From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Jan Beulich" Subject: Re: [PATCH 3/7] x86/mm: Further restrict permissions on some virtual mappings Date: Wed, 03 May 2017 02:49:09 -0600 Message-ID: <5909B5A50200007800156294@prv-mh.provo.novell.com> References: <1493748326-9582-1-git-send-email-andrew.cooper3@citrix.com> <1493748326-9582-4-git-send-email-andrew.cooper3@citrix.com> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Return-path: In-Reply-To: <1493748326-9582-4-git-send-email-andrew.cooper3@citrix.com> Content-Disposition: inline List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xen.org Sender: "Xen-devel" To: Andrew Cooper Cc: George Dunlap , Tim Deegan , Xen-devel List-Id: xen-devel@lists.xenproject.org Pj4+IE9uIDAyLjA1LjE3IGF0IDIwOjA1LCA8YW5kcmV3LmNvb3BlcjNAY2l0cml4LmNvbT4gd3Jv dGU6Cj4gQXMgb3JpZ2luYWxseSByZXBvcnRlZCwgdGhlIExpbmVhciBQYWdldGFibGUgc2xvdCBt YXBzIDUxMkdCIG9mIHJhbSBhcyBSV1gsCj4gd2hlcmUgdGhlIGd1ZXN0IGhhcyBmdWxsIHJlYWQg YWNjZXNzIGFuZCBhIGxvdCBvZiBkaXJlY3Qgb3IgaW5kaXJlY3QgY29udHJvbAo+IG92ZXIgdGhl IHdyaXR0ZW4gY29udGVudC4gIEl0IGlzbid0IGhhcmQgZm9yIGEgUFYgZ3Vlc3QgdG8gaGlkZSBz aGVsbGNvZGUKPiBoZXJlLgo+IAo+IFRoZXJlZm9yZSwgaW5jcmVhc2UgZGVmZW5jZSBpbiBkZXB0 aCBieSBhdWRpdGluZyBvdXIgY3VycmVudCBwYWdldGFibGUKPiBtYXBwaW5ncy4KPiAKPiAgKiBU aGUgcmVndWxhciBsaW5lYXIsIHNoYWRvdyBsaW5lYXIsIGFuZCBwZXItZG9tYWluIHNsb3RzIGhh dmUgbm8gYnVzaW5lc3MKPiAgICBiZWluZyBleGVjdXRhYmxlIChidXQgbmVlZCB0byBiZSB3cml0 dGVuKSwgc28gYXJlIHVwZGF0ZWQgdG8gYmUgTlguCj4gICogVGhlIFJlYWQgT25seSBtYXBwaW5n cyBvZiB0aGUgTTJQIChjb21wYXQgYW5kIHJlZ3VsYXIpIGRvbid0IG5lZWQgdG8gYmUKPiAgICB3 cml0ZWFibGUgb3IgZXhlY3V0YWJsZS4KPiAgKiBUaGUgUFYgR0RUIG1hcHBpbmdzIGRvbid0IG5l ZWQgdG8gYmUgZXhlY3V0YWJsZS4KPiAKPiBSZXBvcnRlZC1ieTogSmFubiBIb3JuIDxqYW5uaEBn b29nbGUuY29tPgo+IFNpZ25lZC1vZmYtYnk6IEFuZHJldyBDb29wZXIgPGFuZHJldy5jb29wZXIz QGNpdHJpeC5jb20+CgpSZXZpZXdlZC1ieTogSmFuIEJldWxpY2ggPGpiZXVsaWNoQHN1c2UuY29t Pgp3aXRoIHR3byByZW1hcmtzOgoKPiAtLS0gYS94ZW4vYXJjaC94ODYvbW0uYwo+ICsrKyBiL3hl bi9hcmNoL3g4Ni9tbS5jCj4gQEAgLTM4NCw3ICszODQsNyBAQCB2b2lkIF9faW5pdCBhcmNoX2lu aXRfbWVtb3J5KHZvaWQpCj4gICAgICAgICAgICAgICAgICAgICAgZm9yICggOyBpIDwgTDNfUEFH RVRBQkxFX0VOVFJJRVM7ICsraSApCj4gICAgICAgICAgICAgICAgICAgICAgICAgIGwzdGFiW2ld ID0gbDNlX2VtcHR5KCk7Cj4gICAgICAgICAgICAgICAgICAgICAgc3BsaXRfbDRlID0gbDRlX2Zy b21fcGZuKHZpcnRfdG9fbWZuKGwzdGFiKSwKPiAtICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAgICAgICAgICAgX19QQUdFX0hZUEVSVklTT1IpOwo+ICsgICAgICAgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICBfX1BBR0VfSFlQRVJWSVNPUl9SVyk7CgpXb3Vs ZCBiZSBuaWNlIGlmIHRoaXMgY2hhbmdlIChhZmZlY3RpbmcgdGhlIGRpcmVjdCBtYXApIHdhcyBh bHNvCm1lbnRpb25lZCBpbiB0aGUgY29tbWl0IG1lc3NhZ2UsIGV2ZW4gaWYgaXQncyBvbmx5IGRl YnVnZ2luZwpjb2RlLgoKPiBAQCAtNTE1LDcgKzUxNSw3IEBAIHZvaWQgX19pbml0IHBhZ2luZ19p bml0KHZvaWQpCj4gICAgICAgICAgICAgIGwzX3JvX21wdCA9IHBhZ2VfdG9fdmlydChsM19wZyk7 Cj4gICAgICAgICAgICAgIGNsZWFyX3BhZ2UobDNfcm9fbXB0KTsKPiAgICAgICAgICAgICAgbDRl X3dyaXRlKCZpZGxlX3BnX3RhYmxlW2w0X3RhYmxlX29mZnNldCh2YSldLAo+IC0gICAgICAgICAg ICAgICAgICAgICAgbDRlX2Zyb21fcGFnZShsM19wZywgX19QQUdFX0hZUEVSVklTT1IpKTsKPiAr ICAgICAgICAgICAgICAgICAgICAgIGw0ZV9mcm9tX3BhZ2UobDNfcGcsIF9fUEFHRV9IWVBFUlZJ U09SX1JXKSk7CgpTaW1pbGFybHkgaGVyZSAoYWdhaW4gYWZmZWN0aW5nIHRoZSBkaXJlY3QgbWFw KS4KCkphbgoKCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f Clhlbi1kZXZlbCBtYWlsaW5nIGxpc3QKWGVuLWRldmVsQGxpc3RzLnhlbi5vcmcKaHR0cHM6Ly9s aXN0cy54ZW4ub3JnL3hlbi1kZXZlbAo=