From randyf@sac.sfbay.sun.com Tue Feb 17 16:03:22 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I03LUT003442
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 16:03:22 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n1I03Cho028321;
	Wed, 18 Feb 2009 00:03:20 GMT
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800G05ITI4400@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 17 Feb 2009 16:03:18 -0800 (PST)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF8007RIITHC320@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 17 Feb 2009 16:03:17 -0800 (PST)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n1I03GWU031759; Tue, 17 Feb 2009 16:03:16 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I03F7L002644; Tue,
 17 Feb 2009 16:03:15 -0800 (PST)
Received: (from randyf@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id n1I03FkA002627; Tue,
 17 Feb 2009 16:03:15 -0800 (PST)
Date: Tue, 17 Feb 2009 16:03:15 -0800 (PST)
From: Randy Fishel <randyf@sac.sfbay.sun.com>
Subject: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
To: PSARC-ext@sun.com
Cc: pm-dev@opensolaris.org
Message-id: <200902180003.n1I03FkA002627@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 2682


I am sponsoring this fasttrack on behalf of myself.  It provides the
replacement CLI tool for the EOF'd CDE sys-suspend command.  The
timeout is 2/23/09.


Template Version: @(#)sac_nextcase %I% %G% SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 sys-suspend(1)
    1.2. Name of Document Author/Supplier:
	 Author:  Randy Fishel
    1.3  Date of This Document:
	17 February, 2009
4. Technical Description

This project proposes a CLI-only replacement for the EOF'd CDE
sys-suspend.  This tool will have the same command-line arguments as
the CDE version, so it can be used as a drop-in replacement, with the
exception that it will not generate any GUI popups.  It will also be
placed in /usr/bin with no symlink to /usr/openwin/bin.

/usr/bin/sys-suspend will also use the power management 'suspend'
authorizations defined in PSARC/2008/021 (see below), and will not use
/etc/default/sys-suspend.  Console user requirements are met by PSARC
2008/034, other users will need to include the authorizations or
profiles defined in PSARC/2008/021. Auditing will be performed in a
manner that is agreeable with the Auditing team.  Known ON consumers of
/usr/openwin/bin/sys-suspend will be updated to use /usr/bin/sys-suspend.

This command is needed due to the removal of the CDE version and the
deprecation of gnome-sys-suspend (as well as will-not-fix bugs against
it), such that there is no command-line tool for OpenSolaris, or after
the removal of /usr/openwin/bin/sys-suspend.

Note: LSARC 2008/763 was approved with the requirement that
/usr/openwin/bin/suspend (et.al.) cannot be removed till a replacement
is available.  This case only describes that replacement, the removal
of /usr/openwin/bin/sys-suspend or /etc/default/sys-suspend is the
responsibility of the project team for LSARC 2008/763 and is not part
of this case.

This project requests a Minor release binding.

Exports:
    Interface				Classification
    =================================================
    /usr/bin/sys-suspend		Committed


Imports
    Interface				Case
    =================================================
    solaris.system.power.suspend.ram	PSARC 2008/021
    solaris.system.power.suspend.disk	PSARC 2008/021


References 

    LSARC 2008/763 EOF of sys-suspend
    PSARC 1996/408 sys-suspend
    LSARC 2007/648 Removal of CDE
    PSARC 2008/021 HAL Power Management Support
    PSARC 2008/034 Defining Workstation Owner Infrastructure


6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From gdamore@sun.com Tue Feb 17 16:23:42 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I0Nf2g023619
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 16:23:42 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n1I0Nd7k000628
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 18 Feb 2009 08:23:41 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800C05JRFCN00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Feb 2009 16:23:39 -0800 (PST)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF8007GMJRE9I60@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Feb 2009 16:23:38 -0800 (PST)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n1I0Ncob028591	for
 <PSARC-ext@sun.com>; Tue, 17 Feb 2009 16:23:38 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KF800B00JMQOB00@fe-sfbay-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Feb 2009 16:23:38 -0800 (PST)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 with ESMTPSA id <0KF800AF4JRD7A80@fe-sfbay-10.sun.com>; Tue,
 17 Feb 2009 16:23:38 -0800 (PST)
Date: Tue, 17 Feb 2009 16:23:37 -0800
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
In-reply-to: <200902180003.n1I03FkA002627@sac.sfbay.sun.com>
Sender: Garrett.Damore@sun.com
To: Randy Fishel <randyf@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com, pm-dev@opensolaris.org
Message-id: <499B5509.9040808@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200902180003.n1I03FkA002627@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 3035

+1.

Is there any desire to provide consistent input/output for this to be 
used in scripting?  (Or are we simply going to expect application 
consumers to call uadmin(2) directly?)

    --Garrett

Randy Fishel wrote:
> I am sponsoring this fasttrack on behalf of myself.  It provides the
> replacement CLI tool for the EOF'd CDE sys-suspend command.  The
> timeout is 2/23/09.
>
>
> Template Version: @(#)sac_nextcase %I% %G% SMI
> This information is Copyright 2009 Sun Microsystems
> 1. Introduction
>     1.1. Project/Component Working Name:
> 	 sys-suspend(1)
>     1.2. Name of Document Author/Supplier:
> 	 Author:  Randy Fishel
>     1.3  Date of This Document:
> 	17 February, 2009
> 4. Technical Description
>
> This project proposes a CLI-only replacement for the EOF'd CDE
> sys-suspend.  This tool will have the same command-line arguments as
> the CDE version, so it can be used as a drop-in replacement, with the
> exception that it will not generate any GUI popups.  It will also be
> placed in /usr/bin with no symlink to /usr/openwin/bin.
>
> /usr/bin/sys-suspend will also use the power management 'suspend'
> authorizations defined in PSARC/2008/021 (see below), and will not use
> /etc/default/sys-suspend.  Console user requirements are met by PSARC
> 2008/034, other users will need to include the authorizations or
> profiles defined in PSARC/2008/021. Auditing will be performed in a
> manner that is agreeable with the Auditing team.  Known ON consumers of
> /usr/openwin/bin/sys-suspend will be updated to use /usr/bin/sys-suspend.
>
> This command is needed due to the removal of the CDE version and the
> deprecation of gnome-sys-suspend (as well as will-not-fix bugs against
> it), such that there is no command-line tool for OpenSolaris, or after
> the removal of /usr/openwin/bin/sys-suspend.
>
> Note: LSARC 2008/763 was approved with the requirement that
> /usr/openwin/bin/suspend (et.al.) cannot be removed till a replacement
> is available.  This case only describes that replacement, the removal
> of /usr/openwin/bin/sys-suspend or /etc/default/sys-suspend is the
> responsibility of the project team for LSARC 2008/763 and is not part
> of this case.
>
> This project requests a Minor release binding.
>
> Exports:
>     Interface				Classification
>     =================================================
>     /usr/bin/sys-suspend		Committed
>
>
> Imports
>     Interface				Case
>     =================================================
>     solaris.system.power.suspend.ram	PSARC 2008/021
>     solaris.system.power.suspend.disk	PSARC 2008/021
>
>
> References 
>
>     LSARC 2008/763 EOF of sys-suspend
>     PSARC 1996/408 sys-suspend
>     LSARC 2007/648 Removal of CDE
>     PSARC 2008/021 HAL Power Management Support
>     PSARC 2008/034 Defining Workstation Owner Infrastructure
>
>
> 6. Resources and Schedule
>     6.4. Steering Committee requested information
>    	6.4.1. Consolidation C-team Name:
> 		ON
>     6.5. ARC review type: FastTrack
>     6.6. ARC Exposure: open
>
>   


From gww@eng.sun.com Tue Feb 17 16:32:34 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I0WXLL024428
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 16:32:34 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n1I0WWrV064298;
	Tue, 17 Feb 2009 17:32:33 -0700 (MST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF80031TK68D500@brm-avmta-1.central.sun.com>; Tue,
 17 Feb 2009 17:32:32 -0700 (MST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF800IL9K67YF30@brm-avmta-1.central.sun.com>; Tue,
 17 Feb 2009 17:32:31 -0700 (MST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n1I0WU7L047872; Tue, 17 Feb 2009 16:32:30 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n1I0UvhZ003552; Tue,
 17 Feb 2009 16:30:57 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n1I0UviZ003551; Tue,
 17 Feb 2009 16:30:57 -0800 (PST)
Date: Tue, 17 Feb 2009 16:30:57 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
To: randyf@sac.sfbay.sun.com, gdamore@sun.com
Cc: PSARC-ext@sun.com, pm-dev@opensolaris.org
Message-id: <200902180030.n1I0UviZ003551@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 758

> Is there any desire to provide consistent input/output for this to be 
> used in scripting?  (Or are we simply going to expect application 
> consumers to call uadmin(2) directly?)

	I've not read the current proposal, but as I believe Randy
	does know: ALL callers of uadmin(2) MUST deal with authorization
	and audit or the system will not work as desired after these
	calls to uadmin(2).  uadmin(1) and a few other applications
	such as halt(1) and the links to halt(1) do this correctly.
	Please, please do not suggest using uadmin(2) to any projects
	that have not contacted the security project teams, in particular
	the Audit team.

Gary..
P.S.	I'll be reading and +1 or commenting soon.  I just wanted to get
	this comment public before my review.

