4 ms·
What about hypervisor as microkernel and VM as app? Is this a viable new model for system security?
by silentOpen 14y ago
What about hypervisor as microkernel and VM as app? Is this a viable new model for system security?
- vy8vWJlco 14y agoA process is basically a lightweight VM instance.
- silentOpen 14y agoYou mean a VM instance is a lightweight process? With hardware-assisted virtualization, multiple cores, and no preemption, shouldn't an OS-less VM be lighter than a general-purpose kernel-scheduled process?
- vy8vWJlco 14y agoLighter how? A VM and a process look almost the same from the running software's point of view. A process is basically the same as it was in DOS - one big memory space, except some memory regions are off limits, and some regions contain kernel trampolines (assembly is still fair game). QEMU/KVM just hooks basic things like MMU/page lookups, and interrupts (using CPU extensions, iff available), so hardware interfaces (ex, PCI) can be simulated, but otherwise the VM runs as a normal process using the kernel's scheduler. Xen just re-implements some of the scheduler stuff on the theory that not everyone needs the full kernel. Unless CPUs start incorporating scheduling (preemption of processes/VMs) and memory-space isolation and kernel interfaces (like fork, and k/exec), I'm not entirely sure what an "OS-less VM" might look like. (It would be great if half the kernel - ex, the Xen part - could be BIOS/CoreBoot-level firmware though, as it'd be nice to just use kernel drivers and common scripts to boot, etc, rather than Grub-specific or iPXE-specific ones, etc...)
- api 14y agoIt's feasible, but I personally think the hypervisor overhead stinks. Better to fix to OS permission model.
- vy8vWJlco 14y agoWhy not use filesystem permissions/ACLs on named pipes to access native interfaces (as a poor-man's microkernel)?
- silentOpen 14y agoHypervisor overhead for hardware-assisted virtualization is worse than OS-level preemptive threading? Why bother with an OS at all and just run mobile apps in a hypervisor with system service ACLs?
- hexonexxon 14y agoThey do not provide real isolation only the illusion of isolation. Remember software engineers have been stamping out bugs in the x86/64 arch for decades and they still find new bugs all the time. ARM arch is no different, they'll be stamping out bugs for decades too. By adding a hypervisor and virtual machines you're layering a whole new set of bugs on top like a bug sandwich. Complexity skyrockets, security is the first casualty. As for not having root on a proprietary device it's a double edged sword. On one hand you're firmly in the land of feudal security leaving everything up to the developers, on the other hand if you root the device you're now opening up priv escalation and NFC exploits galore.