@@ -5707,6 +5707,12 @@
tdfx= [HW,DRM]
+ tdx_host= [X86-64, TDX]
+ Format: {on|off}
+ on: Enable TDX host kernel support
+ off: Disable TDX host kernel support
+ Default is off.
+
test_suspend= [SUSPEND][,N]
Specify "mem" (for Suspend-to-RAM) or "standby" (for
standby suspend) or "freeze" (for suspend type freeze)
@@ -115,6 +115,16 @@ static struct tdsysinfo_struct tdx_sysinfo;
/* TDX global KeyID to protect TDX metadata */
static u32 tdx_global_keyid;
+static bool enable_tdx_host;
+
+static int __init tdx_host_setup(char *s)
+{
+ if (!strcmp(s, "on"))
+ enable_tdx_host = true;
+ return 0;
+}
+__setup("tdx_host=", tdx_host_setup);
+
static bool __seamrr_enabled(void)
{
return (seamrr_mask & SEAMRR_ENABLED_BITS) == SEAMRR_ENABLED_BITS;
@@ -501,6 +511,10 @@ static int detect_p_seamldr(void)
static int __tdx_detect(void)
{
+ /* Disabled by kernel command line */
+ if (!enable_tdx_host)
+ goto no_tdx_module;
+
/*
* TDX module cannot be possibly loaded if SEAMRR is disabled.
* Also do not report TDX module as loaded if there's no enough
Enabling TDX consumes additional memory (used by TDX as metadata) and additional initialization time. Introduce a kernel command line to allow to opt-in TDX host kernel support when user truly wants to use TDX. Signed-off-by: Kai Huang <kai.huang@intel.com> --- Documentation/admin-guide/kernel-parameters.txt | 6 ++++++ arch/x86/virt/vmx/tdx.c | 14 ++++++++++++++ 2 files changed, 20 insertions(+)