diff --git a/docs/news.xml b/docs/news.xml index dc924ff1bf8dddb2aa1b813d9f3375812328122d..f6aee74884c53bb1f1bec573db7680a4c93708d4 100644 --- a/docs/news.xml +++ b/docs/news.xml @@ -85,13 +85,13 @@ - Split libvirtd into separate daemons + Experimental split of libvirtd into separate daemons The big monolithic libvirtd daemon can now be replaced by smaller - per-driver daemons. Distributions can chose if they want the former - or the latter. The libvirtd is still kept around for backwards - compatibility. + per-driver daemons. The new split daemons are considered experimental + at this time and distributions are encouraged to continue using the + traditional libvirtd by default. @@ -156,13 +156,22 @@ - Stop linking virt-login-shell and NSS plugins with libvirt.so + Stop linking NSS plugins with libvirt.so - In order to allow libvirt to abort on out of memory, we need to stop - linking libvirt.so to virt-login-shell or the NSS plugins where we - don't want to abort. This change also resulted in smaller binaries - and libraries. + This reduces the amount of code and 3rd party libraries are that + loaded into all processes. + + + + + Split the setuid virt-login-shell binary into two pieces + + + The setuid virt-login-shell binary is now a tiny shim that + sanitizes the process execution environment variables and + arguments, before launching the trusted virt-login-shell-helper + binary.