3 ms·
I don't know details. I was thinking about doing GPU passthrough myself, but whenever developers chimed in on any posts about the topic, this is essentially wha
by Nojlk 6y ago
I don't know details. I was thinking about doing GPU passthrough myself, but whenever developers chimed in on any posts about the topic, this is essentially what they said.
Some links I remember going through:
https://www.qubes-os.org/doc/device-handling-security/#pci-security https://www.qubes-os.org/doc/device-handling-security/#pci-s...
> Additionally, Qubes restricts the config-space a VM may use to communicate with a PCI device. Only whitelisted registers are accessible. However, some devices or applications require full PCI access. In these cases, the whole config-space may be allowed. You’re potentially weakening the device isolation, especially if your system is not equipped with a VT-d Interrupt Remapping unit. This increases the VM’s ability to run a side channel attack and vulnerability to the same. See Xen PCI Passthrough: PV guests and PCI quirks and Software Attacks on Intel VT-d (page 7) for more details.
https://security.stackexchange.com/questions/162122/gpu-passthrough-security/162175 https://security.stackexchange.com/questions/162122/gpu-pass...