Re: [PATCH v3 0/8] Alternate Injection: Secure Interrupt Delivery for SEV-SNP Guests - Guest Support

From: Borislav Petkov

Date: Fri Sep 25 2026 - 00:47:41 EST


On Thu, Sep 24, 2026 at 09:06:00PM +0200, Ard Biesheuvel wrote:
> What I would like to see is an abstraction implemented in OVMF that encapsulates
> the logic that you are adding here. All the EFI stub would have to do is call
> the protocol, nothing more.

Out of pure curiosity, why?

Is the answer something along the lines of, before ExitBootServices(), the
firmware owns the machine, the kernel should not poke at anything but should
call the fw and latter is supposed to do the init and synchronization and
setup of resources, yadda yadda...

Thx.

--
Regards/Gruss,
Boris.

https://people.kernel.org/tglx/notes-about-netiquette