• Peter Gonda's avatar
    KVM: SEV: Allow some commands for mirror VM · 5b92b6ca
    Peter Gonda authored
    A mirrored SEV-ES VM will need to call KVM_SEV_LAUNCH_UPDATE_VMSA to
    setup its vCPUs and have them measured, and their VMSAs encrypted. Without
    this change, it is impossible to have mirror VMs as part of SEV-ES VMs.
    
    Also allow the guest status check and debugging commands since they do
    not change any guest state.
    Signed-off-by: default avatarPeter Gonda <pgonda@google.com>
    Cc: Marc Orr <marcorr@google.com>
    Cc: Nathan Tempelman <natet@google.com>
    Cc: Paolo Bonzini <pbonzini@redhat.com>
    Cc: Sean Christopherson <seanjc@google.com>
    Cc: Steve Rutherford <srutherford@google.com>
    Cc: Brijesh Singh <brijesh.singh@amd.com>
    Cc: kvm@vger.kernel.org
    Cc: linux-kernel@vger.kernel.org
    Cc: stable@vger.kernel.org
    Fixes: 54526d1f ("KVM: x86: Support KVM VMs sharing SEV context", 2021-04-21)
    Message-Id: <20210921150345.2221634-3-pgonda@google.com>
    Signed-off-by: default avatarPaolo Bonzini <pbonzini@redhat.com>
    5b92b6ca
sev.c 66.5 KB