xref: /openbmc/linux/arch/x86/kvm/Kconfig (revision f125e2d4)
1# SPDX-License-Identifier: GPL-2.0
2#
3# KVM configuration
4#
5
6source "virt/kvm/Kconfig"
7
8menuconfig VIRTUALIZATION
9	bool "Virtualization"
10	depends on HAVE_KVM || X86
11	default y
12	---help---
13	  Say Y here to get to see options for using your Linux host to run other
14	  operating systems inside virtual machines (guests).
15	  This option alone does not add any kernel code.
16
17	  If you say N, all options in this submenu will be skipped and disabled.
18
19if VIRTUALIZATION
20
21config KVM
22	tristate "Kernel-based Virtual Machine (KVM) support"
23	depends on HAVE_KVM
24	depends on HIGH_RES_TIMERS
25	# for TASKSTATS/TASK_DELAY_ACCT:
26	depends on NET && MULTIUSER
27	depends on X86_LOCAL_APIC
28	select PREEMPT_NOTIFIERS
29	select MMU_NOTIFIER
30	select HAVE_KVM_IRQCHIP
31	select HAVE_KVM_IRQFD
32	select IRQ_BYPASS_MANAGER
33	select HAVE_KVM_IRQ_BYPASS
34	select HAVE_KVM_IRQ_ROUTING
35	select HAVE_KVM_EVENTFD
36	select KVM_ASYNC_PF
37	select USER_RETURN_NOTIFIER
38	select KVM_MMIO
39	select TASKSTATS
40	select TASK_DELAY_ACCT
41	select PERF_EVENTS
42	select HAVE_KVM_MSI
43	select HAVE_KVM_CPU_RELAX_INTERCEPT
44	select HAVE_KVM_NO_POLL
45	select KVM_GENERIC_DIRTYLOG_READ_PROTECT
46	select KVM_VFIO
47	select SRCU
48	---help---
49	  Support hosting fully virtualized guest machines using hardware
50	  virtualization extensions.  You will need a fairly recent
51	  processor equipped with virtualization extensions. You will also
52	  need to select one or more of the processor modules below.
53
54	  This module provides access to the hardware capabilities through
55	  a character device node named /dev/kvm.
56
57	  To compile this as a module, choose M here: the module
58	  will be called kvm.
59
60	  If unsure, say N.
61
62config KVM_WERROR
63	bool "Compile KVM with -Werror"
64	# KASAN may cause the build to fail due to larger frames
65	default y if X86_64 && !KASAN
66	# We use the dependency on !COMPILE_TEST to not be enabled
67	# blindly in allmodconfig or allyesconfig configurations
68	depends on (X86_64 && !KASAN) || !COMPILE_TEST
69	depends on EXPERT
70	help
71	  Add -Werror to the build flags for (and only for) i915.ko.
72
73	  If in doubt, say "N".
74
75config KVM_INTEL
76	tristate "KVM for Intel (and compatible) processors support"
77	depends on KVM && IA32_FEAT_CTL
78	---help---
79	  Provides support for KVM on processors equipped with Intel's VT
80	  extensions, a.k.a. Virtual Machine Extensions (VMX).
81
82	  To compile this as a module, choose M here: the module
83	  will be called kvm-intel.
84
85config KVM_AMD
86	tristate "KVM for AMD processors support"
87	depends on KVM
88	---help---
89	  Provides support for KVM on AMD processors equipped with the AMD-V
90	  (SVM) extensions.
91
92	  To compile this as a module, choose M here: the module
93	  will be called kvm-amd.
94
95config KVM_AMD_SEV
96	def_bool y
97	bool "AMD Secure Encrypted Virtualization (SEV) support"
98	depends on KVM_AMD && X86_64
99	depends on CRYPTO_DEV_SP_PSP && !(KVM_AMD=y && CRYPTO_DEV_CCP_DD=m)
100	---help---
101	Provides support for launching Encrypted VMs on AMD processors.
102
103config KVM_MMU_AUDIT
104	bool "Audit KVM MMU"
105	depends on KVM && TRACEPOINTS
106	---help---
107	 This option adds a R/W kVM module parameter 'mmu_audit', which allows
108	 auditing of KVM MMU events at runtime.
109
110# OK, it's a little counter-intuitive to do this, but it puts it neatly under
111# the virtualization menu.
112source "drivers/vhost/Kconfig"
113
114endif # VIRTUALIZATION
115