From nobody Sat May 4 19:02:46 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) client-ip=66.175.222.108; envelope-from=bounce+27952+68298+1787277+3901457@groups.io; helo=mail02.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+68298+1787277+3901457@groups.io; arc=fail (BodyHash is different from the expected one); dmarc=fail(p=none dis=none) header.from=amd.com Received: from mail02.groups.io (mail02.groups.io [66.175.222.108]) by mx.zohomail.com with SMTPS id 1607040226240864.6710748120964; Thu, 3 Dec 2020 16:03:46 -0800 (PST) Return-Path: X-Received: by 127.0.0.2 with SMTP id UyJpYY1788612x1y6vPCavuF; Thu, 03 Dec 2020 16:03:45 -0800 X-Received: from NAM11-BN8-obe.outbound.protection.outlook.com (NAM11-BN8-obe.outbound.protection.outlook.com [40.107.236.82]) by mx.groups.io with SMTP id smtpd.web12.6554.1607040220312075004 for ; Thu, 03 Dec 2020 16:03:40 -0800 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=h4F0Fwh4arIvccpgOHOI+FcwLqocuEOa/Etwa3X9nOnuwx44+YQZpug1fz4wBZDGO3rOiYVqsOQjCQdKqcbJMztDoKRhECPzLenIOwrDoDVF9QvXaObLOkdo8VyW5XtKqg5kUAlqCXQPGhVcpD37hMZsQD6b5l0bwdHnWPAdNgNzaZSmOqor8lcfMwSM9tI6P1KdzGcmVWEZIHjnBRBljRz77cvmbTOJEVX/WYXNMnM76vLqjgXrPOF1Gs+tFzH+Fz4sIg5E9VzdsS0Va4HzuJF3gbDLufaonD5nM03ucuOVR5W9/KayWtZeFi/TJWes81UYPNmC5b4wkN84o6FbPQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=1t6oC4lZ57xjNaS6GKs/9SY1UpL5VsqK5gUKYx1x8Y8=; b=nNTHgYLW9LXGqGeo5SWFkGLE/aNXi3KUnowEtOIYmttIkAzjzbu7KiGYt/wFcJ4E9yuF2xrpfGgXq7hMd12mZN6O2BTWzCuMNMM4bz8lPi87oxSv6C9msdZkQ4og6wCT7V9rcuLuxu6A7f1vvuH5jfMzgABerkT2xX8BvaaZiMQ80/rQJIOypTaH/kSu3uS0lsvaIq7UiB+I9Nmu1Q6zv0LovBkejTvPjRMmQkqMCmR/pLmPnjdBpp8KchtEdPxYEZxvjMcLF/01hD5CjEXxhv1ZnlqPWUxfiI4dC88IvVBReZUA8ssdOcueok3w+CWi2gfkozFS/yFxIN7jIXLzJA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none X-Received: from SN6PR12MB2767.namprd12.prod.outlook.com (2603:10b6:805:75::23) by SN6PR12MB2783.namprd12.prod.outlook.com (2603:10b6:805:78::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3611.25; Fri, 4 Dec 2020 00:03:37 +0000 X-Received: from SN6PR12MB2767.namprd12.prod.outlook.com ([fe80::d8f2:fde4:5e1d:afec]) by SN6PR12MB2767.namprd12.prod.outlook.com ([fe80::d8f2:fde4:5e1d:afec%3]) with mapi id 15.20.3611.025; Fri, 4 Dec 2020 00:03:37 +0000 From: "Ashish Kalra" To: devel@edk2.groups.io Cc: dovmurik@linux.vnet.ibm.com, brijesh.singh@amd.com, tobin@ibm.com, Jon.Grimm@amd.com, Thomas.Lendacky@amd.com, jejb@linux.ibm.com, frankeh@us.ibm.com, dgilbert@redhat.com, lersek@redhat.com, jordan.l.justen@intel.com, ard.biesheuvel@arm.com Subject: [edk2-devel] [PATCH v3 1/3] OvmfPkg/MemEncryptHypercallLib: add library to support SEV hypercalls. Date: Fri, 4 Dec 2020 00:03:27 +0000 Message-Id: <5d84e29cb02eada513738fb4f0c54a6dfe35f416.1607038824.git.ashish.kalra@amd.com> In-Reply-To: References: X-Originating-IP: [165.204.77.1] X-ClientProxiedBy: SN4PR0501CA0031.namprd05.prod.outlook.com (2603:10b6:803:40::44) To SN6PR12MB2767.namprd12.prod.outlook.com (2603:10b6:805:75::23) MIME-Version: 1.0 X-MS-Exchange-MessageSentRepresentingType: 1 X-Received: from ashkalra_ubuntu_server.amd.com (165.204.77.1) by SN4PR0501CA0031.namprd05.prod.outlook.com (2603:10b6:803:40::44) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3654.7 via Frontend Transport; Fri, 4 Dec 2020 00:03:36 +0000 X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-HT: Tenant X-MS-Office365-Filtering-Correlation-Id: 0cdc504d-669e-4c8a-21ee-08d897e80c53 X-MS-TrafficTypeDiagnostic: SN6PR12MB2783: X-MS-Exchange-Transport-Forked: True X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:7691; X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam-Message-Info: PDy5MGXeRNlwlz0o+OOgK+NilzMvWuAjLeLWeUfigWYG4oNOdZTTp9G48wni2mmztUO9eJHaJ2VDKv1hAIEcuBoobon0nuYl5ooZy2ra24FuhWF+MZtHiqSjoCUHdRiGTXcw3fcaeKd+m19d6nTvYPzUgnegqmfquLp9l1c7+DXt9vVhfNU8+g91OqTR8yS6/LPxktr8QDVZOjtVCrw+UUw7qii/4XmQOSoxXpxwTbTYwspJfONuNNnBaxzoZrcAjSIg+kPzApBQ79en0SP2Rwwwyv7WQCKZujnl4FhjjMrf6GjXHbHAE4iepIA4z1jya/2assI+9tJhziySXV/r8A== X-MS-Exchange-AntiSpam-MessageData: =?us-ascii?Q?0J8to90XTGzTsCAeSLamUyhqdPa7pEgO0sy64pNiPduHSmEO/hdD1Gk0wLAj?