[edk2-devel] [PATCH] OvmfPkg/OvmfPkgX64: Use different CcProbeLib when SMM is on or off

Min Xu posted 1 patch 1 year, 11 months ago
Failed in applying to current master (apply log)
OvmfPkg/OvmfPkgX64.dsc | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
[edk2-devel] [PATCH] OvmfPkg/OvmfPkgX64: Use different CcProbeLib when SMM is on or off
Posted by Min Xu 1 year, 11 months ago
CcProbeLib is designed to check the vm guest type. The OvmfPkg/CcProbeLib
reads the OvmfWorkArea (0x80B000) to get the vm guest type which is
written by each guest (SEV or TDX guest). But in SMM drivers the access
to OvmfWorkArea is illegal. PiSmmCpuDxeSmm.inf is an example. It uses
IoLib which in OvmfPkgX64 BaseIoLibIntrinsicSev.inf is included. The
IoLib probes if the working guest is td guest by calling CcProbe().

So CcProbeLibNull will be included when SMM_REQUIRE is set. Currently
only TDVF uses CcProbe to check the guest type, and TDVF doesn't
support SMM, so this fix has no side-effect.

Cc: dann frazier <dann.frazier@canonical.com>
Cc: Erdem Aktas <erdemaktas@google.com>
Cc: James Bottomley <jejb@linux.ibm.com>
Cc: Jiewen Yao <jiewen.yao@intel.com>
Cc: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Min Xu <min.m.xu@intel.com>
---
 OvmfPkg/OvmfPkgX64.dsc | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/OvmfPkg/OvmfPkgX64.dsc b/OvmfPkg/OvmfPkgX64.dsc
index 71526bba31..db7f4def7a 100644
--- a/OvmfPkg/OvmfPkgX64.dsc
+++ b/OvmfPkg/OvmfPkgX64.dsc
@@ -171,7 +171,6 @@
   PciCapLib|OvmfPkg/Library/BasePciCapLib/BasePciCapLib.inf
   PciCapPciSegmentLib|OvmfPkg/Library/BasePciCapPciSegmentLib/BasePciCapPciSegmentLib.inf
   PciCapPciIoLib|OvmfPkg/Library/UefiPciCapPciIoLib/UefiPciCapPciIoLib.inf
-  CcProbeLib|OvmfPkg/Library/CcProbeLib/CcProbeLib.inf
   IoLib|MdePkg/Library/BaseIoLibIntrinsic/BaseIoLibIntrinsicSev.inf
   OemHookStatusCodeLib|MdeModulePkg/Library/OemHookStatusCodeLibNull/OemHookStatusCodeLibNull.inf
   SerialPortLib|PcAtChipsetPkg/Library/SerialIoLib/SerialIoLib.inf
@@ -198,6 +197,9 @@
 
 !if $(SMM_REQUIRE) == FALSE
   LockBoxLib|OvmfPkg/Library/LockBoxLib/LockBoxBaseLib.inf
+  CcProbeLib|OvmfPkg/Library/CcProbeLib/CcProbeLib.inf
+!else
+  CcProbeLib|MdePkg/Library/CcProbeLibNull/CcProbeLibNull.inf
 !endif
   CustomizedDisplayLib|MdeModulePkg/Library/CustomizedDisplayLib/CustomizedDisplayLib.inf
   FrameBufferBltLib|MdeModulePkg/Library/FrameBufferBltLib/FrameBufferBltLib.inf
-- 
2.29.2.windows.2



-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#89818): https://edk2.groups.io/g/devel/message/89818
Mute This Topic: https://groups.io/mt/91162384/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-
Re: [edk2-devel] [PATCH] OvmfPkg/OvmfPkgX64: Use different CcProbeLib when SMM is on or off
Posted by dann frazier 1 year, 11 months ago
On Tue, May 17, 2022 at 08:43:14PM +0800, Min Xu wrote:
> CcProbeLib is designed to check the vm guest type. The OvmfPkg/CcProbeLib
> reads the OvmfWorkArea (0x80B000) to get the vm guest type which is
> written by each guest (SEV or TDX guest). But in SMM drivers the access
> to OvmfWorkArea is illegal. PiSmmCpuDxeSmm.inf is an example. It uses
> IoLib which in OvmfPkgX64 BaseIoLibIntrinsicSev.inf is included. The
> IoLib probes if the working guest is td guest by calling CcProbe().
> 
> So CcProbeLibNull will be included when SMM_REQUIRE is set. Currently
> only TDVF uses CcProbe to check the guest type, and TDVF doesn't
> support SMM, so this fix has no side-effect.

This is confirmed to fix the issue I reported, thanks!

Tested-by: dann frazier <dann.frazier@canonical.com>

  -dann

> Cc: dann frazier <dann.frazier@canonical.com>
> Cc: Erdem Aktas <erdemaktas@google.com>
> Cc: James Bottomley <jejb@linux.ibm.com>
> Cc: Jiewen Yao <jiewen.yao@intel.com>
> Cc: Tom Lendacky <thomas.lendacky@amd.com>
> Signed-off-by: Min Xu <min.m.xu@intel.com>
> ---
>  OvmfPkg/OvmfPkgX64.dsc | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)
> 
> diff --git a/OvmfPkg/OvmfPkgX64.dsc b/OvmfPkg/OvmfPkgX64.dsc
> index 71526bba31..db7f4def7a 100644
> --- a/OvmfPkg/OvmfPkgX64.dsc
> +++ b/OvmfPkg/OvmfPkgX64.dsc
> @@ -171,7 +171,6 @@
>    PciCapLib|OvmfPkg/Library/BasePciCapLib/BasePciCapLib.inf
>    PciCapPciSegmentLib|OvmfPkg/Library/BasePciCapPciSegmentLib/BasePciCapPciSegmentLib.inf
>    PciCapPciIoLib|OvmfPkg/Library/UefiPciCapPciIoLib/UefiPciCapPciIoLib.inf
> -  CcProbeLib|OvmfPkg/Library/CcProbeLib/CcProbeLib.inf
>    IoLib|MdePkg/Library/BaseIoLibIntrinsic/BaseIoLibIntrinsicSev.inf
>    OemHookStatusCodeLib|MdeModulePkg/Library/OemHookStatusCodeLibNull/OemHookStatusCodeLibNull.inf
>    SerialPortLib|PcAtChipsetPkg/Library/SerialIoLib/SerialIoLib.inf
> @@ -198,6 +197,9 @@
>  
>  !if $(SMM_REQUIRE) == FALSE
>    LockBoxLib|OvmfPkg/Library/LockBoxLib/LockBoxBaseLib.inf
> +  CcProbeLib|OvmfPkg/Library/CcProbeLib/CcProbeLib.inf
> +!else
> +  CcProbeLib|MdePkg/Library/CcProbeLibNull/CcProbeLibNull.inf
>  !endif
>    CustomizedDisplayLib|MdeModulePkg/Library/CustomizedDisplayLib/CustomizedDisplayLib.inf
>    FrameBufferBltLib|MdeModulePkg/Library/FrameBufferBltLib/FrameBufferBltLib.inf


-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#89829): https://edk2.groups.io/g/devel/message/89829
Mute This Topic: https://groups.io/mt/91162384/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-
Re: [edk2-devel] [PATCH] OvmfPkg/OvmfPkgX64: Use different CcProbeLib when SMM is on or off
Posted by Yao, Jiewen 1 year, 11 months ago
Question: Does this patch need catch release 202205 release?



