[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH v6 2/2] flask: implement xsm_set_system_active


  • To: "Daniel P. Smith" <dpsmith@xxxxxxxxxxxxxxxxxxxx>
  • From: Luca Fancellu <Luca.Fancellu@xxxxxxx>
  • Date: Tue, 3 May 2022 13:23:13 +0000
  • Accept-language: en-GB, en-US
  • Arc-authentication-results: i=2; mx.microsoft.com 1; spf=pass (sender ip is 63.35.35.123) smtp.rcpttodomain=lists.xenproject.org smtp.mailfrom=arm.com; dmarc=pass (p=none sp=none pct=100) action=none header.from=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com; arc=pass (0 oda=1 ltdi=1 spf=[1,1,smtp.mailfrom=arm.com] dkim=[1,1,header.d=arm.com] dmarc=[1,1,header.from=arm.com])
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
  • Arc-message-signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=N9t+UUChBXOgJcqYKB+BpikrXXZ8Xac23COr5d9Phxc=; b=oT1R+4y8EFnGyi2xmXZ+8XTIN27giTMHumA4l/6AWI7oKK6F5qmVKeVAmjwHzCK0XD5+0CQny7wR4a3qmzAaUpWDqOygnlnSAmB1cBYQBYjGU0pHW8MbQNrAAIq3QRe2En1HjBqkTjYBh0vR8K4EonCGp2AIiDkn1zzGk3aIshZaDfVEJsqZDfkUxrZVtAkyFUXx0gv9+/RxiiCUY9m3cxQ1wn8pHuhkrY1YeMn43kwKVZE2Q9avA2/5CoTPXpzjhagKW6RvUGFmNQKURe0OOgt2yAxXpIAfG0PZMs0ntnDxgEBCGpgcXUQTQhS01PS1SBPSt7U4rSBtJNUyno5k/g==
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=N9t+UUChBXOgJcqYKB+BpikrXXZ8Xac23COr5d9Phxc=; b=dkRgy3ZuxPtLh7BeKQXcymnYaKBr1lwJSWPrrcorLaPxjlBY9MKnvyIJp2nMqVzIr647hftVsQfs/oG7ZDjNb2SY76ZWfRS+3oOdv7J4ORmxuAjFgcbhslC1Wd/sejflX0FQNzsPy+wLD1ZCyLJIuXYWgne3dl1KvDJFxqKQ4OM8w6c0IAP10Tyn+Qixr7Mb0w3j+jGiur+NqZDyMa1g1x7ua9Fh8miES3APrjjSKGp+92eLj0AOWX5cst3DPO3i7n31W9BEjxRe7S95qtrVV+tScWOzrXY3R6CymXUDaVepdh7gcd7jMR4pRUCwhrMPP4vL4/h4d401dKmwbmuC6g==
  • Arc-seal: i=2; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=pass; b=gzn1FncayiBuXhxcVuQN29gcEBQlizMHT51rAB5CAOcNWO0TuLHAJxEhRniwELK4/54S7a1h+wx9I+wkeafJeASemu/nOY1lRvF/eiP6W2wp5sddKVRLoVamnkopQkFwBtplefJbOk8Niiy3fFgUqQdYW1Ooj1jTa6hMC8uwBUz3HzTy3TxLsYkJFCh72aQbddurIt/ec0u54unCkhGI7GpP6j33ZLf2tYE0IGRqW+aSBALzpPLM/rtBXbID/CukCzWv6Pz65lIGRGqpXCiCFLwWp1TPAuCFEsQhRvb9Kvi8kArIm3iO0YlQqaXbiK/dfEoHQ3A8Y7rd4GansKGwUA==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=JfewyVNs2WWPeAiYK5FGjcIxX3l5NjPjKGXGskZv8XwMCeqEUI0C/NLdjh2gQrxtzxohYPQhr+6GJCv+VZvZtaH81LcsD542j8FgcU8cuk4dfmhgMnBQKi/cKdO0Yn72K24kW2R8YKCjLUfKvyUqhDly8RAZcxcnnX9KNcYS/vJFRFZVUgR4MuWTZm2UkizKg6NS/TXzFU2c397Q2lTCMbXZeIobwosvUbyobAK5+tFYsz/WVPwoJs/3oI0PTdU9ZLW+w6qGZrAeGwwOCcZWaeMCYOnmvyxmWGnYGh4RLHU4ABt3PfYgldmKQ4au5WvBjcHmu7kKTQHgA9tX1h0WUw==
  • Authentication-results-original: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
  • Cc: xen-devel <xen-devel@xxxxxxxxxxxxxxxxxxxx>, Scott Davis <scott.davis@xxxxxxxxxx>, "jandryuk@xxxxxxxxx" <jandryuk@xxxxxxxxx>, "christopher.clark@xxxxxxxxxx" <christopher.clark@xxxxxxxxxx>, Daniel De Graaf <dgdegra@xxxxxxxxxxxxx>, Wei Liu <wl@xxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>
  • Delivery-date: Tue, 03 May 2022 13:23:44 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Nodisclaimer: true
  • Original-authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
  • Thread-index: AQHYXt+hyRwwXvMDlUWMsukHHGStsK0NJCKA
  • Thread-topic: [PATCH v6 2/2] flask: implement xsm_set_system_active


> On 3 May 2022, at 12:17, Daniel P. Smith <dpsmith@xxxxxxxxxxxxxxxxxxxx> wrote:
> 
> This commit implements full support for starting the idle domain privileged by
> introducing a new flask label xenboot_t which the idle domain is labeled with
> at creation.  It then provides the implementation for the XSM hook
> xsm_set_system_active to relabel the idle domain to the existing xen_t flask
> label.
> 
> In the reference flask policy a new macro, xen_build_domain(target), is
> introduced for creating policies for dom0less/hyperlaunch allowing the
> hypervisor to create and assign the necessary resources for domain
> construction.
> 
> Signed-off-by: Daniel P. Smith <dpsmith@xxxxxxxxxxxxxxxxxxxx>
> Reviewed-by: Jason Andryuk <jandryuk@xxxxxxxxx>

Hi Daniel,

I’ve built and tested the whole serie on arm, checked SILO and FLASK with 
builtin flask policy and I’ve
tested that Dom0 is booting fine.

So for me:

Reviewed-by: Luca Fancellu <luca.fancellu@xxxxxxx>
Tested-by: Luca Fancellu <luca.fancellu@xxxxxxx>

Cheers,
Luca

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.