On 3/31/21 3:06 PM, Sean Christopherson wrote:But I think there are cases (like MCE) where SEAM does not disable them because
I've no objection to a nice message in the #VE handler. What I'm objecting to
is sanity checking the CPUID model provided by the TDX module. If we don't
trust the TDX module to honor the spec, then there are a huge pile of things
that are far higher priority than MONITOR/MWAIT.
In other words: Don't muck with CPUID or the X86_FEATURE at all. Don't
check it to comply with the spec. If something doesn't comply, we'll
get a #VE at *SOME* point. We don't need to do belt-and-suspenders
programming here.
That sounds sane to me.