From gdamore@sun.com Tue Feb 17 16:37:23 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I0bMfE024902
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 16:37:23 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n1I0bJH5008500
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 18 Feb 2009 08:37:21 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800D03KE88A00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Feb 2009 16:37:20 -0800 (PST)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF8007HSKE89O70@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Feb 2009 16:37:20 -0800 (PST)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n1I0bJJY029833	for
 <PSARC-ext@sun.com>; Tue, 17 Feb 2009 16:37:19 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KF800J00J90X600@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Feb 2009 16:18:24 -0800 (PST)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 with ESMTPSA id <0KF8006B9JIN2AD0@fe-sfbay-09.sun.com>; Tue,
 17 Feb 2009 16:18:24 -0800 (PST)
Date: Tue, 17 Feb 2009 16:37:19 -0800
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
In-reply-to: <200902180030.n1I0UviZ003551@marduk.eng.sun.com>
Sender: Garrett.Damore@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: randyf@sac.sfbay.sun.com, PSARC-ext@sun.com, pm-dev@opensolaris.org
Message-id: <499B583F.80409@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200902180030.n1I0UviZ003551@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 1134

Gary Winiger wrote:
>> Is there any desire to provide consistent input/output for this to be 
>> used in scripting?  (Or are we simply going to expect application 
>> consumers to call uadmin(2) directly?)
>>     
>
> 	I've not read the current proposal, but as I believe Randy
> 	does know: ALL callers of uadmin(2) MUST deal with authorization
> 	and audit or the system will not work as desired after these
> 	calls to uadmin(2).  uadmin(1) and a few other applications
> 	such as halt(1) and the links to halt(1) do this correctly.
> 	Please, please do not suggest using uadmin(2) to any projects
> 	that have not contacted the security project teams, in particular
> 	the Audit team.
>   


I'm kind of concerned here -- if there is a requirement for software to 
do something else, then this needs to be fully documented -- including 
in the man pages.

I don't believe it is reasonable to expect 3rd party callers of 
documented system calls to know about undocumented requirements.

    -- Garrett
> Gary..
> P.S.	I'll be reading and +1 or commenting soon.  I just wanted to get
> 	this comment public before my review.
>   


From randy.fishel@sun.com Tue Feb 17 16:41:40 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I0fdD8026175
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 16:41:40 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n1I0fX4P010651;
	Wed, 18 Feb 2009 08:41:37 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800405KLCB400@brm-avmta-1.central.sun.com>; Tue,
 17 Feb 2009 17:41:36 -0700 (MST)
Received: from grimmy.sfbay.sun.com ([129.146.108.114])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF800IK0KLAYK50@brm-avmta-1.central.sun.com>; Tue,
 17 Feb 2009 17:41:35 -0700 (MST)
Received: from grimmy.eng.sun.com (localhost [127.0.0.1])
	by grimmy.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I0XxwZ004402; Tue,
 17 Feb 2009 16:33:59 -0800 (PST)
Received: from localhost (randyf@localhost)
	by grimmy.eng.sun.com (8.13.8+Sun/8.13.8/Submit) with ESMTP id n1I0XxQs004398;
 Tue, 17 Feb 2009 16:33:59 -0800 (PST)
Date: Tue, 17 Feb 2009 16:33:59 -0800 (PST)
From: Randy Fishel <randy.fishel@sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
In-reply-to: <499B5509.9040808@sun.com>
X-X-Sender: randyf@grimmy
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: Randy Fishel <randyf@sac.sfbay.sun.com>, PSARC-ext@sun.com,
        pm-dev@opensolaris.org
Message-id: <alpine.GSO.1.10.0902171628570.4383@grimmy>
MIME-version: 1.0
Content-type: TEXT/PLAIN; charset=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200902180003.n1I03FkA002627@sac.sfbay.sun.com>
 <499B5509.9040808@sun.com>
X-Authentication-warning: grimmy.eng.sun.com: randyf owned process doing -bs
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
Status: RO
Content-Length: 3787



  There is a longer-term project to provide a library for users to 
consume, and not call uadmin(2) directly (in fact, we want to 
discourage this practice, as it doesn't properly audit).

  As the library is a bit more complex, and there is immediate need 
for a (simple) cli, this wraps the equivilent calls (with proper audit 
and authorization calls) till they can be included in the new library 
(that project will need to also update this command to use those 
calls, but that is a different project and case).

