimera, derivatives, dru, lavigne, watson, diomidis, spinellis, marshall, kirk, mckusick, sam, leffler, ben, laurie, mike, karels, poul, henning, kamp, jordan, hubbard, dillon, systat, moused, kqueue, portsnap, openbsm, openpam, dtrace, busdma, sctp, pfsync, carp, ndis, netgraph, ipfw, ipfilter, bluetooth, networking, highly, zfs, vfs, soft, updates, ufs, fdisk, disklabel, vinum, lvm2, geli, gbde, raid5, geom, bhyve, jail, chroot, ule, subsystems, core, team, category, devices, lyme, lyce, lamp, thin, client, ltsp, gaming, desktop, range, adoption, colinux, mklinux, l4linux, openvz, lxc, lguest, vserver, level, xen, kvm, hypervisor, psxlinux, μclinux, mmu, preempt_rt, xenomai, rtai, rtlinux, slurm, compute, node, ink, high, libre, ksplice, kpatch, kgraft, kexec, kernelcare, raw, graphics, pam, tomoyo, smack, selinux, seccomp, exec, shield, apparmor, sched_rr, sched_fifo, sched_deadline, noop, eevdf, earliest, eligible, deadline, first, cfs, completely, fair, brain, fuck, schedulers, zswap, zram, slub, perf, nftables, netlink, netfilter, kms, lvm, framebuffer, lio, ksm, same, merging, evdev, edac, crypt, cache, mapper, bcache, console, cgroups, bluez, liburing, libusb, libevdev, libalsa, libdrm, libcgroup, newlib, musl, klibc, eglibc, dietlibc, libhybris, bionic, uclibc, glibc, wrapper, libraries, binfmt_misc, kmscon, udev, systemd, tmpfs, sysfs, sockfs, securityfs, procfs, pipefs, hugetlbfs, fuse, debugfs, devpts, devfs, configfs, bpffs, daemons, iio, video4linux, rcu, barrier, kernfs, io_uring, crypto, alsa, readahead, inotify, dnotify, splice, epoll, futex, sync, close, select, ioctl, posix, call, apis, x32, abis, initrd, dracut, map, vmlinux, startup, ebpf, systemtap, kdump, ftrace, criu, debugging, technical, chris, wright, harald, welte, stephen, tweedie, theodore, shuah, khan, rusty, russell, hans, reiser, andrew, morton, ingo, molnár, david, miller, love, greg, kroah, hartman, con, kolivas, avi, kivity, garrett, alan, cox, rémy, card, andries, brouwer, suparna, bhattacharya, moshe, bar, jens, axboe, peter, anvin, werner, almesberger, lug, conferences, lkml, supported, menuconfig, linaro, sco, disputes, tux, tanenbaum, debate, law, mark, institute, pxe, cli, shell, usb, hal, supporting, tape, partition, journal, inode, attribute, defragmentation, access, segmentation, ring, paging, bus, error, resource, shortest, job, next, round, robin, multilevel, feedback, queue, fixed, priority, algorithms, sharing, tcb, pcb, ipc, interrupt, context, cooperative, multitasking, unikernel, rump, vkernel, multikernel, microkernel, hybrid, exokernel, supercomputer, oriented, enough, hobbyist, disk, features, usage, share, timeline, forensic, engineering, manual, manager, info, plist, properties, august, mac, kees, cook, outflux, clean, web, january, exploiting, october, honest, 2006, tainting, administrator, tracing, compiling, determines, june, 2001, hewlett, packard, managing, developing, dynamicallyloadable, 2010, topics, introduction, 2021, alternatives, multiple, executables, runtime, readable, implementation, concept, dynamic, optionally, cryptographic, signature, depending, settings, enforce, cryptographically, held, outside, ilom, sparc, based, platforms, initiated, immutable, global, zone, older, osbundleallowuserload, true, including, owned, wheel, writable, fail, holds, particular, entitlement, request, given, members, default, instructs, stop, booting, unsigned, present, integrity, capitan, yosemite, allows, option, disable, makes, very, similar, proc, sys, modules_disabled, while, convenient, method, abused, attackers, compromised, prevent, detection, allowing, them, maintain, many, note, elevated, merely, easier, break, elevation, rootkits, processes, keep, relatively, avoiding, problem, against, work, recompilation, major, must, recompiled, maintained, branch, does, provide, there, differences, internal, structure, function, between, combat, symbol, placed, compared, incompatible, modinfo, configurable, defaults, subdirectories, considered, necessary, point, init, often, found, debug, build, actively, attempts, type, created, generate, out, unld, referred, removed, currently, valid, assigned, parties, various, directories, bundles, kextstat, installed, otherwise, booted, starts, either, through, hand, conf, kldstat, kldunload, kldload, packages, string, tried, determine, whether, gpled, stopped, reached, character, fooled, thinking, declaring, others, applies, consulting, company, attempted, abuse, visible, following, excerpt, terminator, taint, flag, meaning, experienced, effectively, corrupt, structures, produce, able, indeed, opinion, tolerate, distribution, allow, merge, tree, public, nvidia, gpu, derived, works, had, since, previous, emergency, cases, fails, due, broken, parameters, pressing, editing, parameter, line, lsmod, modprobe, one, preferring, modular, static, unpacked, contiguous, setup, routines, never, state, been, contain, insertion, thereby, introducing, entries, causing, misses, mounted, fragmentation, include, anticipated, directly, much, wasting, rebuild, reboot, every, names, although, party, dropped, known, klm, simply, kmod, aix, unix, like, capabilities, typically, adding, longer, order, resources, calls, hardware, encyclopedia, item, projects, printable, download, pdf, print, export, legacy, parser, get, shortened, url, permanent, related, here, actions, english, talk, українська, svenska, русский, português, ਪੰਜਾਬੀ, norsk, bokmål, 한국어, 日本語, bahasa, indonesia, עברית, français, suomi, فارسی, español, ελληνικά, deutsch, čeština, català, العربية, top, personal, special, recent, community, learn, contribute, random, events, navigation, jump, content,
