From patchwork Wed Apr 6 14:44:30 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jan Beulich X-Patchwork-Id: 12803588 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id C0DAAC433F5 for ; Wed, 6 Apr 2022 14:44:58 +0000 (UTC) Received: from list by lists.xenproject.org with outflank-mailman.299935.511284 (Exim 4.92) (envelope-from ) id 1nc6tg-0007yK-7J; Wed, 06 Apr 2022 14:44:36 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version Received: by outflank-mailman (output) from mailman id 299935.511284; Wed, 06 Apr 2022 14:44:36 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1nc6tg-0007yD-3r; Wed, 06 Apr 2022 14:44:36 +0000 Received: by outflank-mailman (input) for mailman id 299935; Wed, 06 Apr 2022 14:44:35 +0000 Received: from se1-gles-flk1-in.inumbo.com ([94.247.172.50] helo=se1-gles-flk1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1nc6tf-0007y7-Os for xen-devel@lists.xenproject.org; Wed, 06 Apr 2022 14:44:35 +0000 Received: from de-smtp-delivery-102.mimecast.com (de-smtp-delivery-102.mimecast.com [194.104.109.102]) by se1-gles-flk1.inumbo.com (Halon) with ESMTPS id 135ae4fc-b5b8-11ec-8fbc-03012f2f19d4; Wed, 06 Apr 2022 16:44:34 +0200 (CEST) Received: from EUR05-VI1-obe.outbound.protection.outlook.com (mail-vi1eur05lp2177.outbound.protection.outlook.com [104.47.17.177]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id de-mta-13-O-OgIMrePVmZKnMezWAYVA-1; Wed, 06 Apr 2022 16:44:33 +0200 Received: from DU2PR04MB8616.eurprd04.prod.outlook.com (2603:10a6:10:2db::16) by VI1PR04MB4560.eurprd04.prod.outlook.com (2603:10a6:803:6d::33) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5144.19; Wed, 6 Apr 2022 14:44:32 +0000 Received: from DU2PR04MB8616.eurprd04.prod.outlook.com ([fe80::914d:e08d:7798:8476]) by DU2PR04MB8616.eurprd04.prod.outlook.com ([fe80::914d:e08d:7798:8476%7]) with mapi id 15.20.5123.031; Wed, 6 Apr 2022 14:44:32 +0000 X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: 135ae4fc-b5b8-11ec-8fbc-03012f2f19d4 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=mimecast20200619; t=1649256274; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=0bgJSju+vdmXtXwH09gQNY2F0IdkUhfF3FPg22gDVs8=; b=YB4w3WkPmuJn7Tku5ki5mAgCrDkT21klYVmNKpNda+3icWYcBHXVB+ZDNa9uD9gHsf3owM q8c0pREzJS/wDXz8T1Fq1Ek/QIUcC8lxHC9bFEwAQi4K4pNbwZbgMy6tr2jNKiESOtBbXb jAZDQZ9ATaE+0rB59PXGAOHUPh5Q57o= X-MC-Unique: O-OgIMrePVmZKnMezWAYVA-1 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=NGF7manSXHSfOWjP/vLdYJmqWCZWfx77J0Xix7ken5zgYZt5d5dq47/7oga+unAZcFJBU6QmN+S/EwaKbhJh8VMgH9UGQ9r1AMiZL+3h6etZy0ppqnnko3fyAM+YbpITIKiAjO6Q2EqxCwbA/EnSM3Tcw8WP/rhLRjIb//JgDfdr08zUn0yEzMkSRg48IIa7w+0Zd7qJDCUCEaarSjgV3DNObUvOxsuQpY7uuRsqOMNoQPA2YblHIN+i0hVwQPJJfqXRGcOAwm6LeqRYkanAx/MzCcANNI78cQhLUJxkg1m5MpI6SD5zUYa6rgod658SlwLQE7za7uQ8FdpK1R0zDA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=0bgJSju+vdmXtXwH09gQNY2F0IdkUhfF3FPg22gDVs8=; b=BOkxYeHn1TnOWsd9b5R8m9wxl7lReAXJzVkA0riihBa74xIUg3N1CZu2cU7ObWg5BzYB442eaE6XO8G86J0Stk/SamST7O5BrVHehRJS1ZaIphxeA7qu68JJ0FyRgWix5be0o9tGsPEQSPNzqAMpJN3NIB7UQG5Cym3FKVfthVgML4Kqj+3MfsFvnk1KX4AfxtxAX3jmWbFoTAw2JmXYVixHJ2WLn0OQqnXAJpNq/gBX/8lRyCLD0wcHNy4edDIrnWp5TCiwY3+93dIR87uui0EsFI0mQpWNaiKJGP6Djm5LCpUTjhOyEi1w0xTHEM9iPGzLiAUtdUqklVv7wY8Z8A== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=suse.com; dmarc=pass