Re: PUBLIC CHALLENGE: (was RE: devfs again, (was RE: USB device a lloc ation) )

Horst von Brand (vonbrand@inf.utfsm.cl)
Fri, 08 Oct 1999 08:41:53 -0400


Shawn Leas <SLEAS@videoupdate.com> said:
> From: Horst von Brand [mailto:vonbrand@inf.utfsm.cl]
> >BTW,
> >the entries there allow you to mount _iff_ you have permissions on the
> >devices themselves. The permission bits are the systems' last (only?) line
> >of defense against miscreants; permissions of devices are extremely
> >critical, much more so than even the most critical normal files. Fooling
> >around with this if there is no *extremely* good reason is out. Needless to
> >say, I've seen only rather weak reasons for some scheme like devfs.

> So why not simply let the driver decide upon it's nodes' permissions?

Ever heard about policy vs mechanism?

If I want to allow all users/some users to access the floppy drive, I have
to recompile the kernel?? Or at least reboot? If you want that, you know
where you can find systems that can't be reconfigured in trivial ways
without rebooting.

> >> The use of a config file to determine permissions/ownership is not >
> >> foreign to the kernel or filesystems.

> >Name one use of configuration files for local permissions/ownership on
> >Unix/Linux.

> This is a straw man argument. You take an easy target, knock it down,
> and it really doesn't mean anything, but you claim victory. Shame.

You claimed the above, I ask where this is done, and now I'm fighting
strawmen set up by me?!

-- 
Dr. Horst H. von Brand                       mailto:vonbrand@inf.utfsm.cl
Departamento de Informatica                     Fono: +56 32 654431
Universidad Tecnica Federico Santa Maria              +56 32 654239
Casilla 110-V, Valparaiso, Chile                Fax:  +56 32 797513

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/