Re: [gentoo-hardened] Grsec X11 Rbac Selinux Priviledged/Raw I/O Mprotect Firefox

2011-11-08 Thread Francisco Blas Izquierdo Riera (klondike)
El 07/11/11 18:45, Javier Juan Martínez Cabezón escribió: At least now (AFAIK) with KMS ioperm/iopl is not required, only propietary drivers need them (and having them running is per se a security bug). I think this doesn't hold for radeon based on my empirical experience should try again

Re: [gentoo-hardened] Grsec X11 Rbac Selinux Priviledged/Raw I/O Mprotect Firefox

2011-11-07 Thread Javier Juan Martínez Cabezón
At least now (AFAIK) with KMS ioperm/iopl is not required, only propietary drivers need them (and having them running is per se a security bug). Since now with CONFIG_STRICT_DEVMEM enabled every process is unable to access to any RAM memory (if not video one and even with CAP_SYS_RAWIO) I think