mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Alan Cox <alan@lxorguk.ukuu.org.uk>
To: Theodore Tso <tytso@mit.edu>
Cc: Kasper Sandberg <lkml@metanurb.dk>,
	Matthew Garrett <mjg59@srcf.ucam.org>, Jan Dittmer <jdi@l4x.org>,
	Pavel Machek <pavel@suse.cz>, Jirka Lenost Benc <jbenc@suse.cz>,
	kernel list <linux-kernel@vger.kernel.org>,
	ipw2100-admin@linux.intel.com
Subject: Re: ipw3945 status
Date: Sun, 30 Jul 2006 18:52:38 +0100	[thread overview]
Message-ID: <1154281958.1615.16.camel@localhost.localdomain> (raw)
In-Reply-To: <20060730145305.GE23279@thunk.org>

Ar Sul, 2006-07-30 am 10:53 -0400, ysgrifennodd Theodore Tso:
> Personally, I don't see why the requirement of an external daemon is
> really considered that evil.  We allow drivers that depend on firmware

An open source daemon doing the supervising seems fine. We do that for
IPv4 even (dhcpd, dhcpcd, routed, gated, zebra, ....) ;)

> loaders, don't we?  I could imagine a device that required a digitally
> signed message (using RSA) with a challenge/response protocol embedded
> inside that was necessary to configure said device, which is
> calculated in userspace and then passed down into the kernel to be
> installed into the device so that it could function.  Do we really
> want to consider that to be objectionable?

If it controls the use of the device inappropriately then yes we should.
Suppose it passes down an RSA signed message that is computed by
verifying you are running a Red Hat Enterprise Linux 4 official shipped
kernel on an approved IBM platform and things like that - that would
annoy me.

Using GPG keys to verify code matches approved code is fine. The ISDN
layer has done this for many years and if its not the signed code
version it didn't have the old silly approvals stuff (Fortunately
nowdays even politicians have realised that if you need approval for
something to stop it doing bad stuff to the phone network then bad
people can do bad stuff anyway and this is bad for national security)

I think from a vendor perspective being able to ship a source set for
such a daemon which Intel has signed as "this source meets the rules" is
great. As an end user I want the flexibility to do other stuff except
where prohibited by law (not by Intel, not by paranoid lawyers and not
by FCC lack of clarity)

I also want to violate the power and other policy rules Intel wishes to
enforce on their hardware for legal and legitimate reasons. As a radio
amateur I am permitted in law to transmit certain classes of signals in
that frequency space at higher power than in the hands of a random UK
user of license exempt technology.

Alan


  parent reply	other threads:[~2006-07-30 17:34 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-07-30 10:40 Pavel Machek
2006-07-30 11:28 ` Matthew Garrett
2006-07-30 11:30   ` Pavel Machek
2006-07-30 11:34   ` Jan Dittmer
2006-07-30 11:47     ` Matthew Garrett
2006-07-30 13:01       ` Kasper Sandberg
2006-07-30 14:53         ` Theodore Tso
2006-07-30 15:00           ` Kasper Sandberg
2006-07-30 15:09             ` Theodore Tso
2006-07-30 16:09               ` Kasper Sandberg
2006-07-30 16:25           ` Jan Dittmer
2006-07-30 16:32             ` Matthew Garrett
2006-07-30 17:52           ` Alan Cox [this message]
2006-07-30 23:12           ` Pavel Machek
2006-07-31  0:23             ` Alistair John Strachan
2006-07-31  1:16               ` Kasper Sandberg
2006-07-31  6:06                 ` Alon Bar-Lev
2006-07-31  8:32                   ` Kasper Sandberg
2006-07-30 16:58         ` James Courtier-Dutton
2006-07-30 17:25           ` Kasper Sandberg
2006-07-30 17:37             ` Rene Rebe
2006-07-30 18:03               ` Kasper Sandberg
2006-07-30 20:09                 ` Rene Rebe
2006-07-30 21:02                   ` Kasper Sandberg
2006-07-30 23:44                     ` Alan Cox
2006-07-31  0:19                       ` Kasper Sandberg
2006-07-31  7:11                         ` Rene Rebe
2006-07-30 15:57   ` Tomasz Torcz
2006-07-30 16:01     ` Matthew Garrett

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1154281958.1615.16.camel@localhost.localdomain \
    --to=alan@lxorguk.ukuu.org.uk \
    --cc=ipw2100-admin@linux.intel.com \
    --cc=jbenc@suse.cz \
    --cc=jdi@l4x.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lkml@metanurb.dk \
    --cc=mjg59@srcf.ucam.org \
    --cc=pavel@suse.cz \
    --cc=tytso@mit.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome