From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Jose A. Lopes" Subject: Re: Guest to Host communication Date: Mon, 4 Nov 2013 11:51:45 +0100 Message-ID: <20131104105145.GB4704@google.com> References: <20131022075936.GB4223@google.com> <9AAE0902D5BC7E449B7C8E4E778ABCD013E890@AMSPEX01CL01.citrite.net> <20131022124857.GC4223@google.com> <9AAE0902D5BC7E449B7C8E4E778ABCD013ED63@AMSPEX01CL01.citrite.net> <20131022134220.GD4223@google.com> <20131031160835.GA30966@google.com> <527281BE.7080008@eu.citrix.com> <1383249749.5436.112.camel@dagon.hellion.org.uk> Mime-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Return-path: Received: from mail6.bemta5.messagelabs.com ([195.245.231.135]) by lists.xen.org with esmtp (Exim 4.72) (envelope-from ) id 1VdHl8-0005Xv-Ef for xen-devel@lists.xenproject.org; Mon, 04 Nov 2013 10:51:50 +0000 Received: by mail-bk0-f51.google.com with SMTP id my12so991726bkb.10 for ; Mon, 04 Nov 2013 02:51:48 -0800 (PST) Content-Disposition: inline In-Reply-To: <1383249749.5436.112.camel@dagon.hellion.org.uk> List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Sender: xen-devel-bounces@lists.xen.org Errors-To: xen-devel-bounces@lists.xen.org To: Ian Campbell Cc: George Dunlap , "xen-devel@lists.xenproject.org" , Paul Durrant List-Id: xen-devel@lists.xenproject.org Hi, Thanks, we'll have a look at that. Regards, Jose On Thu, Oct 31, 2013 at 08:02:29PM +0000, Ian Campbell wrote: > On Thu, 2013-10-31 at 19:42 +0100, Jose A. Lopes wrote: > = > > When you say "look inside" the filesystem do you mean to mount that > > filesystem > > in the host OS? If so, it seems that it is very dangerous to mount > > guest filesystems > > due to a number of exploits. > = > If you only need r/o access from the host then you could use > tools/libfsimage (which has python binding, used by pygrub) which at > least constrains things to a userspace process and not a kernel mode > exploit. With suitable privilege dropping this can be made reasonably > safe... > = > Ian. > = > = -- = Jose Antonio Lopes Ganeti Engineering Google Germany GmbH Dienerstr. 12, 80331, M=FCnchen Registergericht und -nummer: Hamburg, HRB 86891 Sitz der Gesellschaft: Hamburg Gesch=E4ftsf=FChrer: Graham Law, Christine Elizabeth Flores Steuernummer: 48/725/00206 Umsatzsteueridentifikationsnummer: DE813741370