Re: [Xen-devel] [PATCH 0/8] Domain Groups: Introduction

On 22/2/07 20:39, "Chris" <hap10@xxxxxxxxxxxxxx> wrote:

> One of our future developments will be VMM access control frameworks
> like XSM that have the ability to specify access control policy for
> groups of domains instead of just on individual domains.  For us, this
> greatly simplifies both policy development and analysis.

There's nothing preventing you from individually and separately applying
group rules to all domains of a group. There's no reason that a single rule
at the policy-language level cannot correspond to multiple rules within the
hypervisor. From this point of view Domain Groups are potentially an
optimisation that may be worthwhile if observed usage of XSM indicates that
creating extra rules inside Xen is measurably costly in time or space.

 -- Keir

