Re: [PATCH RFC 03/15] backends/cryptodev-vhost-user: add memory isolation bool

Stefan Hajnoczi <[email protected]> Mon, 27 Jul 2026 14:43:05 -0400
Newsgroups dev.linux.lists.virtio-fs,org.nongnu.qemu-devel
Message-ID <20260727184305.GB371693@fedora>
--gY0jI/gfOQgW8+h2
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Fri, Jul 24, 2026 at 08:06:36AM +0200, Markus Armbruster wrote:
> Connor Kite <[email protected]> writes:
>    # @memory-isolation: disable access from cryptodev to guest memory.
>    #     (default: false) (since 11.2)
>=20
> Pardon my ignorance...  What exactly is "cryptodev" here?  Is it code
> running in another process?
>=20
> Should the description answer my question?  Perhaps like this:
>=20
>   # @memory-isolation: isolate guest memory.  Isolated guest memory
>   #     cannot be accessed from uh, what exactly?
>=20
> Fill in the blank.

Maybe it's clearer to mention the potentially untrusted vhost-user
backend process rather than cryptodev (the virtio-crypto vhost-user
device)?

Stefan

--gY0jI/gfOQgW8+h2
Content-Type: application/pgp-signature; name=signature.asc

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEEhpWov9P5fNqsNXdanKSrs4Grc8gFAmpnprkACgkQnKSrs4Gr
c8hfjwgAsUY5rQK5VxV+u2eBHIXa6bJmd0kuVddy2fYB8K4GFM/E7Cd7jMEPNhmL
WpVMMyTYqRcamqsSs8gXJYdXTXf7K6nO3zQW8n4vr6osXq9Ph/QRt+IkQd7RW2Rw
gzYRf/pVUWBhMf14Ds2Ak8s11TsxEngt8ACu5SqrHQR9tvOT1GJ8WrLaljpuyfEP
tTWPNSYXmUF//lXgopDaHni6khrALLfGgFTtT5/EEQlm8A8Bm7q5bNRGxdODz4DE
89UTlZ+cXmv8u9x2jyOXpvL0WtbTej/QhoNZYTetYlOkDE18/5CEFiFU/+sfeRfK
pB4iLbwCio+f3owLNiHykyBb14H2ig==
=k1yY
-----END PGP SIGNATURE-----

--gY0jI/gfOQgW8+h2--