linux-hotplug.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Christer Palm <palm@nogui.se>
To: linux-hotplug@vger.kernel.org
Subject: Re: [Xpert]Re: User-level Tasks in Hotplug Scripts?
Date: Sun, 03 Feb 2002 19:59:51 +0000	[thread overview]
Message-ID: <marc-linux-hotplug-101276645818023@msgid-missing> (raw)
In-Reply-To: <marc-linux-hotplug-101272582331992@msgid-missing>

Jim Gettys wrote:

> 
> We need a secure, interoperable way for configuration scripts running
> as root to pop up configuration GUI's on user's servers, and we need it soon
> (yesterday), as hot-plug is now a reality on Linux systems....
> 
> Handling this for the local case is first priority, but we should give some
> thought about the possibility that the administrator's display is somewhere
> else in the network (e.g. we're configuring a server system's hotplug event,
> so the admin is elsewhere).
> 


Is this really what "we" need?
Having stuff "pop up" when certain event occur is probably very nice in 
many situations, but there are good reasons to why this kind of stuff 
only happens in the windoze world. You need to, for example, ask 
yourself the following questions:

   Who is the "administrator"?
   What if there is no "administrator" logged in?
   What if there's several "administrators" logged in?
   How to you distinguish interactive from non-interactive 
"administrator" logins?

  How do you even know if the "administrator" is running X?

   What happens if the "administrator" isn't running X?
   How do authenticate with the "administators" display?
   How do you know if the "administrators" X session is secure?
   If it isn't, is it still appropriate to pop up a configuration GUI on 
the "administrators" display?

IMHO, interactive configuration needs to be explicitly invoked by the 
administrator whether or not we're talking about configuring 
hot-pluggable devices. Any configuration taking place when a hot-plug 
device becomes available needs to be non-interactive and should be 
limited to picking up a configuration prepared on beforehand or a 
default (secure) minimum configuration.

The way the current pcmcia configuration takes place is, IMHO, The right 
way.

By the way, please don't cross-post excessively like this...

-- 
Christer Palm


_______________________________________________
Linux-hotplug-devel mailing list  http://linux-hotplug.sourceforge.net
Linux-hotplug-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/linux-hotplug-devel

  parent reply	other threads:[~2002-02-03 19:59 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-02-03  8:43 [Xpert]Re: User-level Tasks in Hotplug Scripts? Dr Andrew C Aitchison
2002-02-03 17:43 ` Owen Taylor
2002-02-03 19:06 ` Jim Gettys
2002-02-03 19:59 ` Christer Palm [this message]
2002-02-03 20:46 ` David Brownell
2002-02-03 21:13 ` David Brownell
2002-02-03 23:49 ` Christer Palm
2002-02-04  5:57 ` Owen Taylor
2002-02-04 15:15 ` Vladimir Dergachev
2002-02-04 23:17 ` Oliver Neukum
2002-02-05  1:22 ` Christer Palm
2002-02-05  1:54 ` David Brownell
2002-02-05  2:14 ` Christer Palm
2002-02-05  2:41 ` David Brownell
2002-02-05  4:49 ` Vladimir Dergachev
2002-02-05  7:53 ` Oliver Neukum
2002-02-05  8:47 ` Dr Andrew C Aitchison
2002-02-05  8:56 ` Oliver Neukum
2002-02-05 11:21 ` Christer Palm
2002-02-05 11:35 ` Oliver.Neukum
2002-02-05 15:19 ` Jim Gettys
2002-02-05 18:37 ` Jim Carter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=marc-linux-hotplug-101276645818023@msgid-missing \
    --to=palm@nogui.se \
    --cc=linux-hotplug@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).