All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Mike D. Day" <ncmike@us.ibm.com>
To: "George S. Coker, II" <gscoker@alpha.ncsc.mil>
Cc: xen-devel <xen-devel@lists.xensource.com>,
	Alex Williamson <alex.williamson@hp.com>
Subject: Re: xsm: Consolidate xsm processing within domain control hypercall.
Date: Tue, 4 Dec 2007 16:59:02 -0500	[thread overview]
Message-ID: <20071204215902.GD23369@silverwood.ncultra.org> (raw)
In-Reply-To: <C37B36C2.10B43%gscoker@alpha.ncsc.mil>

On 04/12/07 16:54 -0500, George S. Coker, II wrote:
> 
> > 
> >> 2) This will also impose on the security modules the responsibility to
> >> acquire and hold locks on hypervisor resources.  It would seem dangerous to
> >> give modules this responsibility.
> > 
> > I don't see it, the locking logic is still the same. Can you show me
> > where the module needs to acquire locks differently than without the
> > patch?
> > 
> It's not that the locking logic is different.  A security module may be
> sloppy about its locking and cause Xen to crash without specifically
> indicating a flaw in the security module.
> 
> Getting locks right is tricky business, it would seem the Xen would want the
> responsibility for the locking of resources to avoid the ills of race
> conditions, etc.

I agree with your comments, but I don't think the patch changes
locking at all. If I'm wrong I agree that's a problem. 

Mike

-- 
Mike D. Day
IBM LTC
Cell: 919 412-3900
Sametime: ncmike@us.ibm.com AIM: ncmikeday  Yahoo: ultra.runner
PGP key: http://www.ncultra.org/ncmike/pubkey.asc

  reply	other threads:[~2007-12-04 21:59 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <200712041026.lB4AQPM6004133@latara.uk.xensource.com>
2007-12-04 20:06 ` [Xen-staging] [xen-unstable] xsm: Consolidate xsm processing within domain control hypercall Alex Williamson
2007-12-04 20:44   ` Alex Williamson
2007-12-04 21:20     ` George S. Coker, II
2007-12-04 21:46       ` Mike D. Day
2007-12-04 21:54         ` George S. Coker, II
2007-12-04 21:59           ` Mike D. Day [this message]
2007-12-04 23:26             ` George S. Coker, II
2007-12-04 23:22         ` George S. Coker, II
2007-12-04 21:36     ` Mike D. Day
2007-12-04 21:52       ` Alex Williamson
2007-12-04 21:58         ` George S. Coker, II
2007-12-04 22:26           ` Mike D. Day
2007-12-04 21:49   ` Mike D. Day
2007-12-04 22:05     ` Alex Williamson
2007-12-04 22:23       ` George S. Coker, II
2007-12-05  0:19       ` Alex Williamson
2007-12-04 22:44   ` Mike D. Day
2007-12-04 23:27     ` George S. Coker, II

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20071204215902.GD23369@silverwood.ncultra.org \
    --to=ncmike@us.ibm.com \
    --cc=alex.williamson@hp.com \
    --cc=gscoker@alpha.ncsc.mil \
    --cc=xen-devel@lists.xensource.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.