Hacker News new | ask | show | jobs
by snvzz 450 days ago
In seL4's virtualization support, VM exceptions are turned into messages and handled by VMM, a task running in unprivileged mode.

VMM has no more capabilities than the VM itself, thus a VM escape would be, outside of academics, of no value.

Refer to pages 8 to 10 in the OP PDF.