kvm.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Re: [Qemu-devel] QEMU-KVM and hardened (GRSEC/PaX) kernel
       [not found] <BANLkTi==x5GF+BC4q=fSVvYLE_XY=SvxTw@mail.gmail.com>
@ 2011-04-20 14:29 ` Avi Kivity
  0 siblings, 0 replies; only message in thread
From: Avi Kivity @ 2011-04-20 14:29 UTC (permalink / raw)
  To: anton.kochkov; +Cc: qemu-devel, KVM list

On 04/17/2011 01:45 AM, Антон Кочков wrote:
> Good day!
> I'm trying to make working qemu-kvm with hardened gentoo on hardened kernel.
> When i'm using CONFIG_PAX_KERNPAGEXEC and CONFIG_PAX_MEM_UNDEREF qemu just start
> and go to infinite loop and take 100% of one of my CPU core. adn it
> even can't be killed.
> Also it is dont give answer for qemu monitor/remote gdb.
> When I'm changed these two values as disabled, qemu-kvm now start, and
> stop (i mean qemu monitor show that virtual machine is running, but no
> any activity/output). Also it's load about 0%.
> See details in bug http://bugs.gentoo.org/show_bug.cgi?id=363713
>
> Hope this info help improve qemu-kvm.
>

As Blue says, the problem is likely in kvm, not qemu.

Please try:
- hardened guest on soft host (I expect this to work)
- soft guest on hardened host (I expect this to fail).

Are you using an Intel or AMD host?

Note virtualization hardware will play with segmentation and defeat all 
those games the hardened kernel plays.

-- 
error compiling committee.c: too many arguments to function


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2011-04-20 14:29 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <BANLkTi==x5GF+BC4q=fSVvYLE_XY=SvxTw@mail.gmail.com>
2011-04-20 14:29 ` [Qemu-devel] QEMU-KVM and hardened (GRSEC/PaX) kernel Avi Kivity

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).