From: Dario Faggioli <dario.faggioli@citrix.com>
To: Jan Beulich <JBeulich@suse.com>
Cc: Lars Kurth <lars.kurth@citrix.com>,
Stefano Stabellini <sstabellini@kernel.org>,
Wei Liu <wei.liu2@citrix.com>,
George Dunlap <George.Dunlap@eu.citrix.com>,
Andrew Cooper <andrew.cooper3@citrix.com>,
Anshul Makkar <anshul.makkar@citrix.com>,
Ian Jackson <ian.jackson@eu.citrix.com>, Tim Deegan <tim@xen.org>,
security@xenproject.org, xen-devel@lists.xenproject.org
Subject: Re: [PATCH v2] features: declare the Credit2 scheduler as Supported.
Date: Wed, 2 Nov 2016 12:22:40 +0100 [thread overview]
Message-ID: <1478085760.24942.32.camel@citrix.com> (raw)
In-Reply-To: <5819D525020000780011B8EA@prv-mh.provo.novell.com>
[-- Attachment #1.1: Type: text/plain, Size: 1594 bytes --]
On Wed, 2016-11-02 at 04:59 -0600, Jan Beulich wrote:
> > > > On 02.11.16 at 11:22, <dario.faggioli@citrix.com> wrote:
> > The control domain can issue DOMCTL_SCHEDOP and SYSCTL_SCHEDOP
> > hypercalls. Auditing such code, nothing that looks like a security
> > risk has been found (E.g., there's no risk of leaking content of
> > the hypervisor stack, as no buffer/local variables is returned).
>
> There certainly are buffers being returned here. Namely in the
> credit2 case there's also a 32-bit padding field in the domctl
> interface structure (and uniformly for all schedulers there's one
> in the sysctl structure), which provides the fundamental means
> to leak stack data. However, none of this is a problem, both
> because iirc leaking stack data to Dom0 is not really considered
> a security issue, and because of the way the structures get
> dealt with.
>
Right, what I meant is really "none of this is a problem [...] because
of the way the structures get dealt with".
I.e., there is nothing like what made e0e3b8f64730f3ee necessary.
> Nevertheless I think the above paragraph should be
> re-worded.
>
Yep, I certainly could have said it better. But if leaking to Dom0 is
not worth being considered, I guess I can just remove the paragraph
entirely, can't I?
Thanks and Regards,
Dario
--
<<This happens because I choose it to happen!>> (Raistlin Majere)
-----------------------------------------------------------------
Dario Faggioli, Ph.D, http://about.me/dario.faggioli
Senior Software Engineer, Citrix Systems R&D Ltd., Cambridge (UK)
[-- Attachment #1.2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 819 bytes --]
[-- Attachment #2: Type: text/plain, Size: 127 bytes --]
_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xen.org
https://lists.xen.org/xen-devel
next prev parent reply other threads:[~2016-11-02 11:22 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-11-02 10:22 [PATCH v2] features: declare the Credit2 scheduler as Supported Dario Faggioli
2016-11-02 10:37 ` Andrew Cooper
2016-11-02 10:50 ` Dario Faggioli
2016-11-02 10:59 ` Jan Beulich
2016-11-02 11:22 ` Dario Faggioli [this message]
2016-11-02 11:29 ` Jan Beulich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1478085760.24942.32.camel@citrix.com \
--to=dario.faggioli@citrix.com \
--cc=George.Dunlap@eu.citrix.com \
--cc=JBeulich@suse.com \
--cc=andrew.cooper3@citrix.com \
--cc=anshul.makkar@citrix.com \
--cc=ian.jackson@eu.citrix.com \
--cc=lars.kurth@citrix.com \
--cc=security@xenproject.org \
--cc=sstabellini@kernel.org \
--cc=tim@xen.org \
--cc=wei.liu2@citrix.com \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.