= =?us-ascii?Q?HMT6G781vh2S66moBtdtd4mSLhlPd6PXHwC4UnyhoTUyImFNvDihLnosyPki?= =?us-ascii?Q?06wQcizPHL4WN86gj1X5nkjXbO2kuHGheGRgCz2OlCtzSogNPZX3iWRz8kIW?= =?us-ascii?Q?xpGvZymVHnag3VmPoX+HeXjXWZ+ihquaBtKQ+YBkw9Z5HiWENMzgoW/V2Xrk?= =?us-ascii?Q?ehiW/JVv7Z6yf1A/1pG1A/1mc0o5+kWbw8EtMuAdJcX6PUEadOYip9LdJ2FU?= =?us-ascii?Q?d9wP9k+sM1Jp0+6d+FsoDAgvyogMJPbD93yfVuB1qHstg0ypAgN1GsVy0OVo?= =?us-ascii?Q?z+PFFYx6g28vV8Y97+4G1WT2gd0aasvBWdsp+wyOIEfynzjySZXPrlED8pPf?= =?us-ascii?Q?G7aXJ0GDCt9buxWVLuMQKS/1Yu/bBGd7TDbL1yfREzuASmpdRK3ByrQcpLCX?= =?us-ascii?Q?KqPyHHHl/s7DDbnmrye9m+iZ3doyKjPXrW6Tdl9EXb5NK16abHO5kFt77M3x?= =?us-ascii?Q?PHtLTzacPv7kkguok6ucdbRV/mbtRmsKvAF014e/8ZvKwm67rGB8yvkqTtAN?= =?us-ascii?Q?PQQ2Le0Lf94ZXE6abciQ48bBPb5VSA/nXmSO9W82n0N5c2b8fwHPsgO9W9ej?= =?us-ascii?Q?IJWgMpHwSzB9agoVlP7ob+ltgf+GWn03B3Lsk9bbs6+cqjPGr8KR2Aq5v7d3?= =?us-ascii?Q?h38TcxDGs2Bk9ZoETkfGQ+7qnzIGs1Z2ohzT60+VC30zBZ3w9QNTxldADolT?= =?us-ascii?Q?b42fvvxN94J+jcb9Dkk8zIGZZNJWHLncxUDZ5i+S2xOQVmtKL7CwRBtATrAO?= =?us-ascii?Q?Ui/FDprVNK7+Ua5YcRb+fib7QsLThGLl8OSJt1SGvpND4T7PPrRIOTqCIFv/?= =?us-ascii?Q?Mag6I+jBuCYYcUe7tLoqSx8tG9QMTrEJAUhIDFImvf1XVnChuyINzVJOYvdZ?= =?us-ascii?Q?yQXMp4rV5WeWYBswHCZiaP1/U42IMovO4ic3Fcry5rs7XCjq9CVAGeiZFI9B?= =?us-ascii?Q?sd0H?= X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: 0cdc504d-669e-4c8a-21ee-08d897e80c53 X-MS-Exchange-CrossTenant-AuthSource: SN6PR12MB2767.namprd12.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Dec 2020 00:03:36.9585 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: QmalxMwPPg3kkcLaUqG9rSqFIDVrsqcVde0KK8CELiPgQiMZmQGSjpWDgY+FOKfeZLmr9qe1+JBhB+4xk1R8fg== X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN6PR12MB2783 Precedence: Bulk List-Unsubscribe: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,ashish.kalra@amd.com X-Gm-Message-State: tlvYIcu7HMQrTPag4jNmhRiJx1787277AA= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1607040225; bh=X+XDyk7/ZFTxXSAZUtJ0fxeNhF1R+YmSltQFeVlgn/U=; h=Cc:Content-Type:Date:From:Reply-To:Subject:To; b=mZlE1pTBd7nkzJFcHf0XBW37qHtPztw8m1o9g2KLtDZIPg231UEO7QRI+D9jTQGfcr1 sipnS4wCmiVKprRExlgEUlemxrEmDVdSPbfTIvM8Mpukqgwd8XQAK3snr2C3THpoy5h01 2hcfzJAUDLPGvpOG9SLIi7TNeJCIlnB2p6U= X-ZohoMail-DKIM: pass (identity @groups.io) Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ashish Kalra Add SEV and SEV-ES hypercall abstraction library to support SEV Page encryption/deceryption status hypercalls for SEV and SEV-ES guests. Cc: Jordan Justen Cc: Laszlo Ersek Cc: Ard Biesheuvel Signed-off-by: Ashish Kalra --- OvmfPkg/Include/Library/MemEncryptHypercallLib.h | 37 ++= +++++ OvmfPkg/Library/MemEncryptHypercallLib/MemEncryptHypercallLib.c | 105 ++= ++++++++++++++++++ OvmfPkg/Library/MemEncryptHypercallLib/MemEncryptHypercallLib.inf | 39 ++= ++++++ OvmfPkg/Library/MemEncryptHypercallLib/X64/AsmHelperStub.nasm | 39 ++= ++++++ OvmfPkg/OvmfPkgX64.dsc | 1 + 5 files changed, 221 insertions(+) diff --git a/OvmfPkg/Include/Library/MemEncryptHypercallLib.h b/OvmfPkg/Inc= lude/Library/MemEncryptHypercallLib.h new file mode 100644 index 0000000000..cd46a7f2b3 --- /dev/null +++ b/OvmfPkg/Include/Library/MemEncryptHypercallLib.h @@ -0,0 +1,37 @@ +/** @file + + Define Secure Encrypted Virtualization (SEV) hypercall library. + + Copyright (c) 2020, AMD Incorporated. All rights reserved.
