[IOPL] >>The problem is: X windows needs these calls, so if you forbid them in >>secure mode then bye bye X.
Is there any technical reason why we can't have the full 8k I/O permission
bitmap? Can't we allocate them only when the process first calls ioperm()
and saves the 2k for each process instead?