[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated
From: |
Daniel P . Berrangé |
Subject: |
Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated |
Date: |
Fri, 26 Oct 2018 15:14:58 +0100 |
User-agent: |
Mutt/1.10.1 (2018-07-13) |
On Fri, Oct 26, 2018 at 12:03:35PM +0200, Paolo Bonzini wrote:
> On 26/10/2018 11:59, Daniel P. Berrangé wrote:
> > I should also say that QEMU as an upstream project has multiple goals.
> > Running KVM guests with modern PV hardware is only one of them, albeit
> > a widely used one. Being able to run old legacy OS with old hardware,
> > and running arbitrary embedded boards/devices with emulation are both
> > use cases that QEMU project aims to address. To eliminate all the old
> > "crufty" device emulation in name of improving security for KVM, would
> > be to eliminate core use cases of the project. THis is why we're trying
> > to persue the direction of making it easier for vendors to disable
> > features and devices they don't wish to support & thus limit their
> > downstream CVE exposure.
>
> Indeed. If we had to deprecate a feature just because it had an
> off-by-one bug, no C program would grow beyond 1000 lines of code...
One thing we should do, however, is to make it clear which of the
device models we consider secure, and which we consider only usable
in a friendly guest environment, as we have very different code
maintainership & quality standards for different parts of QEMU.
Essentially virtio devices, and then only a handful of the emulated
devices are things we consider suitable for usage in secure envs.
Likewise for machine types probably.
Regards,
Daniel
--
|: https://berrange.com -o- https://www.flickr.com/photos/dberrange :|
|: https://libvirt.org -o- https://fstop138.berrange.com :|
|: https://entangle-photo.org -o- https://www.instagram.com/dberrange :|
- [Qemu-devel] [PATCH 0/3] RfC: add support for deprecated devices., Gerd Hoffmann, 2018/10/25
- [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, Gerd Hoffmann, 2018/10/25
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, P J P, 2018/10/25
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, Philippe Mathieu-Daudé, 2018/10/25
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, Thomas Huth, 2018/10/25
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, Daniel P . Berrangé, 2018/10/25
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, P J P, 2018/10/26
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, Daniel P . Berrangé, 2018/10/26
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, Daniel P . Berrangé, 2018/10/26
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, Paolo Bonzini, 2018/10/26
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated,
Daniel P . Berrangé <=
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, P J P, 2018/10/26
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, Dr. David Alan Gilbert, 2018/10/26
- Re: [Qemu-devel] [libvirt] [PATCH 3/3] cirrus: mark as deprecated, Christian Borntraeger, 2018/10/26
- Re: [Qemu-devel] [libvirt] [PATCH 3/3] cirrus: mark as deprecated, Cole Robinson, 2018/10/26
- Re: [Qemu-devel] [libvirt] [PATCH 3/3] cirrus: mark as deprecated, Daniel P . Berrangé, 2018/10/26
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, Gerd Hoffmann, 2018/10/29
- Re: [Qemu-devel] [PATCH 3/3] cirrus: mark as deprecated, Daniel P . Berrangé, 2018/10/30
[Qemu-devel] [PATCH 2/3] adlib: mark as insecure and deprecated., Gerd Hoffmann, 2018/10/25