+ + SPDX-License-Identifier: BSD-2-Clause-Patent + +**/ + +#ifndef _MEM_ENCRYPT_HYPERCALL_LIB_H_ +#define _MEM_ENCRYPT_HYPERCALL_LIB_H_ + +#include + +#define SEV_PAGE_ENC_HYPERCALL 12 + +/** + This hyercall is used to notify hypervisor when a page is marked as + 'decrypted' (i.e C-bit removed). + + @param[in] PhysicalAddress The physical address that is the start= address + of a memory region. + @param[in] Length The length of memory region + @param[in] Mode SetCBit or ClearCBit + +**/ + +VOID +EFIAPI +SetMemoryEncDecHypercall3 ( + IN UINTN PhysicalAddress, + IN UINTN Length, + IN UINTN Mode + ); + +#endif diff --git a/OvmfPkg/Library/MemEncryptHypercallLib/MemEncryptHypercallLib.= c b/OvmfPkg/Library/MemEncryptHypercallLib/MemEncryptHypercallLib.c new file mode 100644 index 0000000000..f1136b7d36 --- /dev/null +++ b/OvmfPkg/Library/MemEncryptHypercallLib/MemEncryptHypercallLib.c @@ -0,0 +1,105 @@ +/** @file + + Secure Encrypted Virtualization (SEV) hypercall helper library + + Copyright (c) 2020, AMD Incorporated. All rights reserved.
+ + SPDX-License-Identifier: BSD-2-Clause-Patent + +**/ + +#include +#include +#include +#include +#include +#include +#include +#include +#include + +// +// Interface exposed by the ASM implementation of the core hypercall +// +// + +VOID +EFIAPI +SetMemoryEncDecHypercall3AsmStub ( + IN UINTN HypercallNum, + IN UINTN PhysicalAddress, + IN UINTN Length, + IN UINTN Mode + ); + +/** + This function returns the current CPU privilege level, implemented + in ASM helper stub. + +**/ + +UINT8 +EFIAPI +GetCurrentCpuPrivilegeLevel ( + VOID + ); + +STATIC +VOID +GhcbSetRegValid ( + IN OUT GHCB *Ghcb, + IN GHCB_REGISTER Reg + ) +{ + UINT32 RegIndex; + UINT32 RegBit; + + RegIndex =3D Reg / 8; + RegBit =3D Reg & 0x07; + + Ghcb->SaveArea.ValidBitmap[RegIndex] |=3D (1 << RegBit); +} + +VOID +EFIAPI +SetMemoryEncDecHypercall3 ( + IN PHYSICAL_ADDRESS PhysicalAddress, + IN UINTN Pages, + IN UINTN Mode + ) +{ + if (MemEncryptSevEsIsEnabled ()) { + MSR_SEV_ES_GHCB_REGISTER Msr; + GHCB *Ghcb; + BOOLEAN InterruptState; + UINT64 Status; + + Msr.GhcbPhysicalAddress =3D AsmReadMsr64 (MSR_SEV_ES_GHCB); + Ghcb =3D Msr.Ghcb; + + VmgInit (Ghcb, &InterruptState); + + Ghcb->SaveArea.Rax =3D SEV_PAGE_ENC_HYPERCALL; + GhcbSetRegValid (Ghcb, GhcbRax); + Ghcb->SaveArea.Rbx =3D PhysicalAddress; + GhcbSetRegValid (Ghcb, GhcbRbx); + Ghcb->SaveArea.Rcx =3D Pages; + GhcbSetRegValid (Ghcb, GhcbRcx); + Ghcb->SaveArea.Rdx =3D Mode; + GhcbSetRegValid (Ghcb, GhcbRdx); + Ghcb->SaveArea.Cpl =3D GetCurrentCpuPrivilegeLevel(); + GhcbSetRegValid (Ghcb, GhcbCpl); + + Status =3D VmgExit (Ghcb, SVM_EXIT_VMMCALL, 0, 0); + if (Status) { + DEBUG ((DEBUG_ERROR, "SVM_EXIT_VMMCALL failed %lx\n", Status)); + } + VmgDone (Ghcb, InterruptState); + } else { + SetMemoryEncDecHypercall3AsmStub ( + SEV_PAGE_ENC_HYPERCALL, + PhysicalAddress, + Pages, + Mode); + } +} diff --git a/OvmfPkg/Library/MemEncryptHypercallLib/MemEncryptHypercallLib.= inf b/OvmfPkg/Library/MemEncryptHypercallLib/MemEncryptHypercallLib.inf new file mode 100644 index 0000000000..1936fe5b37 --- /dev/null +++ b/OvmfPkg/Library/MemEncryptHypercallLib/MemEncryptHypercallLib.inf @@ -0,0 +1,39 @@ +## @file +# Library provides the hypervisor helper functions for SEV guest +# +# Copyright (c) 2020 Advanced Micro Devices. All rights reserved.
+# +# SPDX-License-Identifier: BSD-2-Clause-Patent +# +# +## + +[Defines] + INF_VERSION =3D 1.25 + BASE_NAME =3D MemEncryptHypercallLib + FILE_GUID =3D 86f2501e-f128-45f3-91c4-3cff31656ca8 + MODULE_TYPE =3D BASE + VERSION_STRING =3D 1.0 + LIBRARY_CLASS =3D MemEncryptHypercallLib|SEC PEI_CORE P= EIM DXE_DRIVER DXE_RUNTIME_DRIVER DXE_SMM_DRIVER UEFI_DRIVER + +# +# The following information is for reference only and not required by the = build +# tools. +# +# VALID_ARCHITECTURES =3D IA32 X64 +# + +[Packages] + MdeModulePkg/MdeModulePkg.dec + MdePkg/MdePkg.dec + UefiCpuPkg/UefiCpuPkg.dec + OvmfPkg/OvmfPkg.dec + +[Sources.X64] + MemEncryptHypercallLib.c + X64/AsmHelperStub.nasm + +[LibraryClasses] + BaseLib + DebugLib + VmgExitLib diff --git a/OvmfPkg/Library/MemEncryptHypercallLib/X64/AsmHelperStub.nasm = b/OvmfPkg/Library/MemEncryptHypercallLib/X64/AsmHelperStub.nasm new file mode 100644 index 0000000000..5d8a7aa85a --- /dev/null +++ b/OvmfPkg/Library/MemEncryptHypercallLib/X64/AsmHelperStub.nasm @@ -0,0 +1,39 @@ +DEFAULT REL +SECTION .text + +; VOID +; EFIAPI +; SetMemoryEncDecHypercall3AsmStub ( +; IN UINT HypercallNum, +; IN INTN Arg1, +; IN INTN Arg2, +; IN INTN Arg3 +; ); +global ASM_PFX(SetMemoryEncDecHypercall3AsmStub) +ASM_PFX(SetMemoryEncDecHypercall3AsmStub): + ; UEFI calling conventions require RBX to + ; be nonvolatile/callee-saved. + push rbx + ; Copy HypercallNumber to rax + mov rax, rcx + ; Copy Arg1 to the register expected by KVM + mov rbx, rdx + ; Copy Arg2 to register expected by KVM + mov rcx, r8 + ; Copy Arg2 to register expected by KVM + mov rdx, r9 + ; Call VMMCALL + vmmcall + pop rbx + ret + +; UINT8 +; EFIAPI +; GetCurrentCpuPrivilegeLevel ( +; VOID +; ); +global ASM_PFX(GetCurrentCpuPrivilegeLevel) +ASM_PFX(GetCurrentCpuPrivilegeLevel): + mov ax, cs + and al, 0x3 + ret diff --git a/OvmfPkg/OvmfPkgX64.dsc b/OvmfPkg/OvmfPkgX64.dsc index e59ae05b73..97c31c7586 100644 --- a/OvmfPkg/OvmfPkgX64.dsc +++ b/OvmfPkg/OvmfPkgX64.dsc @@ -174,6 +174,7 @@ VirtioLib|OvmfPkg/Library/VirtioLib/VirtioLib.inf LoadLinuxLib|OvmfPkg/Library/LoadLinuxLib/LoadLinuxLib.inf MemEncryptSevLib|OvmfPkg/Library/BaseMemEncryptSevLib/BaseMemEncryptSevL= ib.inf + MemEncryptHypercallLib|OvmfPkg/Library/MemEncryptHypercallLib/MemEncrypt= HypercallLib.inf !if $(SMM_REQUIRE) =3D=3D FALSE LockBoxLib|OvmfPkg/Library/LockBoxLib/LockBoxBaseLib.inf !endif --=20 2.17.1 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#68298): https://edk2.groups.io/g/devel/message/68298 Mute This Topic: https://groups.io/mt/78698838/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- From nobody Sat May 4 19:02:46 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) client-ip=66.175.222.108; envelope-from=bounce+27952+68299+1787277+3901457@groups.io; helo=mail02.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+68299+1787277+3901457@groups.io; arc=fail (BodyHash is different from the expected one); dmarc=fail(p=none dis=none) header.from=amd.com Received: from mail02.groups.io (mail02.groups.io [66.175.222.108]) by mx.zohomail.com with SMTPS id 1607040236827972.4910752921824; Thu, 3 Dec 2020 16:03:56 -0800 (PST) Return-Path: X-Received: by 127.0.0.2 with SMTP id xmlXYY1788612xcwPwaMQ3Ko; Thu, 03 Dec 2020 16:03:55 -0800 X-Received: from NAM04-SN1-obe.outbound.protection.outlook.com (NAM04-SN1-obe.outbound.protection.outlook.com [40.107.70.66]) by mx.groups.io with SMTP id smtpd.web10.6611.1607040234513862741 for ; Thu, 03 Dec 2020 16:03:54 -0800 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Cvr2ZxjOM/Z5dJhwR55FkvLUXy7Dp/K62R/+BsAmXgKQICffMeYn11sBc7u/k6cB6EcrxKkUJT+FjXhmvRroXKPGjSFqpVIKqoezQrV91b0K47ijhzisz0HD+pLT3zkwCL9sLjqKAy0J1/nZhtxSGwrheyjWwLLdal3blFXaHcsZHZxRCKAB369jgTkm3uTszaQ3xF8QHO9ALxEohETYUcuCCAQcExrCh1tvvneiOKfTRDaEJaBRMz3JBYqJdjP+wmg/GzMLHUH+Bs3/JbZ2IrR/gFpdev0m2iZyTMBlRKq1u2JMeJPF07DxVB81DW0OOpwGGLzd1viFUFCp+cXO+w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=p3E/A7M3DwEfsOb1I+VpU+KO/a7vwmEBAoBN+RmnkOU=; b=AbHI1Uov65awLLvifQlK7Jd+6PAy0+c2rEXCWhnOD46SMfj/OBqspyDkP2eNiRDj/hrA7f4lnMzXGAH5oQ99RcrZlbob/M/e0YjCMzPvdakPOyDZk/N698W4u93S5DNmcUzr/81D93JuXFwB7geDBRqLkZVPEsYjx/N802HR+u2S/CSJ/SUgMjEnLbLjE/EFFi8JOytRwJabxgwyacQHOApRcm73SMoSMVTe35qfyDeP8gFNsBFh6z1q+HPBuLidv7pjerX1qeyifc1qiVCGaZWd8XbZcWjDCYHbbb28UmN1jcOv+8vbeeQVJagf1FtKIJolLBDh9fXt/Wl2KmNi9w== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none X-Received: from SN6PR12MB2767.namprd12.prod.outlook.com (2603:10b6:805:75::23) by SN6PR12MB2783.namprd12.prod.outlook.com (2603:10b6:805:78::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3611.25; Fri, 4 Dec 2020 00:03:51 +0000 X-Received: from SN6PR12MB2767.namprd12.prod.outlook.com ([fe80::d8f2:fde4:5e1d:afec]) by SN6PR12MB2767.namprd12.prod.outlook.com ([fe80::d8f2:fde4:5e1d:afec%3]) with mapi id 15.20.3611.025; Fri, 4 Dec 2020 00:03:51 +0000 From: "Ashish Kalra" To: devel@edk2.groups.io Cc: dovmurik@linux.vnet.ibm.com, brijesh.singh@amd.com, tobin@ibm.com, Jon.Grimm@amd.com, Thomas.Lendacky@amd.com, jejb@linux.ibm.com, frankeh@us.ibm.com, dgilbert@redhat.com, lersek@redhat.com, jordan.l.justen@intel.com, ard.biesheuvel@arm.com Subject: [edk2-devel] [PATCH v3 2/3] OvmfPkg/BaseMemEncryptLib: Support to issue unencrypted hypercall Date: Fri, 4 Dec 2020 00:03:42 +0000 Message-Id: <2ebeb0332fa0a077e10fa93a50f9de7ef3029249.1607038824.git.ashish.kalra@amd.com> In-Reply-To: References: X-Originating-IP: [165.204.77.1] X-ClientProxiedBy: SN4PR0501CA0021.namprd05.prod.outlook.com (2603:10b6:803:40::34) To SN6PR12MB2767.namprd12.prod.outlook.com (2603:10b6:805:75::23) MIME-Version: 1.0 X-MS-Exchange-MessageSentRepresentingType: 1 X-Received: from ashkalra_ubuntu_server.amd.com (165.204.77.1) by SN4PR0501CA0021.namprd05.prod.outlook.com (2603:10b6:803:40::34) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3654.7 via Frontend Transport; Fri, 4 Dec 2020 00:03:50 +0000 X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-HT: Tenant X-MS-Office365-Filtering-Correlation-Id: de8b1334-4b70-40ea-20ba-08d897e814fd X-MS-TrafficTypeDiagnostic: SN6PR12MB2783: X-MS-Exchange-Transport-Forked: True X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:5236; X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam-Message-Info: 6xBwEqFyxEjmlvJ47QIA5hfm9rG0Kimlc0Lj4icWh5U8SYZLoXT9f3hd/XpuhaYOn+uMqozQV7pJmxDksXV2TVb+6XeICuxAtvDhDr5rcu1Wdl4hx5c2BHcSmdMPJ38FnAHnuRgk1pTmZA1mesZ8EYEaMMWyucwUcfZB9XSq6W3KevYtBw9zwa4uNxQghxcQvz1/GzTDUhXNqt0KK/SkFwM6OGwBlPs83gyo8L3+r3yb/R6KkBXoO6tfKG2Tm1xgqe9bcQslfkKg4NxO/6SsZV9OfzTbirfYlULfp4tLLwwQKqtrO6Qv8jETVBPc+3sDqCEz1Pr+t2Kr1RNg4pG+DA== X-MS-Exchange-AntiSpam-MessageData: =?us-ascii?Q?Gpi4WSyGHdRhivG+924C6H5UXm1Fhzgj4P5uYx1XkdRxC3br0RS8ndh3Aql+?= =?us-ascii?Q?ZcO7EENwXo2YGnoSzjDU8ClrHxMTFa+1Sx7vg9vxzCw0LB8wzTyydJDSmeI0?= =?us-ascii?Q?ZQ87ajdKwb40J0GY6GTxnMnEoz1ifXxDbfMvTyBiVV6Rg9aHL1bbkSholC3U?= =?us-ascii?Q?WWGp5mbQjrcVKpF7R9Ik7jC+BKdK1oDxQFxANgYz6uptfPtBIAPhQs562K9I?= =?us-ascii?Q?5s0ig2R2gQPlCavHcB+UL15b/TyHIS827OGHZhCSpZqKtXCUSV6Jm7cybb/l?= =?us-ascii?Q?DKc7iytyzn2zkBQ6mw1FQnKL0bO6VdtpUW798vsLEWv8YATWYF2KnMO9/iR0?= =?us-ascii?Q?DvWv0cys6AgFFMs/qLYiue/3AkTr9183/Js3o1rU3IuxAp63/VijcyEXJQBT?= =?us-ascii?Q?UNdYxhbIkEG9QLQ7O3vSHc4dYjxjnfXveWuZK8Gi9ED8eJouclow10iX4hIX?= =?us-ascii?Q?nGqV+kyZxrv9OPEc0cw5vlik/3hY7KYSmWGqCnklDqxlMD0mC3Qpjq7zr1Pl?= =?us-ascii?Q?bsH/9KHIXBVQqZ8Lw384IobyR1r8pE/6cU34+Boq2EajgLH1S3yJmG6rCc64?= =?us-ascii?Q?UEt2fDFOJY98fi+X5XIN2eOsHgnlqSINwXAOBvAEgZeimSwaqXbKYmL2PtIi?= =?us-ascii?Q?v8qnbeOebDiv45A/+UgoQBpQbAs9MJUu1qTGaGPvcVPfzbcyaGLxkURA7v0v?= =?us-ascii?Q?MVNpTJ91lerVIhvmjbLxH/o3qwvxanTCeU0imonqSXCEquK3u+8VnPuftR5k?= =?us-ascii?Q?fK/23flTd9e1AwEXsPRa2oDvsOZsvTPudW3C4/dIHc14dwHCNg2x6k++mgT3?= =?us-ascii?Q?0ouuP0gO6l+QeioEq9tAlpTjRf8fqjC210LMnR6ICVmGDfJWmohiQGaQPw9X?= =?us-ascii?Q?8g431zJLH8cCLXuRxg0McIls14+XmO+xzoptW2sDtD2c0SU2Qh+Ubb85KmDk?= =?us-ascii?Q?xa7tmwxJMYIX29h4lleo+eDwhEbaQ6TZKB5WWc0YJCQDpfsMv+PIlHm+2wgw?= =?us-ascii?Q?h583?= X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: de8b1334-4b70-40ea-20ba-08d897e814fd X-MS-Exchange-CrossTenant-AuthSource: SN6PR12MB2767.namprd12.