This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
Home Products Support Community News


Re: [Xen-devel] [PATCH 04/17] vmx: nest: domain and vcpu flags

To: xen-devel@xxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-devel] [PATCH 04/17] vmx: nest: domain and vcpu flags
From: Christoph Egger <Christoph.Egger@xxxxxxx>
Date: Thu, 20 May 2010 16:06:35 +0200
Cc: Tim Deegan <Tim.Deegan@xxxxxxxxxx>, Qing He <qing.he@xxxxxxxxx>
Delivery-date: Thu, 20 May 2010 07:07:22 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <20100520125341.GA21374@qhe2-db>
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
References: <1271929289-18572-1-git-send-email-qing.he@xxxxxxxxx> <20100520105529.GN4164@xxxxxxxxxxxxxxxxxxxxxxx> <20100520125341.GA21374@qhe2-db>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: KMail/1.9.10
On Thursday 20 May 2010 14:53:41 Qing He wrote:
> On Thu, 2010-05-20 at 18:55 +0800, Tim Deegan wrote:
> > At 10:54 +0100 on 20 May (1274352874), Qing He wrote:
> > > But I still put this flags here because there have been some people
> > > expressing security concerns, that in some situations, hardware
> > > virtualization needs to be explicitly disabled to avoid stealth VMM.
> >
> > I understand that people might want to disable nested HVM, and it's fine
> > to do that in the domain builder; I just don't think that domcrf is te
> > right Xen interface.  Christoph's use of HVM_PARAM sounds right to me.
> OK, I'll change to HVM_PARAM solution.

Do you really want to do duplicate work ? IMO, it is better to adapt my patch.


---to satisfy European Law for business letters:
Advanced Micro Devices GmbH
Einsteinring 24, 85609 Dornach b. Muenchen
Geschaeftsfuehrer: Andrew Bowd, Thomas M. McCoy, Giuliano Meroni
Sitz: Dornach, Gemeinde Aschheim, Landkreis Muenchen
Registergericht Muenchen, HRB Nr. 43632

Xen-devel mailing list