From nobody Thu Apr 2 06:15:11 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 747943C1986; Mon, 30 Mar 2026 10:46:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774867564; cv=none; b=EJPo3ROPMn2QzHJolTGdJ791eKtdSVkud5Tz/0l4DzetvV9t5ayF93tQjW/52Nv9WpGvMu1jcZOwZeotZ44CflFZarm1sIRzjGw15DvU4s6oR2XG1ztafQakSF5HLOmuINvfsWplpHJsrQORTLJEEneLRYmIvON0iCnrNDnCj/c= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774867564; c=relaxed/simple; bh=l1QLvxafdiTxlEqQVEqKqRTDeLWgpc7gOySCPV7xPkw=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=JWfnL5vaki9hkXZb3S9No75JarENsp0HUiUH9+pJ5XLJvgaJgncv54anqxpJi/YJQ2GoPtrNvXBKICqQGZg9C5In5vpNJNvtjpH67A8afHgNEHXNlIjiOgHE7E4kffPLHJg9EwnLmUjJHSnG6aD05a3t9V6lmeMBQEMRt8XNZQg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=f/Y6MYTG; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=KC6mPLdA; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="f/Y6MYTG"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="KC6mPLdA" Date: Mon, 30 Mar 2026 10:46:00 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1774867561; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=f+R0ojth5+efaJrfnPd/XDTA+7KPaI3K2CWEuGIrJYU=; b=f/Y6MYTGh3g8Pfzh7q/cW/8gkZOXqKT1iKTJxxIKHS5QhHkYymV6ADHV5JLJp12xFqJ2QW dDng8m4jaHW6ZVM/RPpTfjyGpFQtkB1vv3C1MLtXZ/2PhcJhVpEGQLz9RD3Gyr4BsARpPy RPFBhWZokoVBD6zbUQ8W9jz/YD5oWJdqbxO7GT+BUd97TMvM0XiTaJ1nZk0Ee+VAUsOX8E YcTc9xmAST9XHT0Uxd0TlMusdOOWxR2m+pS1aa1jHsOFRvnfCu0qZoycC0c2d1XKl4Zo6i 8bZwZRy13uwCmrdo+fuwn5iykd0DZUt7UODfXZWUG6/ruLphgHrwrk2B7H7lzA== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1774867561; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=f+R0ojth5+efaJrfnPd/XDTA+7KPaI3K2CWEuGIrJYU=; b=KC6mPLdAFFIkHGuhS39Z+iSsNsB6QaEbeqihIs6TDS6pbYcine0VLCgt2ClTc8rNVTMRDI JaeY4jvYtVWH2YBQ== From: "tip-bot2 for Tycho Andersen (AMD)" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: x86/sev] x86/sev: Create snp_shutdown() Cc: "Tycho Andersen (AMD)" , "Borislav Petkov (AMD)" , Tom Lendacky , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20260324161301.1353976-4-tycho@kernel.org> References: <20260324161301.1353976-4-tycho@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <177486756049.1647592.13387929622068407514.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the x86/sev branch of tip: Commit-ID: b65546b14d273dde2a56c0313da36a6aeb5c3f32 Gitweb: https://git.kernel.org/tip/b65546b14d273dde2a56c0313da36a6ae= b5c3f32 Author: Tycho Andersen (AMD) AuthorDate: Tue, 24 Mar 2026 10:12:57 -06:00 Committer: Borislav Petkov (AMD) CommitterDate: Sun, 29 Mar 2026 12:15:17 +02:00 x86/sev: Create snp_shutdown() After SNP_SHUTDOWN, two things should be done: 1. clear the RMP table 2. disable MFDM to prevent the FW_WARN in k8_check_syscfg_dram_mod_en() in the event of a kexec Create and export to the CCP driver a function that does them. Also change the MFDM helper to allow for disabling the bit, since the SNP x= 86 shutdown path needs to disable MFDM. The comment for k8_check_syscfg_dram_mod_en() notes, the "BIOS" is supposed clear it, or the kernel in the case of module unload and shutdown followed = by kexec. Signed-off-by: Tycho Andersen (AMD) Signed-off-by: Borislav Petkov (AMD) Reviewed-by: Tom Lendacky Link: https://patch.msgid.link/20260324161301.1353976-4-tycho@kernel.org --- arch/x86/include/asm/sev.h | 2 ++ arch/x86/virt/svm/sev.c | 22 +++++++++++++++++++--- 2 files changed, 21 insertions(+), 3 deletions(-) diff --git a/arch/x86/include/asm/sev.h b/arch/x86/include/asm/sev.h index 2140e26..09e605c 100644 --- a/arch/x86/include/asm/sev.h +++ b/arch/x86/include/asm/sev.h @@ -662,6 +662,7 @@ static inline void snp_leak_pages(u64 pfn, unsigned int= pages) __snp_leak_pages(pfn, pages, true); } void snp_prepare(void); +void snp_shutdown(void); #else static inline bool snp_probe_rmptable_info(void) { return false; } static inline int snp_rmptable_init(void) { return -ENOSYS; } @@ -679,6 +680,7 @@ static inline void snp_leak_pages(u64 pfn, unsigned int= npages) {} static inline void kdump_sev_callback(void) { } static inline void snp_fixup_e820_tables(void) {} static inline void snp_prepare(void) {} +static inline void snp_shutdown(void) {} #endif =20 #endif diff --git a/arch/x86/virt/svm/sev.c b/arch/x86/virt/svm/sev.c index ccec529..3b2273d 100644 --- a/arch/x86/virt/svm/sev.c +++ b/arch/x86/virt/svm/sev.c @@ -132,12 +132,15 @@ static unsigned long snp_nr_leaked_pages; #undef pr_fmt #define pr_fmt(fmt) "SEV-SNP: " fmt =20 -static void mfd_enable(void *arg) +static void mfd_reconfigure(void *arg) { if (!cc_platform_has(CC_ATTR_HOST_SEV_SNP)) return; =20 - msr_set_bit(MSR_AMD64_SYSCFG, MSR_AMD64_SYSCFG_MFDM_BIT); + if (arg) + msr_set_bit(MSR_AMD64_SYSCFG, MSR_AMD64_SYSCFG_MFDM_BIT); + else + msr_clear_bit(MSR_AMD64_SYSCFG, MSR_AMD64_SYSCFG_MFDM_BIT); } =20 static void snp_enable(void *arg) @@ -523,13 +526,26 @@ void snp_prepare(void) * MtrrFixDramModEn is not shared between threads on a core, * therefore it must be set on all CPUs prior to enabling SNP. */ - on_each_cpu(mfd_enable, NULL, 1); + on_each_cpu(mfd_reconfigure, (void *)1, 1); on_each_cpu(snp_enable, NULL, 1); =20 cpus_read_unlock(); } EXPORT_SYMBOL_FOR_MODULES(snp_prepare, "ccp"); =20 +void snp_shutdown(void) +{ + u64 syscfg; + + rdmsrq(MSR_AMD64_SYSCFG, syscfg); + if (syscfg & MSR_AMD64_SYSCFG_SNP_EN) + return; + + clear_rmp(); + on_each_cpu(mfd_reconfigure, NULL, 1); +} +EXPORT_SYMBOL_FOR_MODULES(snp_shutdown, "ccp"); + /* * Do the necessary preparations which are verified by the firmware as * described in the SNP_INIT_EX firmware command description in the SNP