From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id EAB5CCD1288 for ; Wed, 3 Apr 2024 13:31:23 +0000 (UTC) Received: from list by lists.xenproject.org with outflank-mailman.700545.1093865 (Exim 4.92) (envelope-from ) id 1rs0hu-0004Lb-GV; Wed, 03 Apr 2024 13:31:14 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version Received: by outflank-mailman (output) from mailman id 700545.1093865; Wed, 03 Apr 2024 13:31:14 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1rs0hu-0004LU-CZ; Wed, 03 Apr 2024 13:31:14 +0000 Received: by outflank-mailman (input) for mailman id 700545; Wed, 03 Apr 2024 13:31:12 +0000 Received: from se1-gles-sth1-in.inumbo.com ([159.253.27.254] helo=se1-gles-sth1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1rs0hs-0004LM-JD for xen-devel@lists.xenproject.org; Wed, 03 Apr 2024 13:31:12 +0000 Received: from sender4-of-o51.zoho.com (sender4-of-o51.zoho.com [136.143.188.51]) by se1-gles-sth1.inumbo.com (Halon) with ESMTPS id 6e51b356-f1be-11ee-afe5-a90da7624cb6; Wed, 03 Apr 2024 15:31:11 +0200 (CEST) Received: by mx.zohomail.com with SMTPS id 1712151064755188.14610449192196; Wed, 3 Apr 2024 06:31:04 -0700 (PDT) X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: 6e51b356-f1be-11ee-afe5-a90da7624cb6 ARC-Seal: i=1; a=rsa-sha256; t=1712151066; cv=none; d=zohomail.com; s=zohoarc; b=YZcPye6AqfUaWsg0teZxQSvw1HlUma9o9iSy7M9mGpi87DjcGG9sPgd9Yx2P++iEqcpUnLfeZn+JcKXtMAuElD2PKCzbrIPmdOhd8hJKs9aHePgDiPgSix5sV1a7/9paVZm694dIhX4UFYrTMaqNb2FnBxYy82nFuGLQi6RYhOo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1712151066; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:MIME-Version:Message-ID:References:Subject:Subject:To:To:Message-Id:Reply-To; bh=jGb0wbnB4CIEWPYCV1GMNzIV1Nr5eSQsU2upTXfOHHI=; b=PwyTUnuF/D6edtQIs8AVql95/r2q1sScPK2erpuZBlBbUp5/rx6xftmpZWGmozh4DqdWweHBzc6iQlO2Ox87gmKXX46Iz6SxC/ogqfiB+yHzFoYrjEYx15O9oTjhE60a+2uSmQ2tB+n1FA/IVYWKpg/B1Zn+WmJiP0m8E9Iwz9o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=apertussolutions.com; spf=pass smtp.mailfrom=dpsmith@apertussolutions.com; dmarc=pass header.from= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; t=1712151066; s=zoho; d=apertussolutions.com; i=dpsmith@apertussolutions.com; h=Message-ID:Date:Date:MIME-Version:Subject:Subject:To:To:Cc:Cc:References:From:From:In-Reply-To:Content-Type:Content-Transfer-Encoding:Message-Id:Reply-To; bh=jGb0wbnB4CIEWPYCV1GMNzIV1Nr5eSQsU2upTXfOHHI=; b=Eyd9g2dSZzMN/KYbRvY2z/t17iX7tDIy3usoQ4o9V4FYDnXmNkKubXi5v+qfT5Re kVlxz5wRCMK6dbaoHuKwnbN4K9/zzZ0IYB4VAANVbRjutGK0thdqfOhxgNEc+AICaS3 BfpQdzf1TxARiAL4Xywvq820L3Xar+t0PDF4c1OU= Message-ID: Date: Wed, 3 Apr 2024 09:31:03 -0400 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] Revert "evtchn: refuse EVTCHNOP_status for Xen-bound event channels" Content-Language: en-US To: Jan Beulich Cc: George Dunlap , Stefano Stabellini , Julien Grall , Xen-devel , Andrew Cooper References: <20240402170612.2477791-1-andrew.cooper3@citrix.com> <11957460-0b2b-432d-ad92-38350306c9ff@suse.com> <3aa0893b-7efd-4ca1-a405-e897edc7402f@apertussolutions.com> <3b8ec757-d2f3-4143-a843-de8c6d51944d@suse.com> From: "Daniel P. Smith" Autocrypt: addr=dpsmith@apertussolutions.com; keydata= xsJuBFYrueARCACPWL3r2bCSI6TrkIE/aRzj4ksFYPzLkJbWLZGBRlv7HQLvs6i/K4y/b4fs JDq5eL4e9BdfdnZm/b+K+Gweyc0Px2poDWwKVTFFRgxKWq9R7McwNnvuZ4nyXJBVn7PTEn/Z G7D08iZg94ZsnUdeXfgYdJrqmdiWA6iX9u84ARHUtb0K4r5WpLUMcQ8PVmnv1vVrs/3Wy/Rb foxebZNWxgUiSx+d02e3Ad0aEIur1SYXXv71mqKwyi/40CBSHq2jk9eF6zmEhaoFi5+MMMgX X0i+fcBkvmT0N88W4yCtHhHQds+RDbTPLGm8NBVJb7R5zbJmuQX7ADBVuNYIU8hx3dF3AQCm 