Bugtraq mailing list archives

Re: Sun M-class hardware denial of service


From: Brett Lymn <blymn () baesystems com au>
Date: Mon, 29 Sep 2008 11:53:48 +0930

On Sun, Sep 28, 2008 at 08:14:35PM -0600, Theo de Raadt wrote:

OpenBSD of course cannot run in a Solaris zone.


Right.  Glad that is clear.

OpenBSD can run in a hardware zone, and when something it does (which
we don't know yet) locks up that hardware zone, the only way to get
the hardware zone back is to POWER THE MACHINE OFF.  That is a lack
of hardware zoning, or isolation.  That is not what people paid a lot
of money for.


Yes, we all agree that is bad but this is an OpenBSD specific problem
and, whilst interesting, the reality is that there are no going to be
many people that are lunatic enough to run an untrusted third party
operating system on a machine of this class.

Those customers really expected that the machine would not need a
powerdown to get around a bug in hardware zones.


Yes, no arguing with that.


Noone is talking about Solaris zones except you. 


I suggest you go read the archives again then - I was not the only one.


Why don't we wait for Sun to release the fix, and then you can eat
your words.

I can handle being wrong.  Can you?  As I said before, if you know of
a problem with solaris zones then that makes things a lot more of a
problem but all you have at the moment is a firmware bug which
requires loading a random kernel module - something that can be
controlled in Solaris.

-- 
Brett Lymn
"Warning:
The information contained in this email and any attached files is
confidential to BAE Systems Australia. If you are not the intended
recipient, any use, disclosure or copying of this email or any
attachments is expressly prohibited.  If you have received this email
in error, please notify us immediately. VIRUS: Every care has been
taken to ensure this email and its attachments are virus free,
however, any loss or damage incurred in using this email is not the
sender's responsibility.  It is your responsibility to ensure virus
checks are completed before installing any data sent in this email to
your computer."



Current thread: