[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] IOMMU/AMD-Vi not working after XSA-36 with 970A-UD3



On 03/05/2013 21:23, Marcus Osdoba wrote:
> Dear mailinglist,
>
> I own a Gigabyte motherboard GA 970A UD3 with IOMMU support. Since the 
> update XSA-36 (also part of the latest debian wheezy pkg), the 
> IO-Virtualisation does not work any more as discussed on this 
> mailinglist [0] and [1].
>
> I like to ask, if there is an "official" solution in sight.

XSA-36 is the "official" solution, and is correct from a security point
of view.  From what I understand, the root cause of the problem you have
is due to bad ACPI tables from the BIOS.

>
> I'm not sure about my alternatives. How "dangerous" is the mentioned IRQ 
> sharing in [1]? May I just live with the NorthBridge disabled IOAPIC?

If you are the admin of all the VMs, or trust the admin of all the VMs,
then it is fine.  The danger is that an untrusted admin can use the
problems to launch a DoS against other VMs on the system.

~Andrew

>
>
> [0] http://lists.xen.org/archives/html/xen-devel/2013-03/msg01016.html
> [1] http://lists.xen.org/archives/html/xen-devel/2013-04/msg02349.html
>
> _______________________________________________
> Xen-devel mailing list
> Xen-devel@xxxxxxxxxxxxx
> http://lists.xen.org/xen-devel


_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.