On 3/24/2022 5:37 PM, Gerd Hoffmann wrote:
Hi,
#VE can be triggered in various situations. e.g., CPUID on some leaves, and
RD/WRMSR on some MSRs. #VE on pending page is just one of the sources, Linux
just wants to disable this kind of #VE since it wants to prevent unexpected
#VE during SYSCALL gap.
Linux guests can't disable those on their own? Requiring this being
configured on the host looks rather fragile to me ...
Yes, current TDX architecture doesn't allow TD guest to do so. Maybe in
the future, it can be allowed, maybe.
take care,
Gerd