Re: [PATCH v3 0/8] Alternate Injection: Secure Interrupt Delivery for SEV-SNP Guests - Guest Support

From: Borislav Petkov

Date: Fri Sep 25 2026 - 01:48:00 EST


On Fri, Sep 25, 2026 at 08:44:00AM +0300, Ard Biesheuvel wrote:
> Essentially. It is a layering violation.
>
> Before ExitBootServices(), the firmware runs with the timer interrupt enabled.
> So poking at MSRs to reconfigure this behind the back of the firmware while
> it thinks it is still in full control is not a great idea.
>
> Instead, the EFI stub should inform the firmware that it wants alternate
> injection, and the firmware can take care of that at EBS() time.

Ack, makes sense.

Thx.

--
Regards/Gruss,
Boris.

https://people.kernel.org/tglx/notes-about-netiquette