On Tue, Mar 26, 2024 at 4:48 PM Xiaoyao Li <xiaoyao...@intel.com> wrote: > So, this requires confidential guests to call > kvm_mark_guest_state_protected() in its machine_init_done notifier callback? > > But for TDX, the guest_state is protected at the beginning, not some > time later when machine_init_done.
Good point, I will change this to an "if". Paolo