Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1754201AbYKPQUJ (ORCPT ); Sun, 16 Nov 2008 11:20:09 -0500 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1753422AbYKPQTz (ORCPT ); Sun, 16 Nov 2008 11:19:55 -0500 Received: from mail.suse.de ([195.135.220.2]:48430 "EHLO mx1.suse.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750988AbYKPQTy (ORCPT ); Sun, 16 Nov 2008 11:19:54 -0500 Date: Sun, 16 Nov 2008 17:19:52 +0100 From: Bernhard Walle To: Arjan van de Ven Cc: Alan Cox , x86@kernel.org, linux-kernel@vger.kernel.org, linux-arch@vger.kernel.org, crash-utility@redhat.com Subject: Re: Turn CONFIG_STRICT_DEVMEM in sysctl dev.mem.restricted Message-ID: <20081116171952.632947a7@kopernikus.site> In-Reply-To: <20081116080342.3d6c6976@infradead.org> References: <1226846868-9595-1-git-send-email-bwalle@suse.de> <20081116150756.3cece2de@lxorguk.ukuu.org.uk> <20081116162003.04267538@kopernikus.site> <20081116154541.1f196f1e@lxorguk.ukuu.org.uk> <20081116080342.3d6c6976@infradead.org> Organization: SUSE Linux Products GmbH X-Mailer: Claws Mail 3.6.1 (GTK+ 2.14.4; i686-pc-linux-gnu) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 877 Lines: 23 * Arjan van de Ven [2008-11-16 08:03]: > > the point of the /dev/mem restrictions is to not allow things you know > you don't need, while still allowing X to function where it can access > the crap it does. Now in Bernhard's case he DOES need them, so he > shouldn't use the restrictions. Right. But shipping two kernel images is a bit too much to turn a restriction on or off. Get away from that "recompile your kernel". But I get more and more convinced that we really want to just turn that configuration option off. I'm no expert in security, and at some point, I just have to believe what people write. Regards, Bernhard -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/