@JamesG it should be compatible, yes.
you can check the current command-line value with /opt/xensource/libexec/xen-cmdline --get-dom0 xen-pciback.hide and add all 81-84 devices with --set-dom0
@JamesG it should be compatible, yes.
you can check the current command-line value with /opt/xensource/libexec/xen-cmdline --get-dom0 xen-pciback.hide and add all 81-84 devices with --set-dom0
@JamesG Could you pass through 81-84 manually and confirm that it actually fixes the issues for you?
@JamesG You can still manually use xen-cmdline to pass through 81-84 to the VM on 8.3 (this is in fact what xe pci-disable-dom0-access does behind the scenes).
I'll try to see why other devices are omitted and how this can be fixed.
@michael.manley Would it be possible to backport the XSA-498 fixes? I've tried updating the SDK as a whole but it resulted in a lot of churn and caused errors elsewhere: https://github.com/xcp-ng/xenadmin/pull/271
The fixes to the SDK have been posted here https://github.com/xapi-project/xen-api/pull/7176 and here: https://xenbits.xen.org/xsa/advisory-498.html
@Andrew That means you likely don't have any "leaked" VBDs 