Subject: Re: kernel config for X
To: Hume Smith , None <netbsd-help@netbsd.org>
From: Richard Rauch <rauch@rice.edu>
List: netbsd-help
Date: 08/04/2002 05:32:56
(First, could you please turn off your email software's use of MIME
"quoted-printable"?  Follow the URL to see how it looks in the mailing
list archives.  From there I read these lists, as do some others.)

Re. http://mail-index.netbsd.org/netbsd-help/2002/08/02/0011.html

It would help if you had posted the XFree86 output (or at least the last
few error messages).  However, this time it seems to be straightforward:
You have probably removed ``options INSECURE'' which is commented as being
related to X in the GENERIC config.

See: http://www.netbsd.org/Ports/i386/faq.html#x_needs_insecure_kernel
(Maybe the FAQ's question should mention /dev/vga or /dev/xf86, which X
seems to look for if it needs the aperture driver.)

The aperture driver is also available if you use pkgsrc
(...pkgsrc/sysutils/aperture), in addition to via the means listed in the
FAQ.

Also I've heard one person report that he needs *both* INSECURE *and* the
aperture driver.  But since you're gettng complaints about /dev/mem, I
assume that you have removed INSECURE.


There are some who say that the aperture driver reproduces the hole that
you close by removing INSECURE.  Others believe that it increases system
securty to remove INSECURE and use the aperture.  I don't know enough
about the matter to say.  Personally, I use INSECURE if I need X, and
remove INSECURE where I don't need X.  I've never installed the aperture
driver.  Since my home network is fairly homogeneous and only one NetBSD
machine directly accesses the Internet (and it doesn't need X; (^&), I'm
not overly concerned about the security implications of this, at home.



  ``I probably don't know what I'm talking about.'' --rauch@math.rice.edu