Text of the page (random words):
to sidebar hide from wikipedia the free encyclopedia dynamically loadable module that extends a running operating system kernel a loadable kernel module lkm is an executable library that extends the capabilities of a running kernel or so called base kernel of an operating system lkms are typically used to add support for new hardware as device drivers and or filesystems or for adding system calls when the functionality provided by an lkm is no longer required it can be unloaded in order to free memory and other resources most current unix like systems and windows support loadable kernel modules but with different names such as kernel loadable module kld in freebsd kernel extension kext in macos although support for third party modules is being dropped 1 2 kernel extension module in aix dynamically loadable kernel module in hp ux 3 kernel mode driver in windows nt 4 and downloadable kernel module dkm in vxworks they are also known as kernel loadable module klm or simply as kernel module kmod advantages edit without loadable kernel modules an operating system would have to include all possible anticipated functionality compiled directly into the base kernel much of that functionality would reside in memory without being used wasting memory citation needed and would require that users rebuild and reboot the base kernel every time they require new functionality disadvantages edit one minor criticism of preferring a modular kernel over a static kernel is the so called fragmentation penalty the base kernel is always unpacked into real contiguous memory by its setup routines thus the base kernel code is never fragmented once the system is in a state in which modules may be inserted for example once the filesystems have been mounted that contain the modules it is likely that any new kernel code insertion will cause the kernel to become fragmented thereby introducing a minor performance penalty by using more tlb entries causing more tlb misses citation needed implementations in different operating systems edit linux edit loadable kernel modules in linux are loaded and unloaded by the modprobe command they are located in lib modules or usr lib modules and have had the extension ko kernel object since version 2 6 previous versions used the o extension 5 the lsmod command lists the loaded kernel modules in emergency cases when the system fails to boot due to e g broken modules specific modules can be enabled or disabled by modifying the kernel boot parameters list for example if using grub by pressing e in the grub start menu then editing the kernel parameter line license issues edit in the opinion of linux maintainers lkm are derived works of the kernel citation needed the linux maintainers tolerate the distribution of proprietary modules such as nvidia gpu drivers citation needed but allow only gnu general public license gpl modules to merge to kernel tree of mainline linux kernel loading a proprietary or non gpl compatible module will set a taint flag 6 7 in the running kernel meaning that any problems or bugs experienced will be less likely to be investigated by the maintainers 8 9 lkms effectively become part of the running kernel so can corrupt kernel data structures and produce bugs that may not be able to be investigated if the module is indeed proprietary linuxant controversy edit in 2004 linuxant a consulting company that releases proprietary device drivers as loadable kernel modules attempted to abuse a null terminator in their module_license as visible in the following code excerpt module_license gpl 0 for files in the gpl directory for others only license file applies the string comparison code used by the kernel at the time tried to determine whether the module was gpled stopped when it reached a null character 0 so it was fooled into thinking that the module was declaring its license to be just gpl 10 freebsd edit kernel modules for freebsd are stored within boot kernel for modules distributed with the operating system or usually boot modules for modules installed from freebsd ports or freebsd packages or for proprietary or otherwise binary only modules freebsd kernel modules usually have the extension ko once the machine has booted they may be loaded with the kldload command unloaded with kldunload and listed with kldstat modules can also be loaded from the loader before the kernel starts either automatically through boot loader conf or by hand macos edit some loadable kernel modules in macos can be loaded automatically loadable kernel modules can also be loaded by the kextload command they can be listed by the kextstat command loadable kernel modules are