From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753022AbdBIOsD convert rfc822-to-8bit (ORCPT ); Thu, 9 Feb 2017 09:48:03 -0500 Received: from smtp.ctxuk.citrix.com ([185.25.65.24]:31352 "EHLO SMTP.EU.CITRIX.COM" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752250AbdBIOr7 (ORCPT ); Thu, 9 Feb 2017 09:47:59 -0500 X-IronPort-AV: E=Sophos;i="5.35,349,1484006400"; d="scan'208";a="40478898" From: Paul Durrant To: "'Jan Beulich'" CC: "xen-devel@lists.xenproject.org" , "Boris Ostrovsky" , Juergen Gross , "linux-kernel@vger.kernel.org" Subject: RE: [Xen-devel] [PATCH 3/3] xen/privcmd: add IOCTL_PRIVCMD_RESTRICT Thread-Topic: [Xen-devel] [PATCH 3/3] xen/privcmd: add IOCTL_PRIVCMD_RESTRICT Thread-Index: AQHSgt9N7I6XL7iD+kaiG0bRexuF8qFgrzqAgAARTaA= Date: Thu, 9 Feb 2017 14:45:45 +0000 Message-ID: References: <1486649866-4869-1-git-send-email-paul.durrant@citrix.com> <1486649866-4869-4-git-send-email-paul.durrant@citrix.com> <589C8E1D0200007800138448@prv-mh.provo.novell.com> In-Reply-To: <589C8E1D0200007800138448@prv-mh.provo.novell.com> Accept-Language: en-GB, en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-ms-exchange-transport-fromentityheader: Hosted Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 8BIT MIME-Version: 1.0 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org > -----Original Message----- > From: Jan Beulich [mailto:JBeulich@suse.com] > Sent: 09 February 2017 14:43 > To: Paul Durrant > Cc: xen-devel@lists.xenproject.org; Boris Ostrovsky > ; Juergen Gross ; linux- > kernel@vger.kernel.org > Subject: Re: [Xen-devel] [PATCH 3/3] xen/privcmd: add > IOCTL_PRIVCMD_RESTRICT > > >>> On 09.02.17 at 15:17, wrote: > > @@ -666,6 +680,20 @@ static long privcmd_ioctl_dm_op(void __user > *udata) > > return rc; > > } > > > > +static long privcmd_ioctl_restrict(struct file *file, void __user *udata) > > +{ > > + struct privcmd_data *data = file->private_data; > > + domid_t dom; > > + > > + if (copy_from_user(&dom, udata, sizeof(dom))) > > + return -EFAULT; > > + > > + /* Set restriction to the specified domain */ > > + data->domid = dom; > > + > > + return 0; > > +} > > Is it really intended for the caller to be able to undo this, by passing > in DOMID_INVALID? Good point. I was intending to fix that, but forgot. Paul > > Jan