[Bug 231171] New: xorg.conf is set up witto restrictive rights on DRI access
https://bugzilla.novell.com/show_bug.cgi?id=231171 Summary: xorg.conf is set up witto restrictive rights on DRI access Product: openSUSE 10.2 Version: Final Platform: i586 OS/Version: Linux Status: NEW Severity: Major Priority: P5 - None Component: X.Org AssignedTo: sndirsch@novell.com ReportedBy: birger.kollstrand@linar.no QAContact: sndirsch@novell.com In the xorg.conf : Section "DRI" Group "video" Mode 0660 EndSection This is ok with local users. The users are included in the group "video" automatically. When you have users authenticated wia an external mechanism like LDAP, then the users are not part of the video group automatically. This leads to problems for the users when they than need to use 3D graphics, My suggestion is that the limitation should either be - removed, - losened up (0666) - LDAP and SAMBA authentication automatically generates a new group and updates the xorg.conf file with this group in stead. (video_ldap?) This problems leads to frustration and troubleshooting in networks where theuser is not authenticated locally. Regards Birger -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 sndirsch@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |mhopf@novell.com, ms@novell.com, | |sndirsch@novell.com AssignedTo|sndirsch@novell.com |security-team@suse.de Component|X.Org |Security QAContact|sndirsch@novell.com |qa@suse.de ------- Comment #1 from sndirsch@novell.com 2006-12-30 10:12 MST ------- This is a security issue. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 ------- Comment #2 from sndirsch@novell.com 2006-12-30 10:21 MST ------- I remember that we tried to add /dev/dri to /etc/logindevperm in the past, but this was a bad idea since that means that all processes, which access this device are killed when the user's session is terminated. Unfortunately this is also the Xserver, which resulted in undefined behaviour after the first user logged out, mostly machine freezes. :-( BTW, /etc/logindevperm no longer exists. Don't know how in which way it has been replaced. The same problematic applies to /dev/nvidia*. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 ------- Comment #3 from meissner@novell.com 2007-01-05 08:04 MST ------- perhaps a resmgr ACL style solution might come in handy. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 ------- Comment #4 from sndirsch@novell.com 2007-01-05 08:10 MST ------- Maybe, but I don't know anything about it. So any help/suggestion would be appreciated. :-) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 ------- Comment #5 from mhopf@novell.com 2007-01-05 11:11 MST ------- I guess the login manager would have to set the device rights / acls. On server startup time the allowed user is only known if the user started the xserver himself (no login manager). Ok, how should that be done? Using resmgr? Natively? Device owner or ACLs? Where to configure the needed devices? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 meissner@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |security-team@suse.de AssignedTo|security-team@suse.de |lnussel@novell.com ------- Comment #6 from meissner@novell.com 2007-01-09 05:45 MST ------- ludwig can help here. he will be back thursday. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 lnussel@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|lnussel@novell.com |dkukawka@novell.com ------- Comment #7 from lnussel@novell.com 2007-01-11 02:35 MST ------- Hal needs to know about those devices first if you want to trigger permission changes upon user login. For that the devices need to properly appear in /sys, I don't know if that is the case already. Reassigning to hal maintainer. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 sndirsch@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |lnussel@novell.com ------- Comment #8 from sndirsch@novell.com 2007-01-11 02:51 MST ------- I Hope it's ok for you remaining in Cc, Ludwig. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 dkukawka@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |NEEDINFO Info Provider| |birger.kollstrand@googlemail.com ------- Comment #9 from dkukawka@novell.com 2007-01-11 03:22 MST ------- Please provide output of lshal and also the output of hald (in /var/log/messages) started with: --daemon=yes --verbose=yes --use-syslog @sndirsch: Is there a respondig device in sysfs for /dev/dri and /dev/nvidia* ? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 ------- Comment #10 from sndirsch@novell.com 2007-01-11 04:07 MST -------
@sndirsch: Is there a respondig device in sysfs for /dev/dri and /dev/nvidia* ? Probably, but I'm not sure. For nvidia you can verify this on machine "shannon". Matthias, can you help with DRI?
-- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 ------- Comment #11 from mhopf@novell.com 2007-01-17 05:39 MST ------- I cannot find any for nvidia. And I don't really have a clue about how dri drivers behave here right now. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 sndirsch@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |ASSIGNED Info Provider|birger.kollstrand@googlemail| |.com | -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 ------- Comment #12 from sndirsch@novell.com 2007-03-12 20:54 MST ------- Any news on this one, Danny? All the required information for NVIDIA can be found on machine "shannon", for DRI on any notebook with Intel graphics chipset when DRI is enabled. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 sndirsch@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |eich@novell.com ------- Comment #13 from sndirsch@novell.com 2007-05-12 04:28 MST ------- Egbert, JFYI. Since Matthias or me is in Cc of this bugreport or the reported itself, it might be interesting for you as well. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171 ------- Comment #14 from thomas@novell.com 2007-05-21 06:04 MST ------- Any news for this issue? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=231171#c15
--- Comment #15 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c16
Stefan Behlert
https://bugzilla.novell.com/show_bug.cgi?id=231171#c17
--- Comment #17 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c18
--- Comment #18 from Birger Kollstrand
https://bugzilla.novell.com/show_bug.cgi?id=231171
Thomas Biege
https://bugzilla.novell.com/show_bug.cgi?id=231171#c19
--- Comment #19 from Stefan Dirsch
Will there be done anything about this problem for 10.3? No. :-(
It seems a bit forgotten? Yes. :-(
How is this handled in the SLES line? Same problem. :-(
-- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=231171#c20
--- Comment #20 from Birger Kollstrand
https://bugzilla.novell.com/show_bug.cgi?id=231171#c21
Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c23
--- Comment #23 from Stefan Dirsch
Only to clarify: we speak about the drm subsystem (e.g. on intel: /dev/dri/card0)? Yes.
-- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=231171#c24
--- Comment #24 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c25
--- Comment #25 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c27
--- Comment #27 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c28
--- Comment #28 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c31
--- Comment #31 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c33
--- Comment #33 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c35
--- Comment #35 from Danny Kukawka
https://bugzilla.novell.com/show_bug.cgi?id=231171#c36
Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c37
--- Comment #37 from andy ritger
https://bugzilla.novell.com/show_bug.cgi?id=231171#c38
--- Comment #38 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c39
Danny Kukawka
From our experience in other distros, this led to bootstrapping problems due to
https://bugzilla.novell.com/show_bug.cgi?id=231171#c41
--- Comment #41 from andy ritger
https://bugzilla.novell.com/show_bug.cgi?id=231171#c42
--- Comment #42 from Danny Kukawka
https://bugzilla.novell.com/show_bug.cgi?id=231171#c43
Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c44
Danny Kukawka
Thanks, Danny. What exactly should I test?
If you get a device in lshal with property 'info.capability' and value 'drm' on intel and ati machines, and if the value of linux.device_file is what you need. About the nvidia case: We need to discuss this next week personally. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=231171#c45
--- Comment #45 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c46
Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c47
--- Comment #47 from Danny Kukawka
https://bugzilla.novell.com/show_bug.cgi?id=231171#c48
Danny Kukawka
https://bugzilla.novell.com/show_bug.cgi?id=231171#c49
--- Comment #49 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c50
Ludwig Nussel
https://bugzilla.novell.com/show_bug.cgi?id=231171#c51
Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c52
Ludwig Nussel
https://bugzilla.novell.com/show_bug.cgi?id=231171#c53
--- Comment #53 from Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c54
Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c55
Danny Kukawka
https://bugzilla.novell.com/show_bug.cgi?id=231171#c56
Stefan Dirsch
https://bugzilla.novell.com/show_bug.cgi?id=231171#c57
--- Comment #57 from Ludwig Nussel
https://bugzilla.novell.com/show_bug.cgi?id=231171
User lnussel@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=231171#c58
Ludwig Nussel
participants (1)
-
bugzilla_noreply@novell.com