[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [XEN][PATCH v2 0/4] x86: pvh: allow to disable 32-bit (COMPAT) interface support


  • To: "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: Grygorii Strashko <grygorii_strashko@xxxxxxxx>
  • Date: Thu, 18 Dec 2025 18:20:29 +0200
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=+mU+n96SrXtJXz77KEd5uU3Rpb30fbUbKR/2UQQkKB0=; b=kIx2llwA8i0VD77i25AIgOwBDeZbie6lPeq8LG+qWMPxBgcyAvtpcD5yTBbkuOs8wJTuRPCs6BM8LDgaqMRW03H/2sXwj9OSiSbH4PT4pMNwpdEkKbrMHsZez8Jq+SivFwj9CZGoHzFc0NOngeVcGFWfQvUU20YZ/66KqpNOrwFBKXB8N17juuYuOYWwiXsnAIrFvHc7/VWcMsXr96Qi4FB45ho/F0fW29GubAYCnXnfZuAkYipwYlk1hTlf3Eh8g5kyYazVCb/TUUVxViYjkIusEYXLvKm5KbdPAqCTagLDy1xQ3T57a9n/xbJiyDZt9uusJoS3Z/iR6tSkF8/a2Q==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=ynosVvYMuzmwWQ+7A7e7bG+//wVbik6ZkCzV8LDjZSHAZfupknLkgxIkuUychow+lVHzewNn+q2cBytOGN3dwdGdogTD8C5XS9/XizGwF2vRzsCtDh7zsUmyU8uFuml+M4mxU4pGzbAICnFFuCSVk/GXHeG/ptod/+WsQSBgUM2fcTRQaZMRQzdbNjXjf67+BEPaJ15asJEqXhElTqmWpT7pf0fTaJijamKjaN1LWVIHe2ryK9zeF09zFNqtr0wl+ToMAYJXgBoWPiOkuBnpn4h0MjyVKi6SPTFTHqhZfO7cClQxcVO46OEe9YfBKiDlUblktJlKPB+dHifsmP97Ng==
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com;
  • Cc: Jan Beulich <jbeulich@xxxxxxxx>, Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Roger Pau Monné <roger.pau@xxxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Michal Orzel <michal.orzel@xxxxxxx>, Julien Grall <julien@xxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>
  • Delivery-date: Thu, 18 Dec 2025 16:20:39 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

Hi All,

I'm planning to send v3 - so would be appreciated for any other comments.

On 19.11.25 21:30, Grygorii Strashko wrote:
From: Grygorii Strashko <grygorii_strashko@xxxxxxxx>

Hi

This series introduces possibility to disable 32-bit (COMPAT) interface support
in the following case:
       - Only PVH domains are used
       - Guests (OS) are started by using direct Direct Kernel Boot
       - Guests (OS) are 64-bit and Guest early boot code, which is running not
         in 64-bit mode, does not access Xen interfaces
         (hypercalls, shared_info, ..)

If above criterias are met the COMPAT HVM interface become unreachable and can 
be disabled.
Coverage reports analyze and adding guard (debug) exceptions in 
hvm_hypercall/hvm_do_multicall_call
and hvm_latch_shinfo_size() confirm that COMPAT HVM interface is unused for 
safety use-case.

Changes in v2 described in each patch:
- patch "x86: constify has_32bit_shinfo() if !CONFIG_COMPAT" squashed in patch 
2.

v1:
  
https://patchwork.kernel.org/project/xen-devel/cover/20251111175413.3540690-1-grygorii_strashko@xxxxxxxx/

Grygorii Strashko (4):
   x86: hvm: dm: factor out compat code under ifdefs
   x86: hvm: compat: introduce is_hcall_compat() helper
   x86: hvm: factor out COMPAT code under ifdefs
   x86: pvh: allow to disable 32-bit interface support

  xen/arch/x86/hvm/Kconfig          | 19 ++++++++++++++++++-
  xen/arch/x86/hvm/dm.c             |  2 ++
  xen/arch/x86/hvm/hvm.c            | 24 ++++++++++++++++++++----
  xen/arch/x86/hvm/hypercall.c      | 22 +++++++++++++++++-----
  xen/arch/x86/hypercall.c          |  6 +-----
  xen/arch/x86/include/asm/domain.h |  9 +++++++--
  xen/common/kernel.c               |  2 +-
  xen/include/hypercall-defs.c      |  9 +++++++--
  xen/include/xen/sched.h           |  9 +++++++++
  9 files changed, 82 insertions(+), 20 deletions(-)


--
Best regards,
-grygorii




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.