Re: SEV, SEV-ES, SEV-SNP

2023-08-29 Thread Daniel P . Berrangé
On Tue, Aug 29, 2023 at 09:54:40AM +0200, Erik Skultety wrote: > On Mon, Aug 28, 2023 at 02:10:42PM -0700, Derek Lee wrote: > > When SEV is enabled in domcapabilities does that just mean any of SEV, > > SEV-ES, SEV-SNP is possible on the hardware? > > No, only means

Re: SEV, SEV-ES, SEV-SNP

2023-08-29 Thread Erik Skultety
On Mon, Aug 28, 2023 at 02:10:42PM -0700, Derek Lee wrote: > When SEV is enabled in domcapabilities does that just mean any of SEV, > SEV-ES, SEV-SNP is possible on the hardware? No, only means that the CPU has 'sev' in the flags. On its own it doesn't say anything about the ES/SNP fe

SEV, SEV-ES, SEV-SNP

2023-08-28 Thread Derek Lee
When SEV is enabled in domcapabilities does that just mean any of SEV, SEV-ES, SEV-SNP is possible on the hardware? Similarly, does enabling SEV as a launchSecurity option in a domainXML mean that whichever SEV is available will be enabled? And if the guest policy has the ES flag set