WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

[Xen-devel] Re: [Qemu-devel] Recursion in cpu_physical_memory_rw

To: Anthony Liguori <aliguori@xxxxxxxxxx>
Subject: [Xen-devel] Re: [Qemu-devel] Recursion in cpu_physical_memory_rw
From: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Date: Thu, 16 Nov 2006 16:11:58 +1100
Cc: Xen Development Mailing List <xen-devel@xxxxxxxxxxxxxxxxxxx>, qemu-devel@xxxxxxxxxx
Delivery-date: Wed, 15 Nov 2006 21:12:13 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <455B6486.8080604@xxxxxxxxxx>
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
References: <20061115004350.GA21745@xxxxxxxxxxxxxxxxxxx> <200611150057.27235.paul@xxxxxxxxxxxxxxxx> <20061115025839.GA22608@xxxxxxxxxxxxxxxxxxx> <455B6486.8080604@xxxxxxxxxx>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Mutt/1.5.9i
On Wed, Nov 15, 2006 at 01:03:34PM -0600, Anthony Liguori wrote:
>
> >The scenario here is a compromised guest attempting to harm a host such
> >as Xen.
> 
> The only "harm" done to a host is that the process will take as much CPU 
> as it can get.  This is really only a problem in Xen because the device 
> model is in Domain-0.  Once the device model is in a different domain, 
> it doesn't matter anymore as the normal scheduler parameters can be used 
> to ensure that no other hosts are harmed.

Actually it'll still be a problem in a driver domain unless it (and the
hardware) is dedicated to a single guest.

Cheers,
-- 
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel