All of lore.kernel.org
 help / color / mirror / Atom feed
* On x86_64 Xen Implementation
@ 2008-07-21 10:50 BVK Chaitanya
  2008-07-21 11:17 ` Andre Przywara
  0 siblings, 1 reply; 2+ messages in thread
From: BVK Chaitanya @ 2008-07-21 10:50 UTC (permalink / raw)
  To: Xen-devel

Hi,

Xen 3.0 inteface manual says:

On 64-bit systems it is not possible to protect the hypervisor from 
untrusted guest code running in rings 1 and 2. Guests are therefore 
restricted to run in ring 3 only. The guest kernel is protected from its 
applications by context switching between the kernel and currently 
running application.

Can anybody explain (or provide me pointers) to what x86_64 features 
make protecting hypervisor from untrusted guest (kernels) impossible? 
Is x86_64 (by-design) makes x86's 4 rings feature obsolete?


thanks,
--
bvk-chaitanya

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: On x86_64 Xen Implementation
  2008-07-21 10:50 On x86_64 Xen Implementation BVK Chaitanya
@ 2008-07-21 11:17 ` Andre Przywara
  0 siblings, 0 replies; 2+ messages in thread
From: Andre Przywara @ 2008-07-21 11:17 UTC (permalink / raw)
  To: BVK Chaitanya; +Cc: Xen-devel

BVK Chaitanya wrote:
> Hi,
> 
> Xen 3.0 inteface manual says:
> 
> On 64-bit systems it is not possible to protect the hypervisor from 
> untrusted guest code running in rings 1 and 2. Guests are therefore 
> restricted to run in ring 3 only. The guest kernel is protected from its 
> applications by context switching between the kernel and currently 
> running application.
> 
> Can anybody explain (or provide me pointers) to what x86_64 features 
> make protecting hypervisor from untrusted guest (kernels) impossible? Is 
> x86_64 (by-design) makes x86's 4 rings feature obsolete?

Somewhat. Segmentation support has been mostly dropped in x86_64 long 
mode (aka 64bit mode). By using paging you can only differentiate 
between supervisor and user mode. Separating the different rings 
requires different segment descriptors, which can hold a ring number. 
Since segmentation limits, offsets and protection flags are (mostly) 
ignored in 64bit long mode, you actually cannot use the four rings here.

Regards,
Andre.

-- 
Andre Przywara
AMD-Operating System Research Center (OSRC), Dresden, Germany
Tel: +49 351 277-84917
----to satisfy European Law for business letters:
AMD Saxony Limited Liability Company & Co. KG,
Wilschdorfer Landstr. 101, 01109 Dresden, Germany
Register Court Dresden: HRA 4896, General Partner authorized
to represent: AMD Saxony LLC (Wilmington, Delaware, US)
General Manager of AMD Saxony LLC: Dr. Hans-R. Deppe, Thomas McCoy

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2008-07-21 11:17 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-07-21 10:50 On x86_64 Xen Implementation BVK Chaitanya
2008-07-21 11:17 ` Andre Przywara

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.