Re: [PATCH v3 0/8] Alternate Injection: Secure Interrupt Delivery for SEV-SNP Guests - Guest Support
From: Ard Biesheuvel
Date: Fri Sep 25 2026 - 01:44:31 EST
On Fri, 25 Sep 2026, at 07:47, Borislav Petkov wrote:
> On Thu, Sep 24, 2026 at 09:06:00PM +0200, Ard Biesheuvel wrote:
>> What I would like to see is an abstraction implemented in OVMF that encapsulates
>> the logic that you are adding here. All the EFI stub would have to do is call
>> the protocol, nothing more.
>
> Out of pure curiosity, why?
>
> Is the answer something along the lines of, before ExitBootServices(), the
> firmware owns the machine, the kernel should not poke at anything but should
> call the fw and latter is supposed to do the init and synchronization and
> setup of resources, yadda yadda...
>
Essentially. It is a layering violation.
Before ExitBootServices(), the firmware runs with the timer interrupt enabled.
So poking at MSRs to reconfigure this behind the back of the firmware while
it thinks it is still in full control is not a great idea.
Instead, the EFI stub should inform the firmware that it wants alternate
injection, and the firmware can take care of that at EBS() time.