4 ms·
We're still working the details out upstream but the TL;DR is that the way to address Meltdown with Xen PV is to use nested virtualization so that the outer gue
by aliguori 9y ago
We're still working the details out upstream but the TL;DR is that the way to address Meltdown with Xen PV is to use nested virtualization so that the outer guest is an HVM or PVH guest.
- jlgaddis 9y agoIs this what AWS is doing?
- aliguori 9y agoYes, all customer PV instances in EC2 are running in an HVM container and are protected against the guest-to-guest Meltdown vulnerability. As with all virtual and physical machines, patches are necessary to protect against process-to-process Meltdown within the OS itself. Those are starting to roll out from the respective vendors although it will take time for those to work inside a PV instance.
- Vogtinator 9y agoDoesn't this still allow to read memory from the hypervisor shared between the PV VMs in a HVM container?
- bonzini 9y agoNo, because page tables are isolated between guests.
- cthalupa 9y agoThe intention, from my understanding, is not to boot multiple PV guests inside of one HVM shim, but instead treat it as more of a packaged deal - for each PV guest, you will be running it inside an independent vixen shim. So 5 PV guests, 5 vixen shims, etc.
- quanstro 9y agocorrect.
- jacobn 9y agoFrom the post: "all PV instances in EC2 are using this"
- jlgaddis 9y agoYeah, thanks, not sure HTF I missed that the first time.