[Qualcomm feedback] Chapter 6.1.1. Clarify when devices are in TCB of TVMs
rsahita opened this issue · 2 comments
rsahita commented
Reference: link
Table 1 in chapter 6
row for TVM <-> Directly assigned, TEE-IO compliant devices
There may also be non TEE-IO compliant devices assigned to a TVM (e.g. non-PCIe onchip devices).
rsahita commented
That is not the case - if a device is allowed to directly DMA from confidential memory (which is assigned to a TVM), it has to be a TEE-IO capable device (even for non-PCIe onchip devices) -- though the TEE-IO requirements for on-chip devices may be a lower bar (for e.g. no link encryption/integrity may be required)
rsahita commented
closing this one (explanation in the prev. comment). cc @ozkoyuncu