Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1158334
| Path | csiph.com!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | Paolo Bonzini <pbonzini@redhat.com> |
| Newsgroups | linux.kernel |
| Subject | [PATCH] kvm: x86: default legacy PCI device assignment support to "n" |
| Date | Thu, 04 Jun 2015 10:10:02 +0200 |
| Message-ID | <pxynU-37f-25@gated-at.bofh.it> (permalink) |
| X-Original-To | linux-kernel@vger.kernel.org, kvm@vger.kernel.org |
| Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=sender:from:to:cc:subject:date:message-id; bh=rlCCieAPkEM/vwnV8y4QqnB5AKVqG7bZKhRuMZzw44s=; b=PUTTy4tJNHP5Jpu73sYDP1EQ0IOeEKjfmHQbGTc5xJz8YYE1YPIFF7Y32sLuG1mD8I x75QXapscJS6nQ7d/kjVDqIl40snTtBYAe4I14MxlshffD2+d5h4hBjaCd7CuynMlUtV Sm6EIlBgz+rqc/RUrXYQYMoeDrUUlUCVTptwzw09C+F//wGwiSVkbn7nKW87J0BXOJAy 5ROi6ILCIHPWgdh3P9gD9YN7XqHDDSCWAsl16ilzgI5yEhAuA9Nu9WkOyXU2uV7PlxyL VATw+EVrJQ8q5ZyfT8n2RFawQyH2CCqj43q92tH9OzJ08juCjxA1+shQPJO1hMbvOlQO mcxQ== |
| X-Received | by 10.180.99.166 with SMTP id er6mr5268815wib.58.1433405172073; Thu, 04 Jun 2015 01:06:12 -0700 (PDT) |
| X-Mailer | git-send-email 1.8.3.1 |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 42 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | alex.williamson@redhat.com |
| X-Original-Date | Thu, 4 Jun 2015 10:06:04 +0200 |
| X-Original-Message-ID | <1433405164-2484-1-git-send-email-pbonzini@redhat.com> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | aioe.org linux.kernel:1158334 |
Show key headers only | View raw
VFIO has proved itself a much better option than KVM's built-in device assignment. It is mature, provides better isolation because it enforces ACS, and even the userspace code is being tested on a wider variety of hardware these days than the legacy support. Disable legacy device assignment by default. Signed-off-by: Paolo Bonzini <pbonzini@redhat.com> --- arch/x86/kvm/Kconfig | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/arch/x86/kvm/Kconfig b/arch/x86/kvm/Kconfig index 413a7bf9efbb..a0f06a5947c5 100644 --- a/arch/x86/kvm/Kconfig +++ b/arch/x86/kvm/Kconfig @@ -88,13 +88,14 @@ config KVM_MMU_AUDIT config KVM_DEVICE_ASSIGNMENT bool "KVM legacy PCI device assignment support" depends on KVM && PCI && IOMMU_API - default y + default n ---help--- Provide support for legacy PCI device assignment through KVM. The kernel now also supports a full featured userspace device driver - framework through VFIO, which supersedes much of this support. + framework through VFIO, which supersedes this support and provides + better security. - If unsure, say Y. + If unsure, say N. # OK, it's a little counter-intuitive to do this, but it puts it neatly under # the virtualization menu. -- 1.8.3.1 -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next | Find similar | Unroll thread
[PATCH] kvm: x86: default legacy PCI device assignment support to "n" Paolo Bonzini <pbonzini@redhat.com> - 2015-06-04 10:10 +0200
csiph-web