[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH 02/28] accel: mark kvm and xen accelerators as secure



On 11/9/26 16:36, Daniel P. Berrangé wrote:
TCG is too complex to be considered to provide a security boundary
for malicious guest workloads. QTest is only used for functional
testing and thus is not relevant to mark secure.

KVM and Xen are servicing virtualization use cases which must
provide security and actively maintained.

While HVF would be in scope conceptually, it is not sufficiently
mature or maintained to claim a security boundary at this time.

Signed-off-by: Daniel P. Berrangé <berrange@xxxxxxxxxx>
---
  accel/accel-common.c      | 2 ++
  accel/accel-system.c      | 1 +
  accel/kvm/kvm-accel-ops.c | 1 +
  accel/kvm/kvm-all.c       | 1 +

Maybe split so maintainers can Ack separately?

  accel/xen/xen-all.c       | 2 ++
  5 files changed, 7 insertions(+)

I think accel/nitro/ is also meant to be secure (in patch 6
you mark hw/virtio/virtio-nsm.c as secure).



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.