	---- Randy


On Tue, 17 Feb 2009, Garrett D'Amore wrote:

> +1.
> 
> Is there any desire to provide consistent input/output for this to be used in
> scripting?  (Or are we simply going to expect application consumers to call
> uadmin(2) directly?)
> 
>    --Garrett
> 
> Randy Fishel wrote:
> > I am sponsoring this fasttrack on behalf of myself.  It provides the
> > replacement CLI tool for the EOF'd CDE sys-suspend command.  The
> > timeout is 2/23/09.
> > 
> > 
> > Template Version: @(#)sac_nextcase %I% %G% SMI
> > This information is Copyright 2009 Sun Microsystems
> > 1. Introduction
> >     1.1. Project/Component Working Name:
> > 	 sys-suspend(1)
> >     1.2. Name of Document Author/Supplier:
> > 	 Author:  Randy Fishel
> >     1.3  Date of This Document:
> > 	17 February, 2009
> > 4. Technical Description
> > 
> > This project proposes a CLI-only replacement for the EOF'd CDE
> > sys-suspend.  This tool will have the same command-line arguments as
> > the CDE version, so it can be used as a drop-in replacement, with the
> > exception that it will not generate any GUI popups.  It will also be
> > placed in /usr/bin with no symlink to /usr/openwin/bin.
> > 
> > /usr/bin/sys-suspend will also use the power management 'suspend'
> > authorizations defined in PSARC/2008/021 (see below), and will not use
> > /etc/default/sys-suspend.  Console user requirements are met by PSARC
> > 2008/034, other users will need to include the authorizations or
> > profiles defined in PSARC/2008/021. Auditing will be performed in a
> > manner that is agreeable with the Auditing team.  Known ON consumers of
> > /usr/openwin/bin/sys-suspend will be updated to use /usr/bin/sys-suspend.
> > 
> > This command is needed due to the removal of the CDE version and the
> > deprecation of gnome-sys-suspend (as well as will-not-fix bugs against
> > it), such that there is no command-line tool for OpenSolaris, or after
> > the removal of /usr/openwin/bin/sys-suspend.
> > 
> > Note: LSARC 2008/763 was approved with the requirement that
> > /usr/openwin/bin/suspend (et.al.) cannot be removed till a replacement
> > is available.  This case only describes that replacement, the removal
> > of /usr/openwin/bin/sys-suspend or /etc/default/sys-suspend is the
> > responsibility of the project team for LSARC 2008/763 and is not part
> > of this case.
> > 
> > This project requests a Minor release binding.
> > 
> > Exports:
> >     Interface				Classification
> >     =================================================
> >     /usr/bin/sys-suspend		Committed
> > 
> > 
> > Imports
> >     Interface				Case
> >     =================================================
> >     solaris.system.power.suspend.ram	PSARC 2008/021
> >     solaris.system.power.suspend.disk	PSARC 2008/021
> > 
> > 
> > References 
> >     LSARC 2008/763 EOF of sys-suspend
> >     PSARC 1996/408 sys-suspend
> >     LSARC 2007/648 Removal of CDE
> >     PSARC 2008/021 HAL Power Management Support
> >     PSARC 2008/034 Defining Workstation Owner Infrastructure
> > 
> > 
> > 6. Resources and Schedule
> >     6.4. Steering Committee requested information
> >    	6.4.1. Consolidation C-team Name:
> > 		ON
> >     6.5. ARC review type: FastTrack
> >     6.6. ARC Exposure: open
> > 
> >   

From gww@eng.sun.com Tue Feb 17 16:46:13 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I0kCax026426
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 16:46:13 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n1I0k0or012904;
	Wed, 18 Feb 2009 08:46:10 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800D03KSWR100@nwk-avmta-2.sfbay.sun.com>; Tue,
 17 Feb 2009 16:46:08 -0800 (PST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF8007NOKSV9I70@nwk-avmta-2.sfbay.sun.com>; Tue,
 17 Feb 2009 16:46:07 -0800 (PST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n1I0k7tg055144; Tue, 17 Feb 2009 16:46:07 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n1I0iYTj003603; Tue,
 17 Feb 2009 16:44:34 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n1I0iY16003602; Tue,
 17 Feb 2009 16:44:34 -0800 (PST)
Date: Tue, 17 Feb 2009 16:44:34 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
To: gww@eng.sun.com, gdamore@sun.com
Cc: randyf@sac.sfbay.sun.com, PSARC-ext@sun.com, pm-dev@opensolaris.org
Message-id: <200902180044.n1I0iY16003602@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1113

> I'm kind of concerned here -- if there is a requirement for software to 
> do something else, then this needs to be fully documented -- including 
> in the man pages.

	I've tried to get the folks, if there are any, who own uadmin(2)
	to update the man page to actually describe what it does.  The
	man page CR is not getting any attention.  Beyond the power management
	stuff, which the Audit team is working with, there doesn't
	appear to be anyone who cares.

> I don't believe it is reasonable to expect 3rd party callers of 
> documented system calls to know about undocumented requirements.

	Do you have some suggestions?  I could file a P2 man page
	bug saying this man page is horribly out of date and I don't
	know how to fix it.  Don't use uadmin(1) only call uadmin(1),
	but that seems equally as broken as the uadmin(2) documentation.
	I believe the power management team has a medimum term solution
	to do all the right stuff and maybe even interpose in libc
	with stuff that does all the right stuff.
	sys-suspend(1) proposed here is to help OpenSolaris until
	that solution is in place.

Gary..

