platform-system-interface / psi-spec

Platform System Interface Specification
Creative Commons Zero v1.0 Universal
2 stars 0 forks source link

IOMMU isolation #5

Open orangecms opened 2 years ago

orangecms commented 2 years ago

Raised by @demimarie:

Firmware should provide the ability to not turn on certain devices until the OS and/or hypervisor has brought up IOMMU, so that the OS/hypervisor can enforce isolation. A user should then be able to ensure that all devices are bounced through D3Cold during any reboot.

The purpose of this is to ensure that IOMMU isolation can actually work, even on devices that do not support DRTM or that have no way of verifying the attestations DRTM provides.

orangecms commented 10 months ago

see alco