[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] [PATCH 04/17] vmx: nest: domain and vcpu flags



At 10:54 +0100 on 20 May (1274352874), Qing He wrote:
> But I still put this flags here because there have been some people
> expressing security concerns, that in some situations, hardware
> virtualization needs to be explicitly disabled to avoid stealth VMM.

I understand that people might want to disable nested HVM, and it's fine
to do that in the domain builder; I just don't think that domcrf is te
right Xen interface.  Christoph's use of HVM_PARAM sounds right to me. 

Tim.

-- 
Tim Deegan <Tim.Deegan@xxxxxxxxxx>
Principal Software Engineer, XenServer Engineering
Citrix Systems UK Ltd.  (Company #02937203, SL9 0BG)

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.