From: Francisco Rocha <f.e.liberal-rocha@newcastle.ac.uk>
To: Tim Deegan <tim@xen.org>
Cc: "xen-devel@lists.xen.org" <xen-devel@lists.xen.org>
Subject: Re: reserve e820 ram
Date: Wed, 18 Apr 2012 15:36:44 +0100 [thread overview]
Message-ID: <4F8ED17C.4090203@newcastle.ac.uk> (raw)
In-Reply-To: <20120418120236.GB7013@ocelot.phlegethon.org>
[-- Attachment #1.1: Type: text/plain, Size: 2359 bytes --]
On 04/18/2012 01:02 PM, Tim Deegan wrote:
Hi,
Can you please set up your mail client to indent quoted text? It's not
clear which parts of your email are quoted and which are your replies.
Sorry about that.
At 13:53 +0100 on 11 Apr (1334152395), Francisco Rocha wrote:
> You can handle the second by using
> stub domains to run qemu in a different domain, or by only usoing PV
> domUs.
>
> If I use the stub domain provided with xen the dom0 will not perform the
> second mapping, right?
Yes; instead, the stub domain will perform it - so you'll need to allow
that to happen. (Basically the stub domain's code lives inside the
guest's protection boundary, like its BIOS code &c).
> The third is pretty much a requirement if the domU's going to do
> any I/O via dom0, but at least with grant tables the ACL is under domU's
> control. Or if you have an IOMMU you can give the domU direct access to
> its own network card and disk controller.
>
> I only have one ethernet card but i can get an ethernet expresscard.
>
> Can I do this in my the machine that gives me the output that follows?
>
> (XEN) Intel VT-d Snoop Control not enabled.
> (XEN) Intel VT-d Dom0 DMA Passthrough not enabled.
> (XEN) Intel VT-d Queued Invalidation enabled.
> (XEN) Intel VT-d Interrupt Remapping enabled.
> (XEN) Intel VT-d Shared EPT tables not enabled.
Yes; you should be able to do it on this machine without changing any
BIOS settings.
Tim.
Hi Tim,
I was thinking about changing my approach.
I think that for now I will leave those pages off because I am
mostly interested in protecting other areas.
Those accesses for now are inevitable to get the VM to properly
operate. Now, the question is if it is possible to use page table
entries to do what I want to do.
The objective would be to use a bit flag that would determine if
the pages are returned when a call to map_foreign_range is made.
So, my final objective would be that only pages used for the three
operations you describe are accessible to Dom0.
Everything that is not BIOS and related, Qemu or PV backend
drivers will not be returned.
>From what I see in the header files you use 12-bits from a 24-bit
flag (x86_64). Can we do it? This would again take us to controlling
access at get_page_from_l1e(), right?
Thank you,
Francisco
[-- Attachment #1.2: Type: text/html, Size: 3979 bytes --]
[-- Attachment #2: Type: text/plain, Size: 126 bytes --]
_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xen.org
http://lists.xen.org/xen-devel
next prev parent reply other threads:[~2012-04-18 14:36 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-03-29 11:52 reserve e820 ram Francisco Rocha
2012-04-05 10:37 ` Tim Deegan
2012-04-05 11:02 ` Francisco Rocha
2012-04-11 11:22 ` Francisco Rocha
2012-04-11 11:58 ` Tim Deegan
2012-04-11 12:53 ` Francisco Rocha
2012-04-18 12:02 ` Tim Deegan
2012-04-18 14:36 ` Francisco Rocha [this message]
2012-04-18 16:43 ` Tim Deegan
2012-04-18 17:10 ` Francisco Rocha
2012-04-20 8:16 ` Tim Deegan
2012-04-27 9:31 ` Francisco Rocha
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4F8ED17C.4090203@newcastle.ac.uk \
--to=f.e.liberal-rocha@newcastle.ac.uk \
--cc=tim@xen.org \
--cc=xen-devel@lists.xen.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.