From: Jon Smirl <jonsmirl@gmail.com>
To: linux-hotplug@vger.kernel.org
Subject: Re: udev and sysfs permissions
Date: Fri, 20 May 2005 21:11:01 +0000 [thread overview]
Message-ID: <9e47339105052014113b1af7f8@mail.gmail.com> (raw)
In-Reply-To: <9e47339105051915025188e535@mail.gmail.com>
On 5/20/05, Greg KH <greg@kroah.com> wrote:
> On Fri, May 20, 2005 at 10:06:24AM -0400, Jon Smirl wrote:
> > On 5/20/05, Greg KH <greg@kroah.com> wrote:
> > > Nope, the kernel is. You must have provided enough memory pressure to
> > > push the file out of the dcache, and then when you went to look at it
> > > again, it was created on the fly from scratch again, with the proper
> > > permissions (as the kernel thinks the files have.) Nice to see it's all
> > > working properly :)
> > >
> > > > Can udev control sysfs permissions (I though it only controlled the
> > > > device permissions).
> > >
> > > No, only the kernel can control sysfs permissions.
> >
> > We were planning on having PAM assign ownership of the video device
> > and sysfs attributes to the logged in user.
>
> video device, fine. sysfs attributes, no.
>
> > I need read/write access to the sysfs attributes but it need to be
> > restricted to whoever owns the device.
>
> Ick. what kind of attributes do you want the logged in user to be able
> to change?
After everyone complained that IOCTLs were so evil and that sysfs
attributes were the way to go, I added a bunch of attributes for
controlling the framebuffer device. Load a fbdev driver and look in
/sys/class/graphics/fb0.
[jonsmirl@jonsmirl fb0]$ ls
bits_per_pixel color_map cursor device modes virtual_size
blank console dev mode pan
[jonsmirl@jonsmirl fb0]$
You can change the mode, cursor position, screen size, pan, etc by
writing to sysfs attributes. These attributes need to only be writable
only by the person who owns the device.
If I can't control permissions on these attributes I'll just get rid
of them all and go back to IOCTLs.
The whole point of this design was to remove the need for the Xserver
to run as root. The server instead runs as a process of the logged in
user.
>
> > What's the right way to implement this?
>
> we do have a function to change the mode of the file on the fly, but in
> general, I think you might need to just write a small helper program to
> mediate access properly.
>
> Good luck,
>
> greg k-h
>
--
Jon Smirl
jonsmirl@gmail.com
-------------------------------------------------------
This SF.Net email is sponsored by Oracle Space Sweepstakes
Want to be the first software developer in space?
Enter now for the Oracle Space Sweepstakes!
http://ads.osdn.com/?ad_idt12&alloc_id\x16344&opÌk
_______________________________________________
Linux-hotplug-devel mailing list http://linux-hotplug.sourceforge.net
Linux-hotplug-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/linux-hotplug-devel
next prev parent reply other threads:[~2005-05-20 21:11 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-05-19 22:02 udev and sysfs permissions Jon Smirl
2005-05-19 22:10 ` Kay Sievers
2005-05-20 4:33 ` Greg KH
2005-05-20 14:06 ` Jon Smirl
2005-05-20 18:33 ` Greg KH
2005-05-20 21:11 ` Jon Smirl [this message]
2005-05-20 21:26 ` Jon Smirl
2005-05-20 21:27 ` Greg KH
2005-05-20 21:40 ` Jon Smirl
2005-05-20 21:40 ` Greg KH
2005-05-20 21:41 ` Jon Smirl
2005-05-20 21:53 ` Jon Smirl
2005-05-20 21:54 ` Greg KH
2005-05-20 21:56 ` Greg KH
2005-05-20 22:07 ` Kay Sievers
2005-05-20 22:09 ` Greg KH
2005-05-26 23:09 ` Greg KH
2005-05-27 12:44 ` Maneesh Soni
2005-05-27 16:39 ` Jon Smirl
2005-05-27 21:51 ` Greg KH
2005-05-28 5:06 ` maneesh
2005-05-28 5:08 ` maneesh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=9e47339105052014113b1af7f8@mail.gmail.com \
--to=jonsmirl@gmail.com \
--cc=linux-hotplug@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).