[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] [PATCH] xenstored: allow guests to reintroduce themselves

On Tue, Aug 09, Vincent Hanquez wrote:

> What about security wise ?

Its not about security, just the usual UNIX gun->foot thing.

> Guest userspace suddenly becomes able to do this operation (and DoS themself)
> where they used to be limited to normal read/write/.. operations.

The guest userspace does most likely not talk to xenstored directly.
Whatever acts as the proxy could filter the XS_INTRODUCE command.

> Also you're changing the C xenstored behavior without changing
> the OCaml one.

I better leave that to the maintainers of that code.


Xen-devel mailing list



Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.