<<< Date Index >>>     <<< Thread Index >>>

Re: Sun M-class hardware denial of service



On Sun, Sep 28, 2008 at 08:14:35PM -0600, Theo de Raadt wrote:
> 
> OpenBSD of course cannot run in a Solaris zone.
> 

Right.  Glad that is clear.

> OpenBSD can run in a hardware zone, and when something it does (which
> we don't know yet) locks up that hardware zone, the only way to get
> the hardware zone back is to POWER THE MACHINE OFF.  That is a lack
> of hardware zoning, or isolation.  That is not what people paid a lot
> of money for.
> 

Yes, we all agree that is bad but this is an OpenBSD specific problem
and, whilst interesting, the reality is that there are no going to be
many people that are lunatic enough to run an untrusted third party
operating system on a machine of this class.

> Those customers really expected that the machine would not need a
> powerdown to get around a bug in hardware zones.
> 

Yes, no arguing with that.

> 
> Noone is talking about Solaris zones except you. 
>

I suggest you go read the archives again then - I was not the only one.

> 
> Why don't we wait for Sun to release the fix, and then you can eat
> your words.

I can handle being wrong.  Can you?  As I said before, if you know of
a problem with solaris zones then that makes things a lot more of a
problem but all you have at the moment is a firmware bug which
requires loading a random kernel module - something that can be
controlled in Solaris.

-- 
Brett Lymn
"Warning:
The information contained in this email and any attached files is
confidential to BAE Systems Australia. If you are not the intended
recipient, any use, disclosure or copying of this email or any
attachments is expressly prohibited.  If you have received this email
in error, please notify us immediately. VIRUS: Every care has been
taken to ensure this email and its attachments are virus free,
however, any loss or damage incurred in using this email is not the
sender's responsibility.  It is your responsibility to ensure virus
checks are completed before installing any data sent in this email to
your computer."