Re: [PATCH v3 0/4] KVM: TDX: Validate directly configurable CPUID bits
From: Binbin Wu
Date: Wed Sep 09 2026 - 01:38:30 EST
On 9/9/2026 7:54 AM, Binbin Wu wrote:
>
>> So maybe the way to go is to just follow 'msr_preservation.pdf' and
>> adjust the allowlist? I find this approach safe and acceptable.
>>
>
> Rick explained the long history:
> https://lore.kernel.org/all/58c185c82658819454a9950f37c6424226a098bb.camel@xxxxxxxxx/
>
> The Denylist based solution is not a clean solution:
> - It couples the feature enabling for normal VMs with TDX tightly.
> - Each time a new feature is added in the denylist, it needs to be backported to old KVM versions
>
Please ignore this part since I replied to the wrong thread.
>
>> Artem.
>