On 05/16/2017 04:36 AM, Andrew Cooper wrote:
On 16/05/17 03:54, Boris Ostrovsky wrote:

  2) Or, perhaps more importantly, what distinguishes said guest?

Simplifying things a bit, it's an HVM guest that doesn't have device
model (i.e. qemu) and which is booted directly (i.e. without hvmloader)

The "booted directly" isn't relevant here.

While being able to boot a PVH kernel directly is useful for development
purposes, it is problematic for production purposes.  For production
systems, mounting of the guest filesystem and parsing of the guest
kernel should happen in guest context, rather than dom0 context, to
remove the security attack surfaces present in the PV guest model.

Okay, stupid question time (again).

I interpret the above to mean that the (referenced) disk image would be used
to find a boot loader and run it (e.g. grub2). No pygrub, no special boot
kernel such as appears to be needed by a PV guest.

So if I install an OS (e.g. Ubuntu 14 or 16) onto a raw device (e.g. an LV on
a VG on dom0), then build a 4.11 kernel and install it (on that xvda), that
device would be bootable in a PVH guest.