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Dec 2020 00:03:51.4904 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: hd+fNPMNewkSc3Htrxh9JXW6ESojBSTN1u9lXKBUqrKoTWQD8g7W41RrSY749QJQf5fz6YsmMOmWYG0cXwIM9Q== X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN6PR12MB2783 Precedence: Bulk List-Unsubscribe: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,ashish.kalra@amd.com X-Gm-Message-State: 1RFC8YegbnSXiT5dML8CJRvfx1787277AA= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1607040235; bh=Fg6Tfx+yYCq8mqLLJnrs9Ry05zrKUWhV52iwI/PMNBg=; h=Cc:Content-Type:Date:From:Reply-To:Subject:To; b=Cep6swQ1uzHrNDgMYLN1/rkRHccWNEfb6zSiJGlrBMWjdNMmh75Rsx3Pk8CfwRE/l2+ JT92+42ZK9+KF3R4sJZS7ouW2StILoh6XiHEelIkQ2hAnxbChmzooh2fioqyRjv/7jN5/ 3WpwjtEhm7G5P6lC7GeQedBhv1CHkJXg2oM= X-ZohoMail-DKIM: pass (identity @groups.io) Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Brijesh Singh By default all the SEV guest memory regions are considered encrypted, if a guest changes the encryption attribute of the page (e.g mark a page as decrypted) then notify hypervisor. Hypervisor will need to track the unencrypted pages. The information will be used during guest live migration, guest page migration and guest debugging. Invoke hypercall via the new hypercall library. This hypercall is used to notify hypervisor when a page is marked as 'decrypted' (i.e C-bit removed). Cc: Jordan Justen Cc: Laszlo Ersek Cc: Ard Biesheuvel Signed-off-by: Brijesh Singh Signed-off-by: Ashish Kalra --- OvmfPkg/Library/BaseMemEncryptSevLib/BaseMemEncryptSevLib.inf | 1 + OvmfPkg/Library/BaseMemEncryptSevLib/X64/VirtualMemory.c | 18 +++++++= +++++++++++ 2 files changed, 19 insertions(+) diff --git a/OvmfPkg/Library/BaseMemEncryptSevLib/BaseMemEncryptSevLib.inf = b/OvmfPkg/Library/BaseMemEncryptSevLib/BaseMemEncryptSevLib.inf index 7c44d09528..95ee707918 100644 --- a/OvmfPkg/Library/BaseMemEncryptSevLib/BaseMemEncryptSevLib.inf +++ b/OvmfPkg/Library/BaseMemEncryptSevLib/BaseMemEncryptSevLib.inf @@ -46,6 +46,7 @@ DebugLib MemoryAllocationLib PcdLib + MemEncryptHypercallLib =20 [FeaturePcd] gUefiOvmfPkgTokenSpaceGuid.PcdSmmSmramRequire diff --git a/OvmfPkg/Library/BaseMemEncryptSevLib/X64/VirtualMemory.c b/Ovm= fPkg/Library/BaseMemEncryptSevLib/X64/VirtualMemory.c index 5e110c84ff..1e670b6200 100644 --- a/OvmfPkg/Library/BaseMemEncryptSevLib/X64/VirtualMemory.c +++ b/OvmfPkg/Library/BaseMemEncryptSevLib/X64/VirtualMemory.c @@ -14,6 +14,7 @@ #include #include #include +#include =20 #include "VirtualMemory.h" =20 @@ -589,6 +590,9 @@ SetMemoryEncDec ( UINT64 AddressEncMask; BOOLEAN IsWpEnabled; RETURN_STATUS Status; + UINTN Size; + BOOLEAN CBitChanged; + PHYSICAL_ADDRESS OrigPhysicalAddress; =20 // // Set PageMapLevel4Entry to suppress incorrect compiler/analyzer warnin= gs. @@ -640,6 +644,10 @@ SetMemoryEncDec ( =20 Status =3D EFI_SUCCESS; =20 + Size =3D Length; + CBitChanged =3D FALSE; + OrigPhysicalAddress =3D PhysicalAddress; + while (Length) { // @@ -699,6 +707,7 @@ SetMemoryEncDec ( )); PhysicalAddress +=3D BIT30; Length -=3D BIT30; + CBitChanged =3D TRUE; } else { // // We must split the page @@ -753,6 +762,7 @@ SetMemoryEncDec ( SetOrClearCBit (&PageDirectory2MEntry->Uint64, Mode); PhysicalAddress +=3D BIT21; Length -=3D BIT21; + CBitChanged =3D TRUE; } else { // // We must split up this page into 4K pages @@ -795,6 +805,7 @@ SetMemoryEncDec ( SetOrClearCBit (&PageTableEntry->Uint64, Mode); PhysicalAddress +=3D EFI_PAGE_SIZE; Length -=3D EFI_PAGE_SIZE; + CBitChanged =3D TRUE; } } } @@ -812,6 +823,13 @@ SetMemoryEncDec ( // CpuFlushTlb(); =20 + // + // Notify Hypervisor on C-bit status + // + if (CBitChanged) { + SetMemoryEncDecHypercall3 (OrigPhysicalAddress, EFI_SIZE_TO_PAGES(Size= ), !Mode); + } + Done: // // Restore page table write protection, if any. --=20 2.17.1 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#68299): https://edk2.groups.io/g/devel/message/68299 Mute This Topic: https://groups.io/mt/78698844/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- From nobody Sat May 4 19:02:46 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) client-ip=66.175.222.108; envelope-from=bounce+27952+68300+1787277+3901457@groups.io; helo=mail02.