Skip to content

fedora: CONFIG_CRYPTO_DEV_CCP_DD should be m

Since e67703d7 CONFIG_CRYPTO_DEV_CCP_DD moved from m to y, but this makes it practically impossible to update the SEV firmware without rebooting the machine, whereas if CCP is a module, simply unloading and re-loading the module would be enough to trigger an update, as documented at https://github.com/AMDESE/AMDSEV?tab=readme-ov-file#faq-8:

Since, on Linux, the firmware is updated on driver load of the ccp module, it is possible to update the firmware level after the system has booted. At this time, all guests would need to be shutdown and the kvm_amd module unloaded before the ccp module could be unloaded and reloaded.

@jwrdegoede can we move this back to m?

CC @osteffen