Re: [RFC PATCH 00/62] Linux as SEV-ES Guest Support

From: Joerg Roedel
Date: Tue Feb 11 2020 - 10:43:26 EST


On Tue, Feb 11, 2020 at 03:50:08PM +0100, Peter Zijlstra wrote:

> Oh gawd; so instead of improving the whole NMI situation, AMD went and
> made it worse still ?!?

Well, depends on how you want to see it. Under SEV-ES an IRET will not
re-open the NMI window, but the guest has to tell the hypervisor
explicitly when it is ready to receive new NMIs via the NMI_COMPLETE
message. NMIs stay blocked even when an exception happens in the
handler, so this could also be seen as a (slight) improvement.

Regards,

Joerg