bhyve - JSON format and capsicum support for the snapshot feature
Ionuţ Mihalache, Maria-Elena Mihăilescu, Darius Mihai, Mihai Carabaș, Nicolae Ţăpuş · 2021
The current implementation for the snapshot feature of the bhyve supervisor uses three files to save the state of the guest virtual machine. One of the files has binary format, which makes the debug process and data interpretation, two laborious processes.The file descriptors that are used for the files containing the state of the guest virtual machine have more permissions than needed. Without all the necessary restrictions bhyve, the BSD hypervisor, is vulnerable because an attacker can open new files, sockets or write to read only file descriptors.