From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752017AbdBIQTb (ORCPT ); Thu, 9 Feb 2017 11:19:31 -0500 Received: from smtp.eu.citrix.com ([185.25.65.24]:5880 "EHLO SMTP.EU.CITRIX.COM" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751446AbdBIQTa (ORCPT ); Thu, 9 Feb 2017 11:19:30 -0500 X-IronPort-AV: E=Sophos;i="5.35,137,1484006400"; d="scan'208";a="40487776" Subject: Re: [Xen-devel] [PATCH 2/3] xen/privcmd: Add IOCTL_PRIVCMD_DM_OP To: Jan Beulich , Paul Durrant , Boris Ostrovsky References: <1486649866-4869-1-git-send-email-paul.durrant@citrix.com> <1486649866-4869-3-git-send-email-paul.durrant@citrix.com> <8ef1299559e24d96ba8bbab49baee5ae@AMSPEX02CL03.citrite.net> <16ec962f-0835-1244-ddd5-e711c5d7cefd@citrix.com> <589CA0FA0200007800138547@prv-mh.provo.novell.com> CC: "xen-devel@lists.xenproject.org" , Juergen Gross , "linux-kernel@vger.kernel.org" From: Andrew Cooper Message-ID: <680886ee-cdeb-e047-9bae-9f68cf87e69d@citrix.com> Date: Thu, 9 Feb 2017 16:08:10 +0000 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Icedove/45.6.0 MIME-Version: 1.0 In-Reply-To: <589CA0FA0200007800138547@prv-mh.provo.novell.com> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit X-ClientProxiedBy: AMSPEX02CAS01.citrite.net (10.69.22.112) To AMSPEX02CL02.citrite.net (10.69.22.126) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 09/02/17 16:03, Jan Beulich wrote: >>>> On 09.02.17 at 16:56, wrote: >> On 09/02/17 15:50, Boris Ostrovsky wrote: >>> >>> On 02/09/2017 09:27 AM, Paul Durrant wrote: >>>>> -----Original Message----- >>>>> From: Paul Durrant [mailto:paul.durrant@citrix.com] >>>>> Sent: 09 February 2017 14:18 >>>>> To: xen-devel@lists.xenproject.org; linux-kernel@vger.kernel.org >>>>> Cc: Paul Durrant ; Boris Ostrovsky >>>>> ; Juergen Gross >>>>> Subject: [PATCH 2/3] xen/privcmd: Add IOCTL_PRIVCMD_DM_OP >>>>> >>>>> Recently a new dm_op[1] hypercall was added to Xen to provide a >>>>> mechanism >>>>> for restricting device emulators (such as QEMU) to a limited set of >>>>> hypervisor operations, and being able to audit those operations in the >>>>> kernel of the domain in which they run. >>>>> >>>>> This patch adds IOCTL_PRIVCMD_DM_OP as gateway for >>>>> __HYPERVISOR_dm_op, >>>>> bouncing the callers buffers through kernel memory to allow the address >>>>> ranges to be audited (and negating the need to bounce through locked >>>>> memory in user-space). >>>> Actually, it strikes me (now that I've posted the patch) that I >>>> should probably just mlock the user buffers rather than bouncing them >>>> through kernel... Anyway, I'd still appreciate review on other >>>> aspects of the patch. >>> >>> Are you suggesting that the caller (user) mlocks the buffers? >> Doesn't libxc already use the hypercall buffer API for each of the buffers? >> >> The kernel oughtn’t to need to do anything special to the user pointers >> it has, other than call access_ok() on them. > And translate 32-bit layout to 64-bit for a compat caller. Ah yes (although that looks to be done suitably in the patch as presented). ~Andrew