On Monday 14 November 2005 14:59, Nix wrote:
> On Tue, 8 Nov 2005, Jeff Dike prattled cheerily:
> > On Tue, Nov 08, 2005 at 01:09:06AM -0600, Rob Landley wrote:
> >> > So I don't care about systemcall interception or anything like that,
> >>
> >> *blink*  *blink*
> >>
> >> Ok, you want user mode linux, but you don't want it to actually run user
> >> processes, nor do want it to be able to intercept system calls.
> >>
> >> Um...  What's left?
> >
> > Only all of Linux.  It so happens that I want exactly the same thing for
> > libUML, except I haven't had time to do anything about it.

> I've long wanted to do the same sort of thing,

I guess you would like to run userspace processes or at least to call libUML 
to configure something (but I don't think you can ask a kernel to do so much, 
without allowing it to run userspace processes)...

> to do with a UML the same 
> sort of thing you can do with a real Linux box: that is, set up
> networking and a bridging firewall, 

> then halt it: 

I.e. "shutdown now" without -h? Halt without poweroff?

> the kernel keeps 
> processing network packets and firewalling and bridging them perfectly
> well, but attackers now have *real* trouble changing the configuration.

_BLINK_ _BLINK_

Is this a _documented_ feature 8-() ?

> You stop it with kill() on the host, or mconsole; as it's halted and all
> fsen are unmounted and so on, you're safe from filesystem corruption.
>
> When combined with CONFIG_NETCONSOLE, you can even keep an eye on it. :)
>
> The necessary hack looks quite simple: I just haven't got around to it.

-- 
Inform me of my mistakes, so I can keep imitating Homer Simpson's "Doh!".
Paolo Giarrusso, aka Blaisorblade (Skype ID "PaoloGiarrusso", ICQ 215621894)
http://www.user-mode-linux.org/~blaisorblade

        

        
                
___________________________________ 
Yahoo! Mail: gratis 1GB per i messaggi e allegati da 10MB 
http://mail.yahoo.it



-------------------------------------------------------
SF.Net email is sponsored by:
Tame your development challenges with Apache's Geronimo App Server. Download
it for free - -and be entered to win a 42" plasma tv or your very own
Sony(tm)PSP.  Click here to play: http://sourceforge.net/geronimo.php
_______________________________________________
User-mode-linux-devel mailing list
User-mode-linux-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/user-mode-linux-devel

Reply via email to