located in bundles with the extension kext modules supplied with the operating system are stored in the system library extensions directory modules supplied by third parties are in various other directories netware edit a netware kernel module is referred to as a netware loadable module nlm nlms are inserted into the netware kernel by means of the load command and removed by means of the unload command the modules command lists currently loaded kernel modules nlms may reside in any valid search path assigned on the netware server and they have nlm as the file name extension vxworks edit a downloadable kernel module dkm type project can be created to generate a out file which can then be loaded to kernel space using ld command this downloadable kernel module can be unloaded using unld command solaris edit solaris has a configurable kernel module load path which defaults to platform platform name kernel kernel usr kernel most kernel modules live in subdirectories under kernel those not considered necessary to boot the system to the point that init can start are often but not always found in usr kernel when running a debug kernel build the system actively attempts to unload modules binary compatibility edit linux does not provide a stable api or abi for kernel modules this means that there are differences in internal structure and function between different kernel versions which can cause compatibility problems in an attempt to combat those problems symbol versioning data is placed within the modinfo section of loadable elf modules this versioning information can be compared with that of the running kernel before loading a module if the versions are incompatible the module will not be loaded other operating systems such as solaris freebsd macos and windows keep the kernel api and abi relatively stable thus avoiding this problem for example freebsd kernel modules compiled against kernel version 6 0 will work without recompilation on any other freebsd 6 x version e g 6 4 however they are not compatible with other major versions and must be recompiled for use with freebsd 7 x as api and abi compatibility is maintained only within a branch security edit while loadable kernel modules are a convenient method of modifying the running kernel this can be abused by attackers on a compromised system to prevent detection of their processes or files allowing them to maintain control over the system many rootkits make use of lkms in this way note that on most operating systems modules do not help privilege elevation in any way as elevated privilege is required to load a lkm they merely make it easier for the attacker to hide the break in 11 linux edit linux allows disabling module loading via sysctl option proc sys kernel modules_disabled 12 13 an initramfs system may load specific modules needed for a machine at boot and then disable module loading this makes the security very similar to a monolithic kernel if an attacker can change the initramfs they can change the kernel binary macos edit in os x yosemite and later releases a kernel extension has to be code signed with a developer certificate that holds a particular entitlement such a developer certificate is only provided by apple on request and not automatically given to apple developer members this feature called kext signing is enabled by default and it instructs the kernel to stop booting if unsigned kernel extensions are present 14 in os x el capitan and later releases it is part of system integrity protection in older versions of macos or if kext signing is disabled a loadable kernel module in a kernel extension bundle can be loaded by non root users if the osbundleallowuserload property is set to true in the bundle s property list 15 however if any of the files in the bundle including the executable code file are not owned by root and group wheel or are writable by the group or other the attempt to load the kernel loadable module will fail 16 solaris edit kernel modules can optionally have a cryptographic signature elf section which is verified on load depending on the verified boot policy settings the kernel can enforce that modules are cryptographically signed by a set of trusted certificates the list of trusted certificates is held outside of the os in the ilom on some sparc based platforms userspace initiated kernel module loading is only possible from the trusted path when the system is running with the immutable global zone feature enabled see also edit dynamic link library microsoft s implementation of the shared library concept in windows and os 2 pages displaying short descriptions of redirect targets netware loadable module novell compatible computer readable software shared library software library in memory that multiple executables can use at runtime references edit deprecated kernel extensions and system extension alternatives apple inc retrieved 13 march 2021 kernel extension programming topics introduction apple inc september 1 2010 archived from the original on may 4 2013 retrieved may 5 2013 managing and developing dynamicallyloadable kernel modules hewlett packard june 7 2001 what determines when a driver is loaded