All of lore.kernel.org
 help / color / mirror / Atom feed
From: Nix <nix@esperi.org.uk>
To: Jeff Dike <jdike@addtoit.com>
Cc: Rob Landley <rob@landley.net>,
	user-mode-linux-devel@lists.sourceforge.net,
	Can Sar <csar@stanford.edu>
Subject: Re: [uml-devel] Making UML Single Threader
Date: Mon, 14 Nov 2005 13:59:40 +0000	[thread overview]
Message-ID: <87lkzrwcs3.fsf@amaterasu.srvr.nix> (raw)
In-Reply-To: <20051108154618.GB4131@ccure.user-mode-linux.org> (Jeff Dike's message of "Tue, 8 Nov 2005 10:46:18 -0500")

On Tue, 8 Nov 2005, Jeff Dike prattled cheerily:
> On Tue, Nov 08, 2005 at 01:09:06AM -0600, Rob Landley wrote:
>> > So I don't care about systemcall interception or anything like that,
>> 
>> *blink*  *blink*
>> 
>> Ok, you want user mode linux, but you don't want it to actually run user 
>> processes, nor do want it to be able to intercept system calls.
>> 
>> Um...  What's left?
> 
> Only all of Linux.  It so happens that I want exactly the same thing for 
> libUML, except I haven't had time to do anything about it.

I've long wanted to do the same sort of thing, to do with a UML the same
sort of thing you can do with a real Linux box: that is, set up
networking and a bridging firewall, then halt it: the kernel keeps
processing network packets and firewalling and bridging them perfectly
well, but attackers now have *real* trouble changing the configuration.
You stop it with kill() on the host, or mconsole; as it's halted and all
fsen are unmounted and so on, you're safe from filesystem corruption.

When combined with CONFIG_NETCONSOLE, you can even keep an eye on it. :)

The necessary hack looks quite simple: I just haven't got around to it.

-- 
`Holy Google, pray for us sinners now and in the hour of our job interview.'


-------------------------------------------------------
SF.Net email is sponsored by:
Tame your development challenges with Apache's Geronimo App Server. Download
it for free - -and be entered to win a 42" plasma tv or your very own
Sony(tm)PSP.  Click here to play: http://sourceforge.net/geronimo.php
_______________________________________________
User-mode-linux-devel mailing list
User-mode-linux-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/user-mode-linux-devel

  parent reply	other threads:[~2005-11-14 14:00 UTC|newest]

Thread overview: 35+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-11-06 23:23 [uml-devel] Does UML 2.6.14 work under x86-64? Rob Landley
2005-11-07 16:25 ` Jeff Dike
2005-11-07 19:32 ` Blaisorblade
2005-11-07 14:38   ` David Lang
2005-11-07 19:44   ` Blaisorblade
2005-11-08  0:53   ` Rob Landley
2005-11-07 14:47     ` David Lang
2005-11-07 15:30       ` David Lang
2005-11-08  3:39       ` Rob Landley
2005-11-08  5:13 ` [uml-devel] Making UML Single Threader Can Sar
2005-11-08  7:09   ` Rob Landley
2005-11-08  7:44     ` Can Sar
2005-11-09  0:35       ` Rob Landley
2005-11-09  0:48         ` Blaisorblade
2005-11-09  1:17           ` Rob Landley
2005-11-09  1:31             ` Blaisorblade
2005-11-09  3:18               ` Rob Landley
2005-11-10  4:18                 ` Jeff Dike
2005-11-10  4:58                   ` Rob Landley
2005-11-10  6:23                     ` Henrik Nordstrom
2005-11-10  4:07         ` Jeff Dike
2005-11-10  3:55           ` Rob Landley
2005-11-08 15:46     ` Jeff Dike
2005-11-09  0:27       ` Rob Landley
2005-11-14 13:59       ` Nix [this message]
2005-11-14 19:37         ` Blaisorblade
2005-11-14 20:00           ` Nix
2005-11-14 20:05             ` Geert Uytterhoeven
2005-11-15 11:39           ` Henrik Nordstrom
2005-11-16  1:23             ` Rob Landley
2005-11-08 16:13     ` Blaisorblade
2005-11-09  0:51       ` Rob Landley
2005-11-08 15:43   ` Jeff Dike
2005-11-08 16:10     ` Blaisorblade
2005-11-08 19:11     ` Can Sar

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87lkzrwcs3.fsf@amaterasu.srvr.nix \
    --to=nix@esperi.org.uk \
    --cc=csar@stanford.edu \
    --cc=jdike@addtoit.com \
    --cc=rob@landley.net \
    --cc=user-mode-linux-devel@lists.sourceforge.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.