RE: [PATCH v2 4/4] hv_netvsc: Restrict configurations on isolated guests
From: Haiyang Zhang <haiyangz@microsoft.com>
Date: 2021-01-26 15:44:50
Also in:
lkml, netdev
From: Haiyang Zhang <haiyangz@microsoft.com>
Date: 2021-01-26 15:44:50
Also in:
lkml, netdev
-----Original Message----- From: Andrea Parri (Microsoft) <parri.andrea@gmail.com> Sent: Tuesday, January 26, 2021 6:57 AM To: linux-kernel@vger.kernel.org Cc: KY Srinivasan <kys@microsoft.com>; Haiyang Zhang [off-list ref]; Stephen Hemminger [off-list ref]; Wei Liu [off-list ref]; Michael Kelley [off-list ref]; linux-hyperv@vger.kernel.org; Tianyu Lan [off-list ref]; Saruhan Karademir [off-list ref]; Juan Vazquez [off-list ref]; Andrea Parri (Microsoft) [off-list ref]; Jakub Kicinski [off-list ref]; David S. Miller [off-list ref]; netdev@vger.kernel.org Subject: [PATCH v2 4/4] hv_netvsc: Restrict configurations on isolated guests Restrict the NVSP protocol version(s) that will be negotiated with the host to be NVSP_PROTOCOL_VERSION_61 or greater if the guest is running isolated. Moreover, do not advertise the SR-IOV capability and ignore NVSP_MSG_4_TYPE_SEND_VF_ASSOCIATION messages in isolated guests, which are not supposed to support SR-IOV. This reduces the footprint of the code that will be exercised by Confidential VMs and hence the exposure to bugs and vulnerabilities. Signed-off-by: Andrea Parri (Microsoft) <parri.andrea@gmail.com> Acked-by: Jakub Kicinski <kuba@kernel.org> Cc: "David S. Miller" <davem@davemloft.net> Cc: Jakub Kicinski <kuba@kernel.org> Cc: netdev@vger.kernel.org
Reviewed-by: Haiyang Zhang <haiyangz@microsoft.com> Thanks.