On Mon, 2003-12-08 at 11:39, Hermann Härtig wrote:
Jonathan S. Shapiro wrote: That is a result of using thread ids for identification of senders which I consider a bad idea. If we need indeed (which I tend to believe) sender identification, the id space should be designed such that ids can be managed in user space and enforced by the kernel, i.e. Pb and the file server should be enabled to act under the same sender id.
We need to talk further about whether sender ID's are useful, but let me answer on the assumption that they are necessary.
If sender ID's are used, then any change to a sender ID must be a privileged operation. It can be managed in user mode, but the software that does the management must be universally trusted.
shap