xsm, argo: XSM control for any access to argo by a domain
authorChristopher Clark <christopher.w.clark@gmail.com>
Wed, 6 Feb 2019 08:56:00 +0000 (09:56 +0100)
committerJan Beulich <jbeulich@suse.com>
Thu, 7 Feb 2019 13:26:19 +0000 (14:26 +0100)
commit789cab9d676341b260b540c23c29fab242b1747e
tree8e78f8081c3ae08edbecf7fad53e8a67b8df4be5
parent4c0526b739975604d1c73cb3c3eb89281fda0aa4
xsm, argo: XSM control for any access to argo by a domain

Will inhibit initialization of the domain's argo data structure to
prevent receiving any messages or notifications and access to any of
the argo hypercall operations.

Signed-off-by: Christopher Clark <christopher.clark6@baesystems.com>
Acked-by: Daniel De Graaf <dgdegra@tycho.nsa.gov>
Tested-by: Chris Patterson <pattersonc@ainfosec.com>
Release-acked-by: Juergen Gross <jgross@suse.com>
tools/flask/policy/modules/guest_features.te
xen/common/argo.c
xen/include/xsm/dummy.h
xen/include/xsm/xsm.h
xen/xsm/dummy.c
xen/xsm/flask/hooks.c
xen/xsm/flask/policy/access_vectors