[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] Questions about PVH in Xen 4.3 unstable

>>> On 30.01.13 at 12:04, George Dunlap <George.Dunlap@xxxxxxxxxxxxx> wrote:
> On Wed, Jan 30, 2013 at 10:52 AM, tech mailinglists <
> mailinglists.tech@xxxxxxxxx> wrote:
>> I thought that stubdoms for HVMs are great for security. Can it still be
>> used for PV-on-HVM for security? Can only Linux run as PVH and Windows and
>> so on still run as HVM?
> Stubdoms increase security by isolating the qemu process, so that it's not
> running in domain 0.  PV domains (and by extension PVH domains) don't have
> a qemu process, and are therefore are secure without needing a stubdom.

That's not generally true - PV domains (including Dom0 itself) can
have a qemu e.g. for providing a block backend drivers for certain
disk types.


Xen-devel mailing list



Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.