From nobody Fri Jul 24 04:48:27 2026 Received: from mail-yw1-f179.google.com (mail-yw1-f179.google.com [209.85.128.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E38F425F7A9 for ; Fri, 24 Jul 2026 03:03:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.179 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784862210; cv=none; b=MXhjvu9hfv6cug3NhXPb6W33GSu/onp2f+Xi7v/xzLaXva5ivUHDWPWQUZVtOGJD120wXQTKBp7pgW23qAxRMGKhjhBWSsiN9FsJMUvRXR4ufEDWV6iFoEvMx7t4EK5FZGNb4oJxdVKPyU7CXElPt2OPjiPTIfWoQAT+GA2y4B8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784862210; c=relaxed/simple; bh=PfRcJ7e4SQjqGNgWMgfzHaihMuw+SQv1skLt6o6AXzc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=s+4WH4aik/RLyYIL2fW7dQNvULJPuSV+NPq8baDr6GgYw4D1DAgYnDuxu0TJnSzvqkQ8TmOUDIB/uHmmkfXN6n4nBlFN4B9Bp6S+BBhE55o96UEyum0uAiI5HD6CmEGK3DJtZVpofnzYpv7e6DK9UAq477gmZjbjh17oUMMaqMo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=IqDdZx77; arc=none smtp.client-ip=209.85.128.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="IqDdZx77" Received: by mail-yw1-f179.google.com with SMTP id 00721157ae682-81ecf499af9so11550087b3.1 for ; Thu, 23 Jul 2026 20:03:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784862208; x=1785467008; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/3tybHNKnNM19dzAnuHiNMe1idD5JAAT4NAx0nOQDNA=; b=IqDdZx775HhLbKatZJsCbM2ywwm0Gn7BXO45uvth/i2zJWmPuYbtokV7MZFb0WH7rl uZq1z9ln8a65WzRoBwhMDnQwRzzl+mwalNKLYGLT/9D/dJj2cGl+Sx2yPfz0wMbT1Y6c /MYY4qkLcZIg5u/ha9w5FNZ/L83UYpLocgJJuf1PSDrA4krvnDMDyNypsFu5D8lFIsKz SO/4q22qw+xpnayS3vg7ZRK5AGgDtCHFqak0o9O61jy7kDnspgM/vxJE/njNOPAI/pgY 4YZTnOIcyCwsjy7T1lACFTMpuHjSTBmtie10eYpdtzmv5LQogEbx8QoFXgPmvWdOcmMc EVeQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784862208; x=1785467008; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/3tybHNKnNM19dzAnuHiNMe1idD5JAAT4NAx0nOQDNA=; b=l0Zwil+np4b2H1VGMj1M66Mug2YlJ1qGm4zsb5+MrjBmQ2fh72ne423ZYKS9D72osv cUPC9d/0/gqir52YKkBQK0s6IacnTL7Mt9JUMsz37AtgXbW5Jgv7/YcL3EdXWqKD8Zc5 XgMQSkSkFUeyhctPJiFtk/YqSHbHSVtZPrgAHYuQggq2tIdO5w+PJMdKKYikJGPL0Uzr oBrqYrWr5rf3NMw5Gw7JJzNTcjaEJbO1xzqtmTFv8g81Ct6par15d45FFo4mtsqmcByc KeOK9fa8zYxu4w3ly967wM8Dugcuhc6HAW15BE9Z+3a0Uyor2jvyrs6iNuzSOEwSDteV P2bw== X-Gm-Message-State: AOJu0YzOAKWztRiFCxqKIXv6FZGctPLJ9m8BJG4ItxQJ1EWJ6ut1Nq4S 3+hiJvvgHnwNwUkFF61rITq177JlwHXc2ww4lvctppuFQH0P1gJyDATjx8Cw X-Gm-Gg: AR+sD1121flz7pAd5914+bIj/hN4194u8jAg+SsJpyQqylLmZ+m9yBFEYCCbtR2UQ/l FD67GQ0/7affNG9b6wj1s3f9W8bbv0DKgh/MXhXhpV/lTyw8aGfL4q1NQ0jVI9r9ZqX9JMeBDEd W/2OFN9Y7etLlUxa2vbEmna7LNJQOlt0IdA1OqSDgYkuCmzwfmANPb96txzJ8a4AHSNMOh1342h GUS9+LJp9huXSgItntmQVghuJZgUKgNbIlhbzGnvIGFCRch4QLNgEiU9xSBvRQITFd7/gxQGSTP /wGWCGu+WLEQIhAHSSv4ImqCbn6m4VwsijgMA0Ea8LUA8dx0MYljPLMqEq5ROiPPFLLHgPQtJ22 ea9xhvDLMq+GFMoXxpOpNW9Y4BUcAfnrdQFRZOkUSHO3lf3o2+pWTHOscIUE= X-Received: by 2002:a05:690c:6501:b0:804:a2d5:1d32 with SMTP id 00721157ae682-81f4c2cb2femr18372537b3.36.1784862207943; Thu, 23 Jul 2026 20:03:27 -0700 (PDT) Received: from citadel.lan ([2600:6c4a:4df0:2c10::1dba]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81f33c397c9sm37379477b3.14.2026.07.23.20.03.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 23 Jul 2026 20:03:27 -0700 (PDT) From: Brian Gerst To: linux-kernel@vger.kernel.org, x86@kernel.org Cc: Thomas Gleixner , Borislav Petkov , Ard Biesheuvel , Juergen Gross , Tom Lendacky , Brian Gerst Subject: [PATCH 1/5] x86/sme: Clear decrypted BSS separately Date: Thu, 23 Jul 2026 23:02:52 -0400 Message-ID: <20260724030256.232690-2-brgerst@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260724030256.232690-1-brgerst@gmail.com> References: <20260724030256.232690-1-brgerst@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The decrypted BSS section needs to be cleared after it is remapped as decrypted memory. Separate it so that the normal BSS section can be cleared earlier. Signed-off-by: Brian Gerst --- arch/x86/kernel/vmlinux.lds.S | 2 +- arch/x86/mm/mem_encrypt_amd.c | 3 +++ 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/arch/x86/kernel/vmlinux.lds.S b/arch/x86/kernel/vmlinux.lds.S index 2438b89a4620..e64c797e06c7 100644 --- a/arch/x86/kernel/vmlinux.lds.S +++ b/arch/x86/kernel/vmlinux.lds.S @@ -365,9 +365,9 @@ SECTIONS *(.bss..page_aligned) . =3D ALIGN(PAGE_SIZE); *(BSS_MAIN) - BSS_DECRYPTED . =3D ALIGN(PAGE_SIZE); __bss_stop =3D .; + BSS_DECRYPTED } =20 /* diff --git a/arch/x86/mm/mem_encrypt_amd.c b/arch/x86/mm/mem_encrypt_amd.c index 2f8c32173972..d39e1e29bcb9 100644 --- a/arch/x86/mm/mem_encrypt_amd.c +++ b/arch/x86/mm/mem_encrypt_amd.c @@ -479,6 +479,9 @@ void __init sme_early_init(void) if (!sme_me_mask) return; =20 + memset(__start_bss_decrypted, 0, + (unsigned long) __end_bss_decrypted - (unsigned long) __start_bss_= decrypted); + early_pmd_flags =3D __sme_set(early_pmd_flags); =20 __supported_pte_mask =3D __sme_set(__supported_pte_mask); --=20 2.55.0 From nobody Fri Jul 24 04:48:27 2026 Received: from mail-yw1-f169.google.com (mail-yw1-f169.google.com [209.85.128.