Go to file
Joanna Rutkowska 59f71f634a dom0: Fix xenstore permissions qubes_netvm_external_ip
We should ensure that the first expression in the permisions list
is nX, where X is the owning domain, and not rX or wX, as otherwise
we would be granting all other VMs read access to the key.

This is explained in more detail here:

http://wiki.xensource.com/xenwiki/XenBus

In practice the perms problem applied only to the qubes_netvm_external_ip key
that is exposed by each NetVM to corresponding Proxy VMs. Before this fix,
the key was readable by any VM in the system, which might not be desired in some
more advanced networking setups, such as with Tor Proxy VM.
2011-09-26 17:24:11 +02:00
appvm vm: get rid of "2" from qvm-* names (#340) 2011-09-03 17:12:24 +02:00
common vm: route through specific host, not directly interface (#355) 2011-09-16 00:06:14 +02:00
dom0 dom0: Fix xenstore permissions qubes_netvm_external_ip 2011-09-26 17:24:11 +02:00
netvm vm: try to load pvops modules 2011-09-08 01:06:39 +02:00
proxyvm vm: disable forwarding when iptables rules are being (re)applied 2011-08-18 18:47:08 +02:00
qrexec dom0: qrexec_daemon: use 30s connect timeout instead of 120s 2011-09-09 16:34:41 +02:00
rpm_spec dom0: sync dom0 clock more frequent; start it from init.d script 2011-09-15 14:43:02 +02:00
u2mfn gitignores 2011-03-23 19:57:48 -04:00
vchan Adopt vchan to xen-libs-4.1.0 API. 2011-04-19 01:21:48 +02:00
.gitignore gitignore files - add build products 2011-03-06 14:06:24 +01:00
LICENSE Added LICENSE 2010-04-05 21:21:27 +02:00
Makefile Makefile: don't autoupdate yum repo after copying rpms there 2011-06-30 20:47:48 +02:00
version_dom0 version 1.6.31-dom0 2011-09-16 17:24:34 +02:00
version_vaio_fixes sony-vaio-fixes v1.6.1 2011-07-17 14:15:14 +02:00
version_vm version 1.6.30-vm 2011-09-16 11:55:01 +02:00