From 3f8a4aa9c19aa9f31fa62521b8fc6c5086d5c4e8 Mon Sep 17 00:00:00 2001 From: Jan Beulich Date: Thu, 12 Sep 2013 11:25:34 +0200 Subject: x86: don't allow Dom0 access to the MSI address range In particular, MMIO assignments should not be done using this area. Signed-off-by: Jan Beulich Acked-by Xiantao Zhang master commit: 850188e1278cecd1dfb9b936024bee2d8dfdcc18 master date: 2013-08-27 11:11:38 +0200 --- xen/arch/x86/domain_build.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/xen/arch/x86/domain_build.c b/xen/arch/x86/domain_build.c index 0dbec96b05..2a690fae24 100644 --- a/xen/arch/x86/domain_build.c +++ b/xen/arch/x86/domain_build.c @@ -1261,6 +1261,10 @@ int __init construct_dom0( if ( smp_found_config ) rc |= iomem_deny_access(dom0, mfn, mfn); } + /* MSI range. */ + rc |= iomem_deny_access(dom0, paddr_to_pfn(MSI_ADDR_BASE_LO), + paddr_to_pfn(MSI_ADDR_BASE_LO + + MSI_ADDR_DEST_ID_MASK)); /* Remove access to E820_UNUSABLE I/O regions above 1MB. */ for ( i = 0; i < e820.nr_map; i++ ) -- cgit v1.2.3