From: Brian Swetland <swetland@google.com>
To: Kay Sievers <kay.sievers@vrfy.org>
Cc: Greg KH <greg@kroah.com>,
Andrew Morton <akpm@linux-foundation.org>,
linux-kernel <linux-kernel@vger.kernel.org>,
Jan Blunck <jblunck@suse.de>
Subject: Re: [PATCH] driver-core: devtmpfs - driver core maintained /dev tmpfs
Date: Fri, 1 May 2009 19:02:41 -0700 [thread overview]
Message-ID: <a55d774e0905011902y1827322ascd7d2eb42570d1dc@mail.gmail.com> (raw)
In-Reply-To: <ac3eb2510905011848i51aef8e6wbe9506a13e67377d@mail.gmail.com>
On Fri, May 1, 2009 at 6:48 PM, Kay Sievers <kay.sievers@vrfy.org> wrote:
> On Sat, May 2, 2009 at 03:24, Brian Swetland <swetland@google.com> wrote:
>> It's always struck me as odd that sysfs couldn't provide device node
>> access, given that there's already an entity exposed for everything
>> (or nearly everything).
>
> You really want to be able to run grep-like stuff in sysfs, which
> would do horrible things with device nodes. Also it does not support
> extended attributes, not access control lists, ..., all stuff we need
> for device nodes. You also want userspace to have control over device
> nodes, and possibly mangle them, regardless what the kernel exports,
> that's why it's a tmpfs and not part of sysfs.
That makes sense.
>> It seems weird to have to have an agent in
>> userspace to create another hierarchy in addition to what the kernel
>> already maintains.
>
> Well, until just recently, there was no sane definition how device
> nodes are names and layouted, every system did it differently, some
> even tried to keep the totally useless devfs naming scheme alive. Now
> that we managed to define a common default setup, which almost
> everybody ships it, it makes it possible to add the few needed rules.
That's good news -- I wasn't sure if there was still variety in layout
policies that required somehow supporting multiple different ones.
>> I guess the really tricky bit is how to deal with
>> permissions/ownership sanely.
>
> Simple permissions would be possible without too much hassle, but uid
> gid ownership, I can't see how the kernel could do that.
Yeah, I don't see any easy solution there. Which means we end up
having to have some userspace agent responsible for arranging
permissions as devices are published.
>> I suspect there's no easy way to do
>> something that "just works" for even the majority of userspace
>> environments.
>
> It will work just fine for root environments, what's missing without
> userspace support is if you need to grant specific users access to
> devices.
>
>> Most of the ugly in the microudev thing in our init
>> comes from having to do something about permissions.
>>
>> I would love to have a way for the kernel to do something like devfs
>> (it'd let me kill some ugly userspace code on my side)....
>
> How are permissions defined in your environment? What's the set of
> permissions you need to apply?
In our world we use groups to provide access to specific classes of
hardware resources (audio, video, display, dsp, etc) and processes
that have the appropriate permissions are arranged to run with
necessary additional groups for the hardware they need to access.
Very little of the system ever runs as root -- most runs as a per-app
or per-service untrusted user with permissions granted via group
membership.
Brian
next prev parent reply other threads:[~2009-05-02 2:02 UTC|newest]
Thread overview: 79+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-04-30 13:23 Kay Sievers
2009-05-01 5:29 ` Andrew Morton
2009-05-01 6:17 ` Greg KH
2009-05-01 6:43 ` Andrew Morton
2009-05-01 6:55 ` Greg KH
2009-05-01 7:03 ` Andrew Morton
2009-05-01 10:52 ` Kay Sievers
2009-05-01 11:38 ` Michael Tokarev
2009-05-01 11:44 ` Kay Sievers
2009-05-01 11:03 ` Alan Cox
2009-05-01 11:11 ` Kay Sievers
2009-05-01 13:18 ` Alan Cox
2009-05-01 13:24 ` Kay Sievers
2009-05-02 7:19 ` Christoph Hellwig
2009-05-02 13:46 ` Kay Sievers
2009-05-02 15:18 ` Andy Lutomirski
2009-05-02 15:35 ` Kay Sievers
2009-05-02 18:20 ` Michael Riepe
2009-05-02 19:55 ` Alan Jenkins
2009-05-02 21:47 ` Kay Sievers
2009-05-04 16:20 ` Lars Marowsky-Bree
2009-05-04 16:53 ` Kay Sievers
2009-05-04 17:54 ` Michael Riepe
2009-05-04 18:13 ` Kay Sievers
2009-05-04 18:55 ` Michael Riepe
2009-05-04 19:13 ` Kay Sievers
2009-05-04 19:30 ` Greg KH
2009-05-02 1:24 ` Brian Swetland
2009-05-02 1:48 ` Kay Sievers
2009-05-02 2:02 ` Brian Swetland [this message]
2009-05-02 2:28 ` Kay Sievers
2009-05-02 4:42 ` Brian Swetland
2009-05-02 13:30 ` Kay Sievers
2009-05-01 11:01 ` Alan Cox
2009-05-01 11:02 ` Kay Sievers
2009-05-01 11:16 ` Kay Sievers
2009-05-01 19:26 ` Andrew Morton
2009-05-01 21:59 ` Kay Sievers
2009-05-01 22:21 ` Andrew Morton
2009-05-01 6:57 ` Chris Wedgwood
2009-05-01 14:01 ` Greg KH
2009-05-01 15:43 ` Alan Jenkins
2009-05-01 16:04 ` Greg KH
2009-05-01 21:13 ` Alan Jenkins
2009-05-01 15:53 ` Chris Wedgwood
2009-05-01 16:09 ` Greg KH
2009-05-01 16:17 ` Chris Wedgwood
2009-05-01 10:19 ` Alan Jenkins
2009-05-01 11:13 ` Kay Sievers
2009-05-01 12:38 ` Alan Jenkins
2009-05-01 13:12 ` Alan Cox
2009-05-02 15:03 ` Kyle Moffett
2009-05-01 14:55 ` Kay Sievers
2009-05-01 11:41 ` Hugh Dickins
2009-05-01 11:59 ` Kay Sievers
2009-05-02 7:16 ` Christoph Hellwig
2009-05-02 11:34 ` Kay Sievers
2009-05-02 20:22 ` Alan Jenkins
2009-05-02 21:39 ` Kay Sievers
2009-05-02 22:04 ` Alan Jenkins
2009-05-03 7:29 ` Michael Tokarev
2009-05-02 21:41 ` Alan Jenkins
2009-05-02 21:54 ` Greg KH
2009-05-02 21:59 ` Kay Sievers
2009-05-02 16:59 ` Jeff Garzik
2009-05-02 17:57 ` Kay Sievers
2009-05-06 12:56 ` Kay Sievers
2009-05-07 1:41 ` Arjan van de Ven
2009-05-07 2:08 ` Kay Sievers
2009-05-07 2:25 ` Arjan van de Ven
2009-05-07 2:40 ` Kay Sievers
2009-05-14 9:28 ` Pavel Machek
2009-05-07 8:17 ` Eric W. Biederman
2009-05-07 9:28 ` Kay Sievers
2009-05-07 14:43 ` Theodore Tso
2009-05-07 15:13 ` Kay Sievers
2009-05-10 0:29 ` Eric W. Biederman
2009-05-10 0:56 ` Kay Sievers
2009-05-10 2:11 ` Eric W. Biederman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a55d774e0905011902y1827322ascd7d2eb42570d1dc@mail.gmail.com \
--to=swetland@google.com \
--cc=akpm@linux-foundation.org \
--cc=greg@kroah.com \
--cc=jblunck@suse.de \
--cc=kay.sievers@vrfy.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®