qemu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Qemu-devel] [PATCH 0/5] ATAPI pass through v2


From: Avi Kivity
Subject: Re: [Qemu-devel] [PATCH 0/5] ATAPI pass through v2
Date: Wed, 08 Jul 2009 21:09:19 +0300
User-agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.1b3pre) Gecko/20090513 Fedora/3.0-2.3.beta2.fc11 Thunderbird/3.0b2

On 07/08/2009 08:28 PM, Carl-Daniel Hailfinger wrote:
On 08.07.2009 18:38, Avi Kivity wrote:
On 07/08/2009 07:09 PM, Ian Jackson wrote:
I'm sure something like SELinux can be used to prevent a root QEMU
process from doing a firmware upgrade.

*boggle*  You're not serious, are you ?
selinux can prevent anything.  In fact, I'm sure it does.

I doubt SELinux has a builtin ATAPI command filter which knows all
_undocumented_ firmware upgrade commands. In fact, there are some ATAPI
devices which abuse existing and documented-as-harmless ATAPI commands
(which are regularly used for CD burning) for firmware upgrades.

Come on, it was a joke (though these days you can actually work on a machine with selinux enabled).

--
I have a truly marvellous patch that fixes the bug which this
signature is too narrow to contain.





reply via email to

[Prev in Thread] Current Thread [Next in Thread]