Re: Questions about PAM, GDM and gnome-screensaver

Brian Cameron wrote:
> I don't think that it would be acceptable to run the GUI program with
> privilege.  In order to support xscreensaver on Solaris, we needed to
> break it into two processes as described above.

We had to break into two processes also because GTK+ won't allow you
to run it in a setuid process, since no one wants to make sure all of
GTK and all the other libraries it depends on (gdk, pango, etc.) are
fully clean and safe from a security standpoint, and because we need
to support GTK accessibility, which requires the GTK module loader to
load even more modules at runtime.   (In short, see for why it has to be 2 processes.)

	-Alan Coopersmith-           alan coopersmith sun com
	 Sun Microsystems, Inc. - X Window System Engineering

