Re: [RFC] enhancing the kernel's graphics subsystem

From: Jeff Garzik
Date: Mon May 21 2007 - 19:21:37 EST


Dave Airlie wrote:
3) Eliminate the need for a root priv controlling process. Get rid of
the potential for a security hole.

Stupid idea, we need something to control policy, this isn't going in
the kernel, it can be a lot smaller than X and auditable.. sticking
the DRI protocol in the kernel is just pointless..

It is a quite sensible idea.

The userspace X server SHOULD be running under a non-root user, with appropriate fine-grained privs granted to it.

"I need root to do graphics" is a myopic, antiquated view of the world.

Jeff


-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/