From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:56983) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1UhipO-00035o-0F for qemu-devel@nongnu.org; Wed, 29 May 2013 12:02:22 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1UhipJ-0005NR-HX for qemu-devel@nongnu.org; Wed, 29 May 2013 12:02:17 -0400 Received: from os.inf.tu-dresden.de ([2002:8d4c:3001:48::99]:49511) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1UhipJ-0005N9-BR for qemu-devel@nongnu.org; Wed, 29 May 2013 12:02:13 -0400 Message-ID: <51A62680.2000808@os.inf.tu-dresden.de> Date: Wed, 29 May 2013 18:02:08 +0200 From: Julian Stecklina MIME-Version: 1.0 References: <20130527093409.GH21969@stefanha-thinkpad.redhat.com> <51A496C4.1020602@os.inf.tu-dresden.de> <87r4grca4p.fsf@codemonkey.ws> <20130528171742.GB30296@redhat.com> <20130529074929.GC20199@stefanha-thinkpad.redhat.com> <20130529090859.GH4472@redhat.com> <20130529142143.GA9545@stefanha-thinkpad.redhat.com> In-Reply-To: <20130529142143.GA9545@stefanha-thinkpad.redhat.com> Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="----enig2GKPKECMDOTIMJEMWWSMO" Subject: Re: [Qemu-devel] snabbswitch integration with QEMU for userspace ethernet I/O List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Stefan Hajnoczi Cc: "snabb-devel@googlegroups.com" , qemu-devel@nongnu.org, Anthony Liguori , "Michael S. Tsirkin" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) ------enig2GKPKECMDOTIMJEMWWSMO Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On 05/29/2013 04:21 PM, Stefan Hajnoczi wrote: > The fact that a single switch process has shared memory access to all > guests' RAM is critical. If the switch process is exploited, then that= > exposes other guests' data! (Think of a multi-tenant host with guests > belonging to different users.) True. But people don't mind having instruction decoding and half of virtio in the kernel these days, so it can't be that security critical...= Julian ------enig2GKPKECMDOTIMJEMWWSMO Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.13 (GNU/Linux) iEYEARECAAYFAlGmJoAACgkQ2EtjUdW3H9myawCfTl1SWLEcrA1CauyVvT1Znren sisAoIxTLvzx9BiqINiiZYiljvTJFt9t =NKRs -----END PGP SIGNATURE----- ------enig2GKPKECMDOTIMJEMWWSMO--