|
The current kernel + patch provides a fair level of
isolation between the virtual servers. User root
can't take over the system: He sees only his processes,
has only access to his area of the file system (chroot)
and can't reconfigure the kernel. Yet there are some
potential problems. They are fixable. As usage
grows, we will know if they are real problems. Comments
are welcome:
|