[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: recommended video card?
On Mon, Jun 07, 2010 at 07:33:17PM +0200, Pouya D. Tafti wrote:
> work at all for me). There were some discussions at some point about
> there being some interest among OpenBSD developers in adding support
> for kernel mode switching, in order to make it possible to run X11 at
> higher security levels.
One should note, of course, that "possible" does not mean "safe". If
you can touch any of the registers of any device which can do DMA --
this means almost *any* modern video adapter -- at securelevel > 0,
you've basically punched a hole in the security model that you could
drive a truck through. It's kind of like the old "aperture" driver:
"Hi, can I buy a false sense of security, please? A real one would
be too expensive."
The only safe way is for the kernel to mediate all access to any device
with a DMA engine. But that is not the way modern X servers want to
do it (it is how many of the early ones worked).
Main Index |
Thread Index |