Re: [Xen-devel] [PATCH v3] xsm: add a default policy to .init.data

2016-07-05 Thread Konrad Rzeszutek Wilk
On Fri, Jul 01, 2016 at 01:19:51AM -0600, Jan Beulich wrote: > >>> On 30.06.16 at 17:13, wrote: > > On Thu, Jun 30, 2016 at 10:01:18AM -0400, Daniel De Graaf wrote: > >> On 06/30/2016 09:45 AM, Konrad Rzeszutek Wilk wrote: > >> > On Wed, Jun 29, 2016 at 11:09:01AM -0400, Daniel De Graaf wrote: > >

Re: [Xen-devel] [PATCH v3] xsm: add a default policy to .init.data

2016-07-01 Thread Jan Beulich
>>> On 30.06.16 at 17:13, wrote: > On Thu, Jun 30, 2016 at 10:01:18AM -0400, Daniel De Graaf wrote: >> On 06/30/2016 09:45 AM, Konrad Rzeszutek Wilk wrote: >> > On Wed, Jun 29, 2016 at 11:09:01AM -0400, Daniel De Graaf wrote: >> > > --- a/xen/xsm/xsm_core.c >> > > +++ b/xen/xsm/xsm_core.c >> > > @

Re: [Xen-devel] [PATCH v3] xsm: add a default policy to .init.data

2016-06-30 Thread Konrad Rzeszutek Wilk
On Thu, Jun 30, 2016 at 10:01:18AM -0400, Daniel De Graaf wrote: > On 06/30/2016 09:45 AM, Konrad Rzeszutek Wilk wrote: > > On Wed, Jun 29, 2016 at 11:09:01AM -0400, Daniel De Graaf wrote: > > > This adds a Kconfig option and support for including the XSM policy from > > > tools/flask/policy in the

Re: [Xen-devel] [PATCH v3] xsm: add a default policy to .init.data

2016-06-30 Thread Daniel De Graaf
On 06/30/2016 09:45 AM, Konrad Rzeszutek Wilk wrote: On Wed, Jun 29, 2016 at 11:09:01AM -0400, Daniel De Graaf wrote: This adds a Kconfig option and support for including the XSM policy from tools/flask/policy in the hypervisor so that the bootloader does not need to provide a policy to get sane

Re: [Xen-devel] [PATCH v3] xsm: add a default policy to .init.data

2016-06-30 Thread Konrad Rzeszutek Wilk
On Wed, Jun 29, 2016 at 11:09:01AM -0400, Daniel De Graaf wrote: > This adds a Kconfig option and support for including the XSM policy from > tools/flask/policy in the hypervisor so that the bootloader does not > need to provide a policy to get sane behavior from an XSM-enabled > hypervisor. The p

[Xen-devel] [PATCH v3] xsm: add a default policy to .init.data

2016-06-29 Thread Daniel De Graaf
This adds a Kconfig option and support for including the XSM policy from tools/flask/policy in the hypervisor so that the bootloader does not need to provide a policy to get sane behavior from an XSM-enabled hypervisor. The policy provided by the bootloader, if present, will override the built-in