On 07/24/2013 05:35 AM, cooldharma06 wrote:> Hi all,
>
> xsm policy which is used for controlling the hypercall(communication)
> between vm''s.
>
> and i also i find that there is ''svirt'' which is used for
isolating vm''s.
> I want to know that is svirt will work in xen.?? because i find svirt is
> for KVM.
>
> Anybody clear me these things.
>
>
> Regards,
> cooldharma06.
>
The XSM policy in 4.3 has a type for isolating VMs called isolated_domU_t
which prevents a domain from directly communicating with other domains.
However, indirect communication in Xen can be done using Xenstore, so
a pair of cooperating VMs can still communicate. This may or may not be an
issue for you, depending on what you want from svirt.
--
Daniel De Graaf
National Security Agency