Found-by-inspection (when reviewing Binbin's patch) fixes for incorrect emulation of faults when KVMintercepts and emulates (sort of) ENCLS. Very much compile tested only. Ideally, someone with SGX hardware can confirm that these patches are correct, e.g. my assessment that KVM needs to manually check CR0.PG is based purely of SDM pseudocode. Sean Christopherson (2): KVM: VMX: Inject #GP on ENCLS if vCPU has paging disabled (CR0.PG==0) KVM: VMX: Inject #GP, not #UD, if SGX2 ENCLS leafs are unsupported arch/x86/kvm/vmx/sgx.c | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) base-commit: 27d6845d258b67f4eb3debe062b7dacc67e0c393 -- 2.40.0.348.gf938b09366-goog