-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Fri, Jun 14, 2019 at 05:38:09AM -0700, Aktariel wrote:
> Will Qubes 4.1 include the improvements in Xen 4.12? (qemu security, smaller 
> codebase, PVH/HVM only codepaths, etc)

Yes and no. There will be Xen 4.12, but not all the above is relevant
for Qubes OS. For example "qemu security" improvements is about qemu
running in dom0 only, which we don't do. We already have it isolated in
stubdomain, which in our opinion is significantly stronger than
improvements available in Xen 4.12 (running qemu as non-root user +
some sanboxing mechanisms).
Regarding PV / PVH/HVM, we do plan to migrate away from PV completely
(to the point of disabling it build-time) in subsequent version, but not
this one yet. There are two reasons for that:
 - Dom0 - support for PVH dom0 is only "tech preview"
 - stubdomains and various unikernels (MirageOS for example) still
   require PV


- -- 
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAl0DtuMACgkQ24/THMrX
1yzGDggAmHMins6KJi82gKbuU9JmRwlqDyNH35/f3OsH/t3GzzYB5uck6nnENqy/
MDx3abcQNfqde/EcVwx18M/DiTE6ptbFY+kl+/SQ79kcLlb71Kz2+KSvbeVwQoLr
dRRfo9AOSdssZZ1kN/3ZnbA0WdOATgiSKPMeUklq0mbGapvrknNKDzAcYRshx4zN
zjKBljyOcATeXcHlCgPjLkoGPjHufyYdulTV3DdUKf+OFlfXsoTRP139EpbJoBtM
ypOoWEgqR0oghziiRWm6GWO4Chhs4xhTY3Hb3fZ558xfB6USNmXM/HH3KBIeaHb3
TgJ8hGsernOZMZiHugwZBTJNGdQ3KQ==
=NNGe
-----END PGP SIGNATURE-----

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-devel" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-devel/20190614150155.GO1793%40mail-itl.
For more options, visit https://groups.google.com/d/optout.

Reply via email to