Messages in this thread |  | | Date | Thu, 26 May 2011 11:35:11 +0300 | | Subject | Re: [PATCH 3/5] v2 seccomp_filters: Enable ftrace-based system call filtering | | From | Pekka Enberg <> |
| |
Hi Ingo,
On Thu, May 26, 2011 at 11:24 AM, Ingo Molnar <mingo@elte.hu> wrote: > Unlike Qemu tools/kvm/ has a design that is very fit for MAC > concepts: it uses separate helper threads for separate resources > (this could in many cases even be changed to be separate processes > which only share access to the guest RAM image) - while Qemu is in > most parts a state machine, so in tools/kvm/ we can realistically > have a good object manager and keep an exploit in a networking > interface driver from being able to access disk driver state.
I haven't really followed this particular discussion nor do I know if Qemu is good or bad fit but sure, for tools/kvm Chrome-style sandboxing makes tons of sense and would be a pretty good fit for how our device model works now.
Pekka
|  |