Re: [Part1 PATCH v7 00/17] x86: Secure Encrypted Virtualization (AMD)

From: Borislav Petkov
Date: Thu Nov 16 2017 - 05:02:44 EST


On Wed, Nov 15, 2017 at 03:57:13PM -0800, Steve Rutherford wrote:
> One piece that seems missing here is the handling of the vmm
> communication exception. What's the plan for non-automatic exits? In
> particular, what's the plan for emulated devices that are currently
> accessed through MMIO (e.g. the IOAPIC)?

First of all, please do not top-post.

Then, maybe this would answer some of your questions:

http://support.amd.com/TechDocs/Protecting%20VM%20Register%20State%20with%20SEV-ES.pdf

But I'd look in Tom's direction for further comments.

> Maybe I'm getting ahead of myself: What's the testing story? (since I
> don't think linux would boot with these patches, I'm curious what you
> are doing to ensure these pieces work)

Seems to boot fine here :)

--
Regards/Gruss,
Boris.

Good mailing practices for 400: avoid top-posting and trim the reply.