From nobody Mon Feb 9 08:57:47 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) client-ip=66.175.222.108; envelope-from=bounce+27952+80888+1787277+3901457@groups.io; helo=mail02.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+80888+1787277+3901457@groups.io; arc=fail (BodyHash is different from the expected one); dmarc=pass(p=none dis=none) header.from=groups.io Received: from mail02.groups.io (mail02.groups.io [66.175.222.108]) by mx.zohomail.com with SMTPS id 1632163586041594.1285853760004; Mon, 20 Sep 2021 11:46:26 -0700 (PDT) Return-Path: X-Received: by 127.0.0.2 with SMTP id 2xQjYY1788612xWCx3NSzC5z; Mon, 20 Sep 2021 11:46:25 -0700 X-Received: from NAM11-BN8-obe.outbound.protection.outlook.com (NAM11-BN8-obe.outbound.protection.outlook.com [40.107.236.41]) by mx.groups.io with SMTP id smtpd.web10.1352.1632163583824013575 for ; Mon, 20 Sep 2021 11:46:25 -0700 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=esfLKsDMJdIWBloUiFv5iWQRIcwRphkOzYkEOsJ6SU/7ikvw0Qz3L6SIwyvuuWvL5WqScgP0SQiRy56vHZ3mKxQtE1m+63qlDbM/a3u0tEeFWGYSFbkkdHTserHKI5W1+spnHhqLGBOPKHo9GI/C6Ad4eecObdqzfDSCeYL0anb08pOGMD7XGqUX6VIMWG78PCaeb2b7s+oS1rWNG6N2WHu8fPaBYoF8+fXZCI9fU6YsrComeo+o1HKAgEYbiFNw2g9u5m2wK41jvJiToC7AYzgjLZ5ukIBepru865CJgIlWF979Ohx19IaBCKF98R0Wd+OUtYNIGzIwGoc/RoN8Fw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=RjX4QwqJ3SayVpz7MDBM88sb6iJhTUHLTXxJ6MOb8KI=; b=iW2mkqfBTajcpyTFNVI8gZSVvfHSjZlrv0mN7e/OTIhGUN+MFNgW5M8Lne2x2LgNNpwguFibwSucGHoLsJ7f9+/dRKayrroFqiiTLd0Pib8Fl/inOaBuUptDmf+vIYTNOaJKdtCTUZP77xz+vxoDTOoCMtNpSm1LtgiIFxKXJ1rB41nm0DaMbDx2xbUcCTTq4schCLs9YOgtbDFCoyUNPKMXpvQxjK2d1QynB2VeZJPii8OQ1pDfesLDUPCyRSR/YeH8/+nD03rKjSG3mWZD8t4eYVBgmuG0e+/helsSg/i7faf3ghKxC97ab+/ftmCSXyEhRxxe/6uyw4Niagy5hw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none X-Received: from SN6PR12MB2718.namprd12.prod.outlook.com (2603:10b6:805:6f::22) by SA0PR12MB4512.namprd12.prod.outlook.com (2603:10b6:806:71::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4523.14; Mon, 20 Sep 2021 18:46:22 +0000 X-Received: from SN6PR12MB2718.namprd12.prod.outlook.com ([fe80::78b7:7336:d363:9be3]) by SN6PR12MB2718.namprd12.prod.outlook.com ([fe80::78b7:7336:d363:9be3%6]) with mapi id 15.20.4523.018; Mon, 20 Sep 2021 18:46:22 +0000 From: "Brijesh Singh via groups.io" To: devel@edk2.groups.io CC: James Bottomley , Min Xu , Jiewen Yao , Tom Lendacky , Jordan Justen , Ard Biesheuvel , Erdem Aktas , Michael Roth , Gerd Hoffmann , Brijesh Singh , Michael Roth Subject: [edk2-devel] [PATCH v8 04/32] OvmfPkg/ResetVector: introduce metadata descriptor for VMM use Date: Mon, 20 Sep 2021 13:45:36 -0500 Message-ID: <20210920184604.31590-5-brijesh.singh@amd.com> In-Reply-To: <20210920184604.31590-1-brijesh.singh@amd.com> References: <20210920184604.31590-1-brijesh.singh@amd.com> X-ClientProxiedBy: SN4PR0201CA0034.namprd02.prod.outlook.com (2603:10b6:803:2e::20) To SN6PR12MB2718.namprd12.prod.outlook.com (2603:10b6:805:6f::22) MIME-Version: 1.0 X-Received: from sbrijesh-desktop.amd.com (165.204.77.1) by SN4PR0201CA0034.namprd02.prod.outlook.com (2603:10b6:803:2e::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4523.14 via Frontend Transport; Mon, 20 Sep 2021 18:46:21 +0000 X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: ed861726-8379-426d-4053-08d97c66f0e4 X-MS-TrafficTypeDiagnostic: SA0PR12MB4512: X-MS-Exchange-Transport-Forked: True X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:5797; X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam-Message-Info: JER8rmGENtxi0cq2aNijivzTJhzE/spuDggfQc18Wlhs08rvVepo8Uh2gQCSvYgb+sXH6FC2J/PxxnLn+TPgUF+5efJIV0p19EMRQZd34hkcklDskiPVWGanbBV7fjWXpx4czagcPKc8qffn9JWnvyduqhlUZp5LErlmtpjIbIb1J2UesTF4ADbwk4rN0a9O0ePAPulQ8P8NcrwxexOK9AuQF247XUDAraFx0wcmyrxiZ5+qnF4JJI52wyhKZwDlw2GX1ysjcX1eU78TQkhHqjjIdU0AHzmxiXDA80ZcBpxH/dT1J/U1MUiA2S5nCUYbF9eTFUyVlFSbGsUl+1HKeAXHV5rUXu7tasSo/e2HS2GmnrGVI3da2QoujFdWdeLpmdUszAOXTstXZLgeIH/9ocW2XW5ij/crzugKuSWDWTvMFQHeIVeBHtV918EJLMR80UZqgT7CcAEHenThI0eCZt9h/Itg2bvRvmGdCBgWua83f4v+TmYQZabnd1T5g89G22bGWZgICxH2B262RaYCrb+CD46A9Lb7Cy9DZfnHgeKk8kHF5fk8hyaZeMxm8MdRhLH8cuHdRix9pYP3bxm/UXXUejGkuHS/ubeiDVF5g32/LW+c7l0bVerATyUr+NjPwfS/RLkv4mm5X3Ei+bv9Ncdie1/Ll2wlmGhu9MbM8UsWNDbk2uEKILRSKn3LGyR/ZI+dNWvHGgYAccrj7qliLTtvjEeKHbgJi3dBN5vfbW7BH7mjrIyLIbiB9y+1t0TxVI0f7F2g4C7qie2R6UQ2rw== X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?zi+Uw2LjpXiVgwBNNGV40aTCCsk4jHBUDl5g1HieFFdaGar+QAVBWuiy4L1e?= =?us-ascii?Q?FHyT1OODDZ7OxTSsu1/JCP+uzvhxaAxye5w5TwSKDEwQZ/mtOxjOJDOTR4ow?= =?us-ascii?Q?2ni/eIszFlNBDlIMkKs6QMVMnOZmgsMBo5SbyY7kmqTq/qs7M+mA4N4viQmd?= =?us-ascii?Q?wtktyAgpkPShJ9GDgcZaM5zW/HNj0a+uwqPbWVlSmSFRH/WQQCJX0XP9xorY?= =?us-ascii?Q?kpWzfKapAcuTM5vtkp5JXqZavVXizTFXzWLv9+AtARrMDwOnJPhLK+PlqxTK?= =?us-ascii?Q?OtjcmqV9mQSQQ8sVVPsoSblXEEallycR3dMMg91Is/4yaWQMA/wrS4u7/by9?= =?us-ascii?Q?HSEnvPvRIOW6Z8yasw99gWVaIwS371FAXAhVFx2Ng/Fkt3jdkIfzVNdAMcCx?= =?us-ascii?Q?3s8C4S77hhX+a5ZpHhgjQoD3FVeMLvnd4q0gFdiKPA23sJ1mcSVvGZEG8yNV?= =?us-ascii?Q?XuIniE8HN/Vnt2/8/RpddsmzseQc8U+VxlS/L/5du4Xi/K/7fTlHuO1h164r?= =?us-ascii?Q?kIqcoca7V9Aki3C9cSwAVMnp9M/eewGBSWztktK+lEL8Cb1I4qPcaYIZMAiT?= =?us-ascii?Q?j+KTRdjY4Twuq81hhhvlycn7R317oLSpVJXdumFwxKryaPhuhGkjd154dDW0?= =?us-ascii?Q?9SidkdFXUGcEvs5DxiX646XlGZltxVlwLDWLYyVbz4DxCSWU8JpOgXzTuFqv?= =?us-ascii?Q?InnQsBomRL8lm+Vq9mDx7biYjfWNVl3aIBM4PPkXkH49vyAgwKTMcEt2BsOP?= =?us-ascii?Q?0ghQ7nCSD6veulVT5kLNck3FtnYKwk1bcQolJsJAvVJG2quHT4ezYX9a9l1c?= =?us-ascii?Q?WrRR9rKVxzq9L2Nrlh058c9Bkevc/UGdwJI5RWuiFD9BG6KuXTQrp+Kh8Gqa?= =?us-ascii?Q?8g3b4gqP9vuCcA9of+64PpITCWwzDzQpedZIObt5VMB0KfSWRQT/2F5qfb87?= =?us-ascii?Q?EiNGpVDKDA91r5pgX79HN61H0r8kYp+Gb91dW1TjnnSC9PkRCte2zdXE98h8?= =?us-ascii?Q?1JeA3yelOkLCk0Ym2mztgPPJ3/u0CScu+L27PEGtM5t9XqYoZEj20Imupqc+?= =?us-ascii?Q?R85CJYRL/FtHGs//be7wYECBOYA+Et3avfrYkYZJJg8vGtdBTx4jSw0dXOMg?= =?us-ascii?Q?M0OOyBxW0+qQHfRsayS2NlBteKwvLbmU2y/PnsXfSK6zhRuw9eoimI4W1wEW?= =?us-ascii?Q?dk/xH4M17CzvoNvNKDJc8owUtG4riOQrE8N8v07CB3cKF8t1YcBYt8B8TiRF?= =?us-ascii?Q?hVO6+PSVbOU+qZPN+rWB5D7ivJC4BGa2ThnxY9YhHqFuLIP3dc6HvPYtUGTa?= =?us-ascii?Q?5GLuSLYTYuNG5eAfxvKSobm7?= X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: ed861726-8379-426d-4053-08d97c66f0e4 X-MS-Exchange-CrossTenant-AuthSource: SN6PR12MB2718.namprd12.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Sep 2021 18:46:22.1393 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: zO7BulgH7ZHlbFXUhcKeBxULYftvq/Ei0zEjOQNl7KfBFAwnv9aPy3l/y6L0Rv0L18RF3dZmt2qLjN5aD8nrgw== X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA0PR12MB4512 Precedence: Bulk List-Unsubscribe: List-Subscribe: List-Help: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,brijesh.singh@amd.com X-Gm-Message-State: vJLWGSWja4NdCiT0DgP7Yydgx1787277AA= Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1632163585; bh=7v6QPE3l4D8N+S7J4KBh6106FSKRv4f+zt/oOHVFnDA=; h=CC:Content-Type:Date:From:Reply-To:Subject:To; b=EKf8tsUyBFOBlhFFe6SNDe1YhGbwrMXyNvQyXFymip5E3pGzjIJOMOx8Cq5D0qO786V WcEdMSCz+P9q8wGe+1PHBT17EgpkIVNyjg3RSYMmqRmzzttFBB8+rk9NMFqGo8W1aOCGt aPvqLqXPjcp0CxA1DLjW67y1+gHRJSu3YK4= X-ZohoMail-DKIM: pass (identity @groups.io) X-ZM-MESSAGEID: 1632163588066100021 Content-Type: text/plain; charset="utf-8" BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=3D3275 The OvmfPkgX86 build reserves memory regions in MEMFD. The memory regions get accessed in the SEC phase. Both Intel TDX and AMD SEV-SNP require that the guest's private memory be accepted or validated before access. Introduce a Guided metadata structure that describes the reserved memory regions. The VMM can locate the metadata structure by iterating through the reset vector guid and process the areas based on the platform specific requirements. Min Xu introduced the metadata structure conceptin the TDX patch series [1]. [1] https://www.mail-archive.com/devel@edk2.groups.io/msg33605.html Cc: Michael Roth Cc: James Bottomley Cc: Min Xu Cc: Jiewen Yao Cc: Tom Lendacky Cc: Jordan Justen Cc: Ard Biesheuvel Cc: Erdem Aktas Cc: Gerd Hoffmann Suggested-by: Gerd Hoffmann Signed-off-by: Brijesh Singh --- OvmfPkg/ResetVector/Ia16/ResetVectorVtf0.asm | 17 ++++++++ OvmfPkg/ResetVector/ResetVector.nasmb | 1 + OvmfPkg/ResetVector/X64/OvmfMetadata.asm | 45 ++++++++++++++++++++ 3 files changed, 63 insertions(+) create mode 100644 OvmfPkg/ResetVector/X64/OvmfMetadata.asm diff --git a/OvmfPkg/ResetVector/Ia16/ResetVectorVtf0.asm b/OvmfPkg/ResetVe= ctor/Ia16/ResetVectorVtf0.asm index 7ec3c6e980c3..f0e509d0672e 100644 --- a/OvmfPkg/ResetVector/Ia16/ResetVectorVtf0.asm +++ b/OvmfPkg/ResetVector/Ia16/ResetVectorVtf0.asm @@ -47,6 +47,23 @@ TIMES (15 - ((guidedStructureEnd - guidedStructureStart = + 15) % 16)) DB 0 ; guidedStructureStart: =20 +%ifdef ARCH_X64 +; +; OVMF metadata descriptor for the TDX and SEV-SNP +; +; Provide the start offset of the metadata blob within the OVMF binary. + +; GUID : e47a6535-984a-4798-865e-4685a7bf8ec2 +; +OvmfMetadataOffsetStart: + DD (fourGigabytes - OvmfMetadataGuid - 16) + DW OvmfMetadataOffsetEnd - OvmfMetadataOffsetStart + DB 0x35, 0x65, 0x7a, 0xe4, 0x4a, 0x98, 0x98, 0x47 + DB 0x86, 0x5e, 0x46, 0x85, 0xa7, 0xbf, 0x8e, 0xc2 +OvmfMetadataOffsetEnd: + +%endif + ; SEV Hash Table Block ; ; This describes the guest ram area where the hypervisor should diff --git a/OvmfPkg/ResetVector/ResetVector.nasmb b/OvmfPkg/ResetVector/Re= setVector.nasmb index d1d800c56745..bc61b1d05a24 100644 --- a/OvmfPkg/ResetVector/ResetVector.nasmb +++ b/OvmfPkg/ResetVector/ResetVector.nasmb @@ -80,6 +80,7 @@ %include "Ia32/Flat32ToFlat64.asm" %include "Ia32/AmdSev.asm" %include "Ia32/PageTables64.asm" +%include "X64/OvmfMetadata.asm" %endif =20 %include "Ia16/Real16ToFlat32.asm" diff --git a/OvmfPkg/ResetVector/X64/OvmfMetadata.asm b/OvmfPkg/ResetVector= /X64/OvmfMetadata.asm new file mode 100644 index 000000000000..a1260a1ed029 --- /dev/null +++ b/OvmfPkg/ResetVector/X64/OvmfMetadata.asm @@ -0,0 +1,45 @@ +;-------------------------------------------------------------------------= ---- +; @file +; OVMF metadata for the confidential computing guests (TDX and SEV-SNP) +; +; Copyright (c) 2021, Intel Corporation. All rights reserved.
+; Copyright (c) 2021, AMD Inc. All rights reserved.
+; +; SPDX-License-Identifier: BSD-2-Clause-Patent +;-------------------------------------------------------------------------= ---- + +BITS 64 + +%define OVMF_METADATA_VERSION 1 + +%define OVMF_SECTION_TYPE_UNDEFINED 0 + +;The section contains the code +%define OVMF_SECTION_TYPE_CODE 0x100 + +; The section contains the varaibles +%define OVMF_SECTION_TYPE_VARS 0x101 + +; The section must be accepted or validated by the VMM before the boot +%define OVMF_SECTION_TYPE_SEC_MEM 0x102 + +ALIGN 16 + +TIMES (15 - ((OvmfGuidedStructureEnd - OvmfGuidedStructureStart + 15) % 16= )) DB 0 + +OvmfGuidedStructureStart: +; +; Ovmf metadata descriptor +; +OvmfMetadataGuid: + DB 0xf3, 0xf9, 0xea, 0xe9, 0x8e, 0x16, 0xd5, 0x44 + DB 0xa8, 0xeb, 0x7f, 0x4d, 0x87, 0x38, 0xf6, 0xae + +_Descriptor: + DB 'O','V','M','F' ; Signature + DD OvmfGuidedStructureEnd - _Descriptor ; Length + DD OVMF_METADATA_VERSION ; Version + DD (OvmfGuidedStructureEnd - _Descriptor - 16) / 12 ; Number of sections + +OvmfGuidedStructureEnd: + ALIGN 16 --=20 2.25.1 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#80888): https://edk2.groups.io/g/devel/message/80888 Mute This Topic: https://groups.io/mt/85749017/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-