From mboxrd@z Thu Jan 1 00:00:00 1970 From: Dario Faggioli Subject: Re: Deployment usage and performance of a network domain Date: Wed, 14 Jun 2017 10:10:08 +0200 Message-ID: <1497427808.26212.47.camel@citrix.com> References: <593943F5.3030108@sec.t-labs.tu-berlin.de> <1496941648.26212.4.camel@citrix.com> <593E4E6E.7020303@sec.t-labs.tu-berlin.de> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============2754660993919029860==" Return-path: In-Reply-To: <593E4E6E.7020303@sec.t-labs.tu-berlin.de> List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xen.org Sender: "Xen-devel" To: Kashyap Thimmaraju , xen-devel@lists.xen.org Cc: George Dunlap List-Id: xen-devel@lists.xenproject.org --===============2754660993919029860== Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="=-k1jeJvTFoaKIdHxv1Wb9" --=-k1jeJvTFoaKIdHxv1Wb9 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Mon, 2017-06-12 at 10:18 +0200, Kashyap Thimmaraju wrote: > > Driver domains and stubdomains are hugely used in contexts > > targeting really strong security, like Qubes and OpenXT: > >=20 > > https://www.qubes-os.org/ http://openxt.org/ > >=20 > > Qubes targets laptops. I've tried it on mine, which is quite old, > > and the drop in perf, e.g., wrt a regular (as in, one that does not > > use virtualization at all) Linux desktop, although present, I don't > > think it comes too much from the driver domain(s). > >=20 > > I haven't run any benchmarks with it, but despite (as I said) the=C2=A0 > > laptop being quite old, the system is definitely usable. >=20 > Thanks. I looked for a performance evaluation of such an architecture > but did not find anything. It would be good to know if there are some > meaningful numbers.=20 > Well, I don't know of any either, but I have never looked. Fact is, meaningfulness depends on what each of us needs and actually find meaningful. So, it's entirely possible that no one has preformed before the specific evaluation you would like to see... > The openxt example of having dedicated virtual > network domains for clients is indeed a good one but I could not find > any performance evaluation on that. Would you or anybody here happen > to know where I can find such information? The 2016 summit does not > have anything on it either. > I think you should: - ask them directly, - begin considering doing some evaluation yourself. If you do, we're definitely interested in seeing what you will find out. Regards, Dario --=20 <> (Raistlin Majere) ----------------------------------------------------------------- Dario Faggioli, Ph.D, http://about.me/dario.faggioli Senior Software Engineer, Citrix Systems R&D Ltd., Cambridge (UK) --=-k1jeJvTFoaKIdHxv1Wb9 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAABCAAGBQJZQO9gAAoJEBZCeImluHPukAUQALqmCA3Jq7wodAGl/2O1T7Ee C/rdcMyit0cUjPO/mAJevd32TwqoK2oro8JQHVgVHGTGl7q1XMQadH9//BQ6fUT8 PgaKes1Zo/P4zZ6BI1GA97lH3HDWOqBFUfxQ24F3+EfjXlruKMUkZSpG2Nf5OARr gRd/JTTl4KHIcwH+iW+KMk0Qn5maSkvnkE51kDL7MXukbX9PaSob+aCuN98m2rGA XSSpty29L1QX75pRbOm4vd07+6S77ekYtXUhoK/VJP2U++eCAEPocVAy4BgeJf4P 5x/myHqw5Zaq3EtnRBjPIwJtAG4EDd+u4FXkDq0Q/Y6HOdNJ9iTHYlZ/HZYnehYR p5CLuzJmMkigt9bjK4xJU7GirvqSGxSFISs/dVrWnyZNGPjzg4ypXNwn/g9EMu2k csfXtapB5lLxhhHKpAIW/0c5FS6nhC+8t2rzi3gVu3Y1ICqF8NiC6QM20/YqPMf1 fjgKZ62w7LFl2vMSKaRefS/4mqMgXpa9IBA16fEa0blMvNmJoiNWxWKYjS2z5Uxr GNjD4aXf5vySu+9KtR5Zr71FhDnyzy6+OVIjCKAGG62IpgMtKnuMCXlFwHTfLnFa 28A1UdmHQEMovF8glILtWQ1/7ALG0UwC7xZr9UhBcGWcMmlaHc75G4M/+XMLwPo1 t8CJMhwwO9e3/DaT0w/9 =8rtQ -----END PGP SIGNATURE----- --=-k1jeJvTFoaKIdHxv1Wb9-- --===============2754660993919029860== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KWGVuLWRldmVs IG1haWxpbmcgbGlzdApYZW4tZGV2ZWxAbGlzdHMueGVuLm9yZwpodHRwczovL2xpc3RzLnhlbi5v cmcveGVuLWRldmVsCg== --===============2754660993919029860==--