WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

Re: [Xen-devel] Read-only locking of Guest Memory pages

To: Srujan Kotikela <ksrujandas@xxxxxxxxx>
Subject: Re: [Xen-devel] Read-only locking of Guest Memory pages
From: Tim Deegan <Tim.Deegan@xxxxxxxxxx>
Date: Wed, 15 Jun 2011 11:05:31 +0100
Cc: xen-devel@xxxxxxxxxxxxxxxxxxx
Delivery-date: Wed, 15 Jun 2011 03:07:53 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <BANLkTimH2qgm0pfjPQ19kiOZE=0ngHg1wg@xxxxxxxxxxxxxx>
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
References: <BANLkTinp48h5866AcJXmRcmLK1XZ+L8Zpg@xxxxxxxxxxxxxx> <20110614081445.GB11702@xxxxxxxxxxxxxxxxxxxxxxx> <BANLkTimH2qgm0pfjPQ19kiOZE=0ngHg1wg@xxxxxxxxxxxxxx>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Mutt/1.5.21 (2010-09-15)
At 11:38 -0500 on 14 Jun (1308051493), Srujan Kotikela wrote:
> Hi Tim,
> 
> I am trying to implement a secure architecture where a process' (selected)
> memory pages have to be set as read-only. The process will send the virtual
> address of pages required (through a custom hypercall) to be set read-only.
> I need to compute the physical address of the pages and set them read-only.

Thanks.  In that case I suspect the memory event hypercalls are what you
need.  They allow access rights on guest frames to be set from a tool in
dom0.  They only work on EPT, though. 

Tim.

> On Tue, Jun 14, 2011 at 3:14 AM, Tim Deegan <Tim.Deegan@xxxxxxxxxx> wrote:
> 
> > Hi,
> >
> > At 14:52 -0500 on 13 Jun (1307976734), Srujan Kotikela wrote:
> > > Does Xen provide any mechanism to set read-only access/lock on guest's
> > > pages?
> >
> > Yes, Xen has lots of code that makes guest memory read-only for various
> > reasons, and one of them might be suitable.  What's your overall goal?
> >
> > (BTW, you might want to read
> > http://wiki.xensource.com/xenwiki/AskingXenDevelQuestions)
> >
> > Cheers,
> >
> > Tim.
> >
> > --
> > Tim Deegan <Tim.Deegan@xxxxxxxxxx>
> > Principal Software Engineer, Xen Platform Team
> > Citrix Systems UK Ltd.  (Company #02937203, SL9 0BG)
> >

> _______________________________________________
> Xen-devel mailing list
> Xen-devel@xxxxxxxxxxxxxxxxxxx
> http://lists.xensource.com/xen-devel


-- 
Tim Deegan <Tim.Deegan@xxxxxxxxxx>
Principal Software Engineer, Xen Platform Team
Citrix Systems UK Ltd.  (Company #02937203, SL9 0BG)

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel