From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:33527) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TkKwe-0003AX-5x for qemu-devel@nongnu.org; Sun, 16 Dec 2012 15:36:21 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1TkKwd-0002hM-7Y for qemu-devel@nongnu.org; Sun, 16 Dec 2012 15:36:20 -0500 Received: from e8.ny.us.ibm.com ([32.97.182.138]:35000) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TkKwd-0002cE-3w for qemu-devel@nongnu.org; Sun, 16 Dec 2012 15:36:19 -0500 Received: from /spool/local by e8.ny.us.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Sun, 16 Dec 2012 15:36:14 -0500 Received: from d01relay05.pok.ibm.com (d01relay05.pok.ibm.com [9.56.227.237]) by d01dlp01.pok.ibm.com (Postfix) with ESMTP id F1D4738C8042 for ; Sun, 16 Dec 2012 15:36:12 -0500 (EST) Received: from d01av04.pok.ibm.com (d01av04.pok.ibm.com [9.56.224.64]) by d01relay05.pok.ibm.com (8.13.8/8.13.8/NCO v10.0) with ESMTP id qBGKaC9N339098 for ; Sun, 16 Dec 2012 15:36:12 -0500 Received: from d01av04.pok.ibm.com (loopback [127.0.0.1]) by d01av04.pok.ibm.com (8.14.4/8.13.1/NCO v10.0 AVout) with ESMTP id qBGKaCbn002346 for ; Sun, 16 Dec 2012 15:36:12 -0500 From: Anthony Liguori In-Reply-To: <563127555.23861364.1355471450321.JavaMail.root@redhat.com> References: <563127555.23861364.1355471450321.JavaMail.root@redhat.com> Date: Sun, 16 Dec 2012 14:36:07 -0600 Message-ID: <87obht7n0o.fsf@codemonkey.ws> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Subject: Re: [Qemu-devel] [PATCHv2] virtio: verify that all outstanding buffers are flushed List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Paolo Bonzini , Rusty Russell Cc: Stefan Hajnoczi , qemu-devel@nongnu.org, Stefan Hajnoczi , "Michael S. Tsirkin" Paolo Bonzini writes: >> > We technically should save the addresses and sizes too. It makes >> > it a heck of a lot safer then re-reading guest memory since we do some >> > validation on the size of the sg elements. >> >> Not really. >> >> The guest puts the descriptors in the ring and leaves them there until >> the device acks. If it changes them once they're exposed but before >> they're acked, it can get either before or after version, and always >> could. > > The problems start when the guest tries to race against QEMU and defy > the validation. Always using the validated version is a bit easier > than redoing the validation after migration. Exactly. Regards, Anthony Liguori > > Paolo