SDLab

SDLab
SDLab.org::Adminな脳み

2014年5月12日月曜日

pvh dom0: construct_dom0 changes

[Xen-changelog] [xen master] pvh dom0: construct_dom0 changes
http://lists.xen.org/archives/html/xen-changelog/2014-05/msg00168.html
PVH対応

This patch changes construct_dom0() to boot in pvh mode:
      - Make sure dom0 elf supports pvh mode.
      - Call guest_physmap_add_page for pvh rather than simple p2m setting
      - Map all non-RAM regions 1:1 upto the end region in e820 or 4GB which
        ever is higher.
      - Allocate p2m, copying calculation from toolstack.
      - Allocate shared info page from the virtual space so that dom0 PT
        can be updated. Then update p2m for it with the actual mfn.
      - Since we build the page tables for pvh same as for pv, in
        pvh_fixup_page_tables_for_hap we replace the mfns with pfns.
Linux 3.14 and PVH
http://blog.xen.org/index.php/2014/01/31/linux-3-14-and-pvh/
It is a hybrid PV - hence the ‘PVH’ name - a PV guest within an HVM container.

2014年5月9日金曜日

2014/5/9のMEMO

Revert "CP-7904 - Remove v6 from xe-toolstack-restart."
https://github.com/johnelse/xen-api/commit/cd2955955a9623778b27edfee96d1708e03c0993
xe-toolstack-restartから外されたv6dのrestartを復活させた


pool.conf: always use the path from the config file
https://github.com/xapi-project/xen-api/pull/1730
pool.conf: Pool_roleの整理


Enable blktap3 in xenopsd.conf
https://github.com/simonjbeaumont/xen-api-libs-specs/commit/4ac4a87b445ba3d651037d393d265901eefe4c53
ちょっと古いけどMEMO
default-vbd-backend-kind=vbd3


64-bit XenServer Tech. Preview On Its Way!
http://blogs.citrix.com/2014/05/07/64-bit-xenserver-tech-preview-on-its-way/


<追記>

OpenSSL関連

Configuring Apache, Nginx, and OpenSSL for Forward Secrecy
https://community.qualys.com/blogs/securitylabs/2013/08/05/configuring-apache-nginx-and-openssl-for-forward-secrecy
いいね!

Implementing SSL Perfect Forward Secrecy in NGINX Web-Server
http://www.howtoforge.com/ssl-perfect-forward-secrecy-in-nginx-webserver
上のまとめだね。

2014年5月8日木曜日

Disables non-O_DIRECT workaround

[Xen-changelog] [xen master] libxl: introduce an option for disabling the non-O_DIRECT workaround
http://lists.xen.org/archives/html/xen-changelog/2014-05/msg00136.html

Description:           Disables non-O_DIRECT workaround
There is a memory lifetime bug in some driver domain (dom0) kernels
which can cause crashes when using O_DIRECT.  The bug occurs due to a
mismatch between the backend-visible lifetime of pages used for the
Xen PV network protocol and that expected by the backend kernel's
networking subsystem.  This can cause crashes when using certain
backends with certain underlying storage.
See:
http://lists.xen.org/archives/html/xen-devel/2012-12/msg01154.html

2014年5月7日水曜日

2014/05/07 の MEMO

Red Hat to Acquire Inktank, Provider of Ceph
http://www.redhat.com/about/news/press-archive/2014/4/red-hat-to-acquire-inktank-provider-of-ceph
話題のInktank。
XenServer6.5では、Kernel3.10以降になる可能性が高く、CephやRBDのSRを利用できる可能性が高いのでMEMO。

Hotfix XS61E037 - For XenServer 6.1.0http://support.citrix.com/article/CTX140724

saracota Nightly Build 2014-05-06
http://xenserver.org/overview-xenserver-open-source-virtualization/project-roadmap/2-uncategorised/115-development-snapshots.html
ちょっと追ってる時間が無い・・・。xapiの修正とWindows系のxenvbd/xenbus/xenvifの修正か?


