<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Red Hat-based Linux under Xen, from Debian Etch</title>
	<atom:link href="http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/feed/" rel="self" type="application/rss+xml" />
	<link>http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/</link>
	<description>I'll get there one day.</description>
	<pubDate>Fri, 09 Jan 2009 23:29:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7-beta3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: darkfader</title>
		<link>http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/comment-page-1/#comment-55621</link>
		<dc:creator>darkfader</dc:creator>
		<pubDate>Fri, 23 May 2008 16:16:10 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/#comment-55621</guid>
		<description>there you go, fixed in xensource upstream but not sure if it made it in http://bugzilla.xensource.com/bugzilla/show_bug.cgi?id=1068</description>
		<content:encoded><![CDATA[<p>there you go, fixed in xensource upstream but not sure if it made it in <a href="http://bugzilla.xensource.com/bugzilla/show_bug.cgi?id=1068" rel="nofollow">http://bugzilla.xensource.com/bugzilla/show_bug.cgi?id=1068</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: darkfader</title>
		<link>http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/comment-page-1/#comment-55619</link>
		<dc:creator>darkfader</dc:creator>
		<pubDate>Fri, 23 May 2008 16:13:14 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/#comment-55619</guid>
		<description>of course I hadnt come here just to bash debian...?! I just ran into this site while try to make pygrub work like everyone else; just at some point I got real angry about how many peoples time is spent on this; the libs are missing in the package and it should -obviously- just be fixed.

that aside, I think only rPath has actually bothered to fix the pygrub exploit, at least I didnt find much further references. There's a long way to go for pygrub anyway, it'll be interesting to see if the other grub features like tftp support or trusted grub extensions will go in at some point.

About the exploits nature, let's just say pygrub was very eager to execute domu:/boot/grub/menu.lst, so instructions could be crafted to run in dom0, without using overflows or such.

for shared hosting scenarios this is an obvious nightmare :)</description>
		<content:encoded><![CDATA[<p>of course I hadnt come here just to bash debian&#8230;?! I just ran into this site while try to make pygrub work like everyone else; just at some point I got real angry about how many peoples time is spent on this; the libs are missing in the package and it should -obviously- just be fixed.</p>
<p>that aside, I think only rPath has actually bothered to fix the pygrub exploit, at least I didnt find much further references. There&#8217;s a long way to go for pygrub anyway, it&#8217;ll be interesting to see if the other grub features like tftp support or trusted grub extensions will go in at some point.</p>
<p>About the exploits nature, let&#8217;s just say pygrub was very eager to execute domu:/boot/grub/menu.lst, so instructions could be crafted to run in dom0, without using overflows or such.</p>
<p>for shared hosting scenarios this is an obvious nightmare <img src='http://strugglers.net/~andy/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy</title>
		<link>http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/comment-page-1/#comment-48310</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Sat, 29 Mar 2008 02:42:39 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/#comment-48310</guid>
		<description>Hi,

The broken pygrub is not a security bug so not going to be fixed at least until the next stable release I suppose.

Do you have the details of the pygrub exploit?  I thought I saw it fixed, which is what I wouls expect as a security issue.

If you're just here to bash Debian then I'm not really interested however.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>The broken pygrub is not a security bug so not going to be fixed at least until the next stable release I suppose.</p>
<p>Do you have the details of the pygrub exploit?  I thought I saw it fixed, which is what I wouls expect as a security issue.</p>
<p>If you&#8217;re just here to bash Debian then I&#8217;m not really interested however.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: darkfader</title>
		<link>http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/comment-page-1/#comment-48309</link>
		<dc:creator>darkfader</dc:creator>
		<pubDate>Sat, 29 Mar 2008 02:27:06 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/#comment-48309</guid>
		<description>I really love how i just need to waste an hour googling and messing around in the pygrub source and just download the xen sources on top of it just because noone debian bothers to TEST or FIX this issue since 2006.
wouldnt be as funny if there werent this exec exploit in pygrub which debian now at least can claim to be absolutely prone against.
You can't hack whats broken...</description>
		<content:encoded><![CDATA[<p>I really love how i just need to waste an hour googling and messing around in the pygrub source and just download the xen sources on top of it just because noone debian bothers to TEST or FIX this issue since 2006.<br />
wouldnt be as funny if there werent this exec exploit in pygrub which debian now at least can claim to be absolutely prone against.<br />
You can&#8217;t hack whats broken&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kju</title>
		<link>http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/comment-page-1/#comment-43573</link>
		<dc:creator>kju</dc:creator>
		<pubDate>Thu, 14 Feb 2008 23:45:34 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/#comment-43573</guid>
		<description>Just for the record: The disk corruption problem does not occur when using RAID1 (at least not with Xen 3.1/3.2, kernel 2.6.22 [xen patch from ubuntu] in dom0 and 2.6.18 [xen patch form debian/fedora] in domU. I can't remember if i tried xvda with Xen 3.0.x and 2.6.18 in dom0, though.</description>
		<content:encoded><![CDATA[<p>Just for the record: The disk corruption problem does not occur when using RAID1 (at least not with Xen 3.1/3.2, kernel 2.6.22 [xen patch from ubuntu] in dom0 and 2.6.18 [xen patch form debian/fedora] in domU. I can&#8217;t remember if i tried xvda with Xen 3.0.x and 2.6.18 in dom0, though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/comment-page-1/#comment-40810</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Sat, 26 Jan 2008 21:20:01 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/#comment-40810</guid>
		<description>Thanks for this post.  Pulling my hair out w/ pygrub, trying to build a centos domU on my debian dom0.  I'm also using LV's for domU's, and wasn't about to switch to images.  Downloading the xen source and building the ext2 pieces worked like a champ.</description>
		<content:encoded><![CDATA[<p>Thanks for this post.  Pulling my hair out w/ pygrub, trying to build a centos domU on my debian dom0.  I&#8217;m also using LV&#8217;s for domU&#8217;s, and wasn&#8217;t about to switch to images.  Downloading the xen source and building the ext2 pieces worked like a champ.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy</title>
		<link>http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/comment-page-1/#comment-40001</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Sun, 20 Jan 2008 09:17:13 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/#comment-40001</guid>
		<description>Thanks Ask.  I opened one with Debian also:

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=461644

Cheers,
Andy</description>
		<content:encoded><![CDATA[<p>Thanks Ask.  I opened one with Debian also:</p>
<p><a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=461644" rel="nofollow">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=461644</a></p>
<p>Cheers,<br />
Andy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ask Bjørn Hansen</title>
		<link>http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/comment-page-1/#comment-39998</link>
		<dc:creator>Ask Bjørn Hansen</dc:creator>
		<pubDate>Sun, 20 Jan 2008 08:57:24 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2008/01/20/red-hat-based-linux-under-xen-from-debian-etch/#comment-39998</guid>
		<description>There's an open bug in the RedHat bugtracker regarding the issue:

   https://bugzilla.redhat.com/show_bug.cgi?id=223947


 - ask</description>
		<content:encoded><![CDATA[<p>There&#8217;s an open bug in the RedHat bugtracker regarding the issue:</p>
<p>   <a href="https://bugzilla.redhat.com/show_bug.cgi?id=223947" rel="nofollow">https://bugzilla.redhat.com/show_bug.cgi?id=223947</a></p>
<p> - ask</p>
]]></content:encoded>
	</item>
</channel>
</rss>
