Re: [PATCH v4 34/34] KVM: arm64: Protect the .hyp sections from the host

2021-03-11 Thread Will Deacon
On Wed, Mar 10, 2021 at 05:57:51PM +, Quentin Perret wrote: > When KVM runs in nVHE protected mode, use the host stage 2 to unmap the > hypervisor sections by marking them as owned by the hypervisor itself. > The long-term goal is to ensure the EL2 code can remain robust > regardless of the hos

[PATCH v4 34/34] KVM: arm64: Protect the .hyp sections from the host

2021-03-10 Thread Quentin Perret
When KVM runs in nVHE protected mode, use the host stage 2 to unmap the hypervisor sections by marking them as owned by the hypervisor itself. The long-term goal is to ensure the EL2 code can remain robust regardless of the host's state, so this starts by making sure the host cannot e.g. write to t