Messages in this thread |  | | Subject | Re: [RFC v2 02/32] x86/tdx: Introduce INTEL_TDX_GUEST config option | | From | Randy Dunlap <> | | Date | Mon, 26 Apr 2021 14:09:28 -0700 |
| |
On 4/26/21 11:01 AM, Kuppuswamy Sathyanarayanan wrote: > Add INTEL_TDX_GUEST config option to selectively compile > TDX guest support. > > Signed-off-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com> > Reviewed-by: Andi Kleen <ak@linux.intel.com> > Reviewed-by: Tony Luck <tony.luck@intel.com> > --- > arch/x86/Kconfig | 15 +++++++++++++++ > 1 file changed, 15 insertions(+) > > diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig > index 6b4b682af468..932e6d759ba7 100644 > --- a/arch/x86/Kconfig > +++ b/arch/x86/Kconfig > @@ -875,6 +875,21 @@ config ACRN_GUEST > IOT with small footprint and real-time features. More details can be > found in https://projectacrn.org/. > > +config INTEL_TDX_GUEST > + bool "Intel Trusted Domain eXtensions Guest Support" > + depends on X86_64 && CPU_SUP_INTEL && PARAVIRT > + depends on SECURITY > + select PARAVIRT_XL > + select X86_X2APIC > + select SECURITY_LOCKDOWN_LSM > + help > + Provide support for running in a trusted domain on Intel processors > + equipped with Trusted Domain eXtenstions. TDX is an new Intel
a new Intel
> + technology that extends VMX and Memory Encryption with a new kind of > + virtual machine guest called Trust Domain (TD). A TD is designed to > + run in a CPU mode that protects the confidentiality of TD memory > + contents and the TD’s CPU state from other software, including VMM. > + > endif #HYPERVISOR_GUEST > > source "arch/x86/Kconfig.cpu" >
-- ~Randy
|  |