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+68300+1787277+3901457@groups.io; arc=fail (BodyHash is different from the expected one); dmarc=fail(p=none dis=none) header.from=amd.com Received: from mail02.groups.io (mail02.groups.io [66.175.222.108]) by mx.zohomail.com with SMTPS id 1607040256660200.17650615520017; Thu, 3 Dec 2020 16:04:16 -0800 (PST) Return-Path: X-Received: by 127.0.0.2 with SMTP id DBHRYY1788612xS5U1qOmZF7; Thu, 03 Dec 2020 16:04:16 -0800 X-Received: from NAM11-BN8-obe.outbound.protection.outlook.com (NAM11-BN8-obe.outbound.protection.outlook.com [40.107.236.79]) by mx.groups.io with SMTP id smtpd.web10.6617.1607040250767792302 for ; Thu, 03 Dec 2020 16:04:10 -0800 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=G9feCwzhmJ8zt5fkvkUkP6ltTLa5+uO83S+MYddpco7Td9I4D2MSj0XFEibjnKJuh+w+PvaZ6jqP+dibhpfCgt0zLm+GZn/4tZp95akowtiwpkUUE0QFC6G9/2dSN74Wka22uP2TVVkhn7UN/yXN0NG27PKvRXoGd9P9yeOJOVmuEq5UWPsviCr6r4TG9UkWo/+IJiltXBlu0be+sMPeM97F6oPcSBCk/ceN4zsWWImkvdwi5kNa+tfqiEHAYLfwQa8zDMI4qJTDqh9Hy/um0o/56ota79rGPwT8ddwDmTWvDUZVb5T8BtdNcttUCRxXlgWPZq8TUiqXCK9PRkUPVg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=9NrRjuDbk0gR894EdP5cVW8mfT1mrhqJ0Tz+jGFClXs=; b=CeNcRBZjeQt4WsWiXjLJVniBQWXRtt0LCvgEC9kJaUtri4YzwBiPvMPjfjGTFx4/aujbY0hetxdLr/2/Rtt/DuESLUVsfQV0cA5zSd1D4132XTDRBCmwrySzOfwzw7yul6M2KcGQje2lL5ttMMlh1OREnuKGQUyWLXYLEA7uYk5kigP3ucK0TUzUq397I1fUNndM0IMxBDtfQw3r9160o/ETxS10nNuFsgX9kcqJxI3/87/jNQXc8fldTGA76HtwkznvVSmM/pwz/BiHZikpIBhZBEwRElMs/puwBZMHvga6JM4MG8UkOtXRvjPbEx1d7QlArxXsrSSOE8KJkosQFg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none X-Received: from SN6PR12MB2767.namprd12.prod.outlook.com (2603:10b6:805:75::23) by SN6PR12MB2783.namprd12.prod.outlook.com (2603:10b6:805:78::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3611.25; Fri, 4 Dec 2020 00:04:06 +0000 X-Received: from SN6PR12MB2767.namprd12.prod.outlook.com ([fe80::d8f2:fde4:5e1d:afec]) by SN6PR12MB2767.namprd12.prod.outlook.com ([fe80::d8f2:fde4:5e1d:afec%3]) with mapi id 15.20.3611.025; Fri, 4 Dec 2020 00:04:06 +0000 From: "Ashish Kalra" To: devel@edk2.groups.io Cc: dovmurik@linux.vnet.ibm.com, brijesh.singh@amd.com, tobin@ibm.com, Jon.Grimm@amd.com, Thomas.Lendacky@amd.com, jejb@linux.ibm.com, frankeh@us.ibm.com, dgilbert@redhat.com, lersek@redhat.com, jordan.l.justen@intel.com, ard.biesheuvel@arm.com Subject: [edk2-devel] [PATCH v3 3/3] OvmfPkg/PlatformPei: Mark SEC GHCB page in the page encrpytion bitmap. Date: Fri, 4 Dec 2020 00:03:56 +0000 Message-Id: <1091f14cf79ab501485f247488d71380b5117dbe.1607038824.git.ashish.kalra@amd.com> In-Reply-To: References: X-Originating-IP: [165.204.77.1] X-ClientProxiedBy: SN4PR0401CA0035.namprd04.prod.outlook.com (2603:10b6:803:2a::21) To SN6PR12MB2767.namprd12.prod.outlook.com (2603:10b6:805:75::23) MIME-Version: 1.0 X-MS-Exchange-MessageSentRepresentingType: 1 X-Received: from ashkalra_ubuntu_server.amd.com (165.204.77.1) by SN4PR0401CA0035.namprd04.prod.outlook.com (2603:10b6:803:2a::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3632.17 via Frontend Transport; Fri, 4 Dec 2020 00:04:05 +0000 X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-HT: Tenant X-MS-Office365-Filtering-Correlation-Id: 10c97df5-cbb1-4152-bee8-08d897e81db7 X-MS-TrafficTypeDiagnostic: SN6PR12MB2783: X-MS-Exchange-Transport-Forked: True X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:6430; X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam-Message-Info: 0A8s1WkBGpEy/85HzQYmLUL4c4gc35bOVByxcQZwCNWPKi3lOmErOaxmUv0g5RvgyDMumWfARNYEIzmEYjrW+QTg6Wi3hl/ATXwxWHS96HHpiv4QScc7F3exfc1zpPiyyiDR/CvWNtLnMahWdVxdUqGSAN2q1PEM3V3/dpTcinDP5H59iqA9/InFGS502uWL+78b+QhWCcxD2l4UrLnnH9dJtUbhzkt+LJDljlW7mM1CJapXUHuLbBB8wyhFkZdrwdF3wIIWk6ETVuUVgHcjO6ayRO1F7VZeYTGlu2e8IM+fnWtUtiYS08vISIytR1wILZdVI266cym+4yLIjKKXzg== X-MS-Exchange-AntiSpam-MessageData: =?us-ascii?Q?gF134VJC4ANy6kZ/KB4U9QsRBcdtQpJJ5FNDnr6p/ZC4Gud0r2/myRtmQz8r?