The first stable OpenVZ release
Posted Dec 16, 2005 15:41 UTC (Fri) by PaXTeam
In reply to: The first stable OpenVZ release
Parent article: The first stable OpenVZ release
part of what you described as a potential feature in Xen has been implemented in PaX for something like 2.5 years now (KERNEXEC is the feature name). the reamining parts can be implemented as well, but that's quite some work i haven't found the time for yet. so single kernel image solutions can be made as resistant as what you said about Xen. this is actually the reason i asked about OpenVZ's hardening features, as i've been working on similar techniques and am obviously interested in other ideas.
to post comments)