It's more interesting if they've managed to fully protect the kernel part of this (ie. vmm on OpenBSD, KVM on Linux) from the rest of the kernel.
It's more interesting if they've managed to fully protect the kernel part of this (ie. vmm on OpenBSD, KVM on Linux) from the rest of the kernel.
OpenBSD's VMs seem to be pledge()d to not call most host-side kernel interfaces...
SELinux, seccomp, and all that protect a compromised user space thread in the host (responsible for running emulated guests, or one that provides virtual device support to guests) from other user space threads (other VMs). If there is a some problem in the KVM kernel module that stomps over memory, SELinux and seccomp can't do anything about it.
Nothing can really prevent driver bug causing a crash, this isn't a microkernel, but it can reduce exposure from userland, i.e: pledge restrictions on syscalls/ioctls/sysctls.