action=none header.from=suse.com; dkim=pass header.d=suse.com; arc=none Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=suse.com; Message-ID: <4c49e4cf-9d86-e630-a1bb-37afdf091c99@suse.com> Date: Wed, 6 Apr 2022 16:44:30 +0200 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Thunderbird/91.7.0 Content-Language: en-US To: "xen-devel@lists.xenproject.org" Cc: Andrew Cooper , George Dunlap , Julien Grall , Stefano Stabellini , Wei Liu From: Jan Beulich Subject: [PATCH] SUPPORT.md: extend security support for hosts to 12 TiB of memory X-ClientProxiedBy: AS9PR06CA0196.eurprd06.prod.outlook.com (2603:10a6:20b:45d::22) To DU2PR04MB8616.eurprd04.prod.outlook.com (2603:10a6:10:2db::16) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: 40d9a057-a3c0-4014-00ad-08da17dbf639 X-MS-TrafficTypeDiagnostic: VI1PR04MB4560:EE_ X-Microsoft-Antispam-PRVS: X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: BiefOBBboYpNSfMitqsuBuO8tmCnauCn+Yw29t5FlRcaUtHb6IKa6gxBvXgKKM0IerTw0SWQTHSiPeHhRkte2HjnLLVa0zRAonmh1qhJSbu9XgjiWtvZh8Hk2PpiiRI5kT918wN7OghD63pnphbL/t+LPkQTcMc5TH6G27ZZSZ4ql/lnUsD1AuaQkRZJYkow+spohn1EQPSmOJKu5XEkkEeKOKOdLC2m3bCQLKeqUzeILyPmX2DY7q98Vj1hbo3gLV/PwawqNGwawq5S4340WFgugg1zx7oxvIgHmxrL6MMW06/WeVSWw2qU0xDU8hQrMmVJWDVLn6NtMfbQEwKriGghuX7UcuOHUcn8PujJhJ1FPeSToylunM8VAfwRYTtb/eCZhTATzsmASbnuUorehWoNr5xqD30oo367R8FNcZQHz4tPHqF2mUNOe8Ep934XaUbjpz3YuulD2O3TnL77B5e4WhL+LUJx7Ssr9RRi2wZQ+9Umz+xd/62r5dUZNZAulFDaHo5h9k6Sa9lhEOQP/S2q2BivctIi/hE3nA9OqQkewgGfEzc9DBNlpqtuiYLe//29MgtY73rBrz9H/bBYvaxrfUTqA/jnYmpepKKA0d7hF2AQj6y7Lp8cgw5a4hCMbHSLtDq08sr+di84BKuxU09/q/TWZCM+83QFiEttvDvSktVc88/3ZFRQt6gGbJc0RdmadXLYoIeaaHCHyyxoz4aCm0q+QbdIEyU5VpD8AN3ZRqqSjn2Dv0Xdn6Fx/DfsBiJo9KZAk1NigqfoD/4qVgG27A+G+aYMQdleuHUcz82gkxCOcBbA4ZZKvhKrjNjR X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU2PR04MB8616.eurprd04.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230001)(366004)(54906003)(6506007)(508600001)(966005)(86362001)(66476007)(6486002)(6916009)(316002)(66946007)(4326008)(31696002)(8676002)(66556008)(186003)(6512007)(26005)(2616005)(38100700002)(83380400001)(15650500001)(36756003)(31686004)(5660300002)(8936002)(2906002)(43740500002)(45980500001);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?q?dpOulaQcN8tjEKUQRdeIF3eTYdqT?= =?utf-8?q?L4WeA+YNf1YD+lymbbfTXC3zmI4A78Fsj8V4EhxymtdiuT8BbSmm8jGQXTFR3w09s?= =?utf-8?q?msnUAUCkmq6AoYZGOayrjakZlKcBh9BehAORQ6EQs8JGm0ov/3FHyL1B81ca/nnTH?= =?utf-8?q?X3xyk+iSr7OPU7d3AaYlrIhD2R6xE/gaCa08eQzCn0RVsK1LcPwViL7vfcHn+MAnI?= =?utf-8?q?9IkHfB3dMToWF4GYsPnYxWzD9bFzsSDP3jIaB4DDgxItv5Jp9o/I1fjpRLm1cc6cO?= =?utf-8?q?LTbWIBKiINoIgVtPM3FBOlYsScZIUP3KWdZqUukycly2r+S3/b1hXme2dZ5vFkF6V?= =?utf-8?q?04TGKZczdt3DWdLepMvcpJ4cUbQfi1GkaQTeK7u2Sx8hJNmnd3T1DOjL8qTcxUkZm?= =?utf-8?q?fTaDGxNbB49lKKO+pzLEj5UqRNuiBavc0K7ub9DsMIwxR2Y68ddx9Qncst7QpBVGe?= =?utf-8?q?jeycw5R6hO5wwEmxFTpkUVrcoqsnKrW7RCJ8Akeatx2zz+RPXrF7qr2OUwNcNm9aI?= =?utf-8?q?GHv9NUPXFXqbnQvtYiUZLDh1CnZ+GJjGUFFcEVLSpwb+x32gltBeoAECDZsEb3VdY?