4 ms·
Because you might be root in one VM or container, and you are trying to access another VM or container.
by hackmiester 3y ago
Because you might be root in one VM or container, and you are trying to access another VM or container.
- Thorrez 3y agoOh, interesting. I wonder if the hypervisor would be able to prevent the VM from using those features of the CPU.
- 1oooqooq 3y agoit usually does not. reason why you run security analysts of untrusted code first in a qemu without virtualization.
- kramerger 3y agoWhile your hypervisor may not implement it, ARM allows you to configure this kind of operations. See for example https://developer.arm.com/documentation/ddi0595/2020-12/AArch64-Registers/HDFGWTR-EL2--Hypervisor-Debug-Fine-Grained-Write-Trap-Register?lang=en https://developer.arm.com/documentation/ddi0595/2020-12/AArc...
- 1oooqooq 3y agooh qemu supports this alright, since 8.x but good luck 1. having a cpu with it (can't wait for arm laptops and needing caniuse.org for my assembly code), and 2. figuring out how to use it