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F25D0370AC0 for ; Fri, 24 Jul 2026 03:03:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784862211; cv=none; b=mKdr9GC5Tl23oa9J+NwpL+h96KldXhF597aPzRv07dC7YkZd+4YrAzUSLyvCo3VDqigyS7i5HiztDVnOOOhRzQh9QR9x/bGkcHBl9TmqeZLSIutB74eMfsxEk3ehr3NEnMiSMz++HqaB79abtFIwhKapMQMQByRK6nTtQXWZLRU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784862211; c=relaxed/simple; bh=o9+KJ3IY4LWiFLmck5cvFP1VGp+2zGVD2yi8zok/LY8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=FsTKGtxIRmPUz44RI1XHPEfguqJTrLYYd8fc3Z4Vi0yi7Jr462qBQ2cs/2DLOcgz/WoPrQCeEPoXvp0opaDvn8Fu/Ki6MDBoiYQ1ChmPA8iBLYq+rk8ShoYrBglmoI/Im8MM/F/UwpJ5R3KKrs5S8PP/Xbeylg1uI+ch1qcI7bk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=bTf4ALck; arc=none smtp.client-ip=209.85.128.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="bTf4ALck" Received: by mail-yw1-f169.google.com with SMTP id 00721157ae682-81ecf499af9so11550217b3.1 for ; Thu, 23 Jul 2026 20:03:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784862209; x=1785467009; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uR7kgs000q7qimFucipfbArZHrQ2X+5+dqumsq29gHw=; b=bTf4ALck1ttV+hIuKUDfGTDQ+7QQfSvqYci4WEK5drcKqaZQikvM6001yzlA1s6U/B y53+iuJxxbg1dK+KRF8fYGZ89zkQ3MqCYZzoYjEhd60dkTMi76eo2FOTmv/iilRwRYQ5 4+nE9hTianLNMxGPZXF+jmA+U2vvwRAG/yFJ/M+8uonBdzvqeM4CAbm2+miSFf+FIsM7 82Ae1TX0GPX48G15cP/iPDa6yd0Av42R1XpPer5UFCktHPGu4jpBUjwh+4+6Wx2UjfaO c2WX4q+O3U6pCaV4cCHEIa1Qg0a8ZGzdDEHWlGt6eFUXlThDdgFRaF0UdqvN9y0BHgOc wX5w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784862209; x=1785467009; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=uR7kgs000q7qimFucipfbArZHrQ2X+5+dqumsq29gHw=; b=XxMidoLGL4Rz0mm1SAYh9CaiTKikpFMS1kDuk5iYiCOX6ji/2x3EQzKdrdmSDSRcTQ m/+MVt7b9D/E0GkOHmPAGP4RVqAi2HGE8HMciXSI3Jupp9bWUHutxIX9hQDJhirmZuvy uqWPmJ+l7hyhh1OVLvEJHcwSaYdhyFdyutTyptUVEACDFoyLKTKIwxCWtsmRYDJK++QT +Q2+mxjtAC6POYXtDDTAJZLW/UHgfO1SZem5THhMgmwdxdzy/uA0W/dLhCDUDhJqr4pN ieXbtwuiBZPPntCYzZdpLe0fEoQhJQDJ3NcFxRRjIDAWOAaZgW4hVkKmCkbdulsW3QbE WPcg== X-Gm-Message-State: AOJu0YwPqxejPsH1+1RCELvwIvxt1ywAaRk71q7IWD6ShYCtEbp2+r+w 279R3Q4OxUE+tEBNSWLMV6UZBfR1+RzhEIRpjqaj4adw41e95msrBaJOehsX X-Gm-Gg: AR+sD12M6I5gxfJFvv+rwnvPZ0A37skMzKXpOLkIf1JO8S4OKjs0dZ6D5CcpWiHr7fp DWvWhgTZ9TTQaZVAgbNyZxDTqEP/tGqvXlCQmUCpUaBAWqEjFptUuvMEyuiLm7/6PBRLWQALBsv fJkIsn08F1fAfv3GcG9Rt23AKukPeuCcMwc5gXhAtLjt9Seo+y3IuU6aHIu+t257x2hy4rcbdly ziv3XR4HiohMjAhhKmqJ14TPWn+xD+4aDRZvBmOFtki5ErM4vt8tk5i9DrvY6MWuFCUnQ+jio3f 4zRewkyYtWdgsHwdwaFQnLD4hmkN9qw/8S73Z4yyb54SJGOo3kTAGVp5krdC4CpBeq3ZznasU9Q wzpwvRBVILPtJ0EmpRJEr+HYmHOQTxjfQI1rItDD3UJTokMQVi1G+J3gp+Rg= X-Received: by 2002:a05:690c:305:b0:80c:3848:bdf4 with SMTP id 00721157ae682-81f4c2cb47bmr18926147b3.41.1784862208949; Thu, 23 Jul 2026 20:03:28 -0700 (PDT) Received: from citadel.lan ([2600:6c4a:4df0:2c10::1dba]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81f33c397c9sm37379477b3.14.2026.07.23.20.03.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 23 Jul 2026 20:03:28 -0700 (PDT) From: Brian Gerst To: linux-kernel@vger.kernel.org, x86@kernel.org Cc: Thomas Gleixner , Borislav Petkov , Ard Biesheuvel , Juergen Gross , Tom Lendacky , Brian Gerst Subject: [PATCH 2/5] x86/boot/64: Clear BSS as early as possible Date: Thu, 23 Jul 2026 23:02:53 -0400 Message-ID: <20260724030256.232690-3-brgerst@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260724030256.232690-1-brgerst@gmail.com> References: <20260724030256.232690-1-brgerst@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Currently, the BSS section is not cleared until x86_64_start_kernel(). Using unitialized BSS data before that point leads to difficult to debug problems. Fix this by moving clear_bss() to as early as possible. Signed-off-by: Brian Gerst --- arch/x86/include/asm/setup.h | 2 -- arch/x86/kernel/head64.c | 12 ------------ arch/x86/kernel/head_64.S | 20 ++++++++++++++++++++ arch/x86/xen/enlighten_pv.c | 2 -- arch/x86/xen/xen-head.S | 5 ++++- 5 files changed, 24 insertions(+), 17 deletions(-) diff --git a/arch/x86/include/asm/setup.h b/arch/x86/include/asm/setup.h index 914eb32581c7..5534f4aaf73b 100644 --- a/arch/x86/include/asm/setup.h +++ b/arch/x86/include/asm/setup.h @@ -126,8 +126,6 @@ void *extend_brk(size_t size, size_t align); =20 extern void probe_roms(void); =20 -void clear_bss(void); - #ifdef __i386__ =20 asmlinkage void __init __noreturn i386_start_kernel(void); diff --git a/arch/x86/kernel/head64.c b/arch/x86/kernel/head64.c index fd28b53dbac5..9f19635c6390 100644 --- a/arch/x86/kernel/head64.c +++ b/arch/x86/kernel/head64.c @@ -172,16 +172,6 @@ void __init do_early_exception(struct pt_regs *regs, i= nt trapnr) early_fixup_exception(regs, trapnr); } =20 -/* Don't add a printk in there. printk relies on the PDA which is not init= ialized=20 - yet. */ -void __init clear_bss(void) -{ - memset(__bss_start, 0, - (unsigned long) __bss_stop - (unsigned long) __bss_start); - memset(__brk_base, 0, - (unsigned long) __brk_limit - (unsigned long) __brk_base); -} - static unsigned long get_cmd_line_ptr(void) { unsigned long cmd_line_ptr =3D boot_params.hdr.cmd_line_ptr; @@ -246,8 +236,6 @@ asmlinkage __visible void __init __noreturn x86_64_star= t_kernel(char * real_mode vmemmap_base =3D __VMEMMAP_BASE_L5; } =20 - clear_bss(); - /* * This needs to happen *before* kasan_early_init() because latter maps s= tuff * into that page. diff --git a/arch/x86/kernel/head_64.S b/arch/x86/kernel/head_64.S index 7ed5520dd52e..15ef5ea52b9a 100644 --- a/arch/x86/kernel/head_64.S +++ b/arch/x86/kernel/head_64.S @@ -37,6 +37,8 @@ .code64 SYM_CODE_START_NOALIGN(startup_64) UNWIND_HINT_END_OF_STACK + cld + /* * At this point the CPU runs in 64bit mode CS.L =3D 1 CS.D =3D 0, * and someone has loaded an identity mapped page table @@ -61,6 +63,8 @@ SYM_CODE_START_NOALIGN(startup_64) /* Set up the stack for verify_cpu() */ leaq __top_init_kernel_stack(%rip), %rsp =20 + call clear_bss + /* * Set up GSBASE. * Note that on SMP the boot CPU uses the init data section until @@ -140,6 +144,22 @@ SYM_CODE_START_NOALIGN(startup_64) jmp *.Lcommon_startup_64(%rip) SYM_CODE_END(startup_64) =20 +SYM_FUNC_START(clear_bss) + xorl %eax, %eax + + leaq __bss_start(%rip), %rdi + leaq __bss_stop(%rip), %rcx + subq %rdi, %rcx + rep stosb + + leaq __brk_base(%rip), %rdi + leaq __brk_limit(%rip), %rcx + subq %rdi, %rcx + rep stosb + + RET +SYM_FUNC_END(clear_bss) + __INITRODATA SYM_DATA_LOCAL(.Lcommon_startup_64, .quad common_startup_64) =20 diff --git a/arch/x86/xen/enlighten_pv.c b/arch/x86/xen/enlighten_pv.c index 2c64b388f616..6aa13d19c0a4 100644 --- a/arch/x86/xen/enlighten_pv.c +++ b/arch/x86/xen/enlighten_pv.c @@ -1334,8 +1334,6 @@ asmlinkage __visible void __init xen_start_kernel(str= uct start_info *si) if (!si) return; =20 - clear_bss(); - xen_start_info =3D si; =20 __text_gen_insn(&early_xen_iret_patch, diff --git a/arch/x86/xen/xen-head.S b/arch/x86/xen/xen-head.S index 5dad6c51cdc3..9b56659246fe 100644 --- a/arch/x86/xen/xen-head.S +++ b/arch/x86/xen/xen-head.S @@ -31,6 +31,9 @@ SYM_CODE_START(startup_xen) =20 leaq __top_init_kernel_stack(%rip), %rsp =20 + movq %rsi, %r15 + call clear_bss + /* * Set up GSBASE. * Note that, on SMP, the boot cpu uses init data section until @@ -41,7 +44,7 @@ SYM_CODE_START(startup_xen) xorl %edx, %edx wrmsr =20 - mov %rsi, %rdi + mov %r15, %rdi call xen_start_kernel SYM_CODE_END(startup_xen) __FINIT --=20 2.55.0 From nobody Fri Jul 24 04:48:27 2026 Received: from mail-yw1-f170.google.com (mail-yw1-f170.google.com [209.85.128.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0FAE03749FA for ; Fri, 24 Jul 2026 03:03:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784862212; cv=none; b=IrFzL7uK1wdPnuaJ4p8b884a3DRNJ1FmnGMHipfN8wzQi07cNOWvlcAFO/hSIYx2LH7TJX49ai+BixiOhSjlJ9NqcQaG1BoTD7wwzgszfTXry+lQmOxhVkjGovQ7DUP9MiBmzwIEJSAEKzWOv9lm5bsotTyPBKahyKy6fDlAIFQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784862212; c=relaxed/simple; bh=gCtfnWPg+rPyq2XRQgPAbf/sWC72//bHQwAOPZ81tbc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lVEXGaJdE+V8/trtj7Y8v2JxLf0Ko4zXyhClu4Ozwrqxf7esQ1mhZ4edMQuJlaSHO/Iq7lysGwXEPlVOOvoDgkBHBZnbh9QIpR/yDCqmfNw8P4A+uLnrAjTOus2z82Qwb3g3oRfIvlSNFZrhBJLqsLggio7FNVLk+2H7HdffN9A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=RfJHMV3W; arc=none smtp.client-ip=209.85.128.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="RfJHMV3W" Received: by mail-yw1-f170.google.com with SMTP id 00721157ae682-80e2cfe6918so10120597b3.0 for ; Thu, 23 Jul 2026 20:03:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784862210; x=1785467010; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dPcCPVE6hByu3Jwn/37Fk8BMNH940blIrLxlZI+KWys=; b=RfJHMV3WcJiE9l5bpFmmHMKHsfZVtfik7GVdalnt1HFHVyU8QpVAEMv7fKuG4A5R2S FwpVaDxN42xV4+iApffqr+5aPWi0dPccj8X9k9r7dIpd5qb39fBJh+icmZQ2Fh98xNbn 0Gg3T0WOE7WjmI3V0xW+a0gfAvuCmKBfEo+nIChQbNs/5TwTCU9Uc3K1haAzBerJoC+C ViowpM7u4yNVqYRFV4vmzCCM23szNeH4OmTRlQFxuf8Julvy+l+tCX2La1eSmqPNE+38 +BjvNcHUqg63gjbe7d37fE7AdvWoHigBu/98K0F+SilUnOgpm6KFtHnGfAq9c2d+qi6/ Zg0Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784862210; x=1785467010; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=dPcCPVE6hByu3Jwn/37Fk8BMNH940blIrLxlZI+KWys=; b=IFIBCF9YCmt4eW3IlajpNCCeQWZ/GVVFqBjPf2q/iwONWUHn+661LCTbWiGSX0BEz9 21EwiusQtD30xxtSUuz7OnXvH2aXazhILqIYf6vKcecvDNsKNTRIS7lh3Sy1eI2aI60L lPhQlhAwD4mT7UbagPjvuYktSbuLOE1j6sBK4v3XAgaf6MFvTjQ0Z4jL2RiTkuYb3G/P Rm4HkqSmeTe6L6DBG1pN8GFzIlfiwH2zZ6Y986t4N1IoZTnoLBE/2SJGRMd5fz9Q6SFg WHVSy4927bGYTGR47N4qZZUyvUjGib7vdmbsH0CBPQCnJXo2+1IuxQ8gEUYaVQFlkH9W jIAA== X-Gm-Message-State: AOJu0YxpJhJIDeuxewuxPQ6GciOjUCUCDFpOrvoiiTgcYRl24TIYu9Ny RSrJgmkcOmklqQCOWH1qrdlV++2cKPXLYCfjqKsXQs2lVcG7IYix2ZqiCf/b X-Gm-Gg: AR+sD109nlYcyw4DbC9nNVvxoUsQyjofJ1KO2qm9L0tE7oxO9GU509/qPAS8gIeS10O 4YL0xJ9Ys5cYtGp40OwoB0vo7H1LjhH7bjtBAvDu4iVpXRSLwEgTOfUZr6TrKGu112tqvBivlTT ZYD19Mxs6E/K8krfqurve41GbXo3OEOwNXP3NI8XoBpJQ+b3TyvvE3C8Z4FJ+KhdxZtq6vbTZcq yGHB72+jOiXEQ0alKvwlvNJYgvP55SS3/5nvjGcDZMU5bzL1KTPlQaIoy8E5K07YT2eZFat0q4U 74m4LfQXQyb1fb7tmTQ3Z2IeR5uy14bZkhcHRya/iGGkBBdBd5s4QVgFiI5yyo9I3iywZiRaxnv r/Ae4w8/2R6hykw34Xk+WboVuVw049FoCmpUvhIWVpa7ugBW4LDwzQxt/Dwo= X-Received: by 2002:a05:690c:4d09:b0:814:5f5b:6378 with SMTP id 00721157ae682-81f4c22f8c7mr16030837b3.12.1784862210025; Thu, 23 Jul 2026 20:03:30 -0700 (PDT) Received: from citadel.lan ([2600:6c4a:4df0:2c10::1dba]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81f33c397c9sm37379477b3.14.2026.07.23.20.03.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 23 Jul 2026 20:03:29 -0700 (PDT) From: Brian Gerst To: linux-kernel@vger.kernel.org, x86@kernel.org Cc: Thomas Gleixner , Borislav Petkov , Ard Biesheuvel , Juergen Gross , Tom Lendacky , Brian Gerst Subject: [PATCH 3/5] x86/boot: Remove hardcoded boot_param constants Date: Thu, 23 Jul 2026 23:02:54 -0400 Message-ID: <20260724030256.232690-4-brgerst@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260724030256.232690-1-brgerst@gmail.com> References: <20260724030256.232690-1-brgerst@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Use generated constants or sizeof() instead of hardcoded values. No functional change. Signed-off-by: Brian Gerst --- arch/x86/include/asm/setup.h | 3 --- arch/x86/kernel/asm-offsets.c | 2 ++ arch/x86/kernel/head_32.S | 4 ++-- drivers/firmware/efi/libstub/x86-stub.c | 6 +++--- 4 files changed, 7 insertions(+), 8 deletions(-) diff --git a/arch/x86/include/asm/setup.h b/arch/x86/include/asm/setup.h index 5534f4aaf73b..d23f4272d930 100644 --- a/arch/x86/include/asm/setup.h +++ b/arch/x86/include/asm/setup.h @@ -21,11 +21,8 @@ =20 #endif /* __i386__ */ =20 -#define PARAM_SIZE 4096 /* sizeof(struct boot_params) */ - #define OLD_CL_MAGIC 0xA33F #define OLD_CL_ADDRESS 0x020 /* Relative to real mode data */ -#define NEW_CL_POINTER 0x228 /* Relative to real mode data */ =20 #ifndef __ASSEMBLER__ #include diff --git a/arch/x86/kernel/asm-offsets.c b/arch/x86/kernel/asm-offsets.c index 081816888f7a..0c49bb50188d 100644 --- a/arch/x86/kernel/asm-offsets.c +++ b/arch/x86/kernel/asm-offsets.c @@ -105,6 +105,8 @@ static void __used common(void) OFFSET(BP_kernel_alignment, boot_params, hdr.kernel_alignment); OFFSET(BP_init_size, boot_params, hdr.init_size); OFFSET(BP_pref_address, boot_params, hdr.pref_address); + OFFSET(BP_cmd_line_ptr, boot_params, hdr.cmd_line_ptr); + DEFINE(SIZEOF_boot_params, sizeof(struct boot_params)); =20 BLANK(); DEFINE(PTREGS_SIZE, sizeof(struct pt_regs)); diff --git a/arch/x86/kernel/head_32.S b/arch/x86/kernel/head_32.S index 5171cb746444..1f66ccc36fe8 100644 --- a/arch/x86/kernel/head_32.S +++ b/arch/x86/kernel/head_32.S @@ -96,10 +96,10 @@ SYM_CODE_START(startup_32) * page tables. */ movl $pa(boot_params),%edi - movl $(PARAM_SIZE/4),%ecx + movl $(SIZEOF_boot_params/4),%ecx cld rep movsl - movl pa(boot_params) + NEW_CL_POINTER,%esi + movl pa(boot_params) + BP_cmd_line_ptr,%esi andl %esi,%esi jz 1f # No command line movl $pa(boot_command_line),%edi diff --git a/drivers/firmware/efi/libstub/x86-stub.c b/drivers/firmware/efi= /libstub/x86-stub.c index cef32e2c82d8..c3522d417344 100644 --- a/drivers/firmware/efi/libstub/x86-stub.c +++ b/drivers/firmware/efi/libstub/x86-stub.c @@ -520,11 +520,11 @@ static efi_status_t efi_allocate_bootparams(efi_handl= e_t handle, return status; } =20 - status =3D efi_allocate_pages(PARAM_SIZE, &alloc, ULONG_MAX); + status =3D efi_allocate_pages(sizeof(struct boot_params), &alloc, ULONG_M= AX); if (status !=3D EFI_SUCCESS) return status; =20 - boot_params =3D memset((void *)alloc, 0x0, PARAM_SIZE); + boot_params =3D memset((void *)alloc, 0x0, sizeof(struct boot_params)); hdr =3D &boot_params->hdr; =20 /* Assign the setup_header fields that the kernel actually cares about */ @@ -537,7 +537,7 @@ static efi_status_t efi_allocate_bootparams(efi_handle_= t handle, /* Convert unicode cmdline to ascii */ cmdline_ptr =3D efi_convert_cmdline(image); if (!cmdline_ptr) { - efi_free(PARAM_SIZE, alloc); + efi_free(sizeof(struct boot_params), alloc); return EFI_OUT_OF_RESOURCES; } =20 --=20 2.55.0 From nobody Fri Jul 24 04:48:27 2026 Received: from mail-yw1-f170.google.com (mail-yw1-f170.google.com [209.85.128.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6B01A377EA2 for ; Fri, 24 Jul 2026 03:03:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784862213; cv=none; b=W69qH8h0YlwBg3n0DoSP37AMVhzVcJzE7k2zMJvyGompZiB3toEY4Q5B+yzG3tNuS2HbZsihOpK71lB0J5WNhmee9S7pJ90rJspAqDxXkkk+8SLMQGWjMDSEk1axs9LxKDqbRpGYHk9zRFzAvAJYavwXj2noBenzFMLRKhFbLwk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784862213; c=relaxed/simple; bh=TGRp+2CqscCYAPn3tF8GqHew6N1j0t5jlV/76q9HVd8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=nDgdxuDfASpJADFPjYSd4+cZMdqrYwz3d+JZvzBQU3l8KoICaCQUrFfqieYrcdiUgYpdY9f+pKJo7lNn4w0PwdRvh67RNctHuVHBIORKLUz2upbfnXIKk3jU8K/QyxfI7F8ZrMzQxZpxmCePwN1RBcMmCW4+BHkDkDGUxdvJZIc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XlZOOuJm; arc=none smtp.client-ip=209.85.128.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XlZOOuJm" Received: by mail-yw1-f170.google.com with SMTP id 00721157ae682-7ff05e5d009so9964237b3.1 for ; Thu, 23 Jul 2026 20:03:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784862211; x=1785467011; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Fohv3zQW8en/CdgCeYM+plUC/PZuMWYlz5y9Y9oqxSU=; b=XlZOOuJmIf2Bo2nfuLEpK9hg+iOvRx4+e1B10Sj4cBaUbcOmsAhHqkNzhVb3SrdNd1 DSeVlBIGyNZg8mwq7stkopvMCahVICvKUJKLNwz1yIEw4JKc8jAz4Qw4p1AxX5nVnmut R3usuT3P0FJ0az89AFvTjvifa4O9h4jcRnhnQERwq2s9C9t39U1Ww3hRpQXNw5jGlopv EyQO++U8PlaLrWLQYE3YfigKoS6SNesQkUXkd8HTGs3nHXYWr3ZfRa/DEVGNyiLW8red /ipC6NCSmofmGC1jQFGBCa2q3/jRR8SjFCJV2/udUoCzINekqWpBnHO+7PVrWHFxps9E nV8Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784862211; x=1785467011; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Fohv3zQW8en/CdgCeYM+plUC/PZuMWYlz5y9Y9oqxSU=; b=RknBlaJmhxAnW2V2GUVndFyor5Yfb5CaqxFxQPX83g8XzccZuLXleWzVUDN8Rnq0QQ bK7yTh4vh36JaGz3uL2X3jPJJb+oxFMYOF1cS/GqCBOfrb84ptGOMrjnzpZhKCxbyPNp rkMQYXlqOr6TcDGo73yJpm3+JoonotKiTMoJlrPn9K5NhHXrjkHcPbEXwGQEXCyEZam4 fhxaw8hszz8YKOFCwKBV6pdw1ydsy+VL5YCkqzLpJlZSLfFoq7JlZKhvk7RR3y9Zsz6j 1C/ESuyF27p0Vl2nMX1R/FQFT/8/ZtXdibLsMFV3v/KK7J6YggU6C+c61wIcnhAxt4Ww u6mw== X-Gm-Message-State: AOJu0YyhN6d0SB2eeOV93Gn3mtOkXeqPqtdy0scyvWrFgzOpYilMfSI9 nuO22kVQyA7nuhcOEZ3vkH6qStnEfk+h63kQxGdPzqLyQQSbkVj0oppvTfFz X-Gm-Gg: AR+sD13D1dHvDCB9UvWPO2eZydxsDBdtOhJa5J6gOL/LFxGSfBgv1MVyg7fzQpwgIEp /T1lwvbD9S48Gjv+lxK3229y+y4XV1nHa9lwlNvs6JmTfacCzLkwWab3ge/a/6oCtrvmgdhsnnU OpjX7N47yt9tVYMdj8dET6723aJWGdDNSLCFMRsFRZrCpJsPMZwsVbpZW2+r3GUKilDPh69Mf/Z VfWo+fH8JkYPqAxVszDCFsb+lyKGvHonj2tjOf8+me9Td4zaMks1yVBCFn1RC9kZRerxxn9h+Sh lxovFAV+bpOoe9yUVxFWsiiDTcqx89iZvSQfFm0ldAW9tRn0SlsprZIY8FFTs4Bwu197C7b1S8k JtJutHG0xaKx5wraBEcBO8gSzpBWLLJRbZ0Rgr6Zu+hCtVXB6HAxAn+H+GS0= X-Received: by 2002:a05:690c:610b:b0:81e:eac8:f325 with SMTP id 00721157ae682-81f4c2da489mr18909517b3.42.1784862211211; Thu, 23 Jul 2026 20:03:31 -0700 (PDT) Received: from citadel.lan ([2600:6c4a:4df0:2c10::1dba]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81f33c397c9sm37379477b3.14.2026.07.23.20.03.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 23 Jul 2026 20:03:30 -0700 (PDT) From: Brian Gerst To: linux-kernel@vger.kernel.org, x86@kernel.org Cc: Thomas Gleixner , Borislav Petkov , Ard Biesheuvel , Juergen Gross , Tom Lendacky , Brian Gerst Subject: [PATCH 4/5] x86/boot/64: Remove copy_bootdata() call Date: Thu, 23 Jul 2026 23:02:55 -0400 Message-ID: <20260724030256.232690-5-brgerst@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260724030256.232690-1-brgerst@gmail.com> References: <20260724030256.232690-1-brgerst@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" On a normal boot, copy_bootdata() is first called in x86_64_start_kernel(). The second call in x86_64_start_reservations() is effectively a no-op. Xen PV directly initializes boot_params, so it does not need to call copy_bootdata() at all. Remove the unnecessary call to copy_bootdata() from x86_64_start_reservations(). Signed-off-by: Brian Gerst Cc: Juergen Gross --- arch/x86/include/asm/setup.h | 2 +- arch/x86/kernel/head64.c | 8 ++------ arch/x86/xen/enlighten_pv.c | 2 +- 3 files changed, 4 insertions(+), 8 deletions(-) diff --git a/arch/x86/include/asm/setup.h b/arch/x86/include/asm/setup.h index d23f4272d930..18a4d3826af7 100644 --- a/arch/x86/include/asm/setup.h +++ b/arch/x86/include/asm/setup.h @@ -130,7 +130,7 @@ void __init mk_early_pgtbl_32(void); =20 #else asmlinkage void __init __noreturn x86_64_start_kernel(char *real_mode); -asmlinkage void __init __noreturn x86_64_start_reservations(char *real_mod= e_data); +asmlinkage void __init __noreturn x86_64_start_reservations(void); =20 #endif /* __i386__ */ #endif /* _SETUP */ diff --git a/arch/x86/kernel/head64.c b/arch/x86/kernel/head64.c index 9f19635c6390..d895376e9346 100644 --- a/arch/x86/kernel/head64.c +++ b/arch/x86/kernel/head64.c @@ -276,15 +276,11 @@ asmlinkage __visible void __init __noreturn x86_64_st= art_kernel(char * real_mode /* set init_top_pgt kernel high mapping*/ init_top_pgt[511] =3D early_top_pgt[511]; =20 - x86_64_start_reservations(real_mode_data); + x86_64_start_reservations(); } =20 -void __init __noreturn x86_64_start_reservations(char *real_mode_data) +void __init __noreturn x86_64_start_reservations(void) { - /* version is always not zero if it is copied */ - if (!boot_params.hdr.version) - copy_bootdata(__va(real_mode_data)); - x86_early_init_platform_quirks(); =20 switch (boot_params.hdr.hardware_subarch) { diff --git a/arch/x86/xen/enlighten_pv.c b/arch/x86/xen/enlighten_pv.c index 6aa13d19c0a4..e6e2666da5a1 100644 --- a/arch/x86/xen/enlighten_pv.c +++ b/arch/x86/xen/enlighten_pv.c @@ -1556,7 +1556,7 @@ asmlinkage __visible void __init xen_start_kernel(str= uct start_info *si) =20 /* Start the world */ cr4_init_shadow(); /* 32b kernel does this in i386_start_kernel() */ - x86_64_start_reservations((char *)__pa_symbol(&boot_params)); + x86_64_start_reservations(); } =20 static int xen_cpu_up_prepare_pv(unsigned int cpu) --=20 2.55.0 From nobody Fri Jul 24 04:48:27 2026 Received: from mail-yw1-f174.google.com (mail-yw1-f174.google.com [209.85.128.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AB1E2379C27 for ; Fri, 24 Jul 2026 03:03:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.174 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784862216; cv=none; b=PLZnu4p4xj2cNNaTptxdcjw5qHY6IQ8PLkrxLZ37r+gGIIkIKRq2874c+lf3h6QZl9uCZ8GFVazPT+s/c5k6J+hvi0MB8Yxl23HrqoXYuMbz+rx10LmfnI3QOo2aSRk3C6YvFejoAGgyIcov598GUK++nqz3l1t6VU9X8j/3Tds= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784862216; c=relaxed/simple; bh=yXUVFM7+xThcBODnv3cLS9oZ8kwn3twXFcWz72WiIjk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=E/5kWKBzoFz/MvI40yaCdPQAks1+XU65oB6WL4/ommFDF4pdhMqdv7xR1mDhEyfdx7O9GihjFz/byZs/mQDiLx1yxZV8v8o93RD+f7fcTqgD3deLOg8NY6cR+2sknMDpz11yReSYuwEai/FyVr1aixGuSFggPhWILXN6kYoYnhE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=TIqoBYbt; arc=none smtp.client-ip=209.85.128.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="TIqoBYbt" Received: by mail-yw1-f174.google.com with SMTP id 00721157ae682-81e9d8f3289so12562287b3.1 for ; Thu, 23 Jul 2026 20:03:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784862212; x=1785467012; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=IaF5CqIxrFrYzvtnmM3XUG1/k+ZVxRgQ9dwMSsHnPJ4=; b=TIqoBYbtQ0CuNxx+Rpt7mcUsOyThaeJL2GJqrq9vFxxKIIWvQw4mUSn/3bICLoadrG tjtCjEDrb+wuTa58ZlkWFG9UG3Fuj9aUI4L4LpHqTZQ0VhAUa44jUYS4fomJw0NOVkfk /E6D6XVTSYFmKfTYddEbc1dsDjUYMiEjQR9CM5g6ANffyDr09ujIHHmYuAkzzZ42ohtJ +6j5+PyeMvye/JnSqagQx9NTNZRNs4nQnNcxpJsosN68SKTRtvgZ5xdm6mtQW3EdRbGJ 247MOx7o6eUzGXimkeNF0VHzq8HBO6Pz2v/fuj70YMnkB/GQofdIGnDgRj9cYBjT+UwL SOJA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784862212; x=1785467012; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=IaF5CqIxrFrYzvtnmM3XUG1/k+ZVxRgQ9dwMSsHnPJ4=; b=eQajYFCPkaW6+pBEjMsoIqDb48AoooPtsRU4SoJCSMky5wj+FypiPf5Lu1Kn4FUmP1 lNKg/whgJ9NL23frEnTWRLdMT+qRKGBbBMcNLcG45MYRqOt84rHr6tvfRyBDrakEKCMV BYb40pl+b8h5ugHwksO0ALr4MpNzft00Yovnvl70xLf19k+ewJAnRXB9zhsXwAyjN79D xNZ1iFNaRtPimbz3gIFu+fzZAPUmphm+pWHk3uKkSKFacNCDKXfBtAnqEDBQS3m1/fOe AFwTn4WIxZbYmn1FIRUHOt+t2/hoPBkasCmzgFEVXC6KWLREhs9vJ/nVAN4Q7e2cnjO+ dbsg== X-Gm-Message-State: AOJu0YyzStCtvq0rXIKdWq5FBCl8apt3QrAeeWQ9EBtYj8QukzYYJ+/y debwo5gkyKdkwAexqhPlUX+4pmSV3zgaQf8u6wMUIb+/0H/Kl/mdmerwHxGH X-Gm-Gg: AR+sD13NmPetVg2v2K2XWVexUinJNgVeEJNkfvOOzy66gO0CSTB+2CKXlG+lo8xsu77 Px/WRpYiCcyNICeqwAYwD4m/NaWyDQmcoM5SkiTPMvEXGByyPlf4bbO7jOkDAY1/07WpPuap4HN iaiFjl53FsDXY1QsS1FWCWop6lGczIqByIQg86zexP6J8pN8FBCP2Vq1xDRkzMn5qh2XAwRBzio tTZsFkS97AJ+nxKhp+M7TYTdzuqGZxqIHc5gtqKm3aJc37Ks/ScEgZdYb7LcmKCBPJNy9hmvrZs FSCZPAk+0PMnKxor3A5J5/drh9AJOkqnNT6fZJv1sivJOxAGjVovbxNcpOFPt7epzC75sV7wrlA oOaCTA23sKzUXsM1FQVdzYsSiPo9Grw0GRRYgmbF2m3sjeOMo/g0eWd/EmSaCDxdVv8ToEg== X-Received: by 2002:a05:690c:6383:b0:80c:85c6:898e with SMTP id 00721157ae682-81f4c38111cmr19098697b3.61.1784862212499; Thu, 23 Jul 2026 20:03:32 -0700 (PDT) Received: from citadel.lan ([2600:6c4a:4df0:2c10::1dba]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81f33c397c9sm37379477b3.14.2026.07.23.20.03.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 23 Jul 2026 20:03:31 -0700 (PDT) From: Brian Gerst To: linux-kernel@vger.kernel.org, x86@kernel.org Cc: Thomas Gleixner , Borislav Petkov , Ard Biesheuvel , Juergen Gross , Tom Lendacky , Brian Gerst Subject: [PATCH 5/5] x86/boot/64: Copy boot parameters and command line earlier Date: Thu, 23 Jul 2026 23:02:56 -0400 Message-ID: <20260724030256.232690-6-brgerst@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260724030256.232690-1-brgerst@gmail.com> References: <20260724030256.232690-1-brgerst@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Move the copy of the boot parameters and command line to the early setup code. This eliminates the need to pass the original pointer to several other functions. By copying the data into kernel memory before encryption is enabled, the original location no longer needs to be remapped as decrypted. Signed-off-by: Brian Gerst Cc: Tom Lendacky --- arch/x86/boot/startup/map_kernel.c | 10 ++--- arch/x86/boot/startup/sme.c | 6 ++- arch/x86/include/asm/mem_encrypt.h | 14 ++----- arch/x86/include/asm/setup.h | 4 +- arch/x86/kernel/asm-offsets.c | 1 + arch/x86/kernel/head64.c | 41 +------------------- arch/x86/kernel/head_64.S | 27 ++++++++----- arch/x86/kernel/setup.c | 1 + arch/x86/kernel/smpboot.c | 2 +- arch/x86/mm/mem_encrypt_amd.c | 61 ------------------------------ 10 files changed, 37 insertions(+), 130 deletions(-) diff --git a/arch/x86/boot/startup/map_kernel.c b/arch/x86/boot/startup/map= _kernel.c index 83ba98d61572..874c91f1b57b 100644 --- a/arch/x86/boot/startup/map_kernel.c +++ b/arch/x86/boot/startup/map_kernel.c @@ -30,15 +30,14 @@ static inline bool check_la57_support(void) return true; } =20 -static unsigned long __init sme_postprocess_startup(struct boot_params *bp, - pmdval_t *pmd, +static unsigned long __init sme_postprocess_startup(pmdval_t *pmd, unsigned long p2v_offset) { unsigned long paddr, paddr_end; int i; =20 /* Encrypt the kernel and related (if SME is active) */ - sme_encrypt_kernel(bp); + sme_encrypt_kernel(); =20 /* * Clear the memory encryption mask from the .bss..decrypted section. @@ -84,8 +83,7 @@ static unsigned long __init sme_postprocess_startup(struc= t boot_params *bp, * the 1:1 mapping of memory. Kernel virtual addresses can be determined by * subtracting p2v_offset from the RIP-relative address. */ -unsigned long __init __startup_64(unsigned long p2v_offset, - struct boot_params *bp) +unsigned long __init __startup_64(unsigned long p2v_offset) { pmd_t (*early_pgts)[PTRS_PER_PMD] =3D rip_rel_ptr(early_dynamic_pgts); unsigned long physaddr =3D (unsigned long)rip_rel_ptr(_text); @@ -213,5 +211,5 @@ unsigned long __init __startup_64(unsigned long p2v_off= set, for (; i < PTRS_PER_PMD; i++) pmd[i] &=3D ~_PAGE_PRESENT; =20 - return sme_postprocess_startup(bp, pmd, p2v_offset); + return sme_postprocess_startup(pmd, p2v_offset); } diff --git a/arch/x86/boot/startup/sme.c b/arch/x86/boot/startup/sme.c index c07a2c381ed1..2a6208254fa3 100644 --- a/arch/x86/boot/startup/sme.c +++ b/arch/x86/boot/startup/sme.c @@ -283,8 +283,9 @@ static unsigned long __init sme_pgtable_calc(unsigned l= ong len) return entries + tables; } =20 -void __init sme_encrypt_kernel(struct boot_params *bp) +void __init sme_encrypt_kernel(void) { + struct boot_params *bp =3D rip_rel_ptr(&boot_params); unsigned long workarea_start, workarea_end, workarea_len; unsigned long execute_start, execute_end, execute_len; unsigned long kernel_start, kernel_end, kernel_len; @@ -487,8 +488,9 @@ void __init sme_encrypt_kernel(struct boot_params *bp) native_write_cr3(__native_read_cr3()); } =20 -void __init sme_enable(struct boot_params *bp) +void __init sme_enable(void) { + struct boot_params *bp =3D rip_rel_ptr(&boot_params); unsigned int eax, ebx, ecx, edx; unsigned long feature_mask; unsigned long me_mask; diff --git a/arch/x86/include/asm/mem_encrypt.h b/arch/x86/include/asm/mem_= encrypt.h index ea6494628cb0..72b63b4a0dcb 100644 --- a/arch/x86/include/asm/mem_encrypt.h +++ b/arch/x86/include/asm/mem_encrypt.h @@ -42,13 +42,10 @@ void __init sme_early_encrypt(resource_size_t paddr, void __init sme_early_decrypt(resource_size_t paddr, unsigned long size); =20 -void __init sme_map_bootdata(char *real_mode_data); -void __init sme_unmap_bootdata(char *real_mode_data); - void __init sme_early_init(void); =20 -void sme_encrypt_kernel(struct boot_params *bp); -void sme_enable(struct boot_params *bp); +void sme_encrypt_kernel(void); +void sme_enable(void); =20 int __init early_set_memory_decrypted(unsigned long vaddr, unsigned long s= ize); int __init early_set_memory_encrypted(unsigned long vaddr, unsigned long s= ize); @@ -76,13 +73,10 @@ static inline void __init sme_early_encrypt(resource_si= ze_t paddr, static inline void __init sme_early_decrypt(resource_size_t paddr, unsigned long size) { } =20 -static inline void __init sme_map_bootdata(char *real_mode_data) { } -static inline void __init sme_unmap_bootdata(char *real_mode_data) { } - static inline void __init sme_early_init(void) { } =20 -static inline void sme_encrypt_kernel(struct boot_params *bp) { } -static inline void sme_enable(struct boot_params *bp) { } +static inline void sme_encrypt_kernel(void) { } +static inline void sme_enable(void) { } =20 static inline void sev_es_init_vc_handling(void) { } =20 diff --git a/arch/x86/include/asm/setup.h b/arch/x86/include/asm/setup.h index 18a4d3826af7..0e867910b29b 100644 --- a/arch/x86/include/asm/setup.h +++ b/arch/x86/include/asm/setup.h @@ -47,7 +47,7 @@ extern unsigned long acpi_realmode_flags; =20 extern void reserve_standard_io_resources(void); extern void i386_reserve_resources(void); -extern unsigned long __startup_64(unsigned long p2v_offset, struct boot_pa= rams *bp); +extern unsigned long __startup_64(unsigned long p2v_offset); extern void startup_64_setup_gdt_idt(void); extern void startup_64_load_idt(void *vc_handler); extern void __pi_startup_64_load_idt(void *vc_handler); @@ -129,7 +129,7 @@ asmlinkage void __init __noreturn i386_start_kernel(voi= d); void __init mk_early_pgtbl_32(void); =20 #else -asmlinkage void __init __noreturn x86_64_start_kernel(char *real_mode); +asmlinkage void __init __noreturn x86_64_start_kernel(void); asmlinkage void __init __noreturn x86_64_start_reservations(void); =20 #endif /* __i386__ */ diff --git a/arch/x86/kernel/asm-offsets.c b/arch/x86/kernel/asm-offsets.c index 0c49bb50188d..c7a2c210aaac 100644 --- a/arch/x86/kernel/asm-offsets.c +++ b/arch/x86/kernel/asm-offsets.c @@ -106,6 +106,7 @@ static void __used common(void) OFFSET(BP_init_size, boot_params, hdr.init_size); OFFSET(BP_pref_address, boot_params, hdr.pref_address); OFFSET(BP_cmd_line_ptr, boot_params, hdr.cmd_line_ptr); + OFFSET(BP_ext_cmd_line_ptr, boot_params, ext_cmd_line_ptr); DEFINE(SIZEOF_boot_params, sizeof(struct boot_params)); =20 BLANK(); diff --git a/arch/x86/kernel/head64.c b/arch/x86/kernel/head64.c index d895376e9346..b4d5c7b7dc58 100644 --- a/arch/x86/kernel/head64.c +++ b/arch/x86/kernel/head64.c @@ -172,44 +172,7 @@ void __init do_early_exception(struct pt_regs *regs, i= nt trapnr) early_fixup_exception(regs, trapnr); } =20 -static unsigned long get_cmd_line_ptr(void) -{ - unsigned long cmd_line_ptr =3D boot_params.hdr.cmd_line_ptr; - - cmd_line_ptr |=3D (u64)boot_params.ext_cmd_line_ptr << 32; - - return cmd_line_ptr; -} - -static void __init copy_bootdata(char *real_mode_data) -{ - char * command_line; - unsigned long cmd_line_ptr; - - /* - * If SME is active, this will create decrypted mappings of the - * boot data in advance of the copy operations. - */ - sme_map_bootdata(real_mode_data); - - memcpy(&boot_params, real_mode_data, sizeof(boot_params)); - sanitize_boot_params(&boot_params); - cmd_line_ptr =3D get_cmd_line_ptr(); - if (cmd_line_ptr) { - command_line =3D __va(cmd_line_ptr); - memcpy(boot_command_line, command_line, COMMAND_LINE_SIZE); - } - - /* - * The old boot data is no longer needed and won't be reserved, - * freeing up that memory for use by the system. If SME is active, - * we need to remove the mappings that were created so that the - * memory doesn't remain mapped as decrypted. - */ - sme_unmap_bootdata(real_mode_data); -} - -asmlinkage __visible void __init __noreturn x86_64_start_kernel(char * rea= l_mode_data) +asmlinkage __visible void __init __noreturn x86_64_start_kernel(void) { /* * Build-time sanity checks on the kernel image and module @@ -266,7 +229,7 @@ asmlinkage __visible void __init __noreturn x86_64_star= t_kernel(char * real_mode /* Needed before cc_platform_has() can be used for TDX */ tdx_early_init(); =20 - copy_bootdata(__va(real_mode_data)); + sanitize_boot_params(&boot_params); =20 /* * Load microcode early on BSP. diff --git a/arch/x86/kernel/head_64.S b/arch/x86/kernel/head_64.S index 15ef5ea52b9a..58b5a2654c2b 100644 --- a/arch/x86/kernel/head_64.S +++ b/arch/x86/kernel/head_64.S @@ -27,6 +27,7 @@ #include #include #include +#include =20 /* * We are not able to switch in one step to the final KERNEL ADDRESS SPACE @@ -65,6 +66,22 @@ SYM_CODE_START_NOALIGN(startup_64) =20 call clear_bss =20 + /* Copy the boot parameters and command line into kernel memory. */ + movq %r15, %rsi + leaq boot_params(%rip), %rdi + movl $(SIZEOF_boot_params / 4), %ecx + rep movsl + + movl boot_params + BP_cmd_line_ptr(%rip), %esi + movl boot_params + BP_ext_cmd_line_ptr(%rip), %eax + shlq $32, %rax + orq %rax, %rsi + jz .Lno_command_line + leaq boot_command_line(%rip), %rdi + movl $(COMMAND_LINE_SIZE / 4), %ecx + rep movsl +.Lno_command_line: + /* * Set up GSBASE. * Note that on SMP the boot CPU uses the init data section until @@ -92,9 +109,8 @@ SYM_CODE_START_NOALIGN(startup_64) * Activate SEV/SME memory encryption if supported/enabled. This needs to * be done now, since this also includes setup of the SEV-SNP CPUID table, * which needs to be done before any CPUID instructions are executed in - * subsequent code. Pass the boot_params pointer as the first argument. + * subsequent code. */ - movq %r15, %rdi call __pi_sme_enable #endif =20 @@ -114,7 +130,6 @@ SYM_CODE_START_NOALIGN(startup_64) * is active) to be added to the initial pgdir entry that will be * programmed into CR3. */ - movq %r15, %rsi call __pi___startup_64 =20 /* Form the CR3 value being sure to include the CR3 modifier */ @@ -195,9 +210,6 @@ SYM_INNER_LABEL(secondary_startup_64_no_verify, SYM_L_G= LOBAL) UNWIND_HINT_END_OF_STACK ANNOTATE_NOENDBR =20 - /* Clear %R15 which holds the boot_params pointer on the boot CPU */ - xorl %r15d, %r15d - /* Derive the runtime physical address of init_top_pgt[] */ movq phys_base(%rip), %rax addq $(init_top_pgt - __START_KERNEL_map), %rax @@ -429,9 +441,6 @@ SYM_INNER_LABEL(common_startup_64, SYM_L_LOCAL) pushq $0 popfq =20 - /* Pass the boot_params pointer as first argument */ - movq %r15, %rdi - .Ljump_to_C_code: xorl %ebp, %ebp # clear frame pointer ANNOTATE_RETPOLINE_SAFE diff --git a/arch/x86/kernel/setup.c b/arch/x86/kernel/setup.c index 46882ce79c3a..bd9d42767c8c 100644 --- a/arch/x86/kernel/setup.c +++ b/arch/x86/kernel/setup.c @@ -77,6 +77,7 @@ unsigned long _brk_start =3D (unsigned long)__brk_base; unsigned long _brk_end =3D (unsigned long)__brk_base; =20 struct boot_params boot_params; +SYM_PIC_ALIAS(boot_params); =20 /* * These are the four main kernel memory regions, we put them into diff --git a/arch/x86/kernel/smpboot.c b/arch/x86/kernel/smpboot.c index ba01a9e919b7..06287eed5cbc 100644 --- a/arch/x86/kernel/smpboot.c +++ b/arch/x86/kernel/smpboot.c @@ -226,7 +226,7 @@ static void ap_calibrate_delay(void) /* * Activate a secondary processor. */ -static void notrace __noendbr start_secondary(void *unused) +static void notrace __noendbr start_secondary(void) { /* * Don't put *anything* except direct CPU state initialization diff --git a/arch/x86/mm/mem_encrypt_amd.c b/arch/x86/mm/mem_encrypt_amd.c index d39e1e29bcb9..877d4d85c949 100644 --- a/arch/x86/mm/mem_encrypt_amd.c +++ b/arch/x86/mm/mem_encrypt_amd.c @@ -153,67 +153,6 @@ void __init sme_early_decrypt(resource_size_t paddr, u= nsigned long size) __sme_early_enc_dec(paddr, size, false); } =20 -static void __init __sme_early_map_unmap_mem(void *vaddr, unsigned long si= ze, - bool map) -{ - unsigned long paddr =3D (unsigned long)vaddr - __PAGE_OFFSET; - pmdval_t pmd_flags, pmd; - - /* Use early_pmd_flags but remove the encryption mask */ - pmd_flags =3D __sme_clr(early_pmd_flags); - - do { - pmd =3D map ? (paddr & PMD_MASK) + pmd_flags : 0; - __early_make_pgtable((unsigned long)vaddr, pmd); - - vaddr +=3D PMD_SIZE; - paddr +=3D PMD_SIZE; - size =3D (size <=3D PMD_SIZE) ? 0 : size - PMD_SIZE; - } while (size); - - flush_tlb_local(); -} - -void __init sme_unmap_bootdata(char *real_mode_data) -{ - struct boot_params *boot_data; - unsigned long cmdline_paddr; - - if (!cc_platform_has(CC_ATTR_HOST_MEM_ENCRYPT)) - return; - - /* Get the command line address before unmapping the real_mode_data */ - boot_data =3D (struct boot_params *)real_mode_data; - cmdline_paddr =3D boot_data->hdr.cmd_line_ptr | ((u64)boot_data->ext_cmd_= line_ptr << 32); - - __sme_early_map_unmap_mem(real_mode_data, sizeof(boot_params), false); - - if (!cmdline_paddr) - return; - - __sme_early_map_unmap_mem(__va(cmdline_paddr), COMMAND_LINE_SIZE, false); -} - -void __init sme_map_bootdata(char *real_mode_data) -{ - struct boot_params *boot_data; - unsigned long cmdline_paddr; - - if (!cc_platform_has(CC_ATTR_HOST_MEM_ENCRYPT)) - return; - - __sme_early_map_unmap_mem(real_mode_data, sizeof(boot_params), true); - - /* Get the command line address after mapping the real_mode_data */ - boot_data =3D (struct boot_params *)real_mode_data; - cmdline_paddr =3D boot_data->hdr.cmd_line_ptr | ((u64)boot_data->ext_cmd_= line_ptr << 32); - - if (!cmdline_paddr) - return; - - __sme_early_map_unmap_mem(__va(cmdline_paddr), COMMAND_LINE_SIZE, true); -} - static unsigned long pg_level_to_pfn(int level, pte_t *kpte, pgprot_t *ret= _prot) { unsigned long pfn =3D 0; --=20 2.55.0