= =?utf-8?q?tvPWHI2jRoO7QSUR+frw+sHlyQicUJtQ2XOGSnqeqc7sD2HHjH2hjZImPqfRJuDcM?= =?utf-8?q?lLC+n6K/wLNzTP6dsgy1e4/01pZcwV/bsd8E3W45MGQiLMjp74/ExXwH6muomvgLG?= =?utf-8?q?WhBIvU8J8boQEk5r/svMEqkiz1jJAvlTC/xj4k2kP+o3p9JF5D0tY2mTWLSaNHBcq?= =?utf-8?q?AnIe5jBtGlgsC3B3cCbfqpaEHigTJUry9qZ7IfKzQCXjwAWMsOJd3w2XoEkSFIlsO?= =?utf-8?q?fbfRS6Vrr9m8fEYJQIPg7kUFxpLBDITuX/BLAoLc/a7L5CA0qoVOKhPKYUHorwl44?= =?utf-8?q?nrjzikYCM+Q13m4qKOyNyJcOYWxLZT2smTvo9bQlR/SBcXbrGh13x/9NRgaxeOGpx?= =?utf-8?q?1B1pD5NtoN5QCvPvFPOi3J/8fSr4crNDECQMHelDmWIXrFLGyOxH2Hhm3rXyaE5Yu?= =?utf-8?q?8LP/mt+aGtPNxH7U4nj2PGsmFvuMAU7WJQQ9HwwjkFHPyvsCjUWR7urnS4IpUvinX?= =?utf-8?q?37DvtSpH57KSuanZ1fPg2IrFyDXpHkJaT+k3ECGBGwc9QZm4GqUNez0fD+NZGIKCZ?= =?utf-8?q?vUI3X6r+IUGG3cvF3IC2mFmljuGPbF4UomhKYz1TTF+b3tQt1vPGwBFprvXteXfLi?= =?utf-8?q?71d5qZaMffojiBCHDdJfdTrU13Da+Zw/l7LvmIpcHPGpC//eKoe1wqMChngmnzufC?= =?utf-8?q?yjVHTVE1/wyNMVvaDCuP8Auy2lFvzwz77pwOvUnjBQs1Y/49O6VC/SSFuot6Od5o4?= =?utf-8?q?RqDwIO7fbjztBuMiBU6aKgksFUvBHQyS9o2DBnm7ueeE7IcYDiKWL+WD+rEVQUUVy?= =?utf-8?q?w0ru/ads2ia9UWNnwSwFFs58k1A1cFGraKRliQGtd9yjDkWujUEbPLPytJVqJPlOp?= =?utf-8?q?uFnFt70sqj3dVmLgC8BxjJdWpXhyfGGpuUZGlK0iNEKnoZIVyROO2FrmRTSn9ffLR?= =?utf-8?q?Ryl+WQTfoc72lqgi3MOvYIgePzgS17pNwbEKeOKthIGYVuERAqVHGa0Yc/fG8N3RT?= =?utf-8?q?H5YdiJOvzJyymWqT+7rV+JAoO+tim6z9T5FHnNripAFpam4zILpBO+DhPMxyRn7Pt?= =?utf-8?q?UKDleA1UrUoaMQCdcjRQd37aMVIHqyBQ=3D=3D?= X-OriginatorOrg: suse.com X-MS-Exchange-CrossTenant-Network-Message-Id: 40d9a057-a3c0-4014-00ad-08da17dbf639 X-MS-Exchange-CrossTenant-AuthSource: DU2PR04MB8616.eurprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 06 Apr 2022 14:44:32.3960 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: f7a17af6-1c5c-4a36-aa8b-f5be247aa4ba X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: D7dQvxpCXoJGz/WjHR+wzHswkjJQHKLEwWhbc548r2J6/u4wl/vMDsD1EdPKvYzoxRxw00A/YhMb5su9joS4nw== X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR04MB4560 c49ee0329ff3 ("SUPPORT.md: limit security support for hosts with very much memory"), as a result of XSA-385, restricted security support to 8 TiB of host memory. Extend this to 12 TiB, putting in place a guest restriction to 8 TiB in exchange. A 12 TiB host was certified successfully for use with Xen 4.14 as per https://www.suse.com/nbswebapp/yesBulletin.jsp?bulletinNumber=150753. This in particular included running as many guests (2 TiB each) as possible in parallel, to actually prove that all the memory can be used like this. It may be relevant to note that the Optane memory there was used in memory-only mode, with DRAM acting as cache. Signed-off-by: Jan Beulich --- a/SUPPORT.md +++ b/SUPPORT.md @@ -50,7 +50,7 @@ For the Cortex A57 r0p0 - r1p1, see Erra ### Physical Memory - Status: Supported up to 8 TiB + Status: Supported up to 12 TiB Hosts with more memory are supported, but not security supported. @@ -121,6 +121,14 @@ ARM only has one guest type at the momen Status: Supported +## Guest Limits + +### Memory + + Status: Supported up to 8 TiB + +Guests with more memory are supported, but not security supported. + ## Hypervisor file system ### Build info