WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
Xen

xen-devel

[Top] [All Lists]

RE: [Xen-devel] [PATCH] xend: passthrough: add an option pci-passthrough

To: Simon Horman <horms@xxxxxxxxxxxx>
Subject: RE: [Xen-devel] [PATCH] xend: passthrough: add an option pci-passthrough-strict-check
From: "Cui, Dexuan" <dexuan.cui@xxxxxxxxx>
Date: Tue, 8 Sep 2009 08:23:38 +0800
Accept-language: zh-CN, en-US
Acceptlanguage: zh-CN, en-US
Cc: "xen-devel@xxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxx>, Keir Fraser <keir.fraser@xxxxxxxxxxxxx>
Delivery-date: 2009年9月07日 17:23:00 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <20090907234145.GD14053@xxxxxxxxxxxx>
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
References: <EADF0A36011179459010BDF5142A457501CD85CBB0@xxxxxxxxxxxxxxxxxxxxxxxxxxxx> <20090907234145.GD14053@xxxxxxxxxxxx>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
Thread-index: AcowFMa5TbZDIxXSS4yLnaywr3mcnwAA/hAA
Thread-topic: [Xen-devel] [PATCH] xend: passthrough: add an option pci-passthrough-strict-check
By default the option is "yes" so we're safe and since the option is in the 
global xend config file, only an administrator can change it.
In some cases, if an administrator knows clearly what he's doing, he may want 
to try to use the device assignment feature at the risk of some potential 
security issues -- usually some of the potential issue are not very likely to 
occur. So I guess the option should be useful. :-)
Thanks,
-- Dexuan
-----Original Message-----
From: Simon Horman [mailto:horms@xxxxxxxxxxxx] 
Sent: 2009?9?8? 7:42
To: Cui, Dexuan
Cc: Keir Fraser; xen-devel@xxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-devel] [PATCH] xend: passthrough: add an option 
pci-passthrough-strict-check
On Mon, Sep 07, 2009 at 06:02:02PM +0800, Cui, Dexuan wrote:
> Currently when assigning device to HVM guest, we use the strict check for HVM
> guest by default.(For PV guest we use loose check automatically if necessary.)
>
> When we assign device to HVM guest, if we meet with the co-assignment issues 
> or
> the ACS issue (see changeset 20081: 4a517458406f), we could try changing the
> option to 'no' -- however, we have to realize this may incur security issue 
> and
> we can't make sure the device assignment could really work properly even after
> we do this.
>
> The option is located in /etc/xen/xend-config.sxp:
> (pci-passthrough-strict-check yes)
This sounds like it opens a can of worms to me.
I take it that you have equipment and a set-up in
mind that needs this.
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel
<Prev in Thread] Current Thread [Next in Thread>
Previous by Date: Re: [Xen-devel] Video Presentation on PCI Express x16 VGA PassThrough to Xen-based Windows XP Home Edition HVM Virtual Machine , Mr. Teo En Ming (Zhang Enming)
Next by Date: RE: [Xen-devel] Video Presentation on PCI Express x16 VGA PassThrough to Xen-based Windows XP Home Edition HVM Virtual Machine , Han, Weidong
Previous by Thread: Re: [Xen-devel] [PATCH] xend: passthrough: add an option pci-passthrough-strict-check , Simon Horman
Next by Thread: Re: [Xen-devel] [PATCH] xend: passthrough: add an option pci-passthrough-strict-check , Simon Horman
Indexes: [Date] [Thread] [Top] [All Lists]

Copyright ©, Citrix Systems Inc. All rights reserved. Legal and Privacy
Citrix This site is hosted by Citrix

AltStyle によって変換されたページ (->オリジナル) /