[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [MiNT] XaAES / GEM memory issues



> > arrays by GEM (overriding memory protection) more legitimate. No way. This
> > is a hack and this will remain a hack eventhough the king of Saudi Arabia
> > comes and states otherwise. :-) 

> reason.  Instead of trying to contort the AES to make it run under a
> strict unix system, why not allow MiNT to be a bit different and support
> an AES with special privlidges.

For example, because if the AES is allowed to obtain these privileges,
then in fact anyone (any process) can obtain the same and crash the system
(this is called an exploit). There is no reliable way to verify whether
the process which is just requesting F_OS_SPECIAL, is the "right" one, and
not, for example, a demo which just changed its name to "AESSYS" a while
ago. This, apart from creating problems I tried to point out in quite a
few mails before, creates a big security hole and therefore this facility
should be removed.

It is the business of the AES developers to design and develop an AES
which would not need this to run under memory protection. I am glad most
of them understood this long before this discuss started (Sven, and the
rest of Fenix guys, Mario, Vincent, and the rest of oAESis guys, to
mention a few).

--
Konrad M.Kokoszkiewicz
mail: draco@atari.org
http://draco.atari.org

** Ea natura multitudinis est,
** aut servit humiliter, aut superbe dominatur (Liv. XXIV,25)
*************************************************************
** Taka to juz natura pospolstwa, ze albo sluzy ono unizenie,
** albo bezczelnie sie panoszy.