WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

RE: [Xen-devel] [PATCH] warning when not running "xm" as root

To: "aq" <aquynh@xxxxxxxxx>
Subject: RE: [Xen-devel] [PATCH] warning when not running "xm" as root
From: "Ian Pratt" <m+Ian.Pratt@xxxxxxxxxxxx>
Date: Wed, 18 May 2005 09:08:29 +0100
Cc: xen-devel <xen-devel@xxxxxxxxxxxxxxxxxxx>
Delivery-date: Wed, 18 May 2005 08:08:01 +0000
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
Thread-index: AcVbfVYqnHPcM8MmSjO8JZQak2I7GwAAfaDA
Thread-topic: [Xen-devel] [PATCH] warning when not running "xm" as root
 
> > Thanks. I'd appreciate it if you could knock up a patch 
> that enables 
> > the user/group of the unix domain socket used for xm-xend 
> > communication to be set in xend-config.sxp, defaulting to 
> root/root. 
> > It would be great if you could update the error message accordingly.
> 
> you meant you want user to be able to reconfigure it incase 
> he wishes to run xm under unprivileged user/group?

Yep, that's the idea. 
It's also been suggested that some 'safe' operations like 'xm list'
could optionaly be allowed for any user. Given that the socket needs rw
access, I'm not sure how we could do this without implementing the
permission checking within xend rather than relying on the OS. Perhaps
phase 2...
 
> ok, i will take a look to see what can be done.

Thanks,
Ian

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel

<Prev in Thread] Current Thread [Next in Thread>