All of lore.kernel.org
 help / color / mirror / Atom feed
From: Avi Kivity <avi@redhat.com>
To: Arnd Bergmann <arnd@arndb.de>
Cc: "Michael S. Tsirkin" <mst@redhat.com>,
	anthony@codemonkey.ws, virtualization@lists.linux-foundation.org,
	kvm@vger.kernel.org, Rusty Russell <rusty@rustcorp.com.au>
Subject: Re: vhost-net todo list
Date: Wed, 16 Sep 2009 20:13:03 +0300	[thread overview]
Message-ID: <4AB11C9F.8020001@redhat.com> (raw)
In-Reply-To: <200909161727.26153.arnd@arndb.de>

On 09/16/2009 06:27 PM, Arnd Bergmann wrote:
> That scenario is probably not so relevant for KVM, unless you
> consider the guest taking over the qemu host process a valid
> security threat.
>    

It is.  We address it by using SCM_RIGHTS for all sensitive operations 
and selinuxing qemu as tightly as possible.

-- 
I have a truly marvellous patch that fixes the bug which this
signature is too narrow to contain.


  parent reply	other threads:[~2009-09-16 17:13 UTC|newest]

Thread overview: 41+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-09-16 10:04 vhost-net todo list Michael S. Tsirkin
2009-09-16 14:52 ` Arnd Bergmann
2009-09-16 14:52 ` Arnd Bergmann
2009-09-16 14:58   ` Michael S. Tsirkin
2009-09-16 14:58   ` Michael S. Tsirkin
2009-09-16 15:08     ` Arnd Bergmann
2009-09-16 15:08     ` Arnd Bergmann
2009-09-16 15:19       ` Michael S. Tsirkin
2009-09-16 15:19       ` Michael S. Tsirkin
2009-09-16 15:27         ` Arnd Bergmann
2009-09-16 15:46           ` GDB + KVM Debug Saksena, Abhishek
2009-09-16 16:02             ` Jan Kiszka
2009-09-16 16:24               ` Saksena, Abhishek
2009-09-16 16:37                 ` Jan Kiszka
2009-09-16 17:15                   ` Avi Kivity
2009-09-16 17:56                     ` Jan Kiszka
2009-09-16 18:26                       ` Avi Kivity
2009-09-16 18:49                   ` Saksena, Abhishek
2009-09-17  8:35                     ` Jan Kiszka
2009-10-20 18:48                       ` Saksena, Abhishek
2009-10-23 17:01                         ` Jan Kiszka
2009-10-23 16:19                       ` GDB Debugging Saksena, Abhishek
2009-10-24 16:44                         ` Yolkfull Chow
2009-09-16 16:45           ` vhost-net todo list Michael S. Tsirkin
2009-09-16 16:45           ` Michael S. Tsirkin
2009-09-17 11:30             ` Arnd Bergmann
2009-09-17 11:47               ` Michael S. Tsirkin
2009-09-17 12:14                 ` Arnd Bergmann
2009-09-17 12:14                 ` Arnd Bergmann
2009-09-17 12:25                   ` Michael S. Tsirkin
2009-09-17 15:08                     ` Arnd Bergmann
2009-09-17 15:08                     ` Arnd Bergmann
2009-09-17 12:25                   ` Michael S. Tsirkin
2009-09-17 11:47               ` Michael S. Tsirkin
2009-09-17 11:30             ` Arnd Bergmann
2009-09-16 17:13           ` Avi Kivity
2009-09-16 17:13           ` Avi Kivity [this message]
2009-09-16 15:27         ` Arnd Bergmann
2009-09-16 15:01   ` Michael S. Tsirkin
2009-09-16 15:01   ` Michael S. Tsirkin
  -- strict thread matches above, loose matches on Subject: below --
2009-09-16 10:04 Michael S. Tsirkin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4AB11C9F.8020001@redhat.com \
    --to=avi@redhat.com \
    --cc=anthony@codemonkey.ws \
    --cc=arnd@arndb.de \
    --cc=kvm@vger.kernel.org \
    --cc=mst@redhat.com \
    --cc=rusty@rustcorp.com.au \
    --cc=virtualization@lists.linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.