CL> I also want to see what KVM does here; however, I don't think that
CL> prevents us from implementing our own, since we would still need
CL> similar things for other hypervisors (Xen, etc.).
Right, I think it's important to include the possibility for the
hypervisor to do its own check. Since you mentioned the need for the
user to specify a list of allowable checks, perhaps "ask the hypervisor
too" could be one of those.
--
Dan Smith
IBM Linux Technology Center
Open Hypervisor Team
email: danms(a)us.ibm.com