[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] regarding privileges



> for setting the hardware clock:
> i think things like this shouldn't be granted to dom0 by
> default, but be manually granted to specific doms.
> 
> it would be preferable to run ntpd in an unprivileged domain, dom0 is
> just too valuable for this.

That's a fair point. The intention is to split up the 'privilege'
in to a bit mask to enable finer grained control and granting of
specific privileges to domains, (like the 'CAP_*' stuff in
Linux). It should be a fairly simple task to split the privileges
up -- one for the todo list.

Ian


-------------------------------------------------------
This SF.net email is sponsored by: The SF.net Donation Program.
Do you like what SourceForge.net is doing for the Open
Source Community?  Make a contribution, and help us add new
features and functionality. Click here: http://sourceforge.net/donate/
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxxxx
https://lists.sourceforge.net/lists/listinfo/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.