[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] [PATCH v1 6/6] xsm: add tee access policy support



Hi Julien,

On 23.08.18 16:43, Julien Grall wrote:


I don't think we should use XSM to enforce the use of TEE. This contradictory to your next patch where you let the user configure OP-TEE for a given guest.

IHMO, XSM should only be used to restrict usage of calls in a fine grain. For an overall control, that should be go through a DOMCTL tell Xen to initialize OP-TEE for that domain.

Just to be sure. You are proposing to add flag "TEE_ENABLED" for a domain and set it during domain construction, based on configuration, right?

What did you mean by "fine grain"?

--
Volodymyr Babchuk

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxxx
https://lists.xenproject.org/mailman/listinfo/xen-devel

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.