On Tue, Dec 27, 2022 at 05:17:20PM +0800, Jason Wang wrote:
To track all state? Yea, maybe. For sure it's doable just in virtio,ATM no amount of hardening can prevent a malicious hypervisor fromIn particular, we will also directly break the device.It's kind of hardening for malicious devices.
blocking the guest. Recovering when a hardware device is broken would be
nice but I think if we do bother then we should try harder to recover,
such as by driving device reset.
Probably, but as discussed in another thread, it needs co-operation in the
upper layer (networking core).
but if you can find 1-2 other drivers that do this internally
then factoring this out to net core will likely be accepted.