From nobody Tue Nov 26 22:12:58 2024 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) smtp.mailfrom=bounce+27952+46111+1787277+3901457@groups.io; arc=fail (BodyHash is different from the expected one) Received: from web01.groups.io (web01.groups.io [66.175.222.12]) by mx.zohomail.com with SMTPS id 1566301168868759.589554132065; Tue, 20 Aug 2019 04:39:28 -0700 (PDT) Return-Path: X-Received: from NAM02-SN1-obe.outbound.protection.outlook.com (NAM02-SN1-obe.outbound.protection.outlook.com []) by groups.io with SMTP; Mon, 19 Aug 2019 14:35:58 -0700 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=K3G9P7LlUYm5KUME/FVyHQE7BeR0nE2Y116xDZmrOXE/PE0+iHYrYq7DI2pDfkydqutwmu0FD6+LINziskfsX0nYqBzdbKiY4cpwJjm6Qq+TNXYtYLfL3wfItt4cZATLprWVcBjrK2+S44StWYj6xW2Zzv7K1rXVpm/Dav3watzcWcyc7vykf1uJBE4NfGVh8QpsFQmC3Jq3bc4dXN59sy9dNfz63zpIk/2cSWuCyrQE0XVyeTwO8nZHeVTSLbZDgbgDFiBpyLhCT4ztuLnK4evTCWbpQE++k3mqpni5j4UOeWPtXn/91b+ImOCejrLC7e+h0vmM/RjeaGZ8LGimeA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=eBNu9cI2kiYnFdSGqYg51XXLaJpdHpfAO8W+UzHTCGU=; b=cjvusd8bpX8QthkDUWq9/UMvPF3OK/Qef6eoxQsIB52lOjXUKxe4TSd0HlHABIKT13Lg53yipjRjt8tuuKlq42p7yaD8My0ZbJ1+hBv1giXwhZYrCdguL1mb7lMNFQF4qyFqeSrTxBKDVl0Bs8i51vLwogYcyHeExim5sfq7klq1XTSme5ItwnhwGIGwuhvZRiFH19omg+Xz0m3f40bWjjYqvL7y1Z1eaqeEUwIPjB1giVTkz+HIovrEwTz/BCyt0KSw5aEicZNUuGsiOLZbvV4lsE3L0P/YCc6CLbsVcvchc9bOdwVcS6CTNmcP6yS6tKO+soDxHsnuXRNtXRliwQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none X-Received: from BYAPR12MB3158.namprd12.prod.outlook.com (20.179.92.19) by BYAPR12MB2965.namprd12.prod.outlook.com (20.178.52.214) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2178.18; Mon, 19 Aug 2019 21:35:55 +0000 X-Received: from BYAPR12MB3158.namprd12.prod.outlook.com ([fe80::39b9:76bd:a491:1f27]) by BYAPR12MB3158.namprd12.prod.outlook.com ([fe80::39b9:76bd:a491:1f27%6]) with mapi id 15.20.2157.022; Mon, 19 Aug 2019 21:35:55 +0000 From: "Lendacky, Thomas" To: "devel@edk2.groups.io" CC: Jordan Justen , Laszlo Ersek , Ard Biesheuvel , Michael D Kinney , Liming Gao , Eric Dong , Ray Ni , "Singh, Brijesh" Subject: [edk2-devel] [RFC PATCH 07/28] OvmfPkg/PlatformPei: Move early GDT into ram when SEV-ES is enabled Thread-Topic: [RFC PATCH 07/28] OvmfPkg/PlatformPei: Move early GDT into ram when SEV-ES is enabled Thread-Index: AQHVVtYVQwjttoEikE67yaNazZWrMg== Date: Mon, 19 Aug 2019 21:35:55 +0000 Message-ID: <79bac50e4cea5e261c694a2b875cc2eff32bea68.1566250534.git.thomas.lendacky@amd.com> References: In-Reply-To: Accept-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-clientproxiedby: SN2PR01CA0031.prod.exchangelabs.com (2603:10b6:804:2::41) To BYAPR12MB3158.namprd12.prod.outlook.com (2603:10b6:a03:132::19) x-ms-exchange-messagesentrepresentingtype: 1 x-originating-ip: [165.204.77.1] x-ms-publictraffictype: Email x-ms-office365-filtering-correlation-id: 2fa6bec7-4dd2-485d-8469-08d724ed378b x-ms-office365-filtering-ht: Tenant x-ms-traffictypediagnostic: BYAPR12MB2965: x-ms-exchange-transport-forked: True x-microsoft-antispam-prvs: x-ms-oob-tlc-oobclassifiers: OLM:9508; Received-SPF: pass (zoho.com: domain of groups.io designates 66.175.222.12 as permitted sender) client-ip=66.175.222.12; envelope-from=bounce+27952+46111+1787277+3901457@groups.io; helo=web01.groups.io; received-spf: None (protection.outlook.com: amd.com does not designate permitted sender hosts) x-ms-exchange-senderadcheck: 1 x-microsoft-antispam-message-info: S6j5gbIClAaa9R+2hfXO3+Xq+dMhl1bOmCuwunthFkpDwljI2rjPLiBbYqzYrauy9cwkzyXE7465YA18SxGqbhkBN1M6A1VNE+5vQRSFcaFMeGW3jO7UVe7VwvjGURmE3w3Jy7gfxHWlaYPzfAqtGzA2+dks9ka8f8m9kzdzEjR0l8QD0xFgf+nmU7chShBA7mTllyQt3K8g9Q2tO1KYyN+howwMOQj274Waae1qaw1NL44O1stUibc68gt5U3pBVs2HaKNbbOVh+Unx/gwpqWv5LmhR/INVwjDk9Za4MgIogfJF2m9YR0tD5x0sKTI2j54czvp/93BAe700rNRDI0GdThfKlOQUEnYi3K0aRjKTHYrHFbPRA5KEWGTcDlo0yVRwEJdrwotOnqSnqFulJnD4hWgtLyCUwqOC1w0Qczw= MIME-Version: 1.0 X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: 2fa6bec7-4dd2-485d-8469-08d724ed378b X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Aug 2019 21:35:55.6442 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: ovF80LpqZYXHYtYcIdrmsmfuln5gMo3mRenC2R0KZwSz1XhvPNOfQcJ6DFXwPt/I478V5UaKntsBT8Kvof8ROQ== X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR12MB2965 Precedence: Bulk List-Unsubscribe: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,thomas.lendacky@amd.com Content-Language: en-US Content-ID: Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1566301168; bh=J7EPc8/OTVse3s/hf7H5RK6MqOoNdCXXoBJcU0Xrr3I=; h=CC:Content-Type:Date:From:Reply-To:Subject:To; b=DNDTGphbD3yLa89XCm4SZ+5AUvE377q4C9xQU6Y2la6CjmH5gw9Fjw6/FaZVw7kKReb 1yqSQ5mgxwUsmfzpPwFWFMss1Q/cS28h1q2xxCy1hUCznRq0vN7odKfPcv2BUWt9L0KVO k3ZxX/oH/XX0XzC7qRqYUFdFM2mQvsyu4bM= X-ZohoMail-DKIM: pass (identity @groups.io) Content-Type: text/plain; charset="utf-8" From: Tom Lendacky The SEV support will clear the C-bit from non-RAM areas. The early GDT lives in a non-RAM area, so when an exception occurs (like a #VC) the GDT will be read as un-encrypted even though it is encrypted. This will result in a failure to be able to handle the exception. Move the GDT into RAM so it can be accessed without error when running as an SEV-ES guest. Signed-off-by: Tom Lendacky --- OvmfPkg/PlatformPei/AmdSev.c | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/OvmfPkg/PlatformPei/AmdSev.c b/OvmfPkg/PlatformPei/AmdSev.c index 87ac842a1590..5f4983fd36d8 100644 --- a/OvmfPkg/PlatformPei/AmdSev.c +++ b/OvmfPkg/PlatformPei/AmdSev.c @@ -37,6 +37,8 @@ AmdSevEsInitialize ( PHYSICAL_ADDRESS GhcbBasePa; UINTN GhcbPageCount; RETURN_STATUS DecryptStatus, PcdStatus; + IA32_DESCRIPTOR Gdtr; + VOID *Gdt; =20 if (!MemEncryptSevEsIsEnabled ()) { return; @@ -76,6 +78,20 @@ AmdSevEsInitialize ( DEBUG ((DEBUG_INFO, "SEV-ES is enabled, %u GHCB pages allocated starting= at 0x%lx\n", GhcbPageCount, GhcbBase)); =20 AsmWriteMsr64 (MSR_SEV_ES_GHCB, (UINT64)GhcbBasePa); + + // + // The SEV support will clear the C-bit from the non-RAM areas. Since + // the GDT initially lives in that area and it will be read when a #VC + // exception happens, it needs to be moved to RAM for an SEV-ES guest. + // + AsmReadGdtr (&Gdtr); + + Gdt =3D AllocatePool (Gdtr.Limit + 1); + ASSERT (Gdt); + + CopyMem (Gdt, (VOID *) Gdtr.Base, Gdtr.Limit + 1); + Gdtr.Base =3D (UINTN) Gdt; + AsmWriteGdtr (&Gdtr); } =20 /** --=20 2.17.1 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#46111): https://edk2.groups.io/g/devel/message/46111 Mute This Topic: https://groups.io/mt/32966283/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-