qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] Changing vmexit behavior for a running guest
@ 2011-12-17 14:22 panda23
  0 siblings, 0 replies; only message in thread
From: panda23 @ 2011-12-17 14:22 UTC (permalink / raw)
  To: qemu-devel

[-- Attachment #1: Type: text/plain, Size: 332 bytes --]

For sandboxing some forms of untrusted code, the risk of a red pill
could be greatly reduced if qemu had "seccomp" mode, i.e., a way for a
guest OS to request that qemu drop any future unwhitelisted vmexit
calls.  How complicated would it be to add this functionality to qemu
and which parts of qemu would I need to modify?

Jason


[-- Attachment #2: Type: text/html, Size: 407 bytes --]

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2011-12-17 14:22 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-12-17 14:22 [Qemu-devel] Changing vmexit behavior for a running guest panda23

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).