Thread (5 messages) flat view 5 messages, 4 authors, 2021-06-04

RE: [PATCH] PCI: hv: Move completion variable from stack to heap in hv_compose_msi_msg()

From: Long Li <longli@microsoft.com>
Date: 2021-06-04 08:49:51
Also in: linux-pci, lkml

Subject: Re: [PATCH] PCI: hv: Move completion variable from stack to heap in
hv_compose_msi_msg()
quoted
I agree if the intent is to deal with a untrusted host, I can follow the same
principle to add this support to all requests to VSP. But this is a different
problem to what this patch intends to address. I can see they may share the
same design principle and common code. My question on a untrusted host is:
If a host is untrusted and is misbehaving on purpose, what's the point of
keep the VM running and not crashing the PCI driver?

I think the principle can be summarized with "keep the VM _running, if you
can handle the misbehaviour (possibly, warning on "something
wrong/unexpected just happened"); crash, otherwise".

Of course, this is just a principle: the exact meaning of that 'handle' should be
leverage case by case (which I admittedly haven't here); I'm thinking, e.g., at
corresponding complexity/performance impacts and risks of 'mis-
assessments'.

Thanks,
  Andrea
I will follow Michael's suggestion and send v2.

Long
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help