From: Sheng Yang <sheng@linux.intel.com>
To: Ian Campbell <Ian.Campbell@citrix.com>
Cc: "xen-devel@lists.xensource.com" <xen-devel@lists.xensource.com>,
Keir Fraser <Keir.Fraser@eu.citrix.com>
Subject: Re: [PATCH][v2] Hybrid extension support in Xen
Date: Tue, 2 Feb 2010 21:06:42 +0800 [thread overview]
Message-ID: <201002022106.42451.sheng@linux.intel.com> (raw)
In-Reply-To: <1265110015.2965.22432.camel@zakaz.uk.xensource.com>
On Tuesday 02 February 2010 19:26:55 Ian Campbell wrote:
> On Tue, 2010-02-02 at 08:16 +0000, Sheng Yang wrote:
> > +static hvm_hypercall_t *hvm_hypercall_hybrid64_table[NR_hypercalls] =
> > {
> > + [ __HYPERVISOR_memory_op ] = (hvm_hypercall_t *)hvm_memory_op,
> > + [ __HYPERVISOR_grant_table_op ] = (hvm_hypercall_t
> > *)hvm_grant_table_op,
> > + HYPERCALL(xen_version),
> > + HYPERCALL(console_io),
> > + HYPERCALL(vcpu_op),
> > + HYPERCALL(sched_op),
> > + HYPERCALL(event_channel_op),
> > + HYPERCALL(hvm_op),
> > +};
>
> Why not just expand the exiting hvm hypercall table to incorporate these
> new hypercalls?
I am just afraid the normal HVM guest called these hypercalls would result in
some chaos, so add a limitation(for hybrid only) here. (I admit it didn't much
improve the security for a malicious guest...)
>
> In fact, why is hybrid mode considered a separate mode by the hypervisor
> at all? Shouldn't it just be an extension to regular HVM mode which
> guests may choose to use? This seems like it would eliminate a bunch of
> the random conditionals.
There is still something different from normal HVM guest. For example, to use
PV timer, we should clean the tsc offset in HVM domain; and for event
delivery, we would use predefined VIRQ rather than emulated IOAPIC/APIC. These
code are exclusive, we need them wrapped with flag(which we called "hybrid").
The word "mode" here may be is inaccuracy, a "extension" should be more
proper. I would change the phrase next time.
>
> Have you verified that all of the operations you are making available
> are safe to be called from (hybrid)hvm mode?
You mean malicious guest attack? Sorry, I haven't try it yet...
--
regards
Yang, Sheng
next prev parent reply other threads:[~2010-02-02 13:06 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-02-02 8:16 [PATCH][v2] Hybrid extension support in Xen Sheng Yang
2010-02-02 11:22 ` Ian Campbell
2010-02-02 12:54 ` Sheng Yang
2010-02-02 13:19 ` Ian Campbell
2010-02-02 13:28 ` Sheng Yang
2010-02-02 13:50 ` Ian Campbell
2010-02-02 14:00 ` Tim Deegan
2010-02-02 14:22 ` Sheng Yang
2010-02-02 14:28 ` Sheng Yang
2010-02-02 13:35 ` Keir Fraser
2010-02-02 13:52 ` Sheng Yang
2010-02-02 14:01 ` Keir Fraser
2010-02-02 14:13 ` Sheng Yang
2010-02-02 11:26 ` Ian Campbell
2010-02-02 13:06 ` Sheng Yang [this message]
2010-02-02 13:52 ` Ian Campbell
2010-02-02 14:04 ` Stefano Stabellini
2010-02-02 14:07 ` Sheng Yang
2010-02-02 16:15 ` Ian Campbell
2010-02-02 16:31 ` Sheng Yang
2010-02-02 18:03 ` Ian Campbell
2010-02-02 18:27 ` Stefano Stabellini
2010-02-03 5:15 ` Sheng Yang
2010-02-03 10:39 ` Tim Deegan
2010-02-02 11:32 ` Paul Durrant
2010-02-02 13:23 ` Keir Fraser
2010-02-02 13:37 ` Sheng Yang
2010-02-02 14:03 ` Keir Fraser
2010-02-02 14:08 ` Sheng Yang
2010-02-02 14:32 ` Keir Fraser
2010-02-02 14:37 ` Keir Fraser
2010-02-02 15:51 ` Sheng Yang
2010-02-02 14:39 ` Sheng Yang
2010-02-02 13:52 ` Ian Campbell
2010-02-02 13:53 ` Sheng Yang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=201002022106.42451.sheng@linux.intel.com \
--to=sheng@linux.intel.com \
--cc=Ian.Campbell@citrix.com \
--cc=Keir.Fraser@eu.citrix.com \
--cc=xen-devel@lists.xensource.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.