Thread (67 messages) 67 messages, 6 authors, 2016-10-18

Re: [RFC PATCH v1 09/28] x86/efi: Access EFI data as encrypted when SEV is active

From: Paolo Bonzini <pbonzini@redhat.com>
Date: 2016-09-22 18:51:08
Also in: kvm, linux-crypto, linux-efi, lkml


On 22/09/2016 20:47, Tom Lendacky wrote:
quoted
Because the firmware volume is written to high memory in encrypted form,
and because the PEI phase runs in 32-bit mode, the firmware code will be
encrypted; on the other hand, data that is placed in low memory for the
kernel can be unencrypted, thus limiting differences between SME and SEV.
I like the idea of limiting the differences but it would leave the EFI
data and ACPI tables exposed and able to be manipulated.
Hmm, that makes sense.  So I guess this has to stay, and Borislav's
proposal doesn't fly either.

Paolo

--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org.  For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help