All of lore.kernel.org
 help / color / mirror / Atom feed
* tracking of Xen heap pages shared with guest
@ 2008-03-14 12:59 Jan Beulich
  2008-03-14 13:10 ` Keir Fraser
  0 siblings, 1 reply; 6+ messages in thread
From: Jan Beulich @ 2008-03-14 12:59 UTC (permalink / raw)
  To: xen-devel

I assume I'm overlooking something, but can someone explain how page
tracking works in the following two cases:

a) A guest unintentionally or maliciously frees (e.g. through
decrease_reservation) a page shared from the Xen heap (e.g. the
shared info page). From what I can see, such a page would have a
reference count of 1 (from share_xen_page_with_guest(), assuming
the guest doesn't have the page mapped), and would hence be
immediately freed with the corresponding put_page(). Nevertheless
Xen itself may continue to write to such a page.

b) A domU that had a xenoprof buffer allocated gets killed. Since the
xenoprof code directly calls free_xenheap_pages() on the buffer,
any mapping dom0 may have to it would not be considered, and hence
dom0 would retain a mapping to free memory. Additionally, the
put_page() in unshare_xenoprof_page_with_guest() could revert the
singe reference to the page established through
share_xen_page_with_guest() (i.e. if dom0 never mapped or already
unmapped the buffer), which again would result in the buffer getting
freed (and thus d->xenoprof->rawbuf becoming stale).

Apparently I'm just failing to find the places where extra reference
counts are being established for such pages...

Thanks, Jan

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2008-03-14 15:35 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-03-14 12:59 tracking of Xen heap pages shared with guest Jan Beulich
2008-03-14 13:10 ` Keir Fraser
2008-03-14 13:41   ` Jan Beulich
2008-03-14 13:48     ` Keir Fraser
2008-03-14 14:07       ` Jan Beulich
2008-03-14 15:35         ` Keir Fraser

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.