Re: [PATCH v2 1/3] libxl: Add 'permissive' option for PCI devices

2020-05-22 Thread Jim Fehlig
On 5/21/20 11:01 AM, Laine Stump wrote: On 5/8/20 4:54 PM, Jim Fehlig wrote: On 4/24/20 9:07 PM, Marek Marczykowski-Górecki wrote: From: Simon Gaiser By setting the permissive flag the Xen guest access to the PCI config space is not filtered. This might be a security risk, but it's required

Re: [PATCH v2 1/3] libxl: Add 'permissive' option for PCI devices

2020-05-21 Thread Laine Stump
On 5/8/20 4:54 PM, Jim Fehlig wrote: On 4/24/20 9:07 PM, Marek Marczykowski-Górecki wrote: From: Simon Gaiser By setting the permissive flag the Xen guest access to the PCI config space is not filtered. This might be a security risk, but it's required for some devices and the IOMMU and

Re: [PATCH v2 1/3] libxl: Add 'permissive' option for PCI devices

2020-05-08 Thread Jim Fehlig
On 4/24/20 9:07 PM, Marek Marczykowski-Górecki wrote: From: Simon Gaiser By setting the permissive flag the Xen guest access to the PCI config space is not filtered. This might be a security risk, but it's required for some devices and the IOMMU and interrupt remapping should (mostly?) contain

[PATCH v2 1/3] libxl: Add 'permissive' option for PCI devices

2020-04-24 Thread Marek Marczykowski-Górecki
From: Simon Gaiser By setting the permissive flag the Xen guest access to the PCI config space is not filtered. This might be a security risk, but it's required for some devices and the IOMMU and interrupt remapping should (mostly?) contain it. Because of it (and that the attribute is Xen only),