From: "Jose A. Lopes" <jabolopes@google.com>
To: Ian Campbell <Ian.Campbell@citrix.com>
Cc: George Dunlap <george.dunlap@eu.citrix.com>,
"xen-devel@lists.xenproject.org" <xen-devel@lists.xenproject.org>,
Paul Durrant <Paul.Durrant@citrix.com>
Subject: Re: Guest to Host communication
Date: Mon, 4 Nov 2013 11:51:45 +0100 [thread overview]
Message-ID: <20131104105145.GB4704@google.com> (raw)
In-Reply-To: <1383249749.5436.112.camel@dagon.hellion.org.uk>
Hi,
Thanks, we'll have a look at that.
Regards,
Jose
On Thu, Oct 31, 2013 at 08:02:29PM +0000, Ian Campbell wrote:
> On Thu, 2013-10-31 at 19:42 +0100, Jose A. Lopes wrote:
>
> > When you say "look inside" the filesystem do you mean to mount that
> > filesystem
> > in the host OS? If so, it seems that it is very dangerous to mount
> > guest filesystems
> > due to a number of exploits.
>
> If you only need r/o access from the host then you could use
> tools/libfsimage (which has python binding, used by pygrub) which at
> least constrains things to a userspace process and not a kernel mode
> exploit. With suitable privilege dropping this can be made reasonably
> safe...
>
> Ian.
>
>
--
Jose Antonio Lopes
Ganeti Engineering
Google Germany GmbH
Dienerstr. 12, 80331, München
Registergericht und -nummer: Hamburg, HRB 86891
Sitz der Gesellschaft: Hamburg
Geschäftsführer: Graham Law, Christine Elizabeth Flores
Steuernummer: 48/725/00206
Umsatzsteueridentifikationsnummer: DE813741370
next prev parent reply other threads:[~2013-11-04 10:51 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-10-22 7:59 Guest to Host communication Jose A. Lopes
2013-10-22 8:48 ` Paul Durrant
2013-10-22 12:48 ` Jose A. Lopes
2013-10-22 13:18 ` Paul Durrant
2013-10-22 13:42 ` Jose A. Lopes
2013-10-31 14:21 ` George Dunlap
2013-10-31 16:08 ` Jose A. Lopes
2013-10-31 16:13 ` George Dunlap
2013-10-31 18:42 ` Jose A. Lopes
2013-10-31 20:02 ` Ian Campbell
2013-11-04 10:51 ` Jose A. Lopes [this message]
2013-10-22 13:54 ` Konrad Rzeszutek Wilk
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20131104105145.GB4704@google.com \
--to=jabolopes@google.com \
--cc=Ian.Campbell@citrix.com \
--cc=Paul.Durrant@citrix.com \
--cc=george.dunlap@eu.citrix.com \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).