From nobody Wed Oct 1 20:45:30 2025 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) smtp.mailfrom=bounce+27952+47646+1787277+3901457@groups.io; arc=fail (BodyHash is different from the expected one) Received: from web01.groups.io (web01.groups.io [66.175.222.12]) by mx.zohomail.com with SMTPS id 1568922765826320.7266970251834; Thu, 19 Sep 2019 12:52:45 -0700 (PDT) Return-Path: X-Received: by 127.0.0.2 with SMTP id bDgSYY1788612xCuS5ySdSQ5; Thu, 19 Sep 2019 12:52:45 -0700 X-Received: from NAM02-CY1-obe.outbound.protection.outlook.com (NAM02-CY1-obe.outbound.protection.outlook.com [40.107.76.70]) by groups.io with SMTP; Thu, 19 Sep 2019 12:52:45 -0700 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=icRzi7fkVN3lnrGzhoPK5lhYw0DytxqsVxo4rRgPH2l/B6NmvSa2H4aGZyNS0XnNjq34c8BKVYZrU723Ndj1K7JTtAiwNSgZljeeWhTtMDp3uJI+HClNMzmOm5s+Wo1lKpbb36aDrly84qU/6AIMpPmvcae137PFYIgl8I5KVGONg1IWqPhzSQ0rjdKjcpMnISrbPiMF5RN0JSMohXdnDAebFzljBUf5r7d0LLWMDtGMOCJCvgFXnVVNG/OWEBEIyxqqULgAOL247wFqSCPXvf3kMsTlqelN8WOHVqeBSP2Ps4LzhzjKfm8imB2k2sBIUS6Gs99fGvhR2n2f1YsxCw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Igq3h4zG4I52crtTqr+i3x9mev1jnumlgMYG+0qQxmM=; b=gqFw9TMYm4X83v6jgEZOhmDcLO7JKv2H9J38iZm+D51AMTYNxxVZ5cMu2aOXpP3JXrrt/vaL1HQt2XkMIxR3AojYzs8CaEC6hoUbkadWuqFNv82q3mjJCBkhxY4IdCne8Jvi0R2qyfLyG1ZlFwBTbDtiJvMSlFXSlGNBV1p0o328ywnDzIggqTgaIZNwpckCWfefn4sZ+M2xVHKoMKih7l6gv8BX98CA1LBNoAwqNhyhyiOBCblxrKFVxxaH4wQMnfRIv17Rwrq42P5TNSpZKovx1QNOwyNnZGNoh1rqkyE3EtF2ntfHoAzffcH2rTp4UTqROt5MggO4MBHr0p7udg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none X-Received: from DM6PR12MB3163.namprd12.prod.outlook.com (20.179.104.150) by DM6PR12MB3228.namprd12.prod.outlook.com (20.179.105.96) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2263.13; Thu, 19 Sep 2019 19:52:37 +0000 X-Received: from DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::400e:f0c3:7ca:2fcc]) by DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::400e:f0c3:7ca:2fcc%6]) with mapi id 15.20.2284.009; Thu, 19 Sep 2019 19:52:36 +0000 From: "Lendacky, Thomas" To: "devel@edk2.groups.io" CC: Jordan Justen , Laszlo Ersek , Ard Biesheuvel , Michael D Kinney , Liming Gao , Eric Dong , Ray Ni , "Singh, Brijesh" Subject: [edk2-devel] [RFC PATCH v2 11/44] OvmfPkg/PlatformPei: Move early GDT into ram when SEV-ES is enabled Thread-Topic: [RFC PATCH v2 11/44] OvmfPkg/PlatformPei: Move early GDT into ram when SEV-ES is enabled Thread-Index: AQHVbyPJn+3R7DBBt0GZRRCSMmsIBQ== Date: Thu, 19 Sep 2019 19:52:36 +0000 Message-ID: <457424fdcd5ba463dbbc198c1018cedd3857a9b7.1568922728.git.thomas.lendacky@amd.com> References: In-Reply-To: Accept-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-clientproxiedby: SN4PR0501CA0146.namprd05.prod.outlook.com (2603:10b6:803:2c::24) To DM6PR12MB3163.namprd12.prod.outlook.com (2603:10b6:5:182::22) x-ms-exchange-messagesentrepresentingtype: 1 x-originating-ip: [165.204.78.1] x-ms-publictraffictype: Email x-ms-office365-filtering-correlation-id: f0886c32-5b81-4bc3-2b39-08d73d3aeb96 x-ms-office365-filtering-ht: Tenant x-ms-traffictypediagnostic: DM6PR12MB3228: x-ms-exchange-purlcount: 1 x-ms-exchange-transport-forked: True x-microsoft-antispam-prvs: x-ms-oob-tlc-oobclassifiers: OLM:9508; Received-SPF: pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) client-ip=66.175.222.12; envelope-from=bounce+27952+47646+1787277+3901457@groups.io; helo=web01.groups.io; received-spf: None (protection.outlook.com: amd.com does not designate permitted sender hosts) x-ms-exchange-senderadcheck: 1 x-microsoft-antispam-message-info: VIzKiKHT/DOdRX1TaTXbTJech3xyzq8scNeeLtoth0Chjvsj2Ngvw/P3JEflr7yIKTRkm93t7dTtryQCiSn65XusFDmt9445Q4/NsWqYzadX9Y5SrhSx3i2U9SHWiTLtWLmRQOOPb/9i2jR9aVVJm+CieKJQAHIewEnITfsOjPiQzF0XSxHdpuQb1VNpuj+bGksOVxuz/kPX89kQpdjmEuYkZkQlgE/TtbEL2hYKRNzA8KhN7KEgsNJs+eg41vFWZJlsNe/S4sLt9Yeoi5CnOPdi2T+rF4fU73+uRZScCCrJtAh3msfI9AaO3CIHP9cKK+eoT7RMfJjjdz5rsNDiWIfSx+uBIY+asj1AST4ZLjaq+Hv9KhuaaNpV3X2qn6t42ieW4hAOIs+x5GRcfToe5vLo3DrOfz3kxfY2L5UsZA8= MIME-Version: 1.0 X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: f0886c32-5b81-4bc3-2b39-08d73d3aeb96 X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Sep 2019 19:52:36.8058 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: w9DqEP4eXv0SICPuW6Ic53Y0CPCqaQU8YrQqt48Lwuyn668MSOcixKrIQcg/uyZCjVW20UIZRP12i6CXdXZcWA== X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR12MB3228 Precedence: Bulk List-Unsubscribe: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,thomas.lendacky@amd.com X-Gm-Message-State: csI67v4yAw4sVZNAuyJsY7I6x1787277AA= Content-Language: en-US Content-ID: Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1568922765; bh=xcFgDjzpg2zgUIg8nhMcILdtKwr9kn5rUnNtkGtQmYM=; h=CC:Content-Type:Date:From:Reply-To:Subject:To; b=xXb5aTwC57ckpeGN9YYg33XzJWoTIMIs2pRl6LbJ30LMW3wJoiKo1INhOBJoFKhHis0 cVG0VcHq9iJvIgp0VwgEwVlXPbXfpbITMIa7FV0Y8ffGPS3MhA3V87T5n9zO3yRUVP/DZ p5j3r0823YdMX8BY1mQX6an8VmBeDbHSM/g= X-ZohoMail-DKIM: pass (identity @groups.io) Content-Type: text/plain; charset="utf-8" From: Tom Lendacky BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=3D2198 The SEV support will clear the C-bit from non-RAM areas. The early GDT lives in a non-RAM area, so when an exception occurs (like a #VC) the GDT will be read as un-encrypted even though it is encrypted. This will result in a failure to be able to handle the exception. Move the GDT into RAM so it can be accessed without error when running as an SEV-ES guest. Cc: Jordan Justen Cc: Laszlo Ersek Cc: Ard Biesheuvel Signed-off-by: Tom Lendacky Reviewed-by: Laszlo Ersek --- OvmfPkg/PlatformPei/AmdSev.c | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/OvmfPkg/PlatformPei/AmdSev.c b/OvmfPkg/PlatformPei/AmdSev.c index 699bb8b11557..d6733447bdf2 100644 --- a/OvmfPkg/PlatformPei/AmdSev.c +++ b/OvmfPkg/PlatformPei/AmdSev.c @@ -37,6 +37,8 @@ AmdSevEsInitialize ( PHYSICAL_ADDRESS GhcbBasePa; UINTN GhcbPageCount; RETURN_STATUS PcdStatus, DecryptStatus; + IA32_DESCRIPTOR Gdtr; + VOID *Gdt; =20 if (!MemEncryptSevEsIsEnabled ()) { return; @@ -72,6 +74,20 @@ AmdSevEsInitialize ( DEBUG ((DEBUG_INFO, "SEV-ES is enabled, %u GHCB pages allocated starting= at 0x%lx\n", GhcbPageCount, GhcbBase)); =20 AsmWriteMsr64 (MSR_SEV_ES_GHCB, (UINT64)GhcbBasePa); + + // + // The SEV support will clear the C-bit from the non-RAM areas. Since + // the GDT initially lives in that area and it will be read when a #VC + // exception happens, it needs to be moved to RAM for an SEV-ES guest. + // + AsmReadGdtr (&Gdtr); + + Gdt =3D AllocatePages (EFI_SIZE_TO_PAGES (Gdtr.Limit + 1)); + ASSERT (Gdt); + + CopyMem (Gdt, (VOID *) Gdtr.Base, Gdtr.Limit + 1); + Gdtr.Base =3D (UINTN) Gdt; + AsmWriteGdtr (&Gdtr); } =20 /** --=20 2.17.1 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#47646): https://edk2.groups.io/g/devel/message/47646 Mute This Topic: https://groups.io/mt/34203548/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-