601w0oZJ0jGOV1vXQgHqZYJGHg5wuImhzhZJCRESIwf+PJxik7TJOgBicko1hUVOxJBZxoe0 x+/SO6tn+s8wKlR1Yxy8gYN9ZRqV2I83JsWZbBXMG1kLzV0SAfk/wq0PAppA1VzrQ3JqXg7T MZ3tFgxvxkYqUP11tO2vrgys+InkZAfjBVMjqXWHokyQPpihUaW0a8mr40w9Qui6DoJj7+Gg DtDWDZ7Zcn2hoyrypuht88rUuh1JuGYD434Q6qwQjUDlY+4lgrUxKdMD8R7JJWt38MNlTWvy rMVscvZUNc7gxcmnFUn41NPSKqzp4DDRbmf37Iz/fL7i01y7IGFTXaYaF3nEACyIUTr/xxi+ MD1FVtEtJncZNkRn7WBcVFGKMAf+NEeaeQdGYQ6mGgk++i/vJZxkrC/a9ZXme7BhWRP485U5 sXpFoGjdpMn4VlC7TFk2qsnJi3yF0pXCKVRy1ukEls8o+4PF2JiKrtkCrWCimB6jxGPIG3lk 3SuKVS/din3RHz+7Sr1lXWFcGYDENmPd/jTwr1A1FiHrSj+u21hnJEHi8eTa9029F1KRfocp ig+k0zUEKmFPDabpanI323O5Tahsy7hwf2WOQwTDLvQ+eqQu40wbb6NocmCNFjtRhNZWGKJS b5GrGDGu/No5U6w73adighEuNcCSNBsLyUe48CE0uTO7eAL6Vd+2k28ezi6XY4Y0mgASJslb NwW54LzSSM0uRGFuaWVsIFAuIFNtaXRoIDxkcHNtaXRoQGFwZXJ0dXNzb2x1dGlvbnMuY29t PsJ6BBMRCAAiBQJWK7ngAhsjBgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRBTc6WbYpR8 KrQ9AP94+xjtFfJ8gj5c7PVx06Zv9rcmFUqQspZ5wSEkvxOuQQEAg6qEsPYegI7iByLVzNEg 7B7fUG7pqWIfMqFwFghYhQzOwU0EViu54BAIAL6MXXNlrJ5tRUf+KMBtVz1LJQZRt/uxWrCb T06nZjnbp2UcceuYNbISOVHGXTzu38r55YzpkEA8eURQf+5hjtvlrOiHxvpD+Z6WcpV6rrMB kcAKWiZTQihW2HoGgVB3gwG9dCh+n0X5OzliAMiGK2a5iqnIZi3o0SeW6aME94bSkTkuj6/7 OmH9KAzK8UnlhfkoMg3tXW8L6/5CGn2VyrjbB/rcrbIR4mCQ+yCUlocuOjFCJhBd10AG1IcX OXUa/ux+/OAV9S5mkr5Fh3kQxYCTcTRt8RY7+of9RGBk10txi94dXiU2SjPbassvagvu/hEi twNHms8rpkSJIeeq0/cAAwUH/jV3tXpaYubwcL2tkk5ggL9Do+/Yo2WPzXmbp8vDiJPCvSJW rz2NrYkd/RoX+42DGqjfu8Y04F9XehN1zZAFmCDUqBMa4tEJ7kOT1FKJTqzNVcgeKNBGcT7q 27+wsqbAerM4A0X/F/ctjYcKwNtXck1Bmd/T8kiw2IgyeOC+cjyTOSwKJr2gCwZXGi5g+2V8 NhJ8n72ISPnOh5KCMoAJXmCF+SYaJ6hIIFARmnuessCIGw4ylCRIU/TiXK94soilx5aCqb1z ke943EIUts9CmFAHt8cNPYOPRd20pPu4VFNBuT4fv9Ys0iv0XGCEP+sos7/pgJ3gV3pCOric p15jV4PCYQQYEQgACQUCViu54AIbDAAKCRBTc6WbYpR8Khu7AP9NJrBUn94C/3PeNbtQlEGZ NV46Mx5HF0P27lH3sFpNrwD/dVdZ5PCnHQYBZ287ZxVfVr4Zuxjo5yJbRjT93Hl0vMY= In-Reply-To: <3b8ec757-d2f3-4143-a843-de8c6d51944d@suse.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-ZohoMailClient: External On 4/3/24 07:54, Jan Beulich wrote: > On 03.04.2024 13:50, Daniel P. Smith wrote: >> On 4/3/24 02:52, Jan Beulich wrote: >>> On 03.04.2024 08:16, Jan Beulich wrote: >>>> On 02.04.2024 19:06, Andrew Cooper wrote: >>>>> Whether to return information about a xen-owned evtchn is a matter of policy, >>>>> and it's not acceptable to short circuit the XSM on the matter. >>>> >>>> I can certainly accept this as one possible view point. As in so many cases >>>> I'm afraid I dislike you putting it as if it was the only possible one. >>> >>> Further to this: Is there even a way to express the same denial in XSM? >>> alloc_unbound_xen_event_channel() doesn't specifically "mark" such a >>> channel, and (yes, it could in principle be open-coded in Flask code) >>> consumer_is_xen() is private to event_channel.c. I also dare to question >>> whether in SILO mode status information like this should be available. >> >> To build on the previous response: if the natural failure return value >> is -EACCESS in response to a domain resource access attempt, then the >> probability is extremely high that it should be implemented under a XSM >> hook and not hard-coded into the resource logic. > > Possibly. But first of all - could you answer the earlier question I raised? Don't need to, this change subverts/violates the access control framework. If the desire is to make this access decision for the default/dummy policy, then codify it there. Otherwise I will be ack'ing this change since it is access control and falls under the purview of XSM. v/r, dps