public inbox for kvm@vger.kernel.org
 help / color / mirror / Atom feed
From: Markus Armbruster <armbru@redhat.com>
To: Sasha Levin <levinsasha928@gmail.com>
Cc: Pekka Enberg <penberg@kernel.org>,
	Anthony Liguori <anthony@codemonkey.ws>,
	Pekka Enberg <penberg@cs.helsinki.fi>,
	Linus Torvalds <torvalds@linux-foundation.org>,
	Avi Kivity <avi@redhat.com>,
	Andrew Morton <akpm@linux-foundation.org>,
	Ingo Molnar <mingo@elte.hu>,
	linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
	Christoph Hellwig <hch@lst.de>
Subject: Re: [RFC/GIT PULL] Linux KVM tool for v3.2
Date: Thu, 10 Nov 2011 09:57:01 +0100	[thread overview]
Message-ID: <m3fwhws6ci.fsf@blackfin.pond.sub.org> (raw)
In-Reply-To: <CA+1xoqe22z9F3ZyFG_XnV9Y17HtkeSxtf1gbW4+CW1cuNQ=N5g@mail.gmail.com> (Sasha Levin's message of "Thu, 10 Nov 2011 10:23:23 +0200")

Sasha Levin <levinsasha928@gmail.com> writes:

> On Thu, Nov 10, 2011 at 9:57 AM, Markus Armbruster <armbru@redhat.com> wrote:
[...]
>> Start with a clean read/write raw image.  Probing declares it raw.
>> Guest writes QCOW signature to it, with a backing file of its choice.
>>
>> Restart with the same image.  Probing declares it QCOW2.  Guest can read
>> the backing file.  Oops.
>
> Thats an excellent scenario why you'd want to have 'Secure KVM' with
> seccomp filters :)

Yup.

For what it's worth, sVirt (use SELinux to secure virtualization)
mitigates the problem.  Doesn't mean we couldn't use "Secure KVM".

> I'm actually not sure why KVM tool got QCOW support in the first
> place. You can have anything QCOW provides if you use btrfs (among
> several other FSs).

Maybe it's just me, but isn't it weird to have a filesystem (QCOW2)
sitting in the kernel sources that you can't mount(2)?

  parent reply	other threads:[~2011-11-10  8:57 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-11-04  8:38 [RFC/GIT PULL] Linux KVM tool for v3.2 Pekka Enberg
2011-11-04 12:16 ` Christoph Hellwig
2011-11-04 12:35   ` Pekka Enberg
2011-11-04 13:02     ` Christoph Hellwig
2011-11-04 13:32       ` Pekka Enberg
2011-11-04 14:42         ` Jan Kiszka
2011-11-04 15:16           ` Sasha Levin
2011-11-04 16:26             ` Jan Kiszka
2011-11-04 16:48               ` Sasha Levin
2011-11-04 17:33                 ` Jan Kiszka
2011-11-04 16:13           ` Joerg Roedel
2011-11-04 16:42             ` Jan Kiszka
2011-11-04 17:41               ` Pekka Enberg
2011-11-04 13:14     ` Joerg Roedel
2011-11-04 14:47 ` Jan Kiszka
2011-11-08 14:44 ` richard -rw- weinberger
2011-11-08 15:36   ` Pekka Enberg
2011-11-08 16:00     ` richard -rw- weinberger
2011-11-10  3:50 ` Anthony Liguori
2011-11-10  6:46   ` Pekka Enberg
2011-11-10  7:57     ` Markus Armbruster
2011-11-10  8:21       ` Pekka Enberg
2011-11-10  8:23       ` Sasha Levin
2011-11-10  8:28         ` Pekka Enberg
2011-11-10  8:57         ` Markus Armbruster [this message]
2011-11-10  9:04           ` Sasha Levin
2011-11-10  9:09             ` Avi Kivity
2011-11-10  9:14               ` Sasha Levin
2011-11-10  9:23                 ` Avi Kivity
2011-11-10  9:34                   ` Sasha Levin
2011-11-10  9:43                     ` Avi Kivity
2011-11-10  9:49                       ` Sasha Levin
2011-11-10  9:50                         ` Avi Kivity
2011-11-10  9:48             ` Markus Armbruster
2011-11-10 13:43     ` Anthony Liguori
2011-11-10 13:56       ` Pekka Enberg
2011-11-10 14:47         ` Markus Armbruster
2011-11-10 15:33           ` Stefan Hajnoczi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=m3fwhws6ci.fsf@blackfin.pond.sub.org \
    --to=armbru@redhat.com \
    --cc=akpm@linux-foundation.org \
    --cc=anthony@codemonkey.ws \
    --cc=avi@redhat.com \
    --cc=hch@lst.de \
    --cc=kvm@vger.kernel.org \
    --cc=levinsasha928@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@elte.hu \
    --cc=penberg@cs.helsinki.fi \
    --cc=penberg@kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox