WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

Re: [Xen-devel] asterisk, ztdummy, and usb (and HZ = 100 under xen ???)

To: "James Harper" <james.harper@xxxxxxxxxxxxxxxx>
Subject: Re: [Xen-devel] asterisk, ztdummy, and usb (and HZ = 100 under xen ???)
From: Keir Fraser <Keir.Fraser@xxxxxxxxxxxx>
Date: Sun, 22 May 2005 09:08:10 +0100
Cc: xen-devel@xxxxxxxxxxxxxxxxxxx
Delivery-date: Sun, 22 May 2005 08:10:37 +0000
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <AEC6C66638C05B468B556EA548C1A77D7A0BA0@xxxxxxxxxxxxxxxxxxxxxxx>
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
References: <AEC6C66638C05B468B556EA548C1A77D7A0BA0@xxxxxxxxxxxxxxxxxxxxxxx>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx

On 22 May 2005, at 08:56, James Harper wrote:

Assuming you have restricted the domain to just accessing registers
and
IRQs belonging to the device it controls, I think the only way would
be
by programming the device to wreak havoc on its behalf (by DMAing
arbitrary memory).

Is there a way to protect against rogue DMA writes (without knowing the
details of every particular piece of hardware) or is it just the price
to be paid for direct hardware access?

You need an IOMMU. Then the 'bus addresses' you program into the device are checked and translated by the IOMMU when it attempts to access memory.

Chipset extensions to support protection from rogue devices is likely to appear for commodity x86 systems in the next couple of years, I think.

 -- Keir


_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel