X & securelevel=3

From: bofn (bofn_at_irq.org)
Date: 05/29/04


To: freebsd-security@freebsd.org
Date: Sat, 29 May 2004 05:43:23 +0200


running (4-Stable)

Hi,

short form question:
 how does one run XDM under securelevel>0 ?

long version:
i've searched for an answer on how to run Xfree/Xorg at a securelevel
the X server likes access to /dev/io and some other resources but is not
granted access after security is switched on.
one way of doing it seems to be to start it before setting the securelevel, but
then is doesnt allow a restart of X.
the other option seems to be the Aperture patch, ported in 2001 with no recent
updates and no longer usable against the current software.

2nd part of the question..
cd writing needs direct access to /dev/<acd0c> and that is also not allowed in
secure more.
how can one give selective access to only allow (RW) access to one or two
devices ?

if there is no way of doing these things with configs and such, can anyone
point me at the relevant source code that controls these functions so i can add
this specific functionality.

Cheers
* Anna

_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"



Relevant Pages

  • Re: X & securelevel=3
    ... > short form question: ... > i've searched for an answer on how to run Xfree/Xorg at a securelevel ... > granted access after security is switched on. ... to be a magic bullet for security. ...
    (FreeBSD-Security)
  • Re: Running X in securelevels > 0 ?
    ... But the problem is that the securelevel is not ... In this situation xdm is your friend. ... manually set the securelevel in rc.local after xdm has started. ... which BTW will leave you open to memory leaks in the X server. ...
    (FreeBSD-Security)
  • Re: Xdm & Securelevels revisited
    ... >> securelevel is raised before xdm can start which causes fireworks. ... can drop to single user and disable xdm. ...
    (freebsd-questions)
  • Re: Xorg & xdm & securelevels
    ... > booting at securelevel 0 and have the securelevel raised afterwards, ... about authentication methods, but it's certainly ... method and enabling xdm from ttysshould do it. ...
    (freebsd-questions)
  • Re: Xdm & Securelevels revisited
    ... > securelevel is raised before xdm can start which causes fireworks. ... if you raise the securelevel after xdm has started and it ...
    (freebsd-questions)