On Tue, Mar 21, 2023 at 05:48:38PM +0000, Dr. David Alan Gilbert wrote: > I'm curious why you're doing isolation using ring-3 stuff rather than > another VMPL level? Two reasons: 1) CPL switch is much cheaper than VMPL switch 2) CPLs allow to isolate different services within the same VMPL. Having services run at, say, VMPL1 on CPL-0 will allow all services on VMPL1 to access each others memory. Regards, -- Jörg Rödel jroedel@xxxxxxx SUSE Software Solutions Germany GmbH Frankenstraße 146 90461 Nürnberg Germany (HRB 36809, AG Nürnberg) Geschäftsführer: Ivo Totev, Andrew Myers, Andrew McDonald, Boudien Moerman