5 ms·
It's quite reasonable to distinguish QEMU from the hypervisor: QEMU typically runs with strictly lower privileges. The "hardware acceleration" that helps QEMU
by jsolson 7y ago
It's quite reasonable to distinguish QEMU from the hypervisor: QEMU typically runs with strictly lower privileges.
The "hardware acceleration" that helps QEMU emulate a computer operates in root VMX and non-root VMX (when actually executing guest instructions) modes. When operating in root VMX mode as a supervisor, it has approximately the highest privileges in the system (ignoring SMM), as it is operating in host ring 0. QEMU runs in host ring 3, making it a typical user mode process. If you manage to compromise QEMU (and only QEMU), you have only escaped into host user mode. In that case you haven't compromised the hypervisor, merely the virtual machine monitor.
If, on the other hand, you manage to compromise KVM (or vhost) you could reasonably claim to have actually compromised the hypervisor.
Type 2 hypervisors make this generally much uglier than type 1, but it's reasonable to say that the hypervisor in a type 2 deployment is limited to the kernel component rather than the user-mode VMM.
- person_of_color 7y agoWhere do you get this type of academic education of virtualization techniques?
- RaitoBezarius 7y agoDepends on your country, but I suppose it has to do with theoretical computer science at the master level, you can see a lot of academic content around this (in Paris, France for example): https://wikimpri.dptinfo.ens-cachan.fr/doku.php https://wikimpri.dptinfo.ens-cachan.fr/doku.php (yes, HTTPS is broken…)
- jsolson 7y agoSome of it is academic study (BS and MS at Georgia Tech) -- that helped with the theory and a bit of the breadth. That said, most of what I know of modern virtualization was more or less "on the job" from working on Google Compute Engine. Lots of practical experience understanding virtualization boundaries, and really really enormous access to historical domain experts in the space.
- rasz 7y ago> it has approximately the highest privileges in the system (ignoring SMM) and MINIX in case of Intel :-)