Re: [Xen-devel] [PATCH 07/15] flask: unify {get, set}vcpucontext permissions

2016-06-17 Thread Konrad Rzeszutek Wilk
On Thu, Jun 09, 2016 at 10:47:10AM -0400, Daniel De Graaf wrote: > These permissions were initially split because they were in separate > domctls, but this split is very unlikely to actually provide security > benefits: it would require a carefully contrived situation for a domain > to both need ac

[Xen-devel] [PATCH 07/15] flask: unify {get, set}vcpucontext permissions

2016-06-09 Thread Daniel De Graaf
These permissions were initially split because they were in separate domctls, but this split is very unlikely to actually provide security benefits: it would require a carefully contrived situation for a domain to both need access to one type of CPU register and also need to be prohibited from acce