[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] help--Does Xen allow us to grant all the machine memory access authority to another domain rather than Dom0 ?

On Mon, 2014-08-04 at 19:21 +0800, lelema.cn wrote:
> Hello all,
> I want to build an isolated domain (noted as 'Newdomain' below) to
> collect information of the whole machine memory used by all the VMs,
> including dom0.
> So I need to grant the privilege of reading all the machine memory to
> 'Newdomain'. 
> Below are my questions and some immature ideas that needs your help to
> evaluate them:
> 0, Is it possible to do this ?

This is the sort of thing which XSM[0] is designed to allow you to
achieve. I'm afraid I don't know the specifics of how one would
configure it for your exact use case.

[0] http://wiki.xen.org/wiki/Xen_Security_Modules_:_XSM-FLASK

Xen-devel mailing list



Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.