From: Daniel Bareiro <daniel-listas@gmx.net>
To: KVM General <kvm@vger.kernel.org>
Subject: Re: Doubt on KVM-88 vulnerabilities
Date: Mon, 14 Dec 2009 20:27:24 -0300 [thread overview]
Message-ID: <20091214232724.GC7639@defiant.freesoftware> (raw)
In-Reply-To: <4B268610.4000008@redhat.com>
[-- Attachment #1: Type: text/plain, Size: 2670 bytes --]
Hi, Avi.
On Monday, 14 December 2009 20:38:08 +0200,
Avi Kivity wrote:
>> Then, I imagine that only it would be necessary to compile the
>> userspace.
> It is not necessary to rebuild userspace, unless you want to use new
> features.
Good. Then if we did not need new features and we only want to apply
security fixes, installing kvm-kmod would be sufficient?
Backing, for example, to the DSA-1907-1 [1] with KVM-88 and Linux
2.6.30.4 from kernel.org, under this situation what version of kvm-kmod
would have to build? I remember that when I did the compilation at that
time I had to apply the patch mentioned in this [2] thread. This no
longer would be necessary?
The dependencies for kvm-kmod are the same that for kvm-nn?
I guess that during the building of the new modules, the virtual
machines would have to be down. Is this correct?
>> The steps that I habitually followed are the mentioned ones in the
>> section 'Unpacking and configuring kvm components' of this [1]
>> document, but I suppose that to only compile userspace it will be
>> necessary to follow a different procedure. Is there some document
>> that you can indicate to me where are mentioned these steps?
> I suggest downloading qemu-kvm-0.12.0-rc2. All you need is a
> ./configure; make; make install.
I forgot to mention 'configure' in the other mail, although also I had
used it. Thanks to indicate the procedure to me. With the packages
mentioned in the dependencies for kvm-nn [3], it seems that it was
sufficient, although perhaps now it is not necessary to install all.
Now I'm having the problem that told you when I doing 'make'.
>> Very interesting the replies in this thread. It drew attention
>> powerfully to me which Michael Tokarev said that KVM never was and
>> never will be for production. Personally I'm using KVM-88 with 2.6.30
>> and it works wonderfully well.
> I doubt he meant kvm is not for production use.
It can be, or perhaps he didn't have a good day, as he said :-D
> Instead, the development snapshots are not meant for production use
> (as they do not receive updates, for example). Instead, use the
> modules and userspace provided by your distribution, or the kvm-kmod
> and qemu-kvm packages.
Thanks for the explanation.
Thanks for your reply.
Regards,
Daniel
[1] http://lists.debian.org/debian-security-announce/2009/msg00229.html
[2] http://thread.gmane.org/gmane.comp.emulators.kvm.devel/36981/focus=36985
[3] http://www.linux-kvm.org/page/HOWTO1
--
Fingerprint: BFB3 08D6 B4D1 31B2 72B9 29CE 6696 BF1B 14E6 1D37
Powered by Debian GNU/Linux Lenny - Linux user #188.598
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 197 bytes --]
prev parent reply other threads:[~2009-12-14 23:27 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-11-08 18:42 Doubt on KVM-88 vulnerabilities Daniel Bareiro
2009-11-10 10:04 ` Avi Kivity
2009-11-10 11:10 ` Asdo
2009-11-10 12:03 ` Michael Tokarev
2009-11-10 14:19 ` Asdo
2009-11-10 14:42 ` Michael Tokarev
2009-11-10 15:05 ` Asdo
2009-11-10 16:25 ` Jan Kiszka
2009-12-14 11:08 ` Daniel Bareiro
2009-12-14 17:36 ` Daniel Bareiro
2009-12-14 18:39 ` Avi Kivity
2009-12-14 21:07 ` Daniel Bareiro
2009-12-15 1:56 ` Daniel Bareiro
2009-12-15 10:03 ` Avi Kivity
2009-12-14 18:38 ` Avi Kivity
2009-12-14 23:27 ` Daniel Bareiro [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20091214232724.GC7639@defiant.freesoftware \
--to=daniel-listas@gmx.net \
--cc=dbareiro@gmx.net \
--cc=kvm@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox