From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1IC0Tc-0003Mr-VT for qemu-devel@nongnu.org; Fri, 20 Jul 2007 17:57:33 -0400 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1IC0Ta-0003Mf-IW for qemu-devel@nongnu.org; Fri, 20 Jul 2007 17:57:31 -0400 Received: from [199.232.76.173] (helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1IC0Ta-0003Mc-DG for qemu-devel@nongnu.org; Fri, 20 Jul 2007 17:57:30 -0400 Received: from py-out-1112.google.com ([64.233.166.183]) by monty-python.gnu.org with esmtp (Exim 4.60) (envelope-from ) id 1IC0Ta-0004LY-1g for qemu-devel@nongnu.org; Fri, 20 Jul 2007 17:57:30 -0400 Received: by py-out-1112.google.com with SMTP id f47so2045976pye for ; Fri, 20 Jul 2007 14:57:29 -0700 (PDT) Message-ID: <25a1d91b0707201457m6865a505maf93d22c5c28f0cc@mail.gmail.com> Date: Fri, 20 Jul 2007 17:57:29 -0400 From: "David Windsor" In-Reply-To: MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline References: <20070720201101.GC12218@redhat.com> Subject: [Qemu-devel] Re: [kvm-devel] [RFC][PATCH 00/01]qemu VM entrypoints Reply-To: qemu-devel@nongnu.org List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: "Daniel P. Berrange" Cc: David Windsor , kvm-devel , James Morris , qemu-devel , selinux , Joshua Brindle On 7/20/07, James Morris wrote: > On Fri, 20 Jul 2007, Daniel P. Berrange wrote: > > > It could be - if your put the policy at the control API layer instead of > > in QEMU itself. > I think that libvirt may be a bit too high in the virtualization stack for this control. What benefits are there for placing such a hook in libvirt vs qemu? libvirt could still use the vm:entrypoint permission for other types of VMs it manages. > Then you can bypass MAC security by invoking qemu directly. > > > - James > -- > James Morris > > > ------------------------------------------------------------------------- > This SF.net email is sponsored by: Microsoft > Defy all challenges. Microsoft(R) Visual Studio 2005. > http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ > _______________________________________________ > kvm-devel mailing list > kvm-devel@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/kvm-devel >