From 1f65b4c41697b20d5efb3fa4282760f32e5546ae Mon Sep 17 00:00:00 2001 From: Vincent Haupert Date: Mon, 29 Nov 2021 08:03:26 +0100 Subject: [PATCH] linux: enable X86_SGX and X86_SGX_KVM on x86 Enable Intel Software Guard eXtensions (SGX) on x86 when using Linux 5.11.0 or later. Also enable KVM guests to create SGX enclaves if running Linux 5.13.0 or later. --- pkgs/os-specific/linux/kernel/common-config.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/os-specific/linux/kernel/common-config.nix b/pkgs/os-specific/linux/kernel/common-config.nix index 9ddb4ef38001..ebaec16d6d95 100644 --- a/pkgs/os-specific/linux/kernel/common-config.nix +++ b/pkgs/os-specific/linux/kernel/common-config.nix @@ -473,6 +473,11 @@ let # Detect buffer overflows on the stack CC_STACKPROTECTOR_REGULAR = {optional = true; tristate = whenOlder "4.18" "y";}; + } // optionalAttrs stdenv.hostPlatform.isx86 { + # Enable Intel SGX + X86_SGX = whenAtLeast "5.11" yes; + # Allow KVM guests to load SGX enclaves + X86_SGX_KVM = whenAtLeast "5.13" yes; }; microcode = {