From gww@eng.sun.com Tue Feb 17 17:00:18 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I10HrT027690
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 17:00:17 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n1I10AfG006263;
	Wed, 18 Feb 2009 01:00:15 GMT
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800E1RLGEKF00@nwk-avmta-2.sfbay.sun.com>; Tue,
 17 Feb 2009 17:00:14 -0800 (PST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF8007W8LGB9K80@nwk-avmta-2.sfbay.sun.com>; Tue,
 17 Feb 2009 17:00:11 -0800 (PST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n1I10AdZ063214; Tue, 17 Feb 2009 17:00:10 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n1I0wbDM003629; Tue,
 17 Feb 2009 16:58:38 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n1I0wbSm003628; Tue,
 17 Feb 2009 16:58:37 -0800 (PST)
Date: Tue, 17 Feb 2009 16:58:37 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
To: gdamore@sun.com, randy.fishel@sun.com
Cc: randyf@sac.sfbay.sun.com, PSARC-ext@sun.com, pm-dev@opensolaris.org
Message-id: <200902180058.n1I0wbSm003628@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1020

>   There is a longer-term project to provide a library for users to 
> consume, and not call uadmin(2) directly (in fact, we want to 
> discourage this practice, as it doesn't properly audit).

	It's worse than not properly auditing the use, it's that the
	audit subsystem is adversely affected by any direct calls that
	have not properly interacted with the audit subsystem first.

	N.B.  None of this is new.  This has been the case since SunOS
	5.3.  It's only in the last year that a number of disasters
	have occurred that engineering has been working to fix things
	so the disasters are unlikely to occur.  Doing a systrap of
	course can always get around things.

Gary..
> 
>   As the library is a bit more complex, and there is immediate need 
> for a (simple) cli, this wraps the equivilent calls (with proper audit 
> and authorization calls) till they can be included in the new library 
> (that project will need to also update this command to use those 
> calls, but that is a different project and case).

From gww@eng.sun.com Tue Feb 17 17:21:25 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I1LOdE028922
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 17:21:25 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n1I1LGQK020706
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 18 Feb 2009 01:21:23 GMT
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800F05MFLTN00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Feb 2009 17:21:21 -0800 (PST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF8007UKMFL9QA0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Feb 2009 17:21:21 -0800 (PST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n1I1LKt6011336; Tue, 17 Feb 2009 17:21:20 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n1I1Jmsm003680; Tue,
 17 Feb 2009 17:19:48 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n1I1JmaG003679; Tue,
 17 Feb 2009 17:19:48 -0800 (PST)
Date: Tue, 17 Feb 2009 17:19:48 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
To: PSARC-ext@sun.com, randyf@sac.sfbay.sun.com
Cc: pm-dev@opensolaris.org
Message-id: <200902180119.n1I1JmaG003679@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1573

> I am sponsoring this fasttrack on behalf of myself.  It provides the
> replacement CLI tool for the EOF'd CDE sys-suspend command.  The
> timeout is 2/23/09.

+1 with a couple nits (below)

> /usr/bin/sys-suspend will also use the power management 'suspend'
> authorizations defined in PSARC/2008/021 (see below), and will not use
> /etc/default/sys-suspend.

	Nit: the committee should note this is an incompatible change
	as it doesn't account for non-console user.  IMO, this is
	not an issue for this project since it is a Minor release
	and /etc/default/sys-suspend is EOLed in the LSARC/2008/763.
 
> profiles defined in PSARC/2008/021. Auditing will be performed in a
> manner that is agreeable with the Auditing team.

	Nit: it's a little different than just preforming auditing.
	The issue is proper interaction with the Audit subsystem.
	Because the Audit project team (me ;-) has been working with
	the project team, the project team is aware of what's needed.

> This project requests a Minor release binding.
> 

> Imports
>     Interface				Case
>     =================================================
>     solaris.system.power.suspend.ram	PSARC 2008/021
>     solaris.system.power.suspend.disk	PSARC 2008/021

	Nit:  While possibly an implementation detail, as I understand
	how the project team will deal with proper interaction with
	the Audit subsystem is by using uadmin(1).  In the present
	implementation, this would seem an important interface to note.
	IIUC, the future project may replace the use of uadmin(1)
	with a library equivalent.

Gary..

From gww@eng.sun.com Tue Feb 17 17:22:55 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I1MtKY029115
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 17:22:55 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n1I1Ms4i001067;
	Tue, 17 Feb 2009 17:22:55 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800F0BMI7WU00@nwk-avmta-2.sfbay.sun.com>; Tue,
 17 Feb 2009 17:22:55 -0800 (PST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF8007WDMI69G90@nwk-avmta-2.sfbay.sun.com>; Tue,
 17 Feb 2009 17:22:54 -0800 (PST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n1I1Ms2S012156; Tue, 17 Feb 2009 17:22:54 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n1I1LLTI003691; Tue,
 17 Feb 2009 17:21:21 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n1I1LLdX003690; Tue,
 17 Feb 2009 17:21:21 -0800 (PST)
Date: Tue, 17 Feb 2009 17:21:21 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
To: gww@eng.sun.com, gdamore@sun.com
Cc: randyf@sac.sfbay.sun.com, PSARC-ext@sun.com, pm-dev@opensolaris.org
Message-id: <200902180121.n1I1LLdX003690@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 378

> > I don't believe it is reasonable to expect 3rd party callers of 
> > documented system calls to know about undocumented requirements.
> 
> 	Do you have some suggestions?  I could file a P2 man page
> 	bug saying this man page is horribly out of date and I don't
> 	know how to fix it.  Don't use uadmin(1) only call uadmin(1),
					      ^
					      2

	Sigh typo.

Gary..

From gww@eng.sun.com Tue Feb 17 17:50:40 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I1oeuS001525
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 17:50:40 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n1I1oZwZ010460
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 18 Feb 2009 01:50:39 GMT
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800H03NSDOO00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Feb 2009 17:50:37 -0800 (PST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF800792NSD9DD0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Feb 2009 17:50:37 -0800 (PST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n1I1oajM027727; Tue, 17 Feb 2009 17:50:36 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n1I1n3Us003753; Tue,
 17 Feb 2009 17:49:04 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n1I1n3Xq003752; Tue,
 17 Feb 2009 17:49:03 -0800 (PST)
Date: Tue, 17 Feb 2009 17:49:03 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
To: gww@eng.sun.com, randy.fishel@sun.com
Cc: PSARC-ext@sun.com, randyf@sac.sfbay.sun.com, pm-dev@opensolaris.org
Message-id: <200902180149.n1I1n3Xq003752@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 579

>   I forgot to note that there is a proposed man page in the case 
> directory.  This text starts to touch on documenting the RBAC usage.  
> I expect that the paragraph in question can be improved with a little 
> help from Gary before it is integrated (but that can be done offline).

	I just noticed the man page.  Yup there's some cleanup.  The
	only comment relative to the review is how will the -d <displayname>
	switch be handled?

>   It will either use uadmin(1) or the equivilent code.  I will work 
> with the auditing team (Gary) for the best method.

	;-)

Gary..

From randy.fishel@sun.com Tue Feb 17 17:51:43 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I1phPN001596
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 17:51:43 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n1I1pg9U016318
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 17 Feb 2009 17:51:43 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800B0DNU64B00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Feb 2009 18:51:42 -0700 (MST)
Received: from grimmy.sfbay.sun.com ([129.146.108.114])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF800IJDNU5YJ80@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Feb 2009 18:51:42 -0700 (MST)
Received: from grimmy.eng.sun.com (localhost [127.0.0.1])
	by grimmy.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I1i801004601; Tue,
 17 Feb 2009 17:44:08 -0800 (PST)
Received: from localhost (randyf@localhost)
	by grimmy.eng.sun.com (8.13.8+Sun/8.13.8/Submit) with ESMTP id n1I1i8ew004597;
 Tue, 17 Feb 2009 17:44:08 -0800 (PST)
Date: Tue, 17 Feb 2009 17:44:08 -0800 (PST)
From: Randy Fishel <randy.fishel@sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
In-reply-to: <200902180119.n1I1JmaG003679@marduk.eng.sun.com>
X-X-Sender: randyf@grimmy
To: Gary Winiger <gww@eng.sun.com>
Cc: PSARC-ext@sun.com, randyf@sac.sfbay.sun.com, pm-dev@opensolaris.org
Message-id: <alpine.GSO.1.10.0902171732550.4575@grimmy>
MIME-version: 1.0
Content-type: TEXT/PLAIN; charset=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200902180119.n1I1JmaG003679@marduk.eng.sun.com>
X-Authentication-warning: grimmy.eng.sun.com: randyf owned process doing -bs
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
Status: RO
Content-Length: 1672


On Tue, 17 Feb 2009, Gary Winiger wrote:

> > I am sponsoring this fasttrack on behalf of myself.  It provides the
> > replacement CLI tool for the EOF'd CDE sys-suspend command.  The
> > timeout is 2/23/09.
> 
> +1 with a couple nits (below)
> 
> > /usr/bin/sys-suspend will also use the power management 'suspend'
> > authorizations defined in PSARC/2008/021 (see below), and will not use
> > /etc/default/sys-suspend.
> 
> 	Nit: the committee should note this is an incompatible change
> 	as it doesn't account for non-console user.  IMO, this is
> 	not an issue for this project since it is a Minor release
> 	and /etc/default/sys-suspend is EOLed in the LSARC/2008/763.


