WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

Re: [Xen-devel] RE: Building domains as a lesser user (was Re: [Xen-deve

On Fri, 2005-02-04 at 13:27 +0000, Mark Williamson wrote:
> > > > And then, it's yet another kernel to keep updated, etc.
> > >
> > > I don't see any reason to keep it up to date. Its running in a protected
> > > environemnt and doesn't have any extra access that the kernel about to
> > > be booted is going to get.
> >
> > Users don't tend to take that answer very well ;)  The protected
> > environment means you can have a little bit longer to fix it, but they
> > have things like audit requirements, etc.
> 
> OK but the kernel can be essentially airgapped from the rest of the world - 
> not necessary to include network drivers, etc (or if we do, not strictly 
> necessary to connect the device channels).  Security shouldn't be the issue, 
> so if it works I wouldn't think it'd need updating regularly.

And then you get the question "my kernel booting said it was version
x.y.z and you put out a security fix that's x.y.z.w -- why doesn't my
kernel have that fix?"  Users are kind of weird like that sometimes.
And since it's the same source, you really do want to keep the packages
in sync otherwise you have a nitemare from a packaging/distribution
perspective.

So while you might not strictly _need_ to, you'll end up having to do
it.

> To be honest, I think whatever solution we go with is going to look a little 
> messy.

Well, it is the equivalent of a boot loader and I've looked at the code
to most of them... about the only thing they have in common is
"messy" :-)

Jeremy



-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxxxx
https://lists.sourceforge.net/lists/listinfo/xen-devel