Support multiple xenopsds, running at the same time
https://github.com/xapi-project/xen-api/pull/1723


PHPStress: DOS for Apache / NGINX servers running PHP-FPM or PHP-CGI
https://www.nightlionsecurity.com/blog/news/2014/04/phpstress-dos-attack-php-nginx-apache/
設定値の話。



MEMO:
tapdisk (in any of its versions) is not available on NetBSD

2014年5月6日火曜日

答え)XenServerについてのクイズ

問題:これは何でしょう?
rio,
miami,
symc,
orlando,
george,
midnight,
cowley,
boston,
sanibel,
tampa,
tallahassee,
clearwater,
sarasota,


答え:XenServerのプロジェクト名
rio, version = "4.0.0"
miami, version = "4.1.0"
symc, version = "4.1.0"
orlando, version = "5.0.0"
george, version = "5.5.0"
midnight, version = "5.6.0"
cowley, version = "5.6.100" ※XenServer5.6FP1
boston, version = "6.0.0"
sanibel, version = "6.0.2"
tampa, version = "6.1.0"
tallahassee, version = "6.1.1"
clearwater, version = "6.1.2" ※XenServer6.2
sarasota, version = "6.5.0" ※XenServer6.2.5 / XenServer6.2.50

<追記 2014/5/20>
この情報は、2013年6月のもので、古かったです。
https://github.com/Zhengchai/xenadmin/blob/4100f506ca2b832ff0c207bbaaeca93a68b7e0af/XenAdminTests/XenModelTests/TestAPICallVersions.cs

2014年5月4日日曜日

XenServer 6.5 saracota ) CPU Performance Monitoring Unit

Xenでの話はこれ:
Re: [Xen-devel] Virtualization of the CPU Performance Monitoring Unit
http://lists.xen.org/archives/html/xen-devel/2012-04/msg00499.html

サポート状況を確認してみる。
XenServer6.2 Dom0 では、
[root@clearwater ~]# dmesg | grep "Performance Events"
[root@clearwater ~]#
出力なし
[root@clearwater ~]# cat /proc/interrupts | grep "PMI"
[root@clearwater ~]#
出力なし

XenServer6.5 Dom0 では
[root@xs625test ~]# dmesg | grep -i "Performance"
[    4.520424] Performance Events: running under Xen, no PMU driver, software events only.
あ、CPUがAMDだった。
https://github.com/xenserver/linux-3.x.pg/commit/773c3cec4800d0642d4e1cdef8395f0b89fd0d3f
一応、こっちでも確認。
[root@xs625test ~]# cat /proc/interrupts | grep "PMI"
PMI:          0          0          0          0   Performance monitoring interrupts
環境があればいけそうね。
Intel CPU環境で試さないとダメかぁ・・・


ちなみに、Perfのpmu-toolsはココ
https://github.com/andikleen/pmu-tools

2014年5月2日金曜日

vTPM Manager

Virtual Trusted Platform Module (vTPM)

http://wiki.xen.org/wiki/Virtual_Trusted_Platform_Module_(vTPM)


[Xen-changelog] [xen master] vtpmmgr: add TPM group support
http://lists.xenproject.org/archives/html/xen-changelog/2014-05/msg00006.html

+================================================================================
+Overview
+================================================================================
+
+This document describes example platforms which use virtual TPMs to provide
+security properties for guests running on the platforms.  There are several
+tradeoffs between flexibility and trust which must be considered when
+implementing a platform containing vTPMs.

いわゆるDiskイメージの暗号化。
これに合わせて、各方面も修正されてます。
vtpm=["backend=domu-vtpm"]
みたいな感じで指定してやればいいのね。
unsecureDiskイメージを、TPMなDiskイメージに変換するやり方も書いてある。

これで、VMのDiskイメージを安全に破棄できるね。

早速使ってみたいけど、お休みモードなので、後で調べるリストへ。