[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] HVM Driver Domain



On Thu, Jan 23, 2020 at 10:36:34PM +0000, tosher 1 wrote:
> 
> 
> I wasn't able to make the HVM driver domain work even with the latest Xen 
> version which is 4.14. I see the 'xendriverdomain' executable in the 
> /etc/init.d/ directory, but it doesn't seem to be running in the background. 
> 
> On the other hand, I see the official "Qubes OS Architecture" document 
> (https://www.qubes-os.org/attachment/wiki/QubesArchitecture/arch-spec-0.3.pdf)
>  defines the driver domain as the following.
> 
> "A driver domain is an unprivileged PV-domain that has been securely granted 
> access to certain PCI device (e.g. the network card or disk controller) using 
> Intel VT-d." - Page 12
> 
> Moreover, section 6.1 reads "The network domain is granted direct access to 
> the networking hardware, e.g. the WiFi or ethernet card. Besides, it is a 
> regular unprivileged PV domain."
> 
> Maybe you guys later moved to the HVM driver domain from PV. Would you please 
> share the Xen config you use for the network driver domain?

Yes, that PDF is quite outdated, we use HVM now.

As for the configs, as said before, we use libvirt, with some extra
patches, so the config won't be directly useful for you. I'm attaching
both libvirt XML for the driver domain, and also converted to XL (using
virsh domxml-to-native), may be inaccurate.

-- 
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?

Attachment: sys-net.xl
Description: Text document

Attachment: sys-net.xml
Description: XML document

Attachment: signature.asc
Description: PGP signature

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxxx
https://lists.xenproject.org/mailman/listinfo/xen-devel

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.