|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-devel] [PATCH 5/5] Allow all user to create a file under the directory /var/lib/xen
On 30/12/2015 05:25, Wen Congyang wrote: On 12/30/2015 12:11 PM, Doug Goldstein wrote:On 12/29/15 8:39 PM, Wen Congyang wrote: For now, I would avoid running qemu as a non-root user. It doesn't gain you any meaninful security at present (at the expense of a warning which can't be turned off). As to this bug, marking the directory 0777 is not an option, as save records necessarily contain sensitive data. Longterm, (and already identified in one of the threads in the past), the best course of action is to switch away from having files, and passing file descriptors instead. This is more flexible (currently libxl can't function on a read-only root filesystem), and would allow a privileged entity to open the file descriptor and pass it to a non-privileged entity to use. This allows the non-privileged entity to function, and maintains security. ~Andrew _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx http://lists.xen.org/xen-devel
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |