From nobody Tue Aug 25 03:44:14 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=reject dis=none) header.from=google.com ARC-Seal: i=1; a=rsa-sha256; t=1782934387; cv=none; d=zohomail.com; s=zohoarc; b=PR8MVRGbi25IiUXSBNLCXIgj8/AKH7s1cbnNswTS4DL8UqzjufSL9Aj88QSYdYZcqhY9/ktI5IVMCJqkXfw8As+J+agNWaejDBgctj3s2nbHhCHvTndc6kH2iE3EwNeBSA3zqVV7PlxyzT8JfFVOKGfPHxd5FF7x+F/1SePcoP8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782934387; h=Content-Type:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:References:Sender:Subject:Subject:To:To:Message-Id; bh=02bcXtHfI4JvUWCbZ/FGUqsIhMJvDsaJ6tKyxXO+eMA=; b=HATI6hB0K7KH64QSMGYKf8+UCmrxaNNE6H+e3nbd3qjSnAa9rbnT7szbqeVKm1UGQZChlc6Bc8r60xtXnYLZu0M88ubtCA6PkINt9WBesEF1D8dBcSQ3bzN7hgkmLQVwUMox09aTEFS9/9U/AotmWrIk7M8/S4CqS8hwD9EHk1g= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 17829343879261003.9481748343736; Wed, 1 Jul 2026 12:33:07 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1350373.1607880 (Exim 4.92) (envelope-from ) id 1wf0fp-00015w-7L; Wed, 01 Jul 2026 19:32:41 +0000 Received: by outflank-mailman (output) from mailman id 1350373.1607880; Wed, 01 Jul 2026 19:32:41 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wf0fp-000153-1o; Wed, 01 Jul 2026 19:32:41 +0000 Received: by outflank-mailman (input) for mailman id 1350373; Wed, 01 Jul 2026 19:32:39 +0000 Received: from mx.expurgate.net ([194.145.224.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from <3U2tFagYKCZgK62FB48GG8D6.4GEP6F-56N6DDAKLK.P6FHJGB64L.GJ8@flex--seanjc.bounces.google.com>) id 1wf0fm-0000VF-Sj for xen-devel@lists.xenproject.org; Wed, 01 Jul 2026 19:32:38 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wf0fm-004o0g-9V for xen-devel@lists.xenproject.org; Wed, 01 Jul 2026 21:32:38 +0200 Received: from [10.42.69.2] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from <3U2tFagYKCZgK62FB48GG8D6.4GEP6F-56N6DDAKLK.P6FHJGB64L.GJ8@flex--seanjc.bounces.google.com>) id 6a456b1f-2eae-0a2a0a5409dd-0a2a4502c3a4-20 for ; Wed, 01 Jul 2026 21:32:38 +0200 Received: from [209.85.210.202] (helo=mail-pf1-f202.google.com) by tlsNG-720697.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from <3U2tFagYKCZgK62FB48GG8D6.4GEP6F-56N6DDAKLK.P6FHJGB64L.GJ8@flex--seanjc.bounces.google.com>) id 6a456b54-5a27-0a2a45020019-d155d2caed0c-3 for ; Wed, 01 Jul 2026 21:32:38 +0200 Received: by mail-pf1-f202.google.com with SMTP id d2e1a72fcca58-8478e9c4bd2so997146b3a.1 for ; Wed, 01 Jul 2026 12:32:37 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=20251104 header.d=google.com header.i="@google.com" header.h="Content-Type:Cc:To:From:Subject:Message-ID:References:Mime-Version:In-Reply-To:Date:Reply-To" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1782934356; x=1783539156; darn=lists.xenproject.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=02bcXtHfI4JvUWCbZ/FGUqsIhMJvDsaJ6tKyxXO+eMA=; b=r89e7hTquq3IsNKcNxsGOucbtQYJTM88FLrRCZYryO9pfn7x/SSJ5VcDpzJgLLJ6dG qETHvw5ZGp9fIsh9Dy6YpXVk7lAKBYcSs7N6diHXxulw31DlcbgJtDE5JMwgTGW1b9XW YGWBLUDu0Cx8icF1YTxcwNg0QIxA2UJBF55PRfFnKCKLnJOMnRHA2PeaajktUlej2+OP Y451paGiTeZlVC5AIh4TG7J2NOs3dIYvMeiUloHP/wJ2Z0Lo0x19ht7qUfopfEympmyJ qfDGBFmFByZUnADRjlYEqPzDSRUl87JfQpb1z9oXBCM6nVebYT2xIYlTlDGdbG7dSmg3 L2Nw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782934356; x=1783539156; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=02bcXtHfI4JvUWCbZ/FGUqsIhMJvDsaJ6tKyxXO+eMA=; b=J1ZDSUiKS8FPpbPgxzRGokTzEq/B4iW8NcdFf7dTZTKgxDZJewwcnq+1VNEEM4YDH5 NIzhOVLQ8jwzo7CdomfvoAgGahKaquAwNs80aVXr+wHGB4/+rjgIE3BXQgYFylic2ldj sdDaBrb1ff9Sn7o52HcxtR0zhuqRqoilpk6ARf/w6c0soqr1Z1Uq2TWsHs4t1bHiWVgx nS1GImr+sOMv/TB5/tg6cibBCWTt5+WtipkDE1gJSGTkLZcg94fMJLcbeJrAxfFBUtsI wPEzwIFvoRM9hw51ietJ7+jXqbwMGZWqZC5YOapOb1PUUez/m9c1nPn+tslSc1Jydkz4 cz3Q== X-Forwarded-Encrypted: i=1; AFNElJ+m/qOqVTrrAr5Q9eLbuHs9Y3gD8decZF97jgt5e3d0CN0Vyw2c8uEkv3GpxoEfMfilMNM+W84m5tU=@lists.xenproject.org X-Gm-Message-State: AOJu0Yw1t+bYrGT/s5JH6uVGEhkuStP3CeoTcwP/V6+Wg86n51Isstwb Cqijeim+EaIYXdo23kx1y/n6llX39rts5ZB8j8oLGBb78pzFNIZR7fXD2P4zP8n7wlFIV9wFsPm L3cVSKw== X-Received: from pgko8.prod.google.com ([2002:a63:f148:0:b0:c99:aff5:708f]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a20:d807:b0:3bf:9a30:3a20 with SMTP id adf61e73a8af0-3bff40a18cemr2476915637.16.1782934355934; Wed, 01 Jul 2026 12:32:35 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 1 Jul 2026 12:31:29 -0700 In-Reply-To: <20260701193212.749551-1-seanjc@google.com> Mime-Version: 1.0 References: <20260701193212.749551-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.rc0.799.gd6f94ed593-goog Message-ID: <20260701193212.749551-9-seanjc@google.com> Subject: [PATCH v5 08/51] x86/sev: Shove SNP's secure/trusted TSC frequency directly into "calibration" From: Sean Christopherson To: Jonathan Corbet , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, Kiryl Shutsemau , Rick Edgecombe , Sean Christopherson , "K. Y. Srinivasan" , Haiyang Zhang , Wei Liu , Dexuan Cui , Long Li , Ajay Kaher , Alexey Makhalov , Jan Kiszka , Andy Lutomirski , Peter Zijlstra , Juergen Gross , Daniel Lezcano , John Stultz Cc: Shuah Khan , "H. Peter Anvin" , Vitaly Kuznetsov , Broadcom internal kernel review list , Boris Ostrovsky , Stephen Boyd , linux-doc@vger.kernel.org, kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, linux-hyperv@vger.kernel.org, virtualization@lists.linux.dev, xen-devel@lists.xenproject.org, Tom Lendacky , Nikunj A Dadhania , David Woodhouse , David Woodhouse , Michael Kelley , Thomas Gleixner X-purgate-ID: tlsNG-720697/1782934358-564E97C5-FFECAC6D/0/0 X-purgate-type: clean X-purgate-size: 7153 X-ZohoMail-DKIM: pass (identity @google.com) X-ZM-MESSAGEID: 1782934388230158501 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" As a first step towards dropping .calibrate_{cpu,tsc}() and explicitly defining precedence/priority for "calibration" routines, pass the secure TSC frequency obtained from SNP firmware directly to determine_cpu_tsc_frequencies() instead of overriding the .calibrate_tsc() hook. Unlike the native calibration routines, all of the paravirtual overrides, including SNP and TDX, are constant in the sense that the frequency provided by the hypervisor or trusted firmware is fixed, known, and always available during early boot. More importantly, for CoCo (SNP and TDX) VMs, it's imperative that the kernel uses the frequency provided by the trusted firmware, not by the untrusted hypervisor. Enforcing the priority between sources by carefully ordering seemingly unrelated init calls, so that the trusted override "wins", is brittle and all but impossible to follow. Explicitly ignore tsc_early_khz if the exact TSC frequency was obtained from trusted firmware, as per commit bd35c77e32e4 ("x86/tsc: Add tsc_early_khz command line parameter"), the goal of the param is to play nice with setups that provide partial frequency information in CPUID, i.e. is NOT intended to be a hard override. Neither SNP's secure TSC nor TDX was supported when commit bd35c77e32e4 landed back in 2020, i.e. lack of consideration for the interaction was purely due to oversight when SNP and TDX support came along. Signed-off-by: Sean Christopherson Reviewed-by: Nikunj A Dadhania Tested-by: Nikunj A Dadhania --- .../admin-guide/kernel-parameters.txt | 4 +++ arch/x86/coco/sev/core.c | 14 +++-------- arch/x86/include/asm/sev.h | 4 +-- arch/x86/kernel/tsc.c | 25 ++++++++++++++----- 4 files changed, 29 insertions(+), 18 deletions(-) diff --git a/Documentation/admin-guide/kernel-parameters.txt b/Documentatio= n/admin-guide/kernel-parameters.txt index b5493a7f8f22..181149f633c3 100644 --- a/Documentation/admin-guide/kernel-parameters.txt +++ b/Documentation/admin-guide/kernel-parameters.txt @@ -7946,6 +7946,10 @@ Kernel parameters with CPUID.16h support and partial CPUID.15h support. Format: =20 + Note, tsc_early_khz is ignored if the TSC frequency is + provided by trusted firmware when running as an SNP + guest. + tsx=3D [X86] Control Transactional Synchronization Extensions (TSX) feature in Intel processors that support TSX control. diff --git a/arch/x86/coco/sev/core.c b/arch/x86/coco/sev/core.c index 403dcea86452..bc5ae9ef74da 100644 --- a/arch/x86/coco/sev/core.c +++ b/arch/x86/coco/sev/core.c @@ -99,7 +99,6 @@ static const char * const sev_status_feat_names[] =3D { */ static u64 snp_tsc_scale __ro_after_init; static u64 snp_tsc_offset __ro_after_init; -static unsigned long snp_tsc_freq_khz __ro_after_init; =20 DEFINE_PER_CPU(struct sev_es_runtime_data*, runtime_data); DEFINE_PER_CPU(struct sev_es_save_area *, sev_vmsa); @@ -2014,15 +2013,10 @@ void __init snp_secure_tsc_prepare(void) pr_debug("SecureTSC enabled"); } =20 -static unsigned long securetsc_get_tsc_khz(void) -{ - return snp_tsc_freq_khz; -} - -void __init snp_secure_tsc_init(void) +unsigned int __init snp_secure_tsc_init(void) { + unsigned long snp_tsc_freq_khz, tsc_freq_mhz; struct snp_secrets_page *secrets; - unsigned long tsc_freq_mhz; void *mem; =20 mem =3D early_memremap_encrypted(sev_secrets_pa, PAGE_SIZE); @@ -2043,7 +2037,7 @@ void __init snp_secure_tsc_init(void) =20 snp_tsc_freq_khz =3D SNP_SCALE_TSC_FREQ(tsc_freq_mhz * 1000, secrets->tsc= _factor); =20 - x86_platform.calibrate_tsc =3D securetsc_get_tsc_khz; - early_memunmap(mem, PAGE_SIZE); + + return snp_tsc_freq_khz; } diff --git a/arch/x86/include/asm/sev.h b/arch/x86/include/asm/sev.h index 594cfa19cbd4..05ebf0b73ef4 100644 --- a/arch/x86/include/asm/sev.h +++ b/arch/x86/include/asm/sev.h @@ -530,7 +530,7 @@ int snp_send_guest_request(struct snp_msg_desc *mdesc, = struct snp_guest_req *req int snp_svsm_vtpm_send_command(u8 *buffer); =20 void __init snp_secure_tsc_prepare(void); -void __init snp_secure_tsc_init(void); +unsigned int snp_secure_tsc_init(void); enum es_result savic_register_gpa(u64 gpa); enum es_result savic_unregister_gpa(u64 *gpa); u64 savic_ghcb_msr_read(u32 reg); @@ -637,7 +637,7 @@ static inline int snp_send_guest_request(struct snp_msg= _desc *mdesc, struct snp_guest_req *req) { return -ENODEV; } static inline int snp_svsm_vtpm_send_command(u8 *buffer) { return -ENODEV;= } static inline void __init snp_secure_tsc_prepare(void) { } -static inline void __init snp_secure_tsc_init(void) { } +static inline unsigned int __init snp_secure_tsc_init(void) { return 0; } static inline void sev_evict_cache(void *va, int npages) {} static inline enum es_result savic_register_gpa(u64 gpa) { return ES_UNSUP= PORTED; } static inline enum es_result savic_unregister_gpa(u64 *gpa) { return ES_UN= SUPPORTED; } diff --git a/arch/x86/kernel/tsc.c b/arch/x86/kernel/tsc.c index 8f1604ffe986..f049c126e47c 100644 --- a/arch/x86/kernel/tsc.c +++ b/arch/x86/kernel/tsc.c @@ -1440,15 +1440,16 @@ static int __init init_tsc_clocksource(void) */ device_initcall(init_tsc_clocksource); =20 -static bool __init determine_cpu_tsc_frequencies(bool early) +static bool __init determine_cpu_tsc_frequencies(bool early, + unsigned int known_tsc_khz) { /* Make sure that cpu and tsc are not already calibrated */ WARN_ON(cpu_khz || tsc_khz); =20 if (early) { cpu_khz =3D x86_platform.calibrate_cpu(); - if (tsc_early_khz) - tsc_khz =3D tsc_early_khz; + if (known_tsc_khz) + tsc_khz =3D known_tsc_khz; else tsc_khz =3D x86_platform.calibrate_tsc(); } else { @@ -1503,6 +1504,8 @@ static void __init tsc_enable_sched_clock(void) =20 void __init tsc_early_init(void) { + unsigned int known_tsc_khz =3D 0; + if (!boot_cpu_has(X86_FEATURE_TSC)) return; /* Don't change UV TSC multi-chassis synchronization */ @@ -1510,9 +1513,19 @@ void __init tsc_early_init(void) return; =20 if (cc_platform_has(CC_ATTR_GUEST_SNP_SECURE_TSC)) - snp_secure_tsc_init(); + known_tsc_khz =3D snp_secure_tsc_init(); =20 - if (!determine_cpu_tsc_frequencies(true)) + /* + * Ignore the user-provided TSC frequency if the exact frequency was + * obtained from trusted firmware, as the user-provided frequency is + * intended as a "starting point", not a known, guaranteed frequency. + */ + if (!known_tsc_khz) + known_tsc_khz =3D tsc_early_khz; + else if (tsc_early_khz) + pr_err("Ignoring 'tsc_early_khz' in favor of trusted firmware.\n"); + + if (!determine_cpu_tsc_frequencies(true, known_tsc_khz)) return; tsc_enable_sched_clock(); } @@ -1533,7 +1546,7 @@ void __init tsc_init(void) =20 if (!tsc_khz) { /* We failed to determine frequencies earlier, try again */ - if (!determine_cpu_tsc_frequencies(false)) { + if (!determine_cpu_tsc_frequencies(false, 0)) { mark_tsc_unstable("could not calculate TSC khz"); setup_clear_cpu_cap(X86_FEATURE_TSC_DEADLINE_TIMER); return; --=20 2.55.0.rc0.799.gd6f94ed593-goog