[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH 4/4] tools/xenstored: remove permissions related to dead domain


  • To: Juergen Gross <jgross@xxxxxxxx>, <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: Jason Andryuk <jason.andryuk@xxxxxxx>
  • Date: Mon, 27 Apr 2026 18:14:45 -0400
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=suse.com smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0)
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Q2xvCKkDcvutXpaTlJO5HLGwjNnfM1xB8iacdMNkKWY=; b=i3ppMjupcY7DlQ7QpbHrQszYaboRXWcBMlPqnnHURwVxDjCB+8jCKE0RPFoMwZa112HQ2OdExUesH1GiJeRKB7n8u+IuFaGrDmF2OwVAdokcys2NvCPiOO/CederfBhkFy6Tcr3vMdeDf4Xv37CA2uyPKbMeCLoA94n4K7R8E5YTq44b7mPZ+DnHrVsctxFWq0n96sQsD9vf69IbK4S9eYm6YaG/YO+n7Ho73FUlIBD/aeZEYtdcqwo67SD8qFKBS6l8Ga+Sf60x7D3RholNvmS0Ba6Iwz5QKYxfbB+wmXTT2si0MQ/xggV7ArvDOJLNtza+rJ/u7vUFCMHMsN9rgw==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=mRp+73raOMz/5p+FJ0dlp4e30VLCg0y/b7FmM9FWkwZzh3qUIGlixir68ybae18V5cuS/GRb+PnUgQnLhNbEGDiLBHERcqxS9E+jhNeHha92WNO3ETsLsd6bADyszeM/VDh75QHTZJ4UB5wNto4WGshfZMxRD2XdWa9NuPaEoNaiv2j2tsQFMkUDprUo1P4kjUWfv6djSP9pin6pZy+zY5JkQe+5hEWSmkmtNdJDMyE/qcDSdY2UtyzQih4zalxOV0RhGk7ve+0hto13eiBDxAo/+zq0DH0GweYSywAOnOxqLOCffm63BlvXumFVZ3LTSMP2BiJHv90gt3cv8vzaLg==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=amd.com header.i="@amd.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Cc: <dmukhin@xxxxxxxx>, Julien Grall <julien@xxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>
  • Delivery-date: Mon, 27 Apr 2026 22:15:16 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

On 2026-04-23 04:08, Juergen Gross wrote:
Wit unprivileged domains now capable to use the @releaseDomain watch,

s/Wit/With/

there is no reason not to remove any node permissions which relate to
a domain which has been removed.

This resolves a complex scenario where a new domain could inherit the
permissions of an old one with the same domid.

Signed-off-by: Juergen Gross <jgross@xxxxxxxx>

- return domain->acc_val[ACC_NODES] ? ret : WALK_TREE_SUCCESS_STOP;
+       if (node->perms[0].id == domain->domid) {
+               domain_nbentry_dec(NULL, domain->domid);
+               node->perms[0].id = priv_domid;
+               node->acc.memory = 0;
+               domain_nbentry_inc(NULL, priv_domid);
+               trace("moving orphaned node %s to dom0\n", node->name);

Since you are touching this, maybe s/dom0/dom%u/ and priv_domid?

Reviewed-by: Jason Andryuk <jason.andryuk@xxxxxxx>

Thanks,
Jason



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.