lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Fri, 8 Oct 2021 18:45:26 -0700 From: Randy Dunlap <rdunlap@...radead.org> To: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@...ux.intel.com>, Thomas Gleixner <tglx@...utronix.de>, Ingo Molnar <mingo@...hat.com>, Borislav Petkov <bp@...en8.de>, Peter Zijlstra <peterz@...radead.org>, Andy Lutomirski <luto@...nel.org>, Bjorn Helgaas <bhelgaas@...gle.com>, Richard Henderson <rth@...ddle.net>, Thomas Bogendoerfer <tsbogend@...ha.franken.de>, James E J Bottomley <James.Bottomley@...senPartnership.com>, Helge Deller <deller@....de>, "David S . Miller" <davem@...emloft.net>, Arnd Bergmann <arnd@...db.de>, Jonathan Corbet <corbet@....net>, "Michael S . Tsirkin" <mst@...hat.com>, Paolo Bonzini <pbonzini@...hat.com>, David Hildenbrand <david@...hat.com>, Andrea Arcangeli <aarcange@...hat.com>, Josh Poimboeuf <jpoimboe@...hat.com> Cc: Peter H Anvin <hpa@...or.com>, Dave Hansen <dave.hansen@...el.com>, Tony Luck <tony.luck@...el.com>, Dan Williams <dan.j.williams@...el.com>, Andi Kleen <ak@...ux.intel.com>, Kirill Shutemov <kirill.shutemov@...ux.intel.com>, Sean Christopherson <seanjc@...gle.com>, Kuppuswamy Sathyanarayanan <knsathya@...nel.org>, x86@...nel.org, linux-kernel@...r.kernel.org, linux-pci@...r.kernel.org, linux-alpha@...r.kernel.org, linux-mips@...r.kernel.org, linux-parisc@...r.kernel.org, sparclinux@...r.kernel.org, linux-arch@...r.kernel.org, linux-doc@...r.kernel.org, virtualization@...ts.linux-foundation.org Subject: Re: [PATCH v5 16/16] x86/tdx: Add cmdline option to force use of ioremap_host_shared On 10/8/21 5:37 PM, Kuppuswamy Sathyanarayanan wrote: > diff --git a/Documentation/admin-guide/kernel-parameters.txt b/Documentation/admin-guide/kernel-parameters.txt > index 91ba391f9b32..0af19cb1a28c 100644 > --- a/Documentation/admin-guide/kernel-parameters.txt > +++ b/Documentation/admin-guide/kernel-parameters.txt > @@ -2076,6 +2076,18 @@ > 1 - Bypass the IOMMU for DMA. > unset - Use value of CONFIG_IOMMU_DEFAULT_PASSTHROUGH. > > + ioremap_force_shared= [X86_64, CCG] > + Force the kernel to use shared memory mappings which do > + not use ioremap_host_shared/pcimap_host_shared to opt-in > + to shared mappings with the host. This feature is mainly > + used by a confidential guest when enabling new drivers > + without proper shared memory related changes. Please note > + that this option might also allow other non explicitly > + enabled drivers to interact with the host in confidential > + guest, which could cause other security risks. This option > + will also cause BIOS data structures to be shared with the > + host, which might open security holes. Hi, This cmdline option text should have a little bit more info. Just as an example/template: acpi_apic_instance= [ACPI, IOAPIC] Format: <int> 2: use 2nd APIC table, if available 1,0: use 1st APIC table default: 0 So what is expected after the "=" sign?... thanks. -- ~Randy
Powered by blists - more mailing lists