> -----Original Message-----
> From: Xu, Min M <min.m.xu@intel.com>
> Sent: Tuesday, May 17, 2022 8:43 PM
> To: devel@edk2.groups.io
> Cc: Xu, Min M <min.m.xu@intel.com>; dann frazier
> <dann.frazier@canonical.com>; Aktas, Erdem <erdemaktas@google.com>;
> James Bottomley <jejb@linux.ibm.com>; Yao, Jiewen <jiewen.yao@intel.com>;
> Tom Lendacky <thomas.lendacky@amd.com>
> Subject: [PATCH] OvmfPkg/OvmfPkgX64: Use different CcProbeLib when SMM is
> on or off
> 
> CcProbeLib is designed to check the vm guest type. The OvmfPkg/CcProbeLib
> reads the OvmfWorkArea (0x80B000) to get the vm guest type which is
> written by each guest (SEV or TDX guest). But in SMM drivers the access
> to OvmfWorkArea is illegal. PiSmmCpuDxeSmm.inf is an example. It uses
> IoLib which in OvmfPkgX64 BaseIoLibIntrinsicSev.inf is included. The
> IoLib probes if the working guest is td guest by calling CcProbe().
> 
> So CcProbeLibNull will be included when SMM_REQUIRE is set. Currently
> only TDVF uses CcProbe to check the guest type, and TDVF doesn't
> support SMM, so this fix has no side-effect.
> 
> Cc: dann frazier <dann.frazier@canonical.com>
> Cc: Erdem Aktas <erdemaktas@google.com>
> Cc: James Bottomley <jejb@linux.ibm.com>
> Cc: Jiewen Yao <jiewen.yao@intel.com>
> Cc: Tom Lendacky <thomas.lendacky@amd.com>
> Signed-off-by: Min Xu <min.m.xu@intel.com>
> ---
>  OvmfPkg/OvmfPkgX64.dsc | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)
> 
> diff --git a/OvmfPkg/OvmfPkgX64.dsc b/OvmfPkg/OvmfPkgX64.dsc
> index 71526bba31..db7f4def7a 100644
> --- a/OvmfPkg/OvmfPkgX64.dsc
> +++ b/OvmfPkg/OvmfPkgX64.dsc
> @@ -171,7 +171,6 @@
>    PciCapLib|OvmfPkg/Library/BasePciCapLib/BasePciCapLib.inf
> 
> PciCapPciSegmentLib|OvmfPkg/Library/BasePciCapPciSegmentLib/BasePciCapP
> ciSegmentLib.inf
>    PciCapPciIoLib|OvmfPkg/Library/UefiPciCapPciIoLib/UefiPciCapPciIoLib.inf
> -  CcProbeLib|OvmfPkg/Library/CcProbeLib/CcProbeLib.inf
>    IoLib|MdePkg/Library/BaseIoLibIntrinsic/BaseIoLibIntrinsicSev.inf
> 
> OemHookStatusCodeLib|MdeModulePkg/Library/OemHookStatusCodeLibNull/
> OemHookStatusCodeLibNull.inf
>    SerialPortLib|PcAtChipsetPkg/Library/SerialIoLib/SerialIoLib.inf
> @@ -198,6 +197,9 @@
> 
>  !if $(SMM_REQUIRE) == FALSE
>    LockBoxLib|OvmfPkg/Library/LockBoxLib/LockBoxBaseLib.inf
> +  CcProbeLib|OvmfPkg/Library/CcProbeLib/CcProbeLib.inf
> +!else
> +  CcProbeLib|MdePkg/Library/CcProbeLibNull/CcProbeLibNull.inf
>  !endif
> 
> CustomizedDisplayLib|MdeModulePkg/Library/CustomizedDisplayLib/Customize
> dDisplayLib.inf
> 
> FrameBufferBltLib|MdeModulePkg/Library/FrameBufferBltLib/FrameBufferBltLi
> b.inf
> --
> 2.29.2.windows.2



-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#89819): https://edk2.groups.io/g/devel/message/89819
Mute This Topic: https://groups.io/mt/91162384/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-
Re: [edk2-devel] [PATCH] OvmfPkg/OvmfPkgX64: Use different CcProbeLib when SMM is on or off
Posted by dann frazier 1 year, 11 months ago
On Tue, May 17, 2022 at 12:47:21PM +0000, Yao, Jiewen wrote:
> Question: Does this patch need catch release 202205 release?

It does fix a regression since 202202, so I'd hope so :)

