WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

RE: [Xen-devel] problem with netfront.c

To: "Jacob Gorm Hansen" <jacobg@xxxxxxx>, <xen-devel@xxxxxxxxxxxxxxxxxxx>
Subject: RE: [Xen-devel] problem with netfront.c
From: "Ian Pratt" <m+Ian.Pratt@xxxxxxxxxxxx>
Date: Mon, 4 Apr 2005 08:21:23 +0100
Delivery-date: Mon, 04 Apr 2005 07:21:38 +0000
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
Thread-index: AcU4w2IaNzn+fJIpRk2vhmz55ESNZQAItu7A
Thread-topic: [Xen-devel] problem with netfront.c
> Are the grant references capabilities, or how do you prevent 
> domains from inventing their own? 

Domains create and maintain their own grant tables. They don't have to
be capabilities to be secure.

> Who takes care of garbage-collecting them when a domain exists or
dies? 

Since Xen tracks active grant references revocation is possible, but is
a slow-path operation. 

> Can a domain DoS a Xen-system by allocating all the grant refs in 
> the system?

No...


Ian

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel