On Fri, Sep 06, 2024 at 02:46:24AM +0000, Tian, Kevin wrote: > > Further, the vIOMMU, and it's parameters, in the VM must also be > > validated and trusted before the VM can lock the device. The VM and > > the trusted world must verify they have the exclusive control over the > > translation. > > Looking at the TDISP spec it's the host to lock the device (as Dan > described the entry into the LOCKED state) while the VM is allowed > to put the device into the RUN state after validation. > > I guess you actually meant the entry into RUN here? otherwise > there might be some disconnect here. Yeah Jason