Blockers for PVH control domains
Owner: royger

Some of the recent CPU security issues (like Native-BHI) affect PV more than HVM, and adding to that the mitigations provided by the vendors might not be effective on 64bit PV guests as both the kernel and user-space run at the same privilege level (CPL 3).

In light of this possibly not getting better, I would like to discuss the current state of PVH for control domains:

  • Missing bits for PVH dom0 moving into the supported state.

  • New hypercall ABI considerations for translated domains.

  • Performance analysis of control operations from a translated domain.