All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel Bareiro <daniel-listas@gmx.net>
To: KVM General <kvm@vger.kernel.org>
Subject: Re: Doubt on KVM-88 vulnerabilities
Date: Mon, 14 Dec 2009 20:27:24 -0300	[thread overview]
Message-ID: <20091214232724.GC7639@defiant.freesoftware> (raw)
In-Reply-To: <4B268610.4000008@redhat.com>

[-- Attachment #1: Type: text/plain, Size: 2670 bytes --]

Hi, Avi.

On Monday, 14 December 2009 20:38:08 +0200,
Avi Kivity wrote:

>> Then, I imagine that only it would be necessary to compile the
>> userspace.

> It is not necessary to rebuild userspace, unless you want to use new
> features.

Good. Then if we did not need new features and we only want to apply
security fixes, installing kvm-kmod would be sufficient?

Backing, for example, to the DSA-1907-1 [1] with KVM-88 and Linux
2.6.30.4 from kernel.org, under this situation what version of kvm-kmod
would have to build? I remember that when I did the compilation at that
time I had to apply the patch mentioned in this [2] thread. This no
longer would be necessary?

The dependencies for kvm-kmod are the same that for kvm-nn?

I guess that during the building of the new modules, the virtual
machines would have to be down. Is this correct?

>> The steps that I habitually followed are the mentioned ones in the
>> section 'Unpacking and configuring kvm components' of this [1]
>> document, but I suppose that to only compile userspace it will be
>> necessary to follow a different procedure. Is there some document
>> that you can indicate to me where are mentioned these steps?

> I suggest downloading qemu-kvm-0.12.0-rc2.  All you need is a
> ./configure; make; make install.

I forgot to mention 'configure' in the other mail, although also I had
used it. Thanks to indicate the procedure to me. With the packages
mentioned in the dependencies for kvm-nn [3], it seems that it was
sufficient, although perhaps now it is not necessary to install all.

Now I'm having the problem that told you when I doing 'make'.

>> Very interesting the replies in this thread. It drew attention
>> powerfully to me which Michael Tokarev said that KVM never was and
>> never will be for production. Personally I'm using KVM-88 with 2.6.30
>> and it works wonderfully well.

> I doubt he meant kvm is not for production use.

It can be, or perhaps he didn't have a good day, as he said :-D

> Instead, the development snapshots are not meant for production use
> (as they do not receive updates, for example).  Instead, use the
> modules and userspace provided by your distribution, or the kvm-kmod
> and qemu-kvm packages.

Thanks for the explanation.

Thanks for your reply.

Regards,
Daniel

[1] http://lists.debian.org/debian-security-announce/2009/msg00229.html
[2] http://thread.gmane.org/gmane.comp.emulators.kvm.devel/36981/focus=36985
[3] http://www.linux-kvm.org/page/HOWTO1
-- 
Fingerprint: BFB3 08D6 B4D1 31B2 72B9  29CE 6696 BF1B 14E6 1D37
Powered by Debian GNU/Linux Lenny - Linux user #188.598

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 197 bytes --]

      reply	other threads:[~2009-12-14 23:27 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-11-08 18:42 Doubt on KVM-88 vulnerabilities Daniel Bareiro
2009-11-10 10:04 ` Avi Kivity
2009-11-10 11:10   ` Asdo
2009-11-10 12:03     ` Michael Tokarev
2009-11-10 14:19       ` Asdo
2009-11-10 14:42         ` Michael Tokarev
2009-11-10 15:05           ` Asdo
2009-11-10 16:25             ` Jan Kiszka
2009-12-14 11:08   ` Daniel Bareiro
2009-12-14 17:36     ` Daniel Bareiro
2009-12-14 18:39       ` Avi Kivity
2009-12-14 21:07         ` Daniel Bareiro
2009-12-15  1:56           ` Daniel Bareiro
2009-12-15 10:03           ` Avi Kivity
2009-12-14 18:38     ` Avi Kivity
2009-12-14 23:27       ` Daniel Bareiro [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20091214232724.GC7639@defiant.freesoftware \
    --to=daniel-listas@gmx.net \
    --cc=dbareiro@gmx.net \
    --cc=kvm@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.