+16
−0
Loading
Introduce a new command for KVM_MEMORY_ENCRYPT_OP ioctl that can be used to enable fetching of endorsement key certificates from userspace via the new KVM_EXIT_SNP_REQ_CERTS exit type. Also introduce a new KVM_X86_SEV_SNP_REQ_CERTS KVM device attribute so that userspace can query whether the kernel supports the new command/exit. Suggested-by:Sean Christopherson <seanjc@google.com> Reviewed-by:
Liam Merwick <liam.merwick@oracle.com> Tested-by:
Liam Merwick <liam.merwick@oracle.com> Signed-off-by:
Michael Roth <michael.roth@amd.com> Link: https://patch.msgid.link/20260109231732.1160759-3-michael.roth@amd.com Signed-off-by:
Sean Christopherson <seanjc@google.com>