Re: [PATCH] Ability to read the MKTME status from userspace

From: Boris Petkov
Date: Mon Jun 22 2020 - 05:34:07 EST


On June 19, 2020 10:24:23 PM GMT+02:00, Dave Hansen <dave.hansen@xxxxxxxxx> wrote:
>On 6/19/20 1:20 PM, Andy Lutomirski wrote:
>> Boris, etc: would it be reasonable to add a list of CPU features that
>> are present but turned off by firmware? SME is far from the only
>> thing that's frequently in this category. x2apic, fast strings, and
>> virtualization come to mind.
>
>Sounds sane to me. I like the idea of proving ammo to end users to
>either go flip a BIOS switch, or yell at their firmware vendor.

Sure if the reenabling the feature in BIOS would enable the support. Which is not the case with TME, as ypu pointed out, so I'm not sure a list CPU features which are present but turned off in firmware, is enough.

I'm thinking more along the lines of adding freetext doc for such "complex" to enable features which explains to users what and where to check, what to switch on and off and what other prerequisites can be...

And yes, it is ugly. ;-/

--
Sent from a small device: formatting sux and brevity is inevitable.