qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Anthony Liguori <anthony@codemonkey.ws>
To: qemu-devel@nongnu.org
Subject: Re: [Qemu-devel] [PATCH] mark nic as trusted
Date: Thu, 08 Jan 2009 13:58:31 -0600	[thread overview]
Message-ID: <49665AE7.3000708@codemonkey.ws> (raw)
In-Reply-To: <20090107194633.GB19406@redhat.com>

Gleb Natapov wrote:
> On Wed, Jan 07, 2009 at 01:26:05PM -0600, Anthony Liguori wrote:
>   
>> Gleb Natapov wrote:
>>     
>>> On Wed, Jan 07, 2009 at 11:54:29AM -0600, Anthony Liguori wrote:
>>>   
>>>       
>>>> Anthony Liguori wrote:
>>>>     
>>>>         
>>>>>> That is for secure guest<->host communication over network. Guest has to
>>>>>> know somehow which link host uses for communication. If guest has no way
>>>>>> to know this, another computer on untrusted network can pretend 
>>>>>> it is real
>>>>>> host and "own" a guest.           
>>>>>>             
>>>>> So this is for vmchannel?  How do you differentiate a real device 
>>>>> with  that bit set compared to the vmchannel device?
>>>>>       
>>>>>           
>>>> Like if you were doing PCI passthrough of an e1000...
>>>>
>>>>     
>>>>         
>>> It's not just one bit. It is 14 byte string. We can put something unique there.
>>>   
>>>       
>> This is for vmchannel?  Why not add a feature to virtio-net?
>>
>>     
> Yes. This is for vmchannel. Or any other management solution that work
> over network. It has to know what network it can trust. The alternative
> is much more complex (security certificates, etc).  Why do it virtio-net
> specific? What's wrong with more general solution?
>   

Does Windows provide an API for determining "trustedness"?  How is this 
exposed to userspace in Linux?

The thinking behind virtio-net is that you may want to expose a 
different userspace interface in Windows than networking (maybe 
something more direct) since it may be impossible to get around the 
Windows firewalling nonsense.  With virtio-net, you could have the 
Windows driver check the special "vmchannel" flag and present a 
different userspace interface than the traditional network driver.

Although that's just a thought.

Regards,

Anthony Liguori

> --
> 			Gleb.
>
>
>   

  reply	other threads:[~2009-01-08 19:58 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-01-07 14:26 [Qemu-devel] [PATCH] mark nic as trusted Gleb Natapov
2009-01-07 15:04 ` Mark McLoughlin
2009-01-07 15:19   ` Gleb Natapov
2009-01-07 15:41     ` Mark McLoughlin
2009-01-07 16:02       ` Gleb Natapov
2009-01-07 16:34 ` Anthony Liguori
2009-01-07 16:50   ` Gleb Natapov
2009-01-07 17:53     ` Anthony Liguori
2009-01-07 17:54       ` Anthony Liguori
2009-01-07 18:41         ` Gleb Natapov
2009-01-07 19:26           ` Anthony Liguori
2009-01-07 19:46             ` Gleb Natapov
2009-01-08 19:58               ` Anthony Liguori [this message]
2009-01-08 21:26                 ` Gleb Natapov
2009-01-08 21:42                   ` Anthony Liguori
2009-01-08 22:49                     ` Jamie Lokier
2009-01-08 23:14                       ` Dor Laor
2009-01-09 10:41                         ` Daniel P. Berrange
2009-01-10  2:18                           ` Jamie Lokier
2009-01-10 18:22                             ` Anthony Liguori
2009-01-11  4:55                               ` Jamie Lokier
2009-01-11  7:10                                 ` Blue Swirl
2009-01-11 14:08                                   ` Carl-Daniel Hailfinger
2009-01-11 15:07                                     ` Dor Laor
2009-01-11 15:34                                       ` Blue Swirl
2009-01-11 16:01                                         ` Dor Laor
2009-01-12  2:20                                           ` Jamie Lokier
2009-01-12  8:05                                             ` Gleb Natapov
2009-01-12 12:26                                               ` Dor Laor
2009-01-10  2:27                         ` Jamie Lokier
2009-01-08 23:26                       ` Anthony Liguori
2009-01-10  2:31                         ` Jamie Lokier
2009-01-10 18:24                           ` Anthony Liguori
2009-01-11  4:40                             ` Jamie Lokier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=49665AE7.3000708@codemonkey.ws \
    --to=anthony@codemonkey.ws \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).