[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Xen-devel] problem with netfront.c


  • To: "Jacob Gorm Hansen" <jacobg@xxxxxxx>, <xen-devel@xxxxxxxxxxxxxxxxxxx>
  • From: "Ian Pratt" <m+Ian.Pratt@xxxxxxxxxxxx>
  • Date: Mon, 4 Apr 2005 08:21:23 +0100
  • Delivery-date: Mon, 04 Apr 2005 07:21:38 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xensource.com>
  • Thread-index: AcU4w2IaNzn+fJIpRk2vhmz55ESNZQAItu7A
  • Thread-topic: [Xen-devel] problem with netfront.c

> Are the grant references capabilities, or how do you prevent 
> domains from inventing their own? 

Domains create and maintain their own grant tables. They don't have to
be capabilities to be secure.

> Who takes care of garbage-collecting them when a domain exists or
dies? 

Since Xen tracks active grant references revocation is possible, but is
a slow-path operation. 

> Can a domain DoS a Xen-system by allocating all the grant refs in 
> the system?

No...


Ian

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.