xen-devel.lists.xenproject.org archive mirror
 help / color / mirror / Atom feed
From: "Jose A. Lopes" <jabolopes@google.com>
To: Ian Campbell <Ian.Campbell@citrix.com>
Cc: George Dunlap <george.dunlap@eu.citrix.com>,
	"xen-devel@lists.xenproject.org" <xen-devel@lists.xenproject.org>,
	Paul Durrant <Paul.Durrant@citrix.com>
Subject: Re: Guest to Host communication
Date: Mon, 4 Nov 2013 11:51:45 +0100	[thread overview]
Message-ID: <20131104105145.GB4704@google.com> (raw)
In-Reply-To: <1383249749.5436.112.camel@dagon.hellion.org.uk>

Hi,

Thanks, we'll have a look at that.

Regards,
Jose

On Thu, Oct 31, 2013 at 08:02:29PM +0000, Ian Campbell wrote:
> On Thu, 2013-10-31 at 19:42 +0100, Jose A. Lopes wrote:
> 
> > When you say "look inside" the filesystem do you mean to mount that
> > filesystem
> > in the host OS? If so, it seems that it is very dangerous to mount
> > guest filesystems
> > due to a number of exploits.
> 
> If you only need r/o access from the host then you could use
> tools/libfsimage (which has python binding, used by pygrub) which at
> least constrains things to a userspace process and not a kernel mode
> exploit. With suitable privilege dropping this can be made reasonably
> safe...
> 
> Ian.
> 
> 

-- 
Jose Antonio Lopes
Ganeti Engineering
Google Germany GmbH
Dienerstr. 12, 80331, München

Registergericht und -nummer: Hamburg, HRB 86891
Sitz der Gesellschaft: Hamburg
Geschäftsführer: Graham Law, Christine Elizabeth Flores
Steuernummer: 48/725/00206
Umsatzsteueridentifikationsnummer: DE813741370

  reply	other threads:[~2013-11-04 10:51 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-10-22  7:59 Guest to Host communication Jose A. Lopes
2013-10-22  8:48 ` Paul Durrant
2013-10-22 12:48   ` Jose A. Lopes
2013-10-22 13:18     ` Paul Durrant
2013-10-22 13:42       ` Jose A. Lopes
2013-10-31 14:21         ` George Dunlap
2013-10-31 16:08           ` Jose A. Lopes
2013-10-31 16:13             ` George Dunlap
2013-10-31 18:42               ` Jose A. Lopes
2013-10-31 20:02                 ` Ian Campbell
2013-11-04 10:51                   ` Jose A. Lopes [this message]
2013-10-22 13:54       ` Konrad Rzeszutek Wilk

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20131104105145.GB4704@google.com \
    --to=jabolopes@google.com \
    --cc=Ian.Campbell@citrix.com \
    --cc=Paul.Durrant@citrix.com \
    --cc=george.dunlap@eu.citrix.com \
    --cc=xen-devel@lists.xenproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).