Re: [Xen-devel] [PATCH 00/14] XSA-277 followup

2018-11-26 Thread Tamas K Lengyel
On Wed, Nov 21, 2018 at 5:08 PM Andrew Cooper wrote: > > On 21/11/2018 22:42, Tamas K Lengyel wrote: > > On Wed, Nov 21, 2018 at 2:22 PM Andrew Cooper > > wrote: > >> On 21/11/2018 17:19, Tamas K Lengyel wrote: > >>> On Wed, Nov 21, 2018 at 6:21 AM Andrew Cooper > >>> wrote: > This covers

Re: [Xen-devel] [PATCH 00/14] XSA-277 followup

2018-11-23 Thread Roger Pau Monné
On Wed, Nov 21, 2018 at 09:22:25PM +, Andrew Cooper wrote: [...] > The only way I see of fixing this to teach Xen about the guests gfn > layout (as chosen by the domainbuilder), and include within that "space > which definitely doesn't have anything in, and is safe to put shared > mappings into

Re: [Xen-devel] [PATCH 00/14] XSA-277 followup

2018-11-21 Thread Andrew Cooper
On 21/11/2018 22:42, Tamas K Lengyel wrote: > On Wed, Nov 21, 2018 at 2:22 PM Andrew Cooper > wrote: >> On 21/11/2018 17:19, Tamas K Lengyel wrote: >>> On Wed, Nov 21, 2018 at 6:21 AM Andrew Cooper >>> wrote: This covers various fixes related to XSA-277 which weren't in security suppo

Re: [Xen-devel] [PATCH 00/14] XSA-277 followup

2018-11-21 Thread Tamas K Lengyel
On Wed, Nov 21, 2018 at 2:22 PM Andrew Cooper wrote: > > On 21/11/2018 17:19, Tamas K Lengyel wrote: > > On Wed, Nov 21, 2018 at 6:21 AM Andrew Cooper > > wrote: > >> This covers various fixes related to XSA-277 which weren't in security > >> supported areas, and associated cleanup. > >> > >> Th

Re: [Xen-devel] [PATCH 00/14] XSA-277 followup

2018-11-21 Thread Andrew Cooper
On 21/11/2018 17:19, Tamas K Lengyel wrote: > On Wed, Nov 21, 2018 at 6:21 AM Andrew Cooper > wrote: >> This covers various fixes related to XSA-277 which weren't in security >> supported areas, and associated cleanup. >> >> The biggest issue noticed here is that altp2m's use of hardware #VE supp

Re: [Xen-devel] [PATCH 00/14] XSA-277 followup

2018-11-21 Thread Tamas K Lengyel
On Wed, Nov 21, 2018 at 6:21 AM Andrew Cooper wrote: > > This covers various fixes related to XSA-277 which weren't in security > supported areas, and associated cleanup. > > The biggest issue noticed here is that altp2m's use of hardware #VE support > will cause general memory corruption if the g