Re: [PATCH v8 02/15] s390x: protvirt: Support unpack facility

2020-03-10 Thread Janosch Frank
On 3/10/20 4:41 PM, Christian Borntraeger wrote: > > > On 10.03.20 14:39, Janosch Frank wrote: >> The unpack facility provides the means to setup a protected guest. A >> protected guest can not be introspected by the hypervisor or any >> user/administrator of the machine it is running on. >> >>

Re: [PATCH v8 02/15] s390x: protvirt: Support unpack facility

2020-03-10 Thread Janosch Frank
On 3/10/20 4:26 PM, David Hildenbrand wrote: > On 10.03.20 14:39, Janosch Frank wrote: >> The unpack facility provides the means to setup a protected guest. A >> protected guest can not be introspected by the hypervisor or any > > "cannot" > >> user/administrator of the machine it is running on.

Re: [PATCH v8 02/15] s390x: protvirt: Support unpack facility

2020-03-10 Thread Christian Borntraeger
On 10.03.20 14:39, Janosch Frank wrote: > The unpack facility provides the means to setup a protected guest. A > protected guest can not be introspected by the hypervisor or any > user/administrator of the machine it is running on. > > Protected guests are encrypted at rest and need a special

Re: [PATCH v8 02/15] s390x: protvirt: Support unpack facility

2020-03-10 Thread David Hildenbrand
On 10.03.20 14:39, Janosch Frank wrote: > The unpack facility provides the means to setup a protected guest. A > protected guest can not be introspected by the hypervisor or any "cannot" > user/administrator of the machine it is running on. > > Protected guests are encrypted at rest and need a

[PATCH v8 02/15] s390x: protvirt: Support unpack facility

2020-03-10 Thread Janosch Frank
The unpack facility provides the means to setup a protected guest. A protected guest can not be introspected by the hypervisor or any user/administrator of the machine it is running on. Protected guests are encrypted at rest and need a special boot mechanism via diag308 subcode 8 and 10. Code 8