All of lore.kernel.org
 help / color / mirror / Atom feed
From: Philippe Gerum <rpm@xenomai.org>
To: Jan Kiszka <jan.kiszka@siemens.com>,
	Gilles Chanteperdrix <gilles.chanteperdrix@xenomai.org>
Cc: Xenomai <xenomai@xenomai.org>
Subject: Re: [Xenomai] [Xenomai-git] Philippe Gerum: copperplate: add configuration tunable for registry moint point
Date: Tue, 13 Jan 2015 10:22:05 +0100	[thread overview]
Message-ID: <54B4E3BD.7000200@xenomai.org> (raw)
In-Reply-To: <54B3DB8E.4020805@siemens.com>

On 01/12/2015 03:34 PM, Jan Kiszka wrote:
> On 2015-01-12 15:35, Philippe Gerum wrote:
>> On 01/12/2015 12:59 PM, Jan Kiszka wrote:
>>> On 2015-01-12 12:34, Gilles Chanteperdrix wrote:
>>>> On Mon, Jan 12, 2015 at 12:19:20PM +0100, Jan Kiszka wrote:
>>>>> On 2015-01-12 11:42, Gilles Chanteperdrix wrote:
>>>>>> On Wed, Jan 07, 2015 at 07:14:56PM +0100, Jan Kiszka wrote:
>>>>>>> On 2015-01-03 23:25, Gilles Chanteperdrix wrote:
>>>>>>>>>>
>>>>>>>>>> Alternatively (to the last item), the sysregd could be made suid
>>>>>>>>>> root, create the session directory if it does not exist with root
>>>>>>>>>> permissions but with the target user as owner, then drop root
>>>>>>>>>> privileges and continue as a normal user.
>>>>>>>>>
>>>>>>>>> Should work, but unless I stumbled over fundamental issues why sysregd
>>>>>>>>> is not working as normal user right now, I don't see a technical need
>>>>>>>>> for this big hammer for user-managed sessions.
>>>>>>>>
>>>>>>>> The enormous advantage of using the big hammer (in fact, only if we
>>>>>>>> put the three changes into it), is that it avoids explaining things
>>>>>>>> to the users, and avoids as well questions on the mailing list.
>>>>>>>> Given the number of questions we have had about /dev/rtheap and
>>>>>>>> /dev/rtpipe, this would be a win.
>>>>>>>
>>>>>>> We actually need the big suid-hammer: only root has the permission to
>>>>>>> clean up the mounts of other users. Obsoletes my fusermount -u patch.
>>>>>>
>>>>>> Why does root need to clean up the mounts of other users if each
>>>>>> user cleans up its mounts ?
>>>>>
>>>>> As long as the daemon only runs on behalf of the very same user, this
>>>>> works. But this breaks when user A starts a session and B joins it or
>>>>> inherits a still running daemon.
>>>>
>>>> Is it really a case that matters ? As I already said, I believe
>>>> running xenomai programs as simple user should be taken into
>>>> account, but multiple users for the same session ?
>>>
>>> If that is not required, we could make the mount point private in $HOME.
>>> Then it is clear to the user that sessions cannot be shared. And the
>>> namespaces would be isolated automatically.
>>>
>>> Anon will continue to require a root daemon that has to be started in
>>> advance.
>>>
>>
>> Looks ok. Named sessions have been designed as a way to share things
>> between processes composing a larger application, basically. Assuming
>> that all processes sharing a named session must belong to the same uid
>> is part of the original design.
> 
> OK, then let's sketch a design:
> 
> - if sysregd runs as non-root, it uses $HOME/.xenomai as default
>   (open for alternative suggestions as well -
>   DEFAULT_REGISTRY_ROOT/$USER?) registry root, otherwise
>   DEFAULT_REGISTRY_ROOT. Overriding via --root remains unaffected.

$DEFAULT_REGISTRY_ROOT/$USER would align on current practices for
dynamic mounts in other areas (e.g. removable media).

> 
> - remove --shared-registry application option, only provide
>   "sysregd --shared" because we need it for the anon session
> 

Ok.

> - do not install sysregd with suid
> 

Definitely.

> Makes sense?
> 

Works for me.

-- 
Philippe.


  reply	other threads:[~2015-01-13  9:22 UTC|newest]

Thread overview: 49+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <mailman.787.1420134217.6101.xenomai-git@xenomai.org>
2015-01-02 10:28 ` [Xenomai] [Xenomai-git] Philippe Gerum: copperplate: add configuration tunable for registry moint point Jan Kiszka
2015-01-02 10:58   ` Philippe Gerum
2015-01-02 11:11     ` Jan Kiszka
2015-01-02 12:51       ` Gilles Chanteperdrix
2015-01-02 13:05         ` Jan Kiszka
2015-01-02 13:41           ` Gilles Chanteperdrix
2015-01-02 15:05         ` Lennart Sorensen
2015-01-02 15:10           ` Gilles Chanteperdrix
2015-01-02 15:22             ` Gilles Chanteperdrix
2015-01-02 15:47               ` Lennart Sorensen
2015-01-02 18:06                 ` Gilles Chanteperdrix
2015-01-02 12:56       ` Gilles Chanteperdrix
2015-01-02 13:06         ` Jan Kiszka
2015-01-02 13:29       ` Philippe Gerum
2015-01-02 13:24         ` Jan Kiszka
2015-01-02 14:02           ` Philippe Gerum
2015-01-02 13:56             ` Jan Kiszka
2015-01-02 14:16               ` Gilles Chanteperdrix
2015-01-02 15:06                 ` Gilles Chanteperdrix
2015-01-02 15:59                   ` Jan Kiszka
2015-01-02 18:03                     ` Gilles Chanteperdrix
2015-01-02 18:07                     ` Philippe Gerum
2015-01-02 18:09                       ` Jan Kiszka
2015-01-02 19:20                         ` Philippe Gerum
2015-01-02 19:15                           ` Jan Kiszka
2015-01-02 19:31                             ` Philippe Gerum
2015-01-02 19:28                               ` Jan Kiszka
2015-01-02 19:55                                 ` Philippe Gerum
2015-01-02 19:49                                   ` Jan Kiszka
2015-01-02 20:18                                     ` Philippe Gerum
2015-01-02 22:05                                       ` [Xenomai] registry daemon mangement (was: Re: [Xenomai-git] Philippe Gerum: copperplate: add configuration tunable for registry moint point) Jan Kiszka
2015-01-02 22:17                                         ` Gilles Chanteperdrix
2015-01-03 18:36                                         ` [Xenomai] registry daemon mangement Philippe Gerum
2015-01-03 20:09                                           ` Jan Kiszka
2015-01-03 20:55                                             ` Philippe Gerum
2015-01-04 13:03                                               ` Jan Kiszka
2015-01-03 19:40                     ` [Xenomai] [Xenomai-git] Philippe Gerum: copperplate: add configuration tunable for registry moint point Gilles Chanteperdrix
2015-01-03 20:17                       ` Jan Kiszka
2015-01-03 22:25                         ` Gilles Chanteperdrix
2015-01-07 18:14                           ` Jan Kiszka
2015-01-12 10:42                             ` Gilles Chanteperdrix
2015-01-12 11:19                               ` Jan Kiszka
2015-01-12 11:34                                 ` Gilles Chanteperdrix
2015-01-12 11:59                                   ` Jan Kiszka
2015-01-12 14:35                                     ` Philippe Gerum
2015-01-12 14:34                                       ` Jan Kiszka
2015-01-13  9:22                                         ` Philippe Gerum [this message]
2015-01-13  9:11                                           ` Jan Kiszka
2015-01-13  9:45                                             ` Philippe Gerum

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=54B4E3BD.7000200@xenomai.org \
    --to=rpm@xenomai.org \
    --cc=gilles.chanteperdrix@xenomai.org \
    --cc=jan.kiszka@siemens.com \
    --cc=xenomai@xenomai.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.