4 ms·
> All the time if you use libvirt. Does it? Afaik libvirt requires AppArmor/SELinux for this.
by eeZi 11y ago
> All the time if you use libvirt.
Does it? Afaik libvirt requires AppArmor/SELinux for this.
- rwmj 11y agocgroups and SELinux protections are separate. See: https://libvirt.org/cgroups.html https://libvirt.org/cgroups.html Also: https://libvirt.org/drvqemu.html#security https://libvirt.org/drvqemu.html#security
- eeZi 11y agoBut cgroups do not provide isolation, just better resource management.
- rwmj 11y agoIf you bother to read the second link I posted, you'll see that cgroups does both (some) isolation and resource management. It's a layered scheme however and you absolutely should be using SELinux which is where the really comprehensive confinement happens.
- eeZi 11y agoI read both links, and the "isolation" provided by cgroups alone will not prevent exploitation of this bug (or any other, for that matter).
- rwmj 11y agoYou can flat out wrong about this, as you have been in your other answers. I am an upstream libvirt committer so I do know a fair bit about what libvirt can do. The fact is that the isolation of cgroups will prevent various denial of service bugs, and also access to non-whitelisted devices. It is nowhere near as comprehensive as SELinux isolation, as I clearly said way up there in my initial response -- which is also the reason why when you use Docker on RHEL, most of the security comes from the additional SELinux protections Red Hat have added.
- eeZi 11y agoI agree with you that cgroups protect against denial of service attacks, and that the device whitelist provides some additional security (I actually did not know about the latter, so thanks! TIL). Thinking about it, if you exclusively use block devices for storage, this is a lot better than I expected. But still, this is nowhere from a "a least-privilege container for each VM" as you suggested. (I'm a heavy libvirt user myself - thank you for your work on it!)