Re: [PATCH 3/9] add frontend implementation for the IOMMU API

From: Joerg Roedel
Date: Mon Dec 01 2008 - 10:46:37 EST


On Mon, Dec 01, 2008 at 04:33:11PM +0200, Avi Kivity wrote:
> Joerg Roedel wrote:
> > Hmm, is there any hardware IOMMU with which we can't emulate domains by
> > partitioning the IO address space? This concept works for GART and
> > Calgary.
> >
> >
>
> Is partitioning secure? Domain X's user could program its hardware to
> dma to domain Y's addresses, zapping away Domain Y's user's memory.

No its not secure. But this problem exists with pv-dma without iommu
too.

Joerg

--
| AMD Saxony Limited Liability Company & Co. KG
Operating | Wilschdorfer Landstr. 101, 01109 Dresden, Germany
System | Register Court Dresden: HRA 4896
Research | General Partner authorized to represent:
Center | AMD Saxony LLC (Wilmington, Delaware, US)
| General Manager of AMD Saxony LLC: Dr. Hans-R. Deppe, Thomas McCoy

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/