Re: [PATCH] kvm/sev: remove redundant MISC_CG_RES_SEV_ES

From: José Pekkarinen
Date: Thu Oct 12 2023 - 12:45:44 EST


On 2023-10-12 13:43, Paolo Bonzini wrote:
On 10/10/23 19:49, José Pekkarinen wrote:
SEV-ES is an extra encrypted state that shares common resources
with SEV. Using an extra CG for its purpose doesn't seem to
provide much value. This patch will clean up the control group
along with multiple checks that become redundant with it.

The patch will also remove a redundant logic on sev initialization
that produces SEV-ES to be disabled, while supported by the cpu
and requested by the user through the sev_es parameter.

In what sense is it shared? The SEV ASIDs and the SEV-ES ASIDs are
separate (and in both cases limited) resources, and therefore they
have separate cgroups.

Nevermind this patch, after a painful bios upgrade I got sev-es
available in it, and I was able to launch some test vm on it, so this
may only be breaking things. Sorry for the noise!

José.