Re: [PATCH] x86/sev: Make SEV_STATUS available via SYSFS

From: Borislav Petkov
Date: Wed Mar 05 2025 - 06:51:02 EST


On Wed, Mar 05, 2025 at 12:42:41PM +0100, Ingo Molnar wrote:
> So if the convenience of tooling is the argument, the raw feature mask
> exposed is the best option overall.

The convenience of tooling *and* user. I want both. I want to be able to boot
a guest and see what features are enabled without needing a tool.

And, at the same time, tools should be able to use the same interface.

Exactly like we *and glibc* use /proc/cpuinfo today. Now think the same thing
but for confidential guests.

> So the /sys/devices/system/cpu/sev/ directory already exists and your
> arguments already apply to that, don't they?

Lemme repeat:

>> - a .../sev sysfs file clearly doesn't cut it because TDX doesn't have "sev"
>> - it is the Intel version of a confidential guest

>> - we have a general need to expose what a confidential guest supports

> As to the hex numbers - do you prefer to put string versions of these
> into the sysfs file:

See above.

--
Regards/Gruss,
Boris.

https://people.kernel.org/tglx/notes-about-netiquette