  -dann

> 
> 
> > -----Original Message-----
> > From: Xu, Min M <min.m.xu@intel.com>
> > Sent: Tuesday, May 17, 2022 8:43 PM
> > To: devel@edk2.groups.io
> > Cc: Xu, Min M <min.m.xu@intel.com>; dann frazier
> > <dann.frazier@canonical.com>; Aktas, Erdem <erdemaktas@google.com>;
> > James Bottomley <jejb@linux.ibm.com>; Yao, Jiewen <jiewen.yao@intel.com>;
> > Tom Lendacky <thomas.lendacky@amd.com>
> > Subject: [PATCH] OvmfPkg/OvmfPkgX64: Use different CcProbeLib when SMM is
> > on or off
> > 
> > CcProbeLib is designed to check the vm guest type. The OvmfPkg/CcProbeLib
> > reads the OvmfWorkArea (0x80B000) to get the vm guest type which is
> > written by each guest (SEV or TDX guest). But in SMM drivers the access
> > to OvmfWorkArea is illegal. PiSmmCpuDxeSmm.inf is an example. It uses
> > IoLib which in OvmfPkgX64 BaseIoLibIntrinsicSev.inf is included. The
> > IoLib probes if the working guest is td guest by calling CcProbe().
> > 
> > So CcProbeLibNull will be included when SMM_REQUIRE is set. Currently
> > only TDVF uses CcProbe to check the guest type, and TDVF doesn't
> > support SMM, so this fix has no side-effect.
> > 
> > Cc: dann frazier <dann.frazier@canonical.com>
> > Cc: Erdem Aktas <erdemaktas@google.com>
> > Cc: James Bottomley <jejb@linux.ibm.com>
> > Cc: Jiewen Yao <jiewen.yao@intel.com>
> > Cc: Tom Lendacky <thomas.lendacky@amd.com>
> > Signed-off-by: Min Xu <min.m.xu@intel.com>
> > ---
> >  OvmfPkg/OvmfPkgX64.dsc | 4 +++-
> >  1 file changed, 3 insertions(+), 1 deletion(-)
> > 
> > diff --git a/OvmfPkg/OvmfPkgX64.dsc b/OvmfPkg/OvmfPkgX64.dsc
> > index 71526bba31..db7f4def7a 100644
> > --- a/OvmfPkg/OvmfPkgX64.dsc
> > +++ b/OvmfPkg/OvmfPkgX64.dsc
> > @@ -171,7 +171,6 @@
> >    PciCapLib|OvmfPkg/Library/BasePciCapLib/BasePciCapLib.inf
> > 
> > PciCapPciSegmentLib|OvmfPkg/Library/BasePciCapPciSegmentLib/BasePciCapP
> > ciSegmentLib.inf
> >    PciCapPciIoLib|OvmfPkg/Library/UefiPciCapPciIoLib/UefiPciCapPciIoLib.inf
> > -  CcProbeLib|OvmfPkg/Library/CcProbeLib/CcProbeLib.inf
> >    IoLib|MdePkg/Library/BaseIoLibIntrinsic/BaseIoLibIntrinsicSev.inf
> > 
> > OemHookStatusCodeLib|MdeModulePkg/Library/OemHookStatusCodeLibNull/
> > OemHookStatusCodeLibNull.inf
> >    SerialPortLib|PcAtChipsetPkg/Library/SerialIoLib/SerialIoLib.inf
> > @@ -198,6 +197,9 @@
> > 
> >  !if $(SMM_REQUIRE) == FALSE
> >    LockBoxLib|OvmfPkg/Library/LockBoxLib/LockBoxBaseLib.inf
> > +  CcProbeLib|OvmfPkg/Library/CcProbeLib/CcProbeLib.inf
> > +!else
> > +  CcProbeLib|MdePkg/Library/CcProbeLibNull/CcProbeLibNull.inf
> >  !endif
> > 
> > CustomizedDisplayLib|MdeModulePkg/Library/CustomizedDisplayLib/Customize
> > dDisplayLib.inf
> > 
> > FrameBufferBltLib|MdeModulePkg/Library/FrameBufferBltLib/FrameBufferBltLi
> > b.inf
> 


-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#89830): https://edk2.groups.io/g/devel/message/89830
Mute This Topic: https://groups.io/mt/91162384/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-
Re: [edk2-devel] [PATCH] OvmfPkg/OvmfPkgX64: Use different CcProbeLib when SMM is on or off
Posted by Yao, Jiewen 1 year, 11 months ago
Thanks.
Acked-by: Jiewen Yao <Jiewen.yao@intel.com>

Hi Min
Please follow hard free process to proceed.

