qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] [PATCH v2 0/2] restrict the privilege of the xenstore connection
@ 2015-06-04 11:20 Stefano Stabellini
  2015-06-04 11:21 ` [Qemu-devel] [PATCH v2 1/2] xen: separate the xenstore_record_dm_state calls for pv and hvm machines Stefano Stabellini
  2015-06-04 11:21 ` [Qemu-devel] [PATCH v2 2/2] xen: introduce xsrestrict Stefano Stabellini
  0 siblings, 2 replies; 3+ messages in thread
From: Stefano Stabellini @ 2015-06-04 11:20 UTC (permalink / raw)
  To: qemu-devel; +Cc: xen-devel, Ian Jackson, Ian Campbell, Stefano Stabellini

Hi all,

this patch series introduces a new command line option to restrict the
privilege of the xenstore connection. Used together with -runas, can
help secure the execution of QEMU in Dom0.


Changes in v2:
- remove xenstore_record_dm_state and open code the xenstore write
instead
- change the xenpv machine xenstore path for startup notification to
device-model/$DOMID/pv/state


Stefano Stabellini (2):
      xen: separate the xenstore_record_dm_state calls for pv and hvm machines
      xen: introduce xsrestrict

 hw/xenpv/xen_machine_pv.c |   10 ++++++++++
 include/hw/xen/xen.h      |    2 ++
 qemu-options.hx           |   15 +++++++++++++++
 vl.c                      |    8 ++++++++
 xen-common-stub.c         |    2 ++
 xen-common.c              |   29 -----------------------------
 xen-hvm.c                 |   44 ++++++++++++++++++++++++++++++++++++--------
 7 files changed, 73 insertions(+), 37 deletions(-)

Cheers,

Stefano

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2015-06-04 11:22 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-06-04 11:20 [Qemu-devel] [PATCH v2 0/2] restrict the privilege of the xenstore connection Stefano Stabellini
2015-06-04 11:21 ` [Qemu-devel] [PATCH v2 1/2] xen: separate the xenstore_record_dm_state calls for pv and hvm machines Stefano Stabellini
2015-06-04 11:21 ` [Qemu-devel] [PATCH v2 2/2] xen: introduce xsrestrict Stefano Stabellini

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).