[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH 09/28] hw/net: mark e1000, e1000e, IGB, rtl8139 & sPAPR VLAN as secure



> Historically most NICs are only interesting for non-virtualization
> use cases and have not been written with malicious guests in mind.
> 
> As a general rule either virtio-net or xen-net should be used in
> all virtualized guests requiring a security boundary.
> 
> There are a handful of exceptions resulting from historical usage
> in the x86 world, to support virtualized guests lacking virtio
> support.
> 
> Thus the rtl8139, e1000, e1000e & IGB NICs are declared to provide
> a security boundary.
> 
> The PPC sPAPR Virutal LAN device is also marked secure.

Virtual

> 
> Signed-off-by: Daniel P. Berrangé <berrange@xxxxxxxxxx>
> Message-ID: <20260911143627.2743803-10-berrange@xxxxxxxxxx>
>
> diff --git a/hw/net/e1000.c b/hw/net/e1000.c
> index 202ad404013a..da0667c40ec0 100644
> --- a/hw/net/e1000.c
> +++ b/hw/net/e1000.c
> @@ -1759,6 +1759,7 @@ static void e1000_register_types(void)
>          type_info.parent = TYPE_E1000_BASE;
>          type_info.class_data = info;
>          type_info.class_init = e1000_class_init;
> +        type_info.secure = true,

  type_info.secure = true;

>  
>          type_register_static(&type_info);
>      }
> diff --git a/hw/net/e1000e.c b/hw/net/e1000e.c
> index 9faf0c74c3d4..96737ddb51ac 100644
> --- a/hw/net/e1000e.c
> +++ b/hw/net/e1000e.c
> @@ -721,6 +721,7 @@ static const TypeInfo e1000e_info = {
>      .instance_size = sizeof(E1000EState),
>      .class_init = e1000e_class_init,
>      .instance_init = e1000e_instance_init,
> +    .secure = true,
>      .interfaces = (const InterfaceInfo[]) {
>          { INTERFACE_PCIE_DEVICE },
>          { }
> diff --git a/hw/net/igb.c b/hw/net/igb.c
> index c076807e7110..0bd03efea0cd 100644
> --- a/hw/net/igb.c
> +++ b/hw/net/igb.c
> @@ -635,6 +635,7 @@ static const TypeInfo igb_info = {
>      .instance_size = sizeof(IGBState),
>      .class_init = igb_class_init,
>      .instance_init = igb_instance_init,
> +    .secure = true,
>      .interfaces = (const InterfaceInfo[]) {
>          { INTERFACE_PCIE_DEVICE },
>          { }
> diff --git a/hw/net/rtl8139.c b/hw/net/rtl8139.c
> index 16479284eea9..38bc16f312fb 100644
> --- a/hw/net/rtl8139.c
> +++ b/hw/net/rtl8139.c
> @@ -3450,6 +3450,7 @@ static const TypeInfo rtl8139_info = {
>      .instance_size = sizeof(RTL8139State),
>      .class_init    = rtl8139_class_init,
>      .instance_init = rtl8139_instance_init,
> +    .secure        = true,
>      .interfaces = (const InterfaceInfo[]) {
>          { INTERFACE_CONVENTIONAL_PCI_DEVICE },
>          { },
> diff --git a/hw/net/spapr_llan.c b/hw/net/spapr_llan.c
> index 550848307d16..c7ac58273c6f 100644
> --- a/hw/net/spapr_llan.c
> +++ b/hw/net/spapr_llan.c
> @@ -873,6 +873,7 @@ static const TypeInfo spapr_vlan_info = {
>      .class_init    = spapr_vlan_class_init,
>      .instance_init = spapr_vlan_instance_init,
>      .instance_finalize = spapr_vlan_instance_finalize,
> +    .secure        = true,
>  };
>  
>  static void spapr_vlan_register_types(void)

Acked-by: Marc-André Lureau <marcandre.lureau@xxxxxxxxxx>

-- 
Marc-André Lureau <marcandre.lureau@xxxxxxxxxx>




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.