[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH 4/4] tools/xenstored: remove permissions related to dead domain
- To: Juergen Gross <jgross@xxxxxxxx>, <xen-devel@xxxxxxxxxxxxxxxxxxxx>
- From: Jason Andryuk <jason.andryuk@xxxxxxx>
- Date: Mon, 27 Apr 2026 18:14:45 -0400
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=suse.com smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0)
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Q2xvCKkDcvutXpaTlJO5HLGwjNnfM1xB8iacdMNkKWY=; b=i3ppMjupcY7DlQ7QpbHrQszYaboRXWcBMlPqnnHURwVxDjCB+8jCKE0RPFoMwZa112HQ2OdExUesH1GiJeRKB7n8u+IuFaGrDmF2OwVAdokcys2NvCPiOO/CederfBhkFy6Tcr3vMdeDf4Xv37CA2uyPKbMeCLoA94n4K7R8E5YTq44b7mPZ+DnHrVsctxFWq0n96sQsD9vf69IbK4S9eYm6YaG/YO+n7Ho73FUlIBD/aeZEYtdcqwo67SD8qFKBS6l8Ga+Sf60x7D3RholNvmS0Ba6Iwz5QKYxfbB+wmXTT2si0MQ/xggV7ArvDOJLNtza+rJ/u7vUFCMHMsN9rgw==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=mRp+73raOMz/5p+FJ0dlp4e30VLCg0y/b7FmM9FWkwZzh3qUIGlixir68ybae18V5cuS/GRb+PnUgQnLhNbEGDiLBHERcqxS9E+jhNeHha92WNO3ETsLsd6bADyszeM/VDh75QHTZJ4UB5wNto4WGshfZMxRD2XdWa9NuPaEoNaiv2j2tsQFMkUDprUo1P4kjUWfv6djSP9pin6pZy+zY5JkQe+5hEWSmkmtNdJDMyE/qcDSdY2UtyzQih4zalxOV0RhGk7ve+0hto13eiBDxAo/+zq0DH0GweYSywAOnOxqLOCffm63BlvXumFVZ3LTSMP2BiJHv90gt3cv8vzaLg==
- Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=amd.com header.i="@amd.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
- Cc: <dmukhin@xxxxxxxx>, Julien Grall <julien@xxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>
- Delivery-date: Mon, 27 Apr 2026 22:15:16 +0000
- List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
On 2026-04-23 04:08, Juergen Gross wrote:
Wit unprivileged domains now capable to use the @releaseDomain watch,
s/Wit/With/
there is no reason not to remove any node permissions which relate to
a domain which has been removed.
This resolves a complex scenario where a new domain could inherit the
permissions of an old one with the same domid.
Signed-off-by: Juergen Gross <jgross@xxxxxxxx>
- return domain->acc_val[ACC_NODES] ? ret : WALK_TREE_SUCCESS_STOP;
+ if (node->perms[0].id == domain->domid) {
+ domain_nbentry_dec(NULL, domain->domid);
+ node->perms[0].id = priv_domid;
+ node->acc.memory = 0;
+ domain_nbentry_inc(NULL, priv_domid);
+ trace("moving orphaned node %s to dom0\n", node->name);
Since you are touching this, maybe s/dom0/dom%u/ and priv_domid?
Reviewed-by: Jason Andryuk <jason.andryuk@xxxxxxx>
Thanks,
Jason
|