Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Force all PCIe devices through D3Cold #5

Open
DemiMarie opened this issue Jan 21, 2022 · 0 comments
Open

Force all PCIe devices through D3Cold #5

DemiMarie opened this issue Jan 21, 2022 · 0 comments
Labels
P: default Priority: default. Default priority for new issues, to be replaced given sufficient information. T: enhancement Type: enhancement. An enhancement or improvement of existing functionality. W: todo Workflow: todo. The issue is in the initial to do state.

Comments

@DemiMarie
Copy link

The problem you're addressing (if any)
The only quasi-guaranteed way to reset a PCIe device is to force it through D3Cold (electrically powered off). Otherwise, there is an increased risk that state could be carried over, which could be used to compromise the next user of the device.

Describe the solution you'd like
Hold all PCIe devices in D3Cold for long enough for internal capacitors to discharge.

Where is the value to a user, and who might that user be?
All users who use PCIe pass-through to untrusted VMs, or VFIO with untrusted userspace drivers, will benefit from improved security. This includes all users of Qubes OS

Describe alternatives you've considered
None

Additional context
None

Relevant documentation you've consulted
Private communication

Related, non-duplicate issues
None

@DemiMarie DemiMarie added P: default Priority: default. Default priority for new issues, to be replaced given sufficient information. T: enhancement Type: enhancement. An enhancement or improvement of existing functionality. W: todo Workflow: todo. The issue is in the initial to do state. labels Jan 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
P: default Priority: default. Default priority for new issues, to be replaced given sufficient information. T: enhancement Type: enhancement. An enhancement or improvement of existing functionality. W: todo Workflow: todo. The issue is in the initial to do state.
Projects
None yet
Development

No branches or pull requests

1 participant