Thread (38 messages) flat view 38 messages, 5 authors, 2021-06-04

Re: [PATCH v1 2/8] virtio: Add boundary checks to virtio ring

From: Jason Wang <hidden>
Date: 2021-06-03 02:37:20
Also in: linux-iommu, lkml

在 2021/6/3 上午10:18, Andi Kleen 写道:
quoted
It looks to me all the evils came from the fact that we depends on 
the descriptor ring.

So the checks in this patch could is unnecessary if we don't even 
read from the descriptor ring which could be manipulated by the device.

This is what my series tries to achieve:

https://www.spinics.net/lists/kvm/msg241825.html
I would argue that you should boundary check in any case. It was 
always a bug to not have boundary checks in such a data structure with 
multiple users, trust or not.

But yes your patch series is interesting and definitely makes sense 
for TDX too.

Best would be to have both I guess, and always check the boundaries 
everywhere.

I agree but some of the checks are unnecessary in we do this series on 
top of my series.

So what's the merge status of your series?

If I understand correctly from Michael, I will send a formal series and 
he will try to merge it for the 5.14.

Thanks

-Andi
_______________________________________________
Virtualization mailing list
Virtualization@lists.linux-foundation.org
https://lists.linuxfoundation.org/mailman/listinfo/virtualization
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help