Re: [RFC] enhancing the kernel's graphics subsystem

From: Dave Airlie
Date: Tue May 22 2007 - 04:28:00 EST


> Did I say the X server? There are policy decisions that are root only
> also authorisation of processes to render etc..

Root only today, maybe, but this thread is talking about future
directions. Don't lock your design into a coarse-grained security model.


We can add a new capability bit but there are certain operations that
need privs especially if multiple users are involved. binding outputs
to crtcs being one.

Again I can see little reason that this wouldn't be possible going
forward. But i'm seeing policy decisions we currently make in the X
server needing to be made somewhere.

Dave.


> I'm not sure we can punt all that in-kernel.

See my response to Alan.

Jeff




-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/