xen-devel.lists.xenproject.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 00/22] Provide some actual restriction of qemu
@ 2017-09-15 18:48 Ian Jackson
  2017-09-15 18:48 ` [PATCH 01/22] xen: Provide XEN_DMOP_remote_shutdown Ian Jackson
                   ` (21 more replies)
  0 siblings, 22 replies; 68+ messages in thread
From: Ian Jackson @ 2017-09-15 18:48 UTC (permalink / raw)
  To: xen-devel; +Cc: Stefano Stabellini, Wei Liu

With this series, it is possible to run qemu in a way that I think
really does not have global privilege any more>

I have verified that it runs as a non-root user.  I have checked all
of its fds and they are either privcmd (which I have arranged to
neuter), or /dev/null, or harmless sockets and pipes, or evtchn.

Unfortunately this needs a new "xentoolcore" library, which all the
existing libraries register with so that the restrict call is
effective.

Also there are a number of lacunae.  In particular:

 - if we are not using a shared uid, we should kill all processes
   belonging to the chosen uid both at domain start time and at
   domain shutdown time

 - we should have qemu chroot

 - some audit and/or review of the resulting situation would be
   good before we offer security support for the new boundary

 - use of rlimits may be useful to mitigate the risk of DOS
   by a compromised qemu

 - cdrom insert would have to be done via fd passing and is not
   yet implemented

 - we need to think about what happens during migration (currently
   privileges are dropped very late, certainly after the receiving
   qemu has read the migration stream from its
   now-supposedly-untrusted peer)

The series depends for its functionality on a still-RFC qemu series I
have just posted, but should be harmless without the new qemu patches.

Thanks,
Ian.

_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xen.org
https://lists.xen.org/xen-devel

^ permalink raw reply	[flat|nested] 68+ messages in thread

end of thread, other threads:[~2017-09-21 16:18 UTC | newest]

Thread overview: 68+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-09-15 18:48 [PATCH 00/22] Provide some actual restriction of qemu Ian Jackson
2017-09-15 18:48 ` [PATCH 01/22] xen: Provide XEN_DMOP_remote_shutdown Ian Jackson
2017-09-18  9:44   ` Jan Beulich
2017-09-18 13:57     ` Ian Jackson
2017-09-18 14:16       ` Jan Beulich
2017-09-18 14:18   ` Wei Liu
2017-09-15 18:48 ` [PATCH 02/22] tools: libxendevicemodel: Provide xendevicemodel_shutdown Ian Jackson
2017-09-18 14:18   ` Wei Liu
2017-09-18 17:09     ` Ian Jackson
2017-09-15 18:48 ` [PATCH 03/22] xentoolcore, _restrict_all: Introduce new library and implementation Ian Jackson
2017-09-18 14:52   ` Wei Liu
2017-09-18 16:08     ` Ian Jackson
2017-09-19  8:52       ` Wei Liu
2017-09-19  8:52   ` Wei Liu
2017-09-19 10:42     ` Ian Jackson
2017-09-19  9:33   ` Wei Liu
2017-09-19 10:47     ` Ian Jackson
2017-09-19 10:57       ` Wei Liu
2017-09-19 11:04         ` Ian Jackson
2017-09-20 15:24           ` Wei Liu
2017-09-15 18:48 ` [PATCH 04/22] tools: qemu-xen build: prepare to link against xentoolcore Ian Jackson
2017-09-19  8:52   ` Wei Liu
2017-09-15 18:48 ` [PATCH 05/22] libxl: #include "xentoolcore_internal.h" Ian Jackson
2017-09-19  8:53   ` Wei Liu
2017-09-15 18:48 ` [PATCH 06/22] tools: move CONTAINER_OF to xentoolcore_internal.h Ian Jackson
2017-09-19  8:53   ` Wei Liu
2017-09-15 18:48 ` [PATCH 07/22] xentoolcore_restrict_all: Implement for libxendevicemodel Ian Jackson
2017-09-19  9:37   ` Wei Liu
2017-09-15 18:48 ` [PATCH 08/22] xentoolcore_restrict_all: "Implement" for libxencall Ian Jackson
2017-09-19  9:38   ` Wei Liu
2017-09-19 10:49     ` Ian Jackson
2017-09-15 18:48 ` [PATCH 09/22] xentoolcore_restrict: Break out xentoolcore__restrict_by_dup2_null Ian Jackson
2017-09-19  9:38   ` Wei Liu
2017-09-15 18:48 ` [PATCH 10/22] xentoolcore_restrict_all: Implement for libxenforeignmemory Ian Jackson
2017-09-19  9:40   ` Wei Liu
2017-09-19 10:51     ` Ian Jackson
2017-09-19 10:58       ` Wei Liu
2017-09-19 11:08         ` Ian Jackson
2017-09-20 15:25           ` Wei Liu
2017-09-21 16:18             ` Ian Jackson
2017-09-15 18:48 ` [PATCH 11/22] xentoolcore_restrict_all: Declare problems due to no evtchn support Ian Jackson
2017-09-19  9:40   ` Wei Liu
2017-09-15 18:48 ` [PATCH 12/22] xentoolcore_restrict_all: "Implement" for xengnttab Ian Jackson
2017-09-19  9:41   ` Wei Liu
2017-09-15 18:48 ` [PATCH 13/22] tools/xenstore: get_handle: use "goto err" error handling style Ian Jackson
2017-09-19  9:42   ` Wei Liu
2017-09-15 18:48 ` [PATCH 14/22] tools/xenstore: get_handle: Allocate struct before opening fd Ian Jackson
2017-09-19  9:43   ` Wei Liu
2017-09-15 18:48 ` [PATCH 15/22] xentoolcore_restrict_all: "Implement" for xenstore Ian Jackson
2017-09-19  9:43   ` Wei Liu
2017-09-15 18:48 ` [PATCH 16/22] xentoolcore, _restrict_all: Document implementation "complete" Ian Jackson
2017-09-18 14:49   ` Wei Liu
2017-09-18 16:06     ` Ian Jackson
2017-09-15 18:48 ` [PATCH 17/22] xl, libxl: Provide dm_restrict Ian Jackson
2017-09-19  9:48   ` Wei Liu
2017-09-19 10:54     ` Ian Jackson
2017-09-15 18:48 ` [PATCH 18/22] libxl: Rationalise calculation of user to run qemu as Ian Jackson
2017-09-18 14:49   ` Wei Liu
2017-09-15 18:48 ` [PATCH 19/22] libxl: libxl__dm_runas_helper: return pwd Ian Jackson
2017-09-19  9:48   ` Wei Liu
2017-09-15 18:48 ` [PATCH 20/22] libxl: userlookup_helper_getpwnam rename and turn into a macro Ian Jackson
2017-09-19  9:50   ` Wei Liu
2017-09-19 10:57     ` Ian Jackson
2017-09-15 18:48 ` [PATCH 21/22] libxl: dm_restrict: Support uid range user Ian Jackson
2017-09-15 18:48 ` [PATCH 22/22] RFC: tools: xentoolcore_restrict_all: use domid_t Ian Jackson
2017-09-19 10:02   ` Wei Liu
2017-09-19 11:01     ` Ian Jackson
2017-09-20 15:28       ` Wei Liu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).