This series adds support for enabling VMSA SEV features for SEV-ES and
SEV-SNP guests. Since that is already supported for IGVM files, some of
that code is moved to generic path and reused.
Debug-swap is already supported in KVM today, while patches for enabling
Secure TSC have been accepted for the upcoming kernel release.
Roy,
I haven't been able to test IGVM, so would be great if that is tested to
confirm there are no unintended changes there.
Changes since v1 (*):
- Move patch enabling use of KVM_SEV_INIT2 for SEV-ES guests before
patch enabling use of debug-swap VMSA SEV feature (Tom)
- Only issue KVM_SET_TSC_KHZ if user has specified a tsc-frequency for
Secure TSC (Tom)
- Patch 9/9 is new and refactors check_sev_features in preparation for
future SEV feature support (Tom)
- Minor updates to commit log and comments (Tom)
- Collect review tags from Tom
(*) http://lkml.kernel.org/r/cover.1758189463.git.naveen@kernel.org
- Naveen
Naveen N Rao (AMD) (9):
target/i386: SEV: Generalize handling of SVM_SEV_FEAT_SNP_ACTIVE
target/i386: SEV: Ensure SEV features are only set through qemu cli or
IGVM
target/i386: SEV: Consolidate SEV feature validation to common init
path
target/i386: SEV: Validate that SEV-ES is enabled when VMSA features
are used
target/i386: SEV: Enable use of KVM_SEV_INIT2 for SEV-ES guests
target/i386: SEV: Add support for enabling debug-swap SEV feature
target/i386: SEV: Add support for enabling Secure TSC SEV feature
target/i386: SEV: Add support for setting TSC frequency for Secure TSC
target/i386: SEV: Refactor check_sev_features()
target/i386/sev.h | 4 +-
target/i386/sev.c | 170 +++++++++++++++++++++++++++++++++++++---------
qapi/qom.json | 16 ++++-
3 files changed, 155 insertions(+), 35 deletions(-)
base-commit: 95b9e0d2ade5d633fd13ffba96a54e87c65baf39
--
2.51.0