From nobody Sat Sep 26 09:19:18 2026 Received: from mail-pg1-f198.google.com (mail-pg1-f198.google.com [209.85.215.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1AFD44AD4A3 for ; Wed, 2 Sep 2026 19:13:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788376408; cv=none; b=iNqUpT+P2sw5dVnZa62OBfNh/eVxdK9H8InhmgBuzE0ggp4hhkKjhJZqfEckXbNgefCPN/VdEONs3VwYj181ineeNpLMmkD88G9OHg163Wnwtgta5BtSrhDbc0JAhZfGFzRnDUZrMa7jr/5izdVvpFjP2OkO4lQfRCJfxpKrasI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788376408; c=relaxed/simple; bh=PFLrtI8FJvq4Xkwov+zqiL8iQ5uTOI2l8tCCPKjbTGI=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=Nra4NZoW66A+agbOJhCc2yq+frhsYBD84nU8sqYC27j1/nAzAvkHF17UjMytivQAtKmTvXk8BJTig129d+m2IzmM36GvtRmLwCK2hZiWozV96Xekh80B7vvJxls4yA9Ag0g3OZglcnxuGS3/lf1DlowGF4wXewC1FhecZLkhFAo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=roXYkCXy; arc=none smtp.client-ip=209.85.215.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="roXYkCXy" Received: by mail-pg1-f198.google.com with SMTP id 41be03b00d2f7-cc18ced1a5aso2761719a12.1 for ; Wed, 02 Sep 2026 12:13:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788376406; x=1788981206; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=S7KYRpQb2qK2BMI5cWRKmHlXxuXkcNUnDHM16soIFqI=; b=roXYkCXyCM54SxblsxpNDxG7DTcbgBC2NUUrkjgEQQwmBuwkGl3mNZ+o4BTHni3453 M0qV3jll1d6S2c+aTs8ULsgQ2O4Orov5SXxVpCefk4aJUu0jaabCwB8dkVGfXcvTW9m7 VyWClN7K6IWV1c5NWj3E6AekQTuzCnp8+tsSLUw7sj8sCOeaJFK5R3uFaxO/nphbZehi Z4mHutAwcq9euC3d8tjnZnP6jQ/VZpV19rJBNyhL/L4yKEC0Vkte9uLOeUlDwrMdIozo SHv58xx47ZG8/wvmTpgKzlq1wB5iJb32kAuZy6RDSU9weB6m77NY1XGn/lNMK/efA/DH +1Ng== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788376406; x=1788981206; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=S7KYRpQb2qK2BMI5cWRKmHlXxuXkcNUnDHM16soIFqI=; b=JRAlckzyRptuvIazmQxPXuJyam8gdPNgk6riF8bXNMzKCrEhu2OGC98MZk9wHnrmDC V7G4GiF3vIG8TsIbfPa2ule30KI/J5YE6PXp4f2svq1IKX1Pqh2K0uakQXFbXvflR3re 1T+X3IHbbGqmF8EUFv7g20jMf3/13xQlHukrdHJ1rb99T2RytV3J3xN+zM3bQ6cohXw7 RUmPmC0Yz1jis6MYacE2lRtbwKSftOOmrkkegX45f8cZsiXlSsU9B0Rd2WR/0I3Sl4zz QDUakHMC+6+gTwVtEBLoF16pl6OSsrIzk41F8MSCYKGDmqfZP+SPMgLXjFra/N3J5RxB AqAg== X-Forwarded-Encrypted: i=1; AKwUvBwqVST4rmA/TUoWKhnRJgGZm4s5S8jcM7qqQxPtQOLXtoN4/UA1KJMinRYY+19YdDytaA1KnQuwHFkCpLk=@vger.kernel.org X-Gm-Message-State: AFuF++m7dj7VfB7LoLBHcwH4hpGhdby0FII2uHTsYB15i3u3mU2/j38l LcJkJPnx8EN4wtCGVzLsoXzAJCoElpGEKDhAr6dwqd6KD9YCRkAjSeJa3rs/f3kJfZGOQvnfSnm TQyPEkg== X-Received: from pjbhk14.prod.google.com ([2002:a17:90b:224e:b0:398:cd79:3b48]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:4b8b:b0:398:9be5:b419 with SMTP id 98e67ed59e1d1-39aee1c9b76mr7984963a91.20.1788376405725; Wed, 02 Sep 2026 12:13:25 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 2 Sep 2026 12:13:20 -0700 In-Reply-To: <20260902191321.2644150-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260821-stable-item001-snp-builtin-kvm@kernel.org> <20260902191321.2644150-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.970.g62bdec98f9-goog Message-ID: <20260902191321.2644150-2-seanjc@google.com> Subject: [PATCH 6.12.y 1/2] iommu/amd: remove return value of amd_iommu_detect From: Sean Christopherson To: stable@vger.kernel.org, Greg Kroah-Hartman , Sasha Levin Cc: "H. Peter Anvin" , Suravee Suthikulpanit , Robin Murphy , linux-kernel@vger.kernel.org, iommu@lists.linux.dev, Gao Shiyuan , Vasant Hegde , Joerg Roedel , Sean Christopherson , Stable@vger.kernel.org, Ashish Kalra , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, Joerg Roedel , Will Deacon Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Gao Shiyuan [ Upstream commit 5bb494d5cbb9a3403ba8b1c8bc145b42fc119078 ] The return value of amd_iommu_detect is not used, so remove it and is consistent with other iommu detect functions. Signed-off-by: Gao Shiyuan Reviewed-by: Vasant Hegde Link: https://lore.kernel.org/r/20250103165808.80939-1-gaoshiyuan@baidu.com Signed-off-by: Joerg Roedel Signed-off-by: Sean Christopherson --- drivers/iommu/amd/init.c | 10 ++++------ include/linux/amd-iommu.h | 4 ++-- 2 files changed, 6 insertions(+), 8 deletions(-) diff --git a/drivers/iommu/amd/init.c b/drivers/iommu/amd/init.c index 36a814b6c4de..0e270533bf12 100644 --- a/drivers/iommu/amd/init.c +++ b/drivers/iommu/amd/init.c @@ -3484,25 +3484,23 @@ static bool amd_iommu_sme_check(void) * IOMMUs * *************************************************************************= ***/ -int __init amd_iommu_detect(void) +void __init amd_iommu_detect(void) { int ret; =20 if (no_iommu || (iommu_detected && !gart_iommu_aperture)) - return -ENODEV; + return; =20 if (!amd_iommu_sme_check()) - return -ENODEV; + return; =20 ret =3D iommu_go_to_state(IOMMU_IVRS_DETECTED); if (ret) - return ret; + return; =20 amd_iommu_detected =3D true; iommu_detected =3D 1; x86_init.iommu.iommu_init =3D amd_iommu_init; - - return 1; } =20 /*************************************************************************= *** diff --git a/include/linux/amd-iommu.h b/include/linux/amd-iommu.h index 2b90c48a6a87..062fbd4c9b77 100644 --- a/include/linux/amd-iommu.h +++ b/include/linux/amd-iommu.h @@ -31,11 +31,11 @@ struct amd_iommu_pi_data { struct task_struct; struct pci_dev; =20 -extern int amd_iommu_detect(void); +extern void amd_iommu_detect(void); =20 #else /* CONFIG_AMD_IOMMU */ =20 -static inline int amd_iommu_detect(void) { return -ENODEV; } +static inline void amd_iommu_detect(void) { } =20 #endif /* CONFIG_AMD_IOMMU */ =20 --=20 2.55.0.970.g62bdec98f9-goog From nobody Sat Sep 26 09:19:18 2026 Received: from mail-pf1-f199.google.com (mail-pf1-f199.google.com [209.85.210.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 10DC64ACC86 for ; Wed, 2 Sep 2026 19:13:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788376410; cv=none; b=LRA80PBgNrA5842Si2bdLJcQ+5EgQ4zAeG5Nvhicf++U5nhj7G4vZ8wl3rv9Z3/LUSsIo5HlWUI1O6g8ReOplO6KPViTOfbUldW/41xblKlEu0uhwiVO6v82m72kTmMHrNWSYc+dtoZPjC9VYHhsskwlQ68giSzU//reYBDJqvg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788376410; c=relaxed/simple; bh=heFBTe4Azj4loNK0+guseUepFSEbMsjiIjxwRabDFvk=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=lA+NFyy75/+XNjX6hBVWrqfHdkJ59M4aLV0r5B+qo44d3eRCUL2Vf4yEz7X1qH/7YEVU1FDaRkGOFH/y77kQSMjEGWKinwUGH/85q9sP5Ug2asseLdbUfCPfZ2I1fQiC7EI2mCVyeZgYTomPGokWr2ehEaghZIBT4Vy5gWVM/cU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=nVro9Cha; arc=none smtp.client-ip=209.85.210.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="nVro9Cha" Received: by mail-pf1-f199.google.com with SMTP id d2e1a72fcca58-84a67b16217so2432501b3a.3 for ; Wed, 02 Sep 2026 12:13:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788376407; x=1788981207; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=FR4OS7s1XbcA2FA5sOcuBurTuZ/ng9SBzZ/wefEfnhg=; b=nVro9ChaGMFPcL3LaOZgEFYwMy+Isud+a24GCgLUOji9ZzKIkwEWtYg5w1tC/SWAOY fO7gauZw+qEqP7/GAq7eNjgorAyMdmrZM/qKLYO7CnDlXyRec/BEACAZmV+HpSKWpSd3 TRUWZ9rhJ9mTmtF/sU6DkXR1B4fZzjckexvZK89Bz4M0DWmYqtiqNRCAu6SmUkV9AWcy j8clz7a4kUdao9x9NwgAo+I82vux8BDM9mgmEbPSY1S1VtYI/yMz7uPAmNzeLt8JsHX4 8YgoE7pIs7mgeRTeME2OIc1MGRVhknBvX/ovjzF5BCu/qMsG75ge6Ou/4y13/d7yi4JP x5sg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788376407; x=1788981207; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=FR4OS7s1XbcA2FA5sOcuBurTuZ/ng9SBzZ/wefEfnhg=; b=Y2Xf6LsKI0y5clzrL4svbwbv56QdOlafBaPf6HEAZZ5ZainZpJjuhkWPY3I8DMkm9M uLuY6Eirzp9ezL2YLEElB1dQ3f+rDpTYUnO0qwOp3Qvx2Fzj5Wef87ih1sfT6UBI0Dfd NbrUBbYlCczS3rLJPefhFGaePt+FdIeF66W2ENxl7cE6MrZw7GEbLrpsQv5ZefjDeT/+ IbLNaPGChRce+SiPE8MOAwhGtMJbCj9it+5Iwpx1jBcSCAZDZkIhzk2CLP7HdxjHKnjZ UZApMvcVx+OlVuXNDCaAhldNXnS4sNmtbDnMCx9ewtsg6z14DTOCro3LBQexIyDrVGvn um6Q== X-Forwarded-Encrypted: i=1; AKwUvBzCZdCaCfIq8o0tOb66si82c5yiS8431UZz5Ml4AaOdQHiIsofAjH6ATRJI01jf8W/lmTwc+AFta0yZIyk=@vger.kernel.org X-Gm-Message-State: AFuF++kEcUiK/vpUm/e3/A564z00cLU94VOp1nAJKcoOpUkExn8c9pMm mWWaWPpMHT1wGgpX7b7hEpkJlpxgV8nychhKyo5ZN6Mmg9hpzFwipzUJkI9lB3aIctnlQx5euGu KCZTGFQ== X-Received: from pfj21.prod.google.com ([2002:a05:6a00:a415:b0:84a:3bc9:3bcd]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:4287:b0:857:7337:5db5 with SMTP id d2e1a72fcca58-85ed98b4d7amr11675821b3a.19.1788376407043; Wed, 02 Sep 2026 12:13:27 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 2 Sep 2026 12:13:21 -0700 In-Reply-To: <20260902191321.2644150-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260821-stable-item001-snp-builtin-kvm@kernel.org> <20260902191321.2644150-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.970.g62bdec98f9-goog Message-ID: <20260902191321.2644150-3-seanjc@google.com> Subject: [PATCH 6.12.y 2/2] x86/sev: Fix broken SNP support with KVM module built-in From: Sean Christopherson To: stable@vger.kernel.org, Greg Kroah-Hartman , Sasha Levin Cc: "H. Peter Anvin" , Suravee Suthikulpanit , Robin Murphy , linux-kernel@vger.kernel.org, iommu@lists.linux.dev, Gao Shiyuan , Vasant Hegde , Joerg Roedel , Sean Christopherson , Stable@vger.kernel.org, Ashish Kalra , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, Joerg Roedel , Will Deacon Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ashish Kalra [ Upstream commit 409f45387c937145adeeeebc6d6032c2ec232b35 ] Fix issues with enabling SNP host support and effectively SNP support which is broken with respect to the KVM module being built-in. SNP host support is enabled in snp_rmptable_init() which is invoked as device_initcall(). SNP check on IOMMU is done during IOMMU PCI init (IOMMU_PCI_INIT stage). And for that reason snp_rmptable_init() is currently invoked via device_initcall() and cannot be invoked via subsys_initcall() as core IOMMU subsystem gets initialized via subsys_initcall(). Now, if kvm_amd module is built-in, it gets initialized before SNP host support