WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] Xen binary distrib's kernel as domU kernel

To: Sipos Ferenc <frank@xxxxxxx>
Subject: Re: [Xen-users] Xen binary distrib's kernel as domU kernel
From: "Luke S. Crawford" <lsc@xxxxxxxxx>
Date: Wed, 10 Jan 2007 12:01:54 -0800 (PST)
Cc: xen-users@xxxxxxxxxxxxxxxxxxx
Delivery-date: Wed, 10 Jan 2007 12:01:54 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <1168457001.4698.6.camel@localhost>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <1168457001.4698.6.camel@localhost>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx

Running the same kernel in dom0 and domU should not be a problem; the DomU kernel runs with DomU privlige levels, so it shouldn't matter that it is the same kernel with the same drivers as the Dom0. the only downside is the extra kernel size represented by the unused Dom0 code and other non-module drivers.

On Wed, 10 Jan 2007, Sipos Ferenc wrote:
Hi All,

just a quicky. Is it a security breach (by any means) if I run the
official XenSource e.g. vmlinuz-2.6-xen kernel as my domU kernel? I
mean, this has the 'Privilege domain' option compiled in (as the very
same one runs under the dom0 itself) as well as the {net,block}-backend
drivers?

I'm using it in a potentially malicious environment (VPS hosting) and I
want to make sure noone can tamper with system from a domU the way that
is not desirable.

Thanks for your time in advance,
Frank


_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

!DSPAM:45a53b75175798623017290!



_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users