From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([140.186.70.92]:51515) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1RuUWG-0001rP-QU for qemu-devel@nongnu.org; Mon, 06 Feb 2012 14:46:33 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1RuUWE-0006NL-AD for qemu-devel@nongnu.org; Mon, 06 Feb 2012 14:46:32 -0500 Received: from am1ehsobe005.messaging.microsoft.com ([213.199.154.208]:14631 helo=AM1EHSOBE006.bigfish.com) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1RuUWD-0006N6-WB for qemu-devel@nongnu.org; Mon, 06 Feb 2012 14:46:30 -0500 Message-ID: <4F302E0D.20302@freescale.com> Date: Mon, 6 Feb 2012 13:46:21 -0600 From: Scott Wood MIME-Version: 1.0 References: <4F2AB552.2070909@redhat.com> <4F2C6517.3040203@codemonkey.ws> In-Reply-To: <4F2C6517.3040203@codemonkey.ws> Content-Type: text/plain; charset="ISO-8859-1" Content-Transfer-Encoding: 7bit Subject: Re: [Qemu-devel] [RFC] Next gen kvm api List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Anthony Liguori Cc: qemu-devel , linux-kernel , Eric Northup , KVM list , Avi Kivity On 02/03/2012 04:52 PM, Anthony Liguori wrote: > On 02/03/2012 12:07 PM, Eric Northup wrote: >> On Thu, Feb 2, 2012 at 8:09 AM, Avi Kivity wrote: >> [...] >>> >>> Moving to syscalls avoids these problems, but introduces new ones: >>> >>> - adding new syscalls is generally frowned upon, and kvm will need >>> several >>> - syscalls into modules are harder and rarer than into core kernel code >>> - will need to add a vcpu pointer to task_struct, and a kvm pointer to >>> mm_struct >> - Lost a good place to put access control (permissions on /dev/kvm) >> for which user-mode processes can use KVM. >> >> How would the ability to use sys_kvm_* be regulated? > > Why should it be regulated? > > It's not a finite or privileged resource. You're exposing a large, complex kernel subsystem that does very low-level things with the hardware. It's a potential source of exploits (from bugs in KVM or in hardware). I can see people wanting to be selective with access because of that. And sometimes it is a finite resource. I don't know how x86 does it, but on at least some powerpc hardware we have a finite, relatively small number of hardware partition IDs. -Scott