[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] [PATCH]: kexec: framework and i386



  Hi,

> Here is a first cut of kexec for dom0/xen, which will actually
> kexec the physical machine from xen. The approach taken is
> to move the architecture-dependant kexec code into a new hypercall.

First you need some more security checks.  On a first quick look it
seems you can zap and takeover the whole machine from within a domU by
kexec-booting the machine.

Second I think we'll need a new kexec flag to indicate we'll go zap the
physical machine, not the virtual machine.  I'm looking into the later,
and I think we'll be able to do both at some point in the future.  Maybe
it is enougth to care about dom0 (physical machine kexec) vs. domU
(virtual machine kexec) only though.  We certainly don't want allow
domUs kexec the whole machine, and virtual machine kexec for dom0
doesn't make that much sense given how tight xen and dom0 work hand-in-hand.

>   * kexecing into xen does not seem to work, I think that 
>     kexec-tools needs updating, but I have not investigated yet

Yep, actually _alot_ of the kexec magic happens in userspace.

cheers,

  Gerd

-- 
Gerd 'just married' Hoffmann <kraxel@xxxxxxx>
I'm the hacker formerly known as Gerd Knorr.
http://www.suse.de/~kraxel/just-married.jpeg

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.