• B
    sev/i386: register the guest memory range which may contain encrypted data · 2b308e44
    Brijesh Singh 提交于
    When SEV is enabled, the hardware encryption engine uses a tweak such
    that the two identical plaintext at different location will have a
    different ciphertexts. So swapping or moving a ciphertexts of two guest
    pages will not result in plaintexts being swapped. Hence relocating
    a physical backing pages of the SEV guest will require some additional
    steps in KVM driver. The KVM_MEMORY_ENCRYPT_{UN,}REG_REGION ioctl can be
    used to register/unregister the guest memory region which may contain the
    encrypted data. KVM driver will internally handle the relocating physical
    backing pages of registered memory regions.
    
    Cc: Paolo Bonzini <pbonzini@redhat.com>
    Cc: Richard Henderson <rth@twiddle.net>
    Cc: Eduardo Habkost <ehabkost@redhat.com>
    Signed-off-by: NBrijesh Singh <brijesh.singh@amd.com>
    Signed-off-by: NPaolo Bonzini <pbonzini@redhat.com>
    2b308e44
trace-events 549 字节