From: Gleb Natapov <gleb@redhat.com>
To: Kevin O'Connor <kevin@koconnor.net>
Cc: qemu-devel@nongnu.org, Sebastian Herbszt <herbszt@gmx.de>
Subject: Re: [Qemu-devel] Re: POST failure (loop) with isapc and seabios
Date: Mon, 23 Nov 2009 13:17:26 +0200 [thread overview]
Message-ID: <20091123111726.GI2999@redhat.com> (raw)
In-Reply-To: <20091122174024.GD13491@morn.localdomain>
On Sun, Nov 22, 2009 at 12:40:24PM -0500, Kevin O'Connor wrote:
> On Sun, Nov 22, 2009 at 05:38:09PM +0200, Gleb Natapov wrote:
> > On Sun, Nov 22, 2009 at 04:31:24PM +0100, Sebastian Herbszt wrote:
> > > // Write protect bios memory.
> > > make_bios_readonly();
> > Hmmm. How is tpr patching works then? It relies on ability of a guest to
> > write into BIOS memory region. Need to retest if it actually works I
> > guess.
>
> The last time I looked, the TPR patching backend forced the "vapic"
> pages to be writable (effectively overriding the bios decision to make
> it readonly).
>
Don't see where it does this. But now I recall that KVM doesn't support
ROM slots, so BIOS area is always writable under KVM.
> > > Bad things could happen if someone modifies the BIOS because it's unprotected
> > > (e.g. VM crash).
>
> I'm not sure why modification of the BIOS would cause a VM crash. If
> this is true, then a malicious guest could unlock the ram and write to
> it for the same effect.
>
> -Kevin
--
Gleb.
next prev parent reply other threads:[~2009-11-23 11:17 UTC|newest]
Thread overview: 61+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-11-19 21:30 [Qemu-devel] POST failure (loop) with isapc and seabios Sebastian Herbszt
2009-11-20 22:51 ` [Qemu-devel] " Kevin O'Connor
2009-11-21 14:37 ` Sebastian Herbszt
2009-11-22 12:35 ` Gleb Natapov
2009-11-22 15:07 ` Sebastian Herbszt
2009-11-22 15:10 ` Gleb Natapov
2009-11-22 15:31 ` Sebastian Herbszt
2009-11-22 15:38 ` Gleb Natapov
2009-11-22 17:40 ` Kevin O'Connor
2009-11-22 21:15 ` Sebastian Herbszt
2009-11-22 22:04 ` Sebastian Herbszt
2009-11-23 11:14 ` Gleb Natapov
2009-11-23 11:17 ` Gleb Natapov [this message]
2009-11-22 20:01 ` Sebastian Herbszt
2009-11-23 11:11 ` Gleb Natapov
2009-11-23 19:19 ` Sebastian Herbszt
2009-11-23 19:43 ` Gleb Natapov
2009-11-23 21:30 ` Sebastian Herbszt
2009-11-24 6:28 ` Gleb Natapov
2009-11-24 14:38 ` Jamie Lokier
2009-11-24 14:40 ` Gleb Natapov
2009-11-25 6:09 ` Jamie Lokier
2009-11-25 12:20 ` Gleb Natapov
2009-11-25 15:31 ` Kevin O'Connor
2009-11-25 16:42 ` Gleb Natapov
2009-11-25 22:11 ` Sebastian Herbszt
2009-11-27 3:00 ` Jamie Lokier
2009-11-27 19:13 ` Sebastian Herbszt
2009-11-25 22:04 ` Sebastian Herbszt
2009-11-25 22:53 ` Kevin O'Connor
2009-11-26 6:49 ` Gleb Natapov
2009-11-26 7:15 ` Kevin O'Connor
2009-11-26 7:20 ` Gleb Natapov
2009-11-26 7:48 ` Kevin O'Connor
2009-11-26 7:56 ` Gleb Natapov
2009-11-26 8:12 ` Kevin O'Connor
2009-11-26 8:19 ` Gleb Natapov
2009-11-26 16:03 ` Kevin O'Connor
2009-11-26 22:35 ` Sebastian Herbszt
2009-11-27 5:39 ` Kevin O'Connor
2009-11-26 6:45 ` Gleb Natapov
2009-11-26 20:55 ` Sebastian Herbszt
2009-11-27 7:44 ` Gleb Natapov
2009-11-27 20:42 ` Sebastian Herbszt
2009-11-29 8:20 ` Gleb Natapov
2009-11-29 22:53 ` Natalia Portillo
2009-11-30 7:12 ` Gleb Natapov
2009-11-30 20:53 ` Jamie Lokier
2009-11-30 21:02 ` Natalia Portillo
2009-12-01 2:16 ` Kevin O'Connor
2009-11-30 20:34 ` Sebastian Herbszt
2009-12-01 9:37 ` Gleb Natapov
2009-11-25 21:08 ` Sebastian Herbszt
2009-11-24 23:27 ` Sebastian Herbszt
2009-11-25 10:48 ` Gleb Natapov
2009-11-22 15:38 ` Kevin O'Connor
2009-11-23 11:16 ` Gleb Natapov
2009-11-23 17:57 ` Sebastian Herbszt
2009-11-23 18:07 ` Gleb Natapov
2009-11-23 19:12 ` Sebastian Herbszt
2009-11-23 19:18 ` Gleb Natapov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20091123111726.GI2999@redhat.com \
--to=gleb@redhat.com \
--cc=herbszt@gmx.de \
--cc=kevin@koconnor.net \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).