Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 16 Oct 2004 12:04:38 +0930
From:      "Daniel O'Connor" <doconnor@gsoft.com.au>
To:        Peter Jeremy <PeterJeremy@optushome.com.au>
Cc:        freebsd-current@freebsd.org
Subject:   Re: atapicam(4) as KLD?
Message-ID:  <200410161204.46763.doconnor@gsoft.com.au>
In-Reply-To: <20041015214318.GS83620@cirb503493.alcatel.com.au>
References:  <20041013205141.GA874@galgenberg.net> <200410152048.44173.doconnor@gsoft.com.au> <20041015214318.GS83620@cirb503493.alcatel.com.au>

next in thread | previous in thread | raw e-mail | index | archive | help
--nextPart3042432.zRKtrZN11c
Content-Type: text/plain;
  charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

On Sat, 16 Oct 2004 07:13, Peter Jeremy wrote:
> Studying a ktrace, it seems that all it uses /dev/cd0c for it to issue
> a CAMGETPASSTHRU and then it opens /dev/passN but when that fails, it
> issues the above error message :-(.  Changing the permissions on
> /dev/pass0 as well makes it work.
>
> >It sucks having to choose between features (growisofs, cdrecord, cdda2wa=
v)
> > and security (burncd)
>
> Since you can identify the pass/xpt/cd device associated with the ATAPI
> device, it should be safe to make those devices world or group writable
> even if there are other SCSI devices on the system.

I think you need write permissions on all 3 (cd, pass, xpt) but xpt grants =
you=20
access to the entire bus so that would be bad from a security POV.

Although that said in this specific case the CD writer would be the only th=
ing=20
on that bus (unless you had >1 on the same chain, but that is not a good id=
ea=20
for reasons to do with IDE sucking)

Is there a way in devfs/devd to determine which pass and xpt devices are=20
associated with a given cd device? (my guess is you'd need to run camcontro=
l=20
and parse the output..)

=2D-=20
Daniel O'Connor software and network engineer
for Genesis Software - http://www.gsoft.com.au
"The nice thing about standards is that there
are so many of them to choose from."
  -- Andrew Tanenbaum
GPG Fingerprint - 5596 B766 97C0 0E94 4347 295E E593 DC20 7B3F CE8C

--nextPart3042432.zRKtrZN11c
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (FreeBSD)

iD8DBQBBcIjG5ZPcIHs/zowRAr1PAKCY3i+okojptvnnAaxs8pYgsBJzpwCgnZ3i
mW/6k2K4lSd36YhxRkxrIOI=
=DLqo
-----END PGP SIGNATURE-----

--nextPart3042432.zRKtrZN11c--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200410161204.46763.doconnor>