Войти в систему

Home
    - Создать дневник
    - Написать в дневник
       - Подробный режим

LJ.Rossia.org
    - Новости сайта
    - Общие настройки
    - Sitemap
    - Оплата
    - ljr-fif

Редактировать...
    - Настройки
    - Список друзей
    - Дневник
    - Картинки
    - Пароль
    - Вид дневника

Сообщества

Настроить S2

Помощь
    - Забыли пароль?
    - FAQ
    - Тех. поддержка



Пишет LWN.net ([info]syn_lwnheadline)
@ 2019-05-01 19:30:00


Previous Entry  Add to memories!  Tell a Friend!  Next Entry
[$] Containers and address space separation
James Bottomley began his talk at the 2019 Linux Storage, Filesystem, and
Memory-Management Summit (LSFMM) by noting that the main opposition to his ideas
was not present at the summit, which was likely to mean the ideas got a much
easier reception than they would have otherwise. In particular, Peter
Zijlstra and Ingo Molnar expressed some strong reservations to the work
that Bottomley's colleague Mike Rapoport posted
recently; none of those three were in attendance at LSFMM. The idea is to
use address spaces to reduce the attack surface available to virtual
machines (VMs) and containers such that kernel bugs of various sorts have
less reach on multi-tenant systems.


(Читать комментарии) (Добавить комментарий)