Reviewed-by: Jiewen Yao <Jiewen.yao@intel.com>



> -----Original Message-----
> From: devel@edk2.groups.io <devel@edk2.groups.io> On Behalf Of dann frazier
> Sent: Tuesday, May 17, 2022 11:22 PM
> To: Yao, Jiewen <jiewen.yao@intel.com>
> Cc: Xu, Min M <min.m.xu@intel.com>; devel@edk2.groups.io; Aktas, Erdem
> <erdemaktas@google.com>; James Bottomley <jejb@linux.ibm.com>; Tom
> Lendacky <thomas.lendacky@amd.com>
> Subject: Re: [edk2-devel] [PATCH] OvmfPkg/OvmfPkgX64: Use different
> CcProbeLib when SMM is on or off
> 
> On Tue, May 17, 2022 at 12:47:21PM +0000, Yao, Jiewen wrote:
> > Question: Does this patch need catch release 202205 release?
> 
> It does fix a regression since 202202, so I'd hope so :)
> 
>   -dann
> 
> >
> >
> > > -----Original Message-----
> > > From: Xu, Min M <min.m.xu@intel.com>
> > > Sent: Tuesday, May 17, 2022 8:43 PM
> > > To: devel@edk2.groups.io
> > > Cc: Xu, Min M <min.m.xu@intel.com>; dann frazier
> > > <dann.frazier@canonical.com>; Aktas, Erdem <erdemaktas@google.com>;
> > > James Bottomley <jejb@linux.ibm.com>; Yao, Jiewen
> <jiewen.yao@intel.com>;
> > > Tom Lendacky <thomas.lendacky@amd.com>
> > > Subject: [PATCH] OvmfPkg/OvmfPkgX64: Use different CcProbeLib when
> SMM is
> > > on or off
> > >
> > > CcProbeLib is designed to check the vm guest type. The OvmfPkg/CcProbeLib
> > > reads the OvmfWorkArea (0x80B000) to get the vm guest type which is
> > > written by each guest (SEV or TDX guest). But in SMM drivers the access
> > > to OvmfWorkArea is illegal. PiSmmCpuDxeSmm.inf is an example. It uses
> > > IoLib which in OvmfPkgX64 BaseIoLibIntrinsicSev.inf is included. The
> > > IoLib probes if the working guest is td guest by calling CcProbe().
> > >
> > > So CcProbeLibNull will be included when SMM_REQUIRE is set. Currently
> > > only TDVF uses CcProbe to check the guest type, and TDVF doesn't
> > > support SMM, so this fix has no side-effect.
> > >
> > > Cc: dann frazier <dann.frazier@canonical.com>
> > > Cc: Erdem Aktas <erdemaktas@google.com>
> > > Cc: James Bottomley <jejb@linux.ibm.com>
> > > Cc: Jiewen Yao <jiewen.yao@intel.com>
> > > Cc: Tom Lendacky <thomas.lendacky@amd.com>
> > > Signed-off-by: Min Xu <min.m.xu@intel.com>
> > > ---
> > >  OvmfPkg/OvmfPkgX64.dsc | 4 +++-
> > >  1 file changed, 3 insertions(+), 1 deletion(-)
> > >
> > > diff --git a/OvmfPkg/OvmfPkgX64.dsc b/OvmfPkg/OvmfPkgX64.dsc
> > > index 71526bba31..db7f4def7a 100644
> > > --- a/OvmfPkg/OvmfPkgX64.dsc
> > > +++ b/OvmfPkg/OvmfPkgX64.dsc
> > > @@ -171,7 +171,6 @@
> > >    PciCapLib|OvmfPkg/Library/BasePciCapLib/BasePciCapLib.inf
> > >
> > >
> PciCapPciSegmentLib|OvmfPkg/Library/BasePciCapPciSegmentLib/BasePciCapP
> > > ciSegmentLib.inf
> > >    PciCapPciIoLib|OvmfPkg/Library/UefiPciCapPciIoLib/UefiPciCapPciIoLib.inf
> > > -  CcProbeLib|OvmfPkg/Library/CcProbeLib/CcProbeLib.inf
> > >    IoLib|MdePkg/Library/BaseIoLibIntrinsic/BaseIoLibIntrinsicSev.inf
> > >
> > >
> OemHookStatusCodeLib|MdeModulePkg/Library/OemHookStatusCodeLibNull/
> > > OemHookStatusCodeLibNull.inf
> > >    SerialPortLib|PcAtChipsetPkg/Library/SerialIoLib/SerialIoLib.inf
> > > @@ -198,6 +197,9 @@
> > >
> > >  !if $(SMM_REQUIRE) == FALSE
> > >    LockBoxLib|OvmfPkg/Library/LockBoxLib/LockBoxBaseLib.inf
> > > +  CcProbeLib|OvmfPkg/Library/CcProbeLib/CcProbeLib.inf
> > > +!else
> > > +  CcProbeLib|MdePkg/Library/CcProbeLibNull/CcProbeLibNull.inf
> > >  !endif
> > >
> > >
> CustomizedDisplayLib|MdeModulePkg/Library/CustomizedDisplayLib/Customize
> > > dDisplayLib.inf
> > >
> > >
> FrameBufferBltLib|MdeModulePkg/Library/FrameBufferBltLib/FrameBufferBltLi
> > > b.inf
> >
> 
> 
> 
> 



-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#89831): https://edk2.groups.io/g/devel/message/89831
Mute This Topic: https://groups.io/mt/91162384/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-