From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1N52Xo-00009g-Qb for qemu-devel@nongnu.org; Mon, 02 Nov 2009 14:26:24 -0500 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1N52Xm-00009A-8p for qemu-devel@nongnu.org; Mon, 02 Nov 2009 14:26:23 -0500 Received: from [199.232.76.173] (port=33220 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1N52Xm-000097-4B for qemu-devel@nongnu.org; Mon, 02 Nov 2009 14:26:22 -0500 Received: from adelie.canonical.com ([91.189.90.139]:60231) by monty-python.gnu.org with esmtp (Exim 4.60) (envelope-from ) id 1N52Xl-0007Oa-Q7 for qemu-devel@nongnu.org; Mon, 02 Nov 2009 14:26:21 -0500 Subject: Re: [Qemu-devel] Re: [PATCH] whitelist host virtio networking features [was Re: qemu-kvm-0.11 regression, crashes on older ...] From: Dustin Kirkland In-Reply-To: <4AEF2B28.6000303@codemonkey.ws> References: <1256815818-sup-7805@xpc65.scottt> <1256818566.10825.58.camel@blaa> <4AE9A299.5060003@codemonkey.ws> <1256826351.10825.69.camel@blaa> <4AE9A90F.1060108@codemonkey.ws> <1256827719.10825.75.camel@blaa> <1256830455.25064.155.camel@x200> <1257172722.5075.7.camel@blaa> <4AEEFDCE.1000006@codemonkey.ws> <20091102155228.GB9655@shareable.org> <4AEF2B28.6000303@codemonkey.ws> Content-Type: multipart/signed; micalg="pgp-sha1"; protocol="application/pgp-signature"; boundary="=-LjUeVpF10Jq/eNtVWin4" Date: Mon, 02 Nov 2009 13:25:55 -0600 Message-ID: <1257189955.3512.236.camel@x200> Mime-Version: 1.0 Reply-To: kirkland@canonical.com List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Anthony Liguori Cc: Mark McLoughlin , Scott Tsai , kvm , Rusty Russell , qemu-devel , jdstrand@canonical.com, Marc Deslauriers , kees.cook@canonical.com --=-LjUeVpF10Jq/eNtVWin4 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Mon, 2009-11-02 at 12:55 -0600, Anthony Liguori wrote: > They can exit qemu via an ACPI shutdown. I don't see the difference. An ACPI shutdown is triggered by an authenticated user inside of the guest. The present exit is triggered by any other anonymous user on the network, with the ability to send a lot of packets very quickly to the VM guest. The guest isn't able to handle this properly (and rightly that guest's kernel should be fixed). But I do see a difference. :-Dustin --=-LjUeVpF10Jq/eNtVWin4 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEABECAAYFAkrvMkMACgkQs7pNXIOmEZQ8hwCgvJcswNKnVqYjXbIsznNe6ils FZ8AnAvBDqmYK/jTUYCDaK5P3xiYPIWy =zJPc -----END PGP SIGNATURE----- --=-LjUeVpF10Jq/eNtVWin4--