From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1MObbx-0000dR-E3 for qemu-devel@nongnu.org; Wed, 08 Jul 2009 14:11:17 -0400 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1MObbs-0000b5-NK for qemu-devel@nongnu.org; Wed, 08 Jul 2009 14:11:16 -0400 Received: from [199.232.76.173] (port=35300 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1MObbs-0000at-G2 for qemu-devel@nongnu.org; Wed, 08 Jul 2009 14:11:12 -0400 Received: from mx2.redhat.com ([66.187.237.31]:44805) by monty-python.gnu.org with esmtp (Exim 4.60) (envelope-from ) id 1MObbs-0003LJ-3b for qemu-devel@nongnu.org; Wed, 08 Jul 2009 14:11:12 -0400 Message-ID: <4A54E0CF.2010005@redhat.com> Date: Wed, 08 Jul 2009 21:09:19 +0300 From: Avi Kivity MIME-Version: 1.0 Subject: Re: [Qemu-devel] [PATCH 0/5] ATAPI pass through v2 References: <200907011931.53521.alexandre.bique@citrix.com> <20090707200327.GA3902@miranda.arrow> <4A53D2FD.4040004@codemonkey.ws> <5d3bb3090907071421i506a2f0bh5aca170c35a26f62@mail.gmail.com> <200907072344.33893.paul@codesourcery.com> <5d3bb3090907071550s6e832c45k804bca769aa57f70@mail.gmail.com> <4A53D3B1.2020903@codemonkey.ws> <19028.50372.333318.144669@mariner.uk.xensource.com> <4A54CB88.7050809@redhat.com> <4A54D722.3040602@gmx.net> In-Reply-To: <4A54D722.3040602@gmx.net> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Carl-Daniel Hailfinger Cc: Ian Jackson , Paul Brook , Alexandre Bique , qemu-devel@nongnu.org On 07/08/2009 08:28 PM, Carl-Daniel Hailfinger wrote: > On 08.07.2009 18:38, Avi Kivity wrote: > >> On 07/08/2009 07:09 PM, Ian Jackson wrote: >> >>>> I'm sure something like SELinux can be used to prevent a root QEMU >>>> process from doing a firmware upgrade. >>>> >>>> >>> *boggle* You're not serious, are you ? >>> >> selinux can prevent anything. In fact, I'm sure it does. >> > > I doubt SELinux has a builtin ATAPI command filter which knows all > _undocumented_ firmware upgrade commands. In fact, there are some ATAPI > devices which abuse existing and documented-as-harmless ATAPI commands > (which are regularly used for CD burning) for firmware upgrades. > Come on, it was a joke (though these days you can actually work on a machine with selinux enabled). -- I have a truly marvellous patch that fixes the bug which this signature is too narrow to contain.