  I forgot to note that there is a proposed man page in the case 
directory.  This text starts to touch on documenting the RBAC usage.  
I expect that the paragraph in question can be improved with a little 
help from Gary before it is integrated (but that can be done offline).


> > Imports
> >     Interface				Case
> >     =================================================
> >     solaris.system.power.suspend.ram	PSARC 2008/021
> >     solaris.system.power.suspend.disk	PSARC 2008/021
> 
> 	Nit:  While possibly an implementation detail, as I understand
> 	how the project team will deal with proper interaction with
> 	the Audit subsystem is by using uadmin(1).  In the present
> 	implementation, this would seem an important interface to note.
> 	IIUC, the future project may replace the use of uadmin(1)
> 	with a library equivalent.
> 

  It will either use uadmin(1) or the equivilent code.  I will work 
with the auditing team (Gary) for the best method.

> Gary..
> 



	---- Randy

From gdamore@sun.com Tue Feb 17 18:22:49 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I2Mnw7005099
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 18:22:49 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n1I2Mnru004411
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 17 Feb 2009 18:22:49 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800E09P9Z4100@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Feb 2009 19:22:47 -0700 (MST)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF800IOHP9ZYCD0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Feb 2009 19:22:47 -0700 (MST)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n1I2MlsB007487	for
 <PSARC-ext@sun.com>; Tue, 17 Feb 2009 18:22:47 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KF800F00OB27100@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Feb 2009 18:03:51 -0800 (PST)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 with ESMTPSA id <0KF80034AOEA6640@fe-sfbay-09.sun.com>; Tue,
 17 Feb 2009 18:03:51 -0800 (PST)
Date: Tue, 17 Feb 2009 18:22:41 -0800
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
In-reply-to: <200902180044.n1I0iY16003602@marduk.eng.sun.com>
Sender: Garrett.Damore@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: randyf@sac.sfbay.sun.com, PSARC-ext@sun.com, pm-dev@opensolaris.org
Message-id: <499B70F1.2080207@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200902180044.n1I0iY16003602@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 1590

Gary Winiger wrote:
>> I'm kind of concerned here -- if there is a requirement for software to 
>> do something else, then this needs to be fully documented -- including 
>> in the man pages.
>>     
>
> 	I've tried to get the folks, if there are any, who own uadmin(2)
> 	to update the man page to actually describe what it does.  The
> 	man page CR is not getting any attention.  Beyond the power management
> 	stuff, which the Audit team is working with, there doesn't
> 	appear to be anyone who cares.
>
>   
>> I don't believe it is reasonable to expect 3rd party callers of 
>> documented system calls to know about undocumented requirements.
>>     
>
> 	Do you have some suggestions?  I could file a P2 man page
> 	bug saying this man page is horribly out of date and I don't
> 	know how to fix it.  Don't use uadmin(1) only call uadmin(1),
> 	but that seems equally as broken as the uadmin(2) documentation.
> 	I believe the power management team has a medimum term solution
> 	to do all the right stuff and maybe even interpose in libc
> 	with stuff that does all the right stuff.
> 	sys-suspend(1) proposed here is to help OpenSolaris until
> 	that solution is in place.
>   

There are other programs that call uadmin.  I've written one myself 
while I was working at a customer site ages ago.

We need either in-kernel or libc interposer support... or significantly 
improved documentation (and possibly a reclassification  of uadmin(2)'s 
stability level if we think folks shouldn't be calling it directly.)

A P2 man page bug is just a start.

    -- Garrett

> Gary..
>   


From gww@eng.sun.com Tue Feb 17 20:43:37 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I4hbRR003042
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 20:43:37 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n1I4hVg2009364;
	Wed, 18 Feb 2009 04:43:34 GMT
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800503VSLDQ00@nwk-avmta-2.sfbay.sun.com>; Tue,
 17 Feb 2009 20:43:33 -0800 (PST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF8002JCVSKJR30@nwk-avmta-2.sfbay.sun.com>; Tue,
 17 Feb 2009 20:43:33 -0800 (PST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n1I4hW9U049887; Tue, 17 Feb 2009 20:43:32 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n1I4fxPc003958; Tue,
 17 Feb 2009 20:41:59 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n1I4fxOU003957; Tue,
 17 Feb 2009 20:41:59 -0800 (PST)
Date: Tue, 17 Feb 2009 20:41:59 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
To: gww@eng.sun.com, gdamore@sun.com
Cc: randyf@sac.sfbay.sun.com, PSARC-ext@sun.com, pm-dev@opensolaris.org
Message-id: <200902180441.n1I4fxOU003957@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 459

> There are other programs that call uadmin.  I've written one myself 
> while I was working at a customer site ages ago.
> 
> We need either in-kernel or libc interposer support... or significantly 
> improved documentation (and possibly a reclassification  of uadmin(2)'s 
> stability level if we think folks shouldn't be calling it directly.)
> 
> A P2 man page bug is just a start.

