On Tue, Jan 19, 2021 at 08:23:20AM -0800, Sean Christopherson wrote: > It was the AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT dependency that tripped me up. To > get KVM to enable SEV/SEV-ES by default, By default? What would be the use case for that? > Agreed, I'll send a KVM patch to remove the > AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT dependency. Yah, AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT came out of the initial memory enc. SME patchset where the use case was something along the lines of booting a kernel and SME being enabled by default. But Tom doesn't remember exactly either. I guess that thing doesn't belong in kvm code anyway... -- Regards/Gruss, Boris. https://people.kernel.org/tglx/notes-about-netiquette