From: Kip Macy <kip.macy@gmail.com>
To: tanner@real-time.com
Cc: xen-devel <xen-devel@lists.xensource.com>
Subject: Re: xm create as root vs xm destroy as normal user
Date: Sat, 25 Jun 2005 16:52:42 -0700 [thread overview]
Message-ID: <b1fa291705062516522517fb81@mail.gmail.com> (raw)
In-Reply-To: <200506241724.18807@www.mn-linux.org.or.transmuter.real-time.com>
There is currently no notion of capabilities. In 3.0 the default
communication path between xm and xend is now a unix domain socket so
by default only root can execute xm commands.
-Kip
On 6/24/05, Bob Tanner <tanner@real-time.com> wrote:
> Playing around with xen-2.0.6 and I've found something troubling.
>
> I've been creating domU's with 'xm create.' As a simple security check, I did
> a 'xm shutdown' as a normal user. Much to my surprise, that domU shutdown.
>
> Does the default behavior of xen allow a non-root users to shutdown any domU?
> Even domU's that aren't created by the user issuing the 'xm shutdown'?
>
> Thanks.
> --
> Bob Tanner <tanner@real-time.com> | Phone : (952)943-8700
> http://www.real-time.com, Minnesota, Linux | Fax : (952)943-8500
> Key fingerprint = AB15 0BDF BCDE 4369 5B42 1973 7CF1 A709 2CC1 B288
>
>
> _______________________________________________
> Xen-devel mailing list
> Xen-devel@lists.xensource.com
> http://lists.xensource.com/xen-devel
>
>
>
>
next prev parent reply other threads:[~2005-06-25 23:52 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-06-24 22:24 xm create as root vs xm destroy as normal user Bob Tanner
2005-06-25 23:52 ` Kip Macy [this message]
2005-06-27 17:42 ` Bob Tanner
2005-06-27 17:54 ` Mark Williamson
2005-06-27 18:01 ` Josh Triplett
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b1fa291705062516522517fb81@mail.gmail.com \
--to=kip.macy@gmail.com \
--cc=tanner@real-time.com \
--cc=xen-devel@lists.xensource.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.