	Not this case.  And feel free to file it with a suggested fix.

Gary..

From gdamore@sun.com Tue Feb 17 22:05:46 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I65kf3007137
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Feb 2009 22:05:46 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n1I65h31003246
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 18 Feb 2009 06:05:45 GMT
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF800F01ZLKA100@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Tue, 17 Feb 2009 22:05:44 -0800 (PST)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF80027LZLJJIE0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Tue,
 17 Feb 2009 22:05:43 -0800 (PST)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n1I65h1J016269	for
 <PSARC-ext@Sun.COM>; Tue, 17 Feb 2009 22:05:43 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KF800I00Z9MAR00@fe-sfbay-10.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Tue, 17 Feb 2009 22:05:43 -0800 (PST)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 with ESMTPSA id <0KF800DXKZL963C0@fe-sfbay-10.sun.com>; Tue,
 17 Feb 2009 22:05:43 -0800 (PST)
Date: Tue, 17 Feb 2009 22:05:33 -0800
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
In-reply-to: <200902180441.n1I4fxOU003957@marduk.eng.sun.com>
Sender: Garrett.Damore@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: randyf@sac.sfbay.sun.com, PSARC-ext@sun.com, pm-dev@opensolaris.org
Message-id: <499BA52D.5060104@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200902180441.n1I4fxOU003957@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 985

Gary Winiger wrote:
>> There are other programs that call uadmin.  I've written one myself 
>> while I was working at a customer site ages ago.
>>
>> We need either in-kernel or libc interposer support... or significantly 
>> improved documentation (and possibly a reclassification  of uadmin(2)'s 
>> stability level if we think folks shouldn't be calling it directly.)
>>
>> A P2 man page bug is just a start.
>>     
>
> 	Not this case.  And feel free to file it with a suggested fix.
>
> Gary..
>   

I agree not this case.  The case it should have been is the case where 
ever the new requirements surrounding use of uadmin(2) were established.

I'm not the right one to file the uadmin(2) man page bug, because I have 
*no* idea what the content should say.  Indeed, I have no clear idea 
what the audit requirements (or other requirements) for callers of 
uadmin(2) would be -- the very fact that there were such requirements 
came as a complete surprise to me.

    -- Garrett

From Darren.Moffat@sun.com Wed Feb 18 01:55:28 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1I9tS8C007212
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 18 Feb 2009 01:55:28 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n1I9tRY6003903
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 18 Feb 2009 01:55:27 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KF900D09A8FL400@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 18 Feb 2009 02:55:27 -0700 (MST)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KF9001W7A8DP7E0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 18 Feb 2009 02:55:26 -0700 (MST)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n1I9tPD9010559	for
 <PSARC-ext@sun.com>; Wed, 18 Feb 2009 09:55:25 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KF900400A372H00@fe-emea-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 18 Feb 2009 09:55:25 +0000 (GMT)
Received: from [129.156.173.21] ([unknown] [129.156.173.21])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 with ESMTPSA id <0KF900KUGA7WI040@fe-emea-10.sun.com>; Wed,
 18 Feb 2009 09:55:09 +0000 (GMT)
Date: Wed, 18 Feb 2009 09:55:08 +0000
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: sys-suspend(1) [PSARC/2009/112 FastTrack timeout 02/23/2009]
In-reply-to: <200902180119.n1I1JmaG003679@marduk.eng.sun.com>
Sender: Darren.Moffat@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: PSARC-ext@sun.com, randyf@sac.sfbay.sun.com, pm-dev@opensolaris.org
Message-id: <499BDAFC.8030209@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200902180119.n1I1JmaG003679@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 1206

Gary Winiger wrote:
>> I am sponsoring this fasttrack on behalf of myself.  It provides the
>> replacement CLI tool for the EOF'd CDE sys-suspend command.  The
>> timeout is 2/23/09.
> 
> +1 with a couple nits (below)
> 
>> /usr/bin/sys-suspend will also use the power management 'suspend'
>> authorizations defined in PSARC/2008/021 (see below), and will not use
>> /etc/default/sys-suspend.
> 
> 	Nit: the committee should note this is an incompatible change
> 	as it doesn't account for non-console user. 

Except that it does but by RBAC authorisations instead of the 
/etc/default/sys-suspend file.  The default behaviour is the same, ie 
the user on the console can suspend/shutdown because of infrastructure 
provided in other cases.

 >						 IMO, this is
> 	not an issue for this project since it is a Minor release
> 	and /etc/default/sys-suspend is EOLed in the LSARC/2008/763.

Not just that but 2008/021 provided full and better replacement for 
those interfaces anyway.

Overall I'm happy with the case and I'm also happy that this project 
team is actively working on the Audit issues not just in this case but 
for the future too.  So this case has my +1 as specified.

-- 
Darren J Moffat

