-
Epic
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
Instrument INF file for DMAR support level
-
rhel-sst-virtualization-windows
-
ssg_virtualization
-
20
-
5
-
False
-
Description
Currently virtio-win drivers do not declare any kind of compatibility with DMAR.
For futher compatibility with Windows "Device Guard" feature they should declare one of 3 possible levels: Not compatible (0), Fully compatible (1), Compatible when Driver Verifier /DMA verifier is enabled(2). When nothing is declared, according to MSFT means "Let the system determine", which seems dangerous.
virtio-fs device is currently not compatible with DMAR
the rest of virtio devices are compatible (assuming IOMMU is present and iommu_platform=on,ats=on)
Some of built-in devices in Windows declare "1" (always), some declare "2" (when Driver Verifier enabled)
Currently we can recommend "2"