On Fri, Aug 22, 2025, Tom Lendacky wrote: > @@ -1014,6 +1031,7 @@ void *snp_alloc_firmware_page(gfp_t mask); > void snp_free_firmware_page(void *addr); > void sev_platform_shutdown(void); > bool sev_is_snp_ciphertext_hiding_supported(void); > +u64 sev_get_snp_policy_bits(void); > > #else /* !CONFIG_CRYPTO_DEV_SP_PSP */ > > @@ -1052,6 +1070,8 @@ static inline void sev_platform_shutdown(void) { } > > static inline bool sev_is_snp_ciphertext_hiding_supported(void) { return false; } > > +static inline u64 sev_get_snp_policy_bits(void) { return 0; } I don't think you need a stub (the ciphertext hiding one should have been omitted too). arch/x86/kvm/svm/sev.c depends on CONFIG_KVM_AMD_SEV=y, which in turn depends on CRYPTO_DEV_SP_PSP=y, so nothing will ever actually need the stub. I bet the same holds true for the majority of these stubs.