microsoft developer network microsoft november 21 2012 archived from the original on march 6 2013 retrieved may 5 2013 the linux kernel module programming guide section 2 2 compiling kernel modules retrieved 2020 10 05 linus torvalds et al 2011 06 21 documentation oops tracing txt kernel org archived from the original on 2011 10 02 retrieved 2011 10 03 tainted kernels the linux kernel user s and administrator s guide jonathan corbet 2006 03 24 tainting from user space lwn net archived from the original on 2011 11 16 retrieved 2011 10 03 novell support documentation tainted kernel 2007 07 26 retrieved 2011 10 03 jonathan corbet april 27 2004 being honest with module_license lwn net archived from the original on november 2 2012 retrieved october 30 2012 exploiting loadable kernel modules archived 2012 02 04 at the wayback machine sysctl kernel txt retrieved january 4 2013 cite web cs1 maint deprecated archival service link kees cook 2012 11 28 clean module disabling outflux net retrieved 2020 10 05 kernel extensions mac developer library apple september 16 2015 archived from the original on august 17 2016 retrieved september 29 2016 info plist properties for kernel extensions apple inc archived from the original on september 26 2012 retrieved september 27 2012 kextload 8 darwin and macos system manager s manual v t e operating systems general comparison forensic engineering history list timeline usage share user features comparison variants disk operating system distributed operating system embedded operating system hobbyist operating system just enough operating system mobile operating system network operating system object oriented operating system real time operating system supercomputer operating system kernel architectures exokernel hybrid microkernel monolithic multikernel vkernel rump kernel unikernel components device driver loadable kernel module user space and kernel space process management concepts computer multitasking cooperative preemptive context switch interrupt ipc process process control block pcb real time thread thread control block tcb time sharing scheduling algorithms fixed priority preemptive multilevel feedback queue round robin shortest job next memory management resource protection bus error general protection fault memory paging memory protection protection ring segmentation fault virtual memory storage access file systems boot loader defragmentation device file file attribute inode journal partition virtual file system virtual tape library supporting concepts api computer network hal live cd live usb shell cli user interface pxe v t e linux kernel organization kernel linux foundation linux mark institute linus s law tanenbaum torvalds debate tux sco disputes linaro gnu gpl v2 menuconfig supported computer architectures version history criticism support developers the linux programming interface kernel org lkml linux conferences users linux user group lug people werner almesberger h peter anvin jens axboe moshe bar suparna bhattacharya andries brouwer rémy card alan cox matthew garrett avi kivity con kolivas greg kroah hartman robert love david s miller ingo molnár andrew morton hans reiser rusty russell shuah khan linus torvalds theodore ts o stephen tweedie harald welte chris wright technical debugging criu ftrace kdump linux kernel oops systemtap bpf ebpf startup vmlinux system map dracut initrd initramfs abis linux standard base x32 abi apis kernel system call interface posix ioctl select open read close sync linux only futex epoll splice dnotify inotify readahead in kernel alsa crypto api io_uring drm kernfs memory barrier new api rcu video4linux iio userspace daemons file systems bpffs configfs devfs devpts debugfs fuse hugetlbfs pipefs procfs securityfs sockfs sysfs tmpfs systemd udev kmscon binfmt_misc wrapper libraries c standard library glibc uclibc bionic libhybris dietlibc eglibc klibc musl newlib libcgroup libdrm libalsa libevdev libusb liburing components kernel modules bluez cgroups console bcache device mapper dm cache dm crypt drm edac evdev kernel same page merging ksm lio framebuffer lvm kms driver netfilter netlink nftables network scheduler perf slub zram zswap process and i o schedulers brain fuck scheduler completely fair scheduler cfs earliest eligible virtual deadline first eevdf noop scheduler o n scheduler o 1 scheduler sched_deadline sched_fifo sched_rr security modules apparmor exec shield seccomp selinux smack tomoyo linux linux pam device drivers 802 11 graphics raw device initramfs kernelcare kexec kgraft kpatch ksplice variants mainline linux kernel linux libre high performance computing ink compute node linux slurm real time computing rtlinux rtai xenomai preempt_rt mmu less μclinux psxlinux virtualization hypervisor kvm xen os level virtualization linux vserver lguest lxc openvz other l4linux user mode linux mklinux colinux adoption range of use desktop embedded gaming thin client ltsp server lamp lyme lyce devices adopters list of linux adopters linux portal free and open source software portal category v t e the freebsd project freebsd freebsd core team freebsd documentation license freebsd foundation freebsd ports ver...
|