= =?us-ascii?Q?2+qI5BkRitpagOXm1Qq32OjQ0ZSQJtd/voUImN/h9GQq7P1qw370yobgqDgX?= =?us-ascii?Q?03kV9qAaZu+Ep78/1GLHTPypYlQG4Nc6uoHi7bTalUoCk098+Xhpb3zurE9+?= =?us-ascii?Q?CyjKJSx511Ynr9XhIFmKFb8l/rkF5LbgsRN7VA5FGmFAvQkpcBQz5UixIdQK?= =?us-ascii?Q?DkdKSwEfiB6BYcwXfnWZjMEDR6M4t06/HZx3SiFs84waInHzmwLwIUwy0tSV?= =?us-ascii?Q?yU3QR0nbNvDDP7N3iOMby5PVXxpF04q1GtAhjNk+XW7hOuuu9jpMbvkrRybm?= =?us-ascii?Q?B5KQnInshv/evbCh2dAzZxz8SE+ApMFR5SxLMSvrc9/bZMZycW8z/yzethIN?= =?us-ascii?Q?aHfYJmDEI2AphQQ9u6dxTzKRagL7GN47/+eWndjihd+RWpn0mOocsRZ/ONI4?= =?us-ascii?Q?6WsVisluiO5nfIn3bRa8ds9MUpRJSEmKr63uxYHN3jhHR8o7w+qXlgYTLpNr?= =?us-ascii?Q?QJgfyys85X0uxtKImJY0RCakKvHNo6iPm1+eid5vhGtKjUD8vRWWhuzeP12a?= =?us-ascii?Q?focqKFzlYE48vt2lnu6ogU8zfN/Kbb/TbpZfKTz5wOaaMH59i3isv4XQXLNZ?= =?us-ascii?Q?pNKiqL22Hs05KBnmixb/629c47uxAYAKeqo+AkYSaYqajmHKDpbY8gU+MxVw?= =?us-ascii?Q?JL0DNuLCu6eQad+b8u4WYkRgHhIL2HnmhbH5FafIwjXtmBF+juHoNY91oUDz?= =?us-ascii?Q?jNiwJNJYsx1Wj1s/Hhmk/imv6iJW4Ciczg1PazE7iCwgMJGOs/ikWLZaN5pP?= =?us-ascii?Q?7vwYNkIuUGAgHjhhMehZuwezt/6z/GftaGEFOTn1keT9JlOahb6hJwfaa1o5?= =?us-ascii?Q?09Wi/awKNeygvrEPH26DKOLKEV8wDCGBwz8rcbHLhx3KnoIsBDwKjAMwSrml?= =?us-ascii?Q?EdQOyysaecNcFXpNsQq7PR2q43g9ZaG/5KkciOhaPuuT2u9944f7Xlwk2VoT?= =?us-ascii?Q?mxtN?= X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: 10c97df5-cbb1-4152-bee8-08d897e81db7 X-MS-Exchange-CrossTenant-AuthSource: SN6PR12MB2767.namprd12.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Dec 2020 00:04:06.1042 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: Vp0O0AwJMhM6CJIDXYftBN3x10gnL2Ta1ChDwWGvL+mmxIO75bJ6s677wYdBDXXabUjV6/k5BGLrtSox9L1X7A== X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN6PR12MB2783 Precedence: Bulk List-Unsubscribe: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,ashish.kalra@amd.com X-Gm-Message-State: LjKhPJbDYc0Gz1scWKAkZErDx1787277AA= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1607040256; bh=JnIcfAoFStjQszKfL9KVjOhE5vn9qxby66i7Dtq+HHs=; h=Cc:Content-Type:Date:From:Reply-To:Subject:To; b=cBhxJhFSU8lPTSXgT2OaynxevaqZxbvv3qwVUPYIljduPIcYPJsDDTPiKKMZNspWR5k HB+YFbGMihSosNMhf+AZWlKNrklo+eBlmjPb2yrvu8YvSafd/vh5ew8xZplOUtBdZEChA gsv2B579JbzbL73A/i4hR/RcPWt+oERPiAk= X-ZohoMail-DKIM: pass (identity @groups.io) Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ashish Kalra Mark the SEC GHCB page that is mapped as unencrypted in ResetVector code in the hypervisor page encryption bitmap. Cc: Jordan Justen Cc: Laszlo Ersek Cc: Ard Biesheuvel Signed-off-by: Ashish Kalra --- OvmfPkg/PlatformPei/AmdSev.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/OvmfPkg/PlatformPei/AmdSev.c b/OvmfPkg/PlatformPei/AmdSev.c index 4a515a4847..da9470db7f 100644 --- a/OvmfPkg/PlatformPei/AmdSev.c +++ b/OvmfPkg/PlatformPei/AmdSev.c @@ -15,6 +15,7 @@ #include #include #include +#include #include #include #include @@ -49,6 +50,15 @@ AmdSevEsInitialize ( PcdStatus =3D PcdSetBoolS (PcdSevEsIsEnabled, TRUE); ASSERT_RETURN_ERROR (PcdStatus); =20 + // + // GHCB_BASE setup during reset-vector needs to be marked as + // decrypted in the hypervisor page encryption bitmap. + // + SetMemoryEncDecHypercall3 (FixedPcdGet32 (PcdOvmfSecGhcbBase), + EFI_SIZE_TO_PAGES(FixedPcdGet32 (PcdOvmfSecGhcbSize)), + FALSE + ); + // // Allocate GHCB and per-CPU variable pages. // Since the pages must survive across the UEFI to OS transition --=20 2.17.1 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#68300): https://edk2.groups.io/g/devel/message/68300 Mute This Topic: https://groups.io/mt/78698851/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-