Securing hypercall support for user space processes in virtual machines
摘要:
In one embodiment, a hypervisor may identify a memory location associated with a user space process operating on a virtual machine and a type of a request to be stored at the memory location by the user space process when the user space process invokes the hypercall. The hypervisor may associate a hypercall parameter with the memory location and the type of the request, the hypercall parameter to be used to determine whether the type of the request associated with the hypercall invoked by the user space process is permitted to be executed. The hypervisor may transmit a notification comprising the hypercall parameter to the user space process to cause the user space process to use the hypercall parameter when invoking the hypercall to indicate to the hypervisor the memory location and type of the request is stored at the memory location.
信息查询
0/0