Re: Debian and the desktop
Le lundi 12 décembre 2005 à 20:25 +0100, Simon Richter a écrit :
> > -default sound setup
> Sound is symptomatic of a much larger class of problems, namely that
> there is no system service that forwards resources other than display
> and keyboard to the user currently logged in. In Unix, the default is to
> lock people out, so in the default setup there is no sound and USB stick
> access (the Windows way of allowing anyone to access all devices opens
> another can of worms). What would be required is some resource
> forwarding framework in which a priviledged process will pass out
> handles to sound/usb/floppy/... to anyone who asks via the proper
> channels (X11 springs to mind, as only clients belonging to the user
> logged in should have access to the display) or presenting the proper
> credentials. This would not be a Debian specific solution.
Currently, there are two ways of handling this situation:
- The Debian way, where this is controlled by Unix groups, and where the
default user belongs to these groups. Your message seems to imply the
opposite, and I welcome you to install a sarge system and try plugging a
USB stick or playing sound.
- The Redhat way, using pam_console. The user logging in gains rights on
some devices. The problem is that when the user logs out, there's no way
to force her to release the rights acquired. This is a limitation of the
Linux kernel, which cannot revoke privileges. AFAIK, that's why it isn't
used by default in Debian.
If you want things to move, you should provide a framework for the
kernel to handle a new revocation system call - far from an easy task.
> > -default wireless setup
> This is also related to the clash of the two approaches ("multiuser
> system with capable admin" versus "single-user personal system where all
> users need admin priviledge to associate to new APs as they roam with
> their laptop"). What we need is a solution that handles the in-between
> cases as well, and it's not Debian specific either.
Some desktop tools doing that exist, but they seriously lack integration
.''`. Josselin Mouette /\./\
: :' : email@example.com
`. `' firstname.lastname@example.org
`- Debian GNU/Linux -- The power of freedom