[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Building domains as a lesser user (was Re: [Xen-devel] boot loaders for domain != 0)



Anthony Liguori wrote:

As an alternative, I was trying to see if there was a way do create a domain as a non-root user. Since root can set up the shared memory segments, it seems like the builder should be able to drop to a lesser user. It could even enter a chroot() so that the only potential attack vector is a syscall exploit (which are rare and well-known enough that that seems to be acceptable).


If we trust Linux to enforce security, we do not need Xen at all ;-)

Jacob


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxxxx
https://lists.sourceforge.net/lists/listinfo/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.