From e3aca60843d603fc33eb0d1eab80ad7c2867ded1 Mon Sep 17 00:00:00 2001 From: Ian Jackson Date: Thu, 12 Oct 2017 12:18:58 +0100 Subject: [PATCH] xl: dm_restrict: Document that it does not work with PV MIME-Version: 1.0 Content-Type: text/plain; charset=utf8 Content-Transfer-Encoding: 8bit Signed-off-by: Ian Jackson Reported-by: Roger Pau Monné Acked-by: Wei Liu --- docs/man/xl.cfg.pod.5.in | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/docs/man/xl.cfg.pod.5.in b/docs/man/xl.cfg.pod.5.in index 9b27233095..b7b91d8627 100644 --- a/docs/man/xl.cfg.pod.5.in +++ b/docs/man/xl.cfg.pod.5.in @@ -1270,7 +1270,7 @@ connectors=id0:1920x1080;id1:800x600;id2:640x480 =item B -Restrict the HVM device model after startup, +Restrict the device model after startup, to limit the consequencese of security vulnerabilities in qemu. With this feature enabled, @@ -1285,6 +1285,11 @@ There are some significant limitations: =item +This is not likely to work at all for PV guests +nor guests using qdisk backends for their block devices. + +=item + You must have a new enough qemu. In particular, if your qemu does not have the commit -- 2.30.2