is enabled in snp_rmptable_init() : [ 10.131811] kvm_amd: TSC scaling supported [ 10.136384] kvm_amd: Nested Virtualization enabled [ 10.141734] kvm_amd: Nested Paging enabled [ 10.146304] kvm_amd: LBR virtualization supported [ 10.151557] kvm_amd: SEV enabled (ASIDs 100 - 509) [ 10.156905] kvm_amd: SEV-ES enabled (ASIDs 1 - 99) [ 10.162256] kvm_amd: SEV-SNP enabled (ASIDs 1 - 99) [ 10.171508] kvm_amd: Virtual VMLOAD VMSAVE supported [ 10.177052] kvm_amd: Virtual GIF supported ... ... [ 10.201648] kvm_amd: in svm_enable_virtualization_cpu And then svm_x86_ops->enable_virtualization_cpu() (svm_enable_virtualization_cpu) programs MSR_VM_HSAVE_PA as following: wrmsrl(MSR_VM_HSAVE_PA, sd->save_area_pa); So VM_HSAVE_PA is non-zero before SNP support is enabled on all CPUs. snp_rmptable_init() gets invoked after svm_enable_virtualization_cpu() as following : ... [ 11.256138] kvm_amd: in svm_enable_virtualization_cpu ... [ 11.264918] SEV-SNP: in snp_rmptable_init This triggers a #GP exception in snp_rmptable_init() when snp_enable() is invoked to set SNP_EN in SYSCFG MSR: [ 11.294289] unchecked MSR access error: WRMSR to 0xc0010010 (tried to wr= ite 0x0000000003fc0000) at rIP: 0xffffffffaf5d5c28 (native_write_msr+0x8/0x= 30) ... [ 11.294404] Call Trace: [ 11.294482] [ 11.294513] ? show_stack_regs+0x26/0x30 [ 11.294522] ? ex_handler_msr+0x10f/0x180 [ 11.294529] ? search_extable+0x2b/0x40 [ 11.294538] ? fixup_exception+0x2dd/0x340 [ 11.294542] ? exc_general_protection+0x14f/0x440 [ 11.294550] ? asm_exc_general_protection+0x2b/0x30 [ 11.294557] ? __pfx_snp_enable+0x10/0x10 [ 11.294567] ? native_write_msr+0x8/0x30 [ 11.294570] ? __snp_enable+0x5d/0x70 [ 11.294575] snp_enable+0x19/0x20 [ 11.294578] __flush_smp_call_function_queue+0x9c/0x3a0 [ 11.294586] generic_smp_call_function_single_interrupt+0x17/0x20 [ 11.294589] __sysvec_call_function+0x20/0x90 [ 11.294596] sysvec_call_function+0x80/0xb0 [ 11.294601] [ 11.294603] [ 11.294605] asm_sysvec_call_function+0x1f/0x30 ... [ 11.294631] arch_cpu_idle+0xd/0x20 [ 11.294633] default_idle_call+0x34/0xd0 [ 11.294636] do_idle+0x1f1/0x230 [ 11.294643] ? complete+0x71/0x80 [ 11.294649] cpu_startup_entry+0x30/0x40 [ 11.294652] start_secondary+0x12d/0x160 [ 11.294655] common_startup_64+0x13e/0x141 [ 11.294662] This #GP exception is getting triggered due to the following errata for AMD family 19h Models 10h-1Fh Processors: Processor may generate spurious #GP(0) Exception on WRMSR instruction: Description: The Processor will generate a spurious #GP(0) Exception on a WRMSR instruction if the following conditions are all met: - the target of the WRMSR is a SYSCFG register. - the write changes the value of SYSCFG.SNPEn from 0 to 1. - One of the threads that share the physical core has a non-zero value in the VM_HSAVE_PA MSR. The document being referred to above: https://www.amd.com/content/dam/amd/en/documents/processor-tech-docs/revisi= on-guides/57095-PUB_1_01.pdf To summarize, with kvm_amd module being built-in, KVM/SVM initialization happens before host SNP is enabled and this SVM initialization sets VM_HSAVE_PA to non-zero, which then triggers a #GP when SYSCFG.SNPEn is being set and this will subsequently cause SNP_INIT(_EX) to fail with INVALID_CONFIG error as SYSCFG[SnpEn] is not set on all CPUs. Essentially SNP host enabling code should be invoked before KVM initialization, which is currently not the case when KVM is built-in. Add fix to call snp_rmptable_init() early from iommu_snp_enable() directly and not invoked via device_initcall() which enables SNP host support before KVM initialization with kvm_amd module built-in. Add additional handling for `iommu=3Doff` or `amd_iommu=3Doff` options. Note that IOMMUs need to be enabled for SNP initialization, therefore, if host SNP support is enabled but late IOMMU initialization fails then that will cause PSP driver's SNP_INIT to fail as IOMMU SNP sanity checks in SNP firmware will fail with invalid configuration error as below: [ 9.723114] ccp 0000:23:00.1: sev enabled [ 9.727602] ccp 0000:23:00.1: psp enabled [ 9.732527] ccp 0000:a2:00.1: enabling device (0000 -> 0002) [ 9.739098] ccp 0000:a2:00.1: no command queues available [ 9.745167] ccp 0000:a2:00.1: psp enabled [ 9.805337] ccp 0000:23:00.1: SEV-SNP: failed to INIT rc -5, error 0x3 [ 9.866426] ccp 0000:23:00.1: SEV API:1.53 build:5 Fixes: c3b86e61b756 ("x86/cpufeatures: Enable/unmask SEV-SNP CPU feature") Co-developed-by: Sean Christopherson Signed-off-by: Sean Christopherson Co-developed-by: Vasant Hegde Signed-off-by: Vasant Hegde Cc: Signed-off-by: Ashish Kalra Acked-by: Joerg Roedel Message-ID: <138b520fb83964782303b43ade4369cd181fdd9c.1739226950.git.ashish= .kalra@amd.com> Signed-off-by: Paolo Bonzini [sean: handcode/port the sev.c changes] Signed-off-by: Sean Christopherson --- arch/x86/include/asm/sev.h | 2 ++ arch/x86/virt/svm/sev.c | 21 ++++++--------------- drivers/iommu/amd/init.c | 34 ++++++++++++++++++++++++++++++---- 3 files changed, 38 insertions(+), 19 deletions(-) diff --git a/arch/x86/include/asm/sev.h b/arch/x86/include/asm/sev.h index ee34ab00a8d6..2524ada3708e 100644 --- a/arch/x86/include/asm/sev.h +++ b/arch/x86/include/asm/sev.h @@ -440,6 +440,7 @@ static inline void snp_update_svsm_ca(void) { } =20 #ifdef CONFIG_KVM_AMD_SEV bool snp_probe_rmptable_info(void); +int snp_rmptable_init(void); int snp_lookup_rmpentry(u64 pfn, bool *assigned, int *level); void snp_dump_hva_rmpentry(unsigned long address); int psmash(u64 pfn); @@ -450,6 +451,7 @@ void kdump_sev_callback(void); void snp_fixup_e820_tables(void); #else static inline bool snp_probe_rmptable_info(void) { return false; } +static inline int snp_rmptable_init(void) { return -ENOSYS; } static inline int snp_lookup_rmpentry(u64 pfn, bool *assigned, int *level)= { return -ENODEV; } static inline void snp_dump_hva_rmpentry(unsigned long address) {} static inline int psmash(u64 pfn) { return -ENODEV; } diff --git a/arch/x86/virt/svm/sev.c b/arch/x86/virt/svm/sev.c index 9a6a943d8e41..738698390ebf 100644 --- a/arch/x86/virt/svm/sev.c +++ b/arch/x86/virt/svm/sev.c @@ -189,7 +189,7 @@ void __init snp_fixup_e820_tables(void) * described in the SNP_INIT_EX firmware command description in the SNP * firmware ABI spec. */ -static int __init snp_rmptable_init(void) +int __init snp_rmptable_init(void) { u64 max_rmp_pfn, calc_rmp_sz, rmptable_size, rmp_end, val; void *rmptable_start; @@ -197,11 +197,11 @@ static int __init snp_rmptable_init(void) if (!cc_platform_has(CC_ATTR_HOST_SEV_SNP)) return 0; =20 - if (!amd_iommu_snp_en) - goto nosnp; + if (WARN_ON_ONCE(!amd_iommu_snp_en)) + return -ENOSYS; =20 if (!probed_rmp_size) - goto nosnp; + return -ENOSYS; =20 rmp_end =3D probed_rmp_base + probed_rmp_size - 1; =20 @@ -218,13 +218,13 @@ static int __init snp_rmptable_init(void) if (calc_rmp_sz > probed_rmp_size) { pr_err("Memory reserved for the RMP table does not cover full system RAM= (expected 0x%llx got 0x%llx)\n", calc_rmp_sz, probed_rmp_size); - goto nosnp; + return -ENOSYS; } =20 rmptable_start =3D memremap(probed_rmp_base, probed_rmp_size, MEMREMAP_WB= ); if (!rmptable_start) { pr_err("Failed to map RMP table\n"); - goto nosnp; + return -ENOSYS; } =20 /* @@ -261,17 +261,8 @@ static int __init snp_rmptable_init(void) crash_kexec_post_notifiers =3D true; =20 return 0; - -nosnp: - cc_platform_clear(CC_ATTR_HOST_SEV_SNP); - return -ENOSYS; } =20 -/* - * This must be called after the IOMMU has been initialized. - */ -device_initcall(snp_rmptable_init); - static struct rmpentry *get_rmpentry(u64 pfn) { if (WARN_ON_ONCE(pfn > rmptable_max_pfn)) diff --git a/drivers/iommu/amd/init.c b/drivers/iommu/amd/init.c index 0e270533bf12..54f3c17520d5 100644 --- a/drivers/iommu/amd/init.c +++ b/drivers/iommu/amd/init.c @@ -3219,7 +3219,7 @@ static bool __init detect_ivrs(void) return true; } =20 -static void iommu_snp_enable(void) +static __init void iommu_snp_enable(void) { #ifdef CONFIG_KVM_AMD_SEV if (!cc_platform_has(CC_ATTR_HOST_SEV_SNP)) @@ -3244,6 +3244,14 @@ static void iommu_snp_enable(void) goto disable_snp; } =20 + /* + * Enable host SNP support once SNP support is checked on IOMMU. + */ + if (snp_rmptable_init()) { + pr_warn("SNP: RMP initialization failed, SNP cannot be supported.\n"); + goto disable_snp; + } + pr_info("IOMMU SNP support enabled.\n"); return; =20 @@ -3381,6 +3389,19 @@ static int __init iommu_go_to_state(enum iommu_init_= state state) ret =3D state_next(); } =20 + /* + * SNP platform initilazation requires IOMMUs to be fully configured. + * If the SNP support on IOMMUs has NOT been checked, simply mark SNP + * as unsupported. If the SNP support on IOMMUs has been checked and + * host SNP support enabled but RMP enforcement has not been enabled + * in IOMMUs, then the system is in a half-baked state, but can limp + * along as all memory should be Hypervisor-Owned in the RMP. WARN, + * but leave SNP as "supported" to avoid confusing the kernel. + */ + if (ret && cc_platform_has(CC_ATTR_HOST_SEV_SNP) && + !WARN_ON_ONCE(amd_iommu_snp_en)) + cc_platform_clear(CC_ATTR_HOST_SEV_SNP); + return ret; } =20 @@ -3489,18 +3510,23 @@ void __init amd_iommu_detect(void) int ret; =20 if (no_iommu || (iommu_detected && !gart_iommu_aperture)) - return; + goto disable_snp; =20 if (!amd_iommu_sme_check()) - return; + goto disable_snp; =20 ret =3D iommu_go_to_state(IOMMU_IVRS_DETECTED); if (ret) - return; + goto disable_snp; =20 amd_iommu_detected =3D true; iommu_detected =3D 1; x86_init.iommu.iommu_init =3D amd_iommu_init; + return; + +disable_snp: + if (cc_platform_has(CC_ATTR_HOST_SEV_SNP)) + cc_platform_clear(CC_ATTR_HOST_SEV_SNP); } =20 /*************************************************************************= *** --=20 2.55.0.970.g62bdec98f9-goog