Hi Roger, On 06/05/2025 09:31, Roger Pau Monne wrote:
Whether a domain is allowed to issue cache-control operations is reported by the cache_flush_permitted() check. Introduce such check to limit the availability of GNTTABOP_cache_flush to only guests that are granted cache control.
Can you outline what's the problem you are trying to solve? Asking, because I don't see the problem of allowing any guest calling GNTTABOP_cache_flush on Arm from any domains.
Cheers, -- Julien Grall