Re: GGI and cli/sti in X

Alan Cox (alan@lxorguk.ukuu.org.uk)
Sun, 29 Mar 1998 16:05:05 +0100 (BST)


> In that kind of secure environment the only thing having the "iopl"
> capability would be the X graphics setup binary, and nothing would have
> the capability to add any new "set-capabilities" (actually, even that
> should probably be a bitmask - the bitmask of which capabilities you can
> add to programs).

Thats still fairly awkward and unacceptable to many people. On the other
hand I still don't see it is a problem. If you choose to run a high security
system you are already making definite sacrifices in some areas. A slightly
slower Xserver using fbcon is hardly unreasonable in this case. You get X
you get 'safe' X, it doesn't play Doom quite as fast. Big deal.

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu