From nobody Fri Sep 25 04:06:51 2026 Received: from CO1PR03CU002.outbound.protection.outlook.com (mail-westus2azon11010058.outbound.protection.outlook.com [52.101.46.58]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 224BA4BA1C7; Wed, 16 Sep 2026 22:14:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.46.58 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789596887; cv=fail; b=tQLsFvMABqNKu7TsNCYUqoEalyUYjqgWan0ZMFt7Z43IOlzHvcv46eaMXwilWfob3UQZoOjQyY3aOxRKgZpNTjKN7fzwtPgrhK8ysMRcyZqajQtlS2Ag66u1XDxpjDXVrgxG1tquSkfMEhzVw3Hs+NuE6yuTNbaa19mcs/GCoxo= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789596887; c=relaxed/simple; bh=9JkAwJ6pMSnB7ov8awr/g1JBp44NzTda1sHLW2w7RaU=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=lnn2m+/PMU39YEN516gVgKio178l22c+pOuS1CUOGGPd/Pns8C06Zmg9qIWwizDz/pEvsxdVFSON1L3vhbrzUk1ZowO11Rw/ft50RU0Zu4JZ3EciQ3Wdy2VS9Nr/LA3R+6O/jQfVND79O3eiM85sucjH0XSrW3oJR554ItdNqqg= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=42K1RuMN; arc=fail smtp.client-ip=52.101.46.58 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="42K1RuMN" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=mADQqJsSpt61ZqhyZI6Nb3EU4Ls/UPJPhRu0qZ4QNZu2xYTo+XZwOybOEduDw0kzhO+4xcTUcy/8Ks33ZccwFO9FQr+st+dzhZnCBKiiYV9a/Pmu88NsIkQuoSslO9BlctsAQV5JCMKvuevGQQkdQcSshLtk2PnUlI73MYiwcTaULOrLRqjUHWm1WLgo374yswTzbeJGLWWQgy0N5/mdMYYK274j8gEO0jD4GpzhX1RCVcsttLEbIutS9zGQ3YcSkmG3qMeNVa1mhgr/iJ4fzZUibOyZlmWpzUk/lvfCfDXJN91G+oWMspW1B6Mr2kYAtsvt59jgX9g19OFfPlrZGw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=NMhbL123iO1Z2WBPQXbvbmYl8SN1+d4H+AT0bA6j95Q=; b=sdT69lijMDU6bcWOGbY4B0jC5Y07xJjekoMVcJLrTaIZkGyvCGJobtxzI0wgU6YquM6mu5MVI7faZV+vHLpWH2DgProRgVhrq8LScFHl9LWQnL7vQFYsrhPhJ4BgeIrxbFcDrSJ+1uyZP+2O5fIjqUM9yStOLjG+oXcJTHJu8TyFItvaEDGV8rJnOP+k/0BoFiWv37vgvGQr9ILuC0yXKHpflhm+e0l7/QnJqeg+srGLHMZgs3cNiWC9OMe84If3hJ5EoJnL23X7oLKtYqidiEJ1n846TlfdBerVSAArRDEdmP1rEU5LLzNnl1QIFMHBq69upzY3YoXc7U45u1O4uA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=kernel.org smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=NMhbL123iO1Z2WBPQXbvbmYl8SN1+d4H+AT0bA6j95Q=; b=42K1RuMNAefjE6aMHS0VMnSmMuBxhToyyJQXOdfeQiLX4ja3mz3adRGfVSIyRrUX1mvWb9w0mApHXfzxjoCJgfRuvI64WhmNIfDOL1yr7/RfGf7Qgk7jXLPSQg9vbsZXKFAJ3V/xRFBjzmnAf1ZC4k/8rF+YW83KE0glPqzKT5U= Received: from SJ0PR13CA0186.namprd13.prod.outlook.com (2603:10b6:a03:2c3::11) by DSVPR12MB999284.namprd12.prod.outlook.com (2603:10b6:8:41d::5) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Wed, 16 Sep 2026 22:14:27 +0000 Received: from SJ5PEPF00000203.namprd05.prod.outlook.com (2603:10b6:a03:2c3:cafe::40) by SJ0PR13CA0186.outlook.office365.com (2603:10b6:a03:2c3::11) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.428.9 via Frontend Transport; Wed, 16 Sep 2026 22:14:27 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 165.204.84.17) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=amd.com; Received-SPF: Pass (protection.outlook.com: domain of amd.com designates 165.204.84.17 as permitted sender) receiver=protection.outlook.com; client-ip=165.204.84.17; helo=satlexmb07.amd.com; pr=C Received: from satlexmb07.amd.com (165.204.84.17) by SJ5PEPF00000203.mail.protection.outlook.com (10.167.244.36) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.7 via Frontend Transport; Wed, 16 Sep 2026 22:14:26 +0000 Received: from nigeria-2635-os.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.49; Wed, 16 Sep 2026 17:14:24 -0500 From: Ashish Kalra To: , , , , , , , , , , , CC: , , , , , , , , , , , , , , , , , , , , Subject: [PATCH v16 1/5] x86/cpufeatures: Add X86_FEATURE_RMPOPT feature flag Date: Wed, 16 Sep 2026 22:14:14 +0000 Message-ID: <40510457d85846fd9138b622a01bebc360e4f72e.1789594774.git.ashish.kalra@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb08.amd.com (10.181.42.217) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: SJ5PEPF00000203:EE_|DSVPR12MB999284:EE_ X-MS-Office365-Filtering-Correlation-Id: 7d889f17-7b26-470d-168d-08df143fdf3f X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|82310400026|36860700016|376014|7416014|23010399003|1800799024|10067099003|3023799007|6133799003|18002099003|22082099003|11063799006|56012099006|13003099007|921020; X-Microsoft-Antispam-Message-Info: XZbg482hdYk1NWsXBNCoHpMG3NxCzhhWLuZwuP+sKMMbYSBvWYnwtvQF93ueHfL37NHaOz7gKr0t6Iz7Hj5nSWu5ylv2UTTE8/4eCA75r47oRebV2et1j8bYclG3R0hz4U8FCQlvYrow7bb5Ok4pxM5App6BWClV+x53CV5ZW+MP9kiIonttEQ7wGix2psZPcCcwydg/vjv//VkpyaHQKbvB8uSX1AffcQvHH+bidlQ7x9+51QcAvgmRCGYNVHwcnv/AGgmvTlZUGGPdIXOdYGtkQvAAQVB6JPEkBc6dILOFaBemINlmjteuvsrAETOFxCwwX9Q4pPYimEPh9QZhpPzjZB2bw0YEwchOdPVzwYhGOCXKEA3EoyaqIwyAtJ0v5OegdnJ3lodESuAS3cfRV4Au2nM00wic9R0v12pPAbfqYOmipx+wlMcLkEQ6E8R4ot/pO3WPexvD7NlpyN+x+ipWRJHh6ot3mpF/gTC9I4zW+PMrcfcTA1mHZLtkMYWWg+u0uWBiUCf+S0nU7HuExpXMqmUMF/i5eo7HxZqrItfIYl+aA1PT7Zdntx3ZWglmGd7mtEkOBRQU+zCU9pymRz1Advyx73x6UFpuHFWxCCKFzT/BP6hT9yphtvKSLTIt1y6RMwEVah8splY9N/O+qLvqNVI7g6B8gpQBkxdYyBxRhIgCZ3iyBUGzvIDfOK0e5FaWpxFfdbCd60l+xgATGA== X-Forefront-Antispam-Report: CIP:165.204.84.17;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230040)(82310400026)(36860700016)(376014)(7416014)(23010399003)(1800799024)(10067099003)(3023799007)(6133799003)(18002099003)(22082099003)(11063799006)(56012099006)(13003099007)(921020);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: sw6CLrDgALUQj6jUs/PZ32rOCaLb7XgPTas3QApSco3OqO+DqSCbfFT57qyqMzz8eVoybvsvqecigyaeoHb/Vnf7FY8Xpv6Slu9wcZw7i3bXPrRvRL5pycGD7psa7tA0uVt4Xe9zX3Q4NxTDie72zFIKHKKcEKuwzFia8l56wPLc1W8/WYUA979c8uWe8GD9moQsUGA+YpDxjmYL0BK6+5kS43YfJYUu654f/uvpKwA63APaUddtevjvW9VT7fidhhZf6Kn3YciKW+AiBxuJ8O8Qn0kCuJ/4W3p2Wwr9N3/u8HgPpcNeY8soo/6zWn7PFXql7/k6c95UieIY8TQlel3CHdw+iAeb3gEBijGPvcLoLWjIuYNprqnMUSYcV2jXhprpZqdOLjkP8KLJulPfuNon0A/FfYUmf6mzrcN+X0/Si/dg1swcuM0LGtgjvL0X X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 16 Sep 2026 22:14:26.9567 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 7d889f17-7b26-470d-168d-08df143fdf3f X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[165.204.84.17];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: SJ5PEPF00000203.namprd05.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: DSVPR12MB999284 Content-Type: text/plain; charset="utf-8" From: Ashish Kalra Add a flag indicating whether RMPOPT instruction is supported. RMPOPT is a new instruction that reduces the performance overhead of RMP checks for the hypervisor and non-SNP guests by allowing those checks to be skipped when 1-GB memory regions are known to contain no SEV-SNP guest memo= ry. For more information on the RMPOPT instruction, see the AMD64 RMPOPT technical documentation. [ bp: Zap respective tools/ change. ] Suggested-by: Borislav Petkov (AMD) Reviewed-by: Tom Lendacky Signed-off-by: Ashish Kalra Signed-off-by: Borislav Petkov (AMD) Reviewed-by: Dave Hansen Reviewed-by: Ackerley Tng Link: https://patch.msgid.link/39e9ee269a572c516a3f4e937bfe12d00697d5e6.178= 2841284.git.ashish.kalra@amd.com --- arch/x86/include/asm/cpufeatures.h | 2 +- arch/x86/kernel/cpu/scattered.c | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/arch/x86/include/asm/cpufeatures.h b/arch/x86/include/asm/cpuf= eatures.h index f70ee74b5f92..3b5b32d3391b 100644 --- a/arch/x86/include/asm/cpufeatures.h +++ b/arch/x86/include/asm/cpufeatures.h @@ -76,7 +76,7 @@ #define X86_FEATURE_K8 ( 3*32+ 4) /* Opteron, Athlon64 */ #define X86_FEATURE_ZEN5 ( 3*32+ 5) /* CPU based on Zen5 microarchitectur= e */ #define X86_FEATURE_ZEN6 ( 3*32+ 6) /* CPU based on Zen6 microarchitectur= e */ -/* Free ( 3*32+ 7) */ +#define X86_FEATURE_RMPOPT ( 3*32+ 7) /* Support for AMD RMPOPT instructi= on */ #define X86_FEATURE_CONSTANT_TSC ( 3*32+ 8) /* "constant_tsc" TSC ticks at= a constant rate */ /* free: was #define X86_FEATURE_UP ( 3*32+ 9) * "up" SMP kernel running o= n UP */ #define X86_FEATURE_ART ( 3*32+10) /* "art" Always running timer (ART) */ diff --git a/arch/x86/kernel/cpu/scattered.c b/arch/x86/kernel/cpu/scattere= d.c index 8665a6474806..d1795ce219da 100644 --- a/arch/x86/kernel/cpu/scattered.c +++ b/arch/x86/kernel/cpu/scattered.c @@ -67,6 +67,7 @@ static const struct cpuid_bit cpuid_bits[] =3D { { X86_FEATURE_PERFMON_V2, CPUID_EAX, 0, 0x80000022, 0 }, { X86_FEATURE_AMD_LBR_V2, CPUID_EAX, 1, 0x80000022, 0 }, { X86_FEATURE_AMD_LBR_PMC_FREEZE, CPUID_EAX, 2, 0x80000022, 0 }, + { X86_FEATURE_RMPOPT, CPUID_EDX, 0, 0x80000025, 0 }, { X86_FEATURE_AMD_HTR_CORES, CPUID_EAX, 30, 0x80000026, 0 }, { 0, 0, 0, 0, 0 } }; --=20 2.43.0 From nobody Fri Sep 25 04:06:51 2026 Received: from MW6PR02CU001.outbound.protection.outlook.com (mail-westus2azon11012056.outbound.protection.outlook.com [52.101.48.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BCE404AEBE4; Wed, 16 Sep 2026 22:14:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.48.56 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789596908; cv=fail; b=G9cablUQgbN1CVA0qg8uSipZn28mCKdkbV4v9PPBmyTT/7V4sM1UytXnrIXQbDVbPuJrM+3noclcTV8F6uNX+8/kmtS9/HDAwuTS/126kK9grHbTD2prHoTkgT3sU4Ysfbpl/GYKFhJpohH5DJ7Uh95LxqjARVAG5xGVmMrLCwY= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789596908; c=relaxed/simple; bh=3I0/vYIJULo4zq1i/nNzduS+ukIwREO6ln2wFgrs3Ik=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=trppOaO2eF98FKlnBKzWxrAkYXXPdgcev8VFt9dVospqONsQJcNUVOy3buzNttiFMfo6VE8dn6l+lZuyqKNXqQ6APYTP0dLJ0QiIoS3zBzbMyrDGa+GhovQhhxI2Ys6eNIBslBLATZ07Cz09sEBaNAfpFon63sdqVJ/pUZKe3Qs= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=BIg1vUSh; arc=fail smtp.client-ip=52.101.48.56 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="BIg1vUSh" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=J3Zwg5qO1YtPu77JP71hT6GtDVuo7rjqeRQ8hJ4irpPY7AenGO4yuJqjBp8pRSLh5LT8R5EspBXrz1jqdS69CIHqfzhJaWbykvTTmnFreY7Y4S1p5Hu3+HtwyLLYo09GexQU9ri7JAfaDu6mDInepCjd/a2Oi+JfX3nWGUVciV6UvFmPhIYDsbCyreThYcTFFvQV9vCB8cp3azW4f+8WjlhMNriizszwfzX8O7NGji6M5IH3DEMU22Sj9kDtgfFYaFrHLHZWEqpJCGLMvf0fJa13MS71n2REnwdxm9H9Nv41mstoqfzKBs7vEwNyTeCYj0UWqUROY3buB55vMZMH0Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=cLHDYBoTAlysx8a2PQHWLBnWRAAJiPAV+MsXE0qTwps=; b=nmXEk4iZ8mfoIrPeA32/ef0SgH3x3yGwsNN0969N2Bpd0h3IkSNz5SqweMRRq9HBYFZwjeoaaUb5rdPsu+bh7ai2xSTnyEVCuxri7txWrvdsGallJVGGZPjlCyvZm1VAF7mht9IBxIcogeUPRtJ/Y0/nd3WIDbdv6oNSte1l4an9LfmYrxhftevTXcCk88WgY23TvA0DQ6uhqAhL3MWtZeOC6uuGs/AozjCEnieNKBkSSZMN8EW7a+ir4YBNTUQ2gt3/ccQNOikBCOFT9jVtQYNqMCI3sDoYxCGJFBfs67qMSq4jaeIAWHotrMd01Nf5sjMdwhFx1Au0ZGUmQNrUzQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=kernel.org smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cLHDYBoTAlysx8a2PQHWLBnWRAAJiPAV+MsXE0qTwps=; b=BIg1vUShOla4eWzFI/el3T7/vNkIKalDlrt2URovSgic23J0iKYjd/R4+9IOtRCQf5l6C2eubiLJJneuFRrl9yotn2RpjNa2Lr12JP9nkTreSrWY1xGbokmOOVlWpMIprrdJux/ioIaCSjsY1OJeShj9hZoJHm47aroegAb3xuc= Received: from YQZPR01CA0046.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:c01:86::25) by SJ0PR12MB5674.namprd12.prod.outlook.com (2603:10b6:a03:42c::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.406.9; Wed, 16 Sep 2026 22:14:48 +0000 Received: from SJ5PEPF0000020A.namprd05.prod.outlook.com (2603:10b6:c01:86:cafe::ab) by YQZPR01CA0046.outlook.office365.com (2603:10b6:c01:86::25) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.428.11 via Frontend Transport; Wed, 16 Sep 2026 22:14:48 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 165.204.84.17) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=amd.com; Received-SPF: Pass (protection.outlook.com: domain of amd.com designates 165.204.84.17 as permitted sender) receiver=protection.outlook.com; client-ip=165.204.84.17; helo=satlexmb07.amd.com; pr=C Received: from satlexmb07.amd.com (165.204.84.17) by SJ5PEPF0000020A.mail.protection.outlook.com (10.167.244.43) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.7 via Frontend Transport; Wed, 16 Sep 2026 22:14:47 +0000 Received: from nigeria-2635-os.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.49; Wed, 16 Sep 2026 17:14:45 -0500 From: Ashish Kalra To: , , , , , , , , , , , CC: , , , , , , , , , , , , , , , , , , , , Subject: [PATCH v16 2/5] x86/sev: Disable CPU hotplug while SNP is active Date: Wed, 16 Sep 2026 22:14:35 +0000 Message-ID: X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb08.amd.com (10.181.42.217) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: SJ5PEPF0000020A:EE_|SJ0PR12MB5674:EE_ X-MS-Office365-Filtering-Correlation-Id: d700f2d5-8d1b-435a-122e-08df143feba6 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|376014|36860700016|23010399003|7416014|1800799024|82310400026|22082099003|10067099003|6133799003|3023799007|11063799006|18002099003|56012099006|5023799004|921020; X-Microsoft-Antispam-Message-Info: wLAg+H8SbidZpbZxN6fUNi9iTnIT5v2aQXb95aBQOVikNsqPqZU5gea3eX1swXkxZLGvcKqGSGnYwtDWIbF9VjGA57kKuhf9VN2in00QF2Dn4gXj1MC9TBoFtZG/LfcOpYdAV08LJcLJnO0vNbtjUWna6pKrWMylFM2Agdnjt1E8HEmLsDJkH0R8CJ83o4eGRF8XlW5qvX7Gc5GJl4Ijv9SXJGbT5Kc9cF1Agh8yD8UEyCOwSmUnQPb+EPl2cXAzjF03HQR4Cb9FFoVOIy9p7Lmr2H3lA+hg8X1tj0s+ilai3qwSjriJ10mSFuS9KxERzpV5cfqL0iD6O7U0WCm1iDKI7C0RqJHsbxXP9JG3y1YrKj8ngwtkkYs+i8PbqZtrb1XU7y6MvRaaozcsLecP3NmBR1FaA4zrJoQxRATbp8shnGX7hMK1pUHbPa4RIlJlPktKHuQ65XH+ZT0krw42YrsPgLkY8gx+zqpso/mnrQhN27X1san1tXyHKQB6jA5G4Cypfi7AOBQV4h9Krpl0AI/hQlZRV0/A+fVJz7ZEurdGuJzdH2vFXBCn2R+Rr//RkvEHRscGYK4UgBvBdGZwyqBcaFuD5XNix+1Qe92GQNRJuffGo+DguBZSFPxZJB1QfIsQAjLFCSTZA6UMkWJC6JmJLm10m5JXsHd7zJ5ePu73BzHU4wozTKcCBV3O7I88+FDMTHAJMM5Ir5/JBxNiYHaQ2GfHam5Gbk60BumSH1Dm+8T5XdiYV9i4SjkEKGvW X-Forefront-Antispam-Report: CIP:165.204.84.17;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230040)(376014)(36860700016)(23010399003)(7416014)(1800799024)(82310400026)(22082099003)(10067099003)(6133799003)(3023799007)(11063799006)(18002099003)(56012099006)(5023799004)(921020);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: L3yBp96a42pEblrz+5/LrZVwEK3LUC/hyNMJ7Xp6nsZu8n9NaK40VFDJ8wcdzD6eQlHte1fA/iKvCu5hYJUA4fIhfzNVjFGrDqYVDRi8crEyfIx1mNfJCy9HLWruBLMX4GAiXzt/2tBzEtO90qGozaaIdrQ9bYhALoGif+LP/Gq59K7fyih1KRRkAyUw24moB+hskI932QrDQGm3sZ3Zx22gP2awdhQQEwFrnOiJVBDDNw83179CHJISIYxIylNL9AFUg+5cqhjDOP5BLvIlsqtP5e2/v4z95AQpbUbuAjl5PLYP021cAbkUCFEUfPFDcq74wsy9494DhhyPBxR81GwG8P+7ZEZKeQXQCFLE1vytEw8KoVN+431AnmnS6yXE/i+QiWE1HhBliUzVE6Z3yG9d6GV2JrCMHBDTbH4/eHPxmwwsMO6/BDrdVPeBhmTI X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 16 Sep 2026 22:14:47.8254 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: d700f2d5-8d1b-435a-122e-08df143feba6 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[165.204.84.17];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: SJ5PEPF0000020A.namprd05.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR12MB5674 Content-Type: text/plain; charset="utf-8" From: Ashish Kalra While SNP is active, every memory write is checked against the RMP to protect SNP guest memory. A core performs these RMP checks only once SNP has been initialized via SNP_INIT and the SNP-enable bit in SYSCFG is set on that core; the firmware requires the SNP-enable bit to be set on every present CPU before SNP initialization. A core that is not SNP-enabled and not SNP-initialized performs no RMP checks at all, so there is no valid configuration with SNP active and any CPU exempt from RMP checks. The firmware determines which CPUs are present from the processor and the BIOS/UEFI configuration (e.g. SMT disabled in the BIOS) and enumerates them at SNP init; it is not aware of the OS bringing CPUs online or offline afterwards. SNP_INIT fails unless SnpEn is set on all CPUs, so a CPU that is offline when SNP_INIT is issued, does not have SnpEn set, SNP_INIT fails, and there can be no SNP guest memory. OS CPU hotplug can thus diverge from the firmware's expectations and break SNP. Tie CPU hotplug to the SNP-enable bit: disable it in snp_prepare() before SNP is enabled, and re-enable it in snp_shutdown() once the firmware has disabled SNP. If snp_prepare() fails before enabling SNP it re-enables hotplug itself; once SNP is enabled hotplug stays disabled, including across a failed SNP_INIT and across the legacy SNP_SHUTDOWN_EX path, both of which leave SNP enabled. A kexec target that boots with SNP already enabled, disables hotplug once in snp_rmptable_init(), since snp_prepare() bails when SNP is already enabled. With CPU hotplug now disabled while SNP is active, the online CPU mask is stable, so the cpus_read_lock() previously taken in snp_prepare() to iterate it is redundant. Drop cpus_read_lock()/cpus_read_unlock() here. Suggested-by: Thomas Lendacky Reviewed-by: Tom Lendacky Signed-off-by: Ashish Kalra --- arch/x86/virt/svm/sev.c | 36 ++++++++++++++++++++++++++---------- 1 file changed, 26 insertions(+), 10 deletions(-) diff --git a/arch/x86/virt/svm/sev.c b/arch/x86/virt/svm/sev.c index cff285d8ad8e..558f7924a3f8 100644 --- a/arch/x86/virt/svm/sev.c +++ b/arch/x86/virt/svm/sev.c @@ -513,7 +513,6 @@ static void clear_hsave_pa(void *arg) =20 int snp_prepare(void) { - int ret; u64 val; =20 /* @@ -526,14 +525,18 @@ int snp_prepare(void) =20 clear_rmp(); =20 - cpus_read_lock(); + /* + * No CPU may come online without SnpEn while SNP is active; disable + * hotplug here and re-enable it in snp_shutdown(). + */ + cpu_hotplug_disable(); =20 if (!cpumask_equal(cpu_online_mask, cpu_present_mask)) { - ret =3D -EOPNOTSUPP; + cpu_hotplug_enable(); pr_warn("SNP init failed: not all CPUs online. (%*pbl online <-> %*pbl p= resent masks).\n", cpumask_pr_args(cpu_online_mask), cpumask_pr_args(cpu_present_mask)); - goto unlock; + return -EOPNOTSUPP; } =20 wbinvd_on_all_cpus(); @@ -548,12 +551,7 @@ int snp_prepare(void) /* SNP_INIT requires MSR_VM_HSAVE_PA to be cleared on all CPUs. */ on_each_cpu(clear_hsave_pa, NULL, 1); =20 - ret =3D 0; - -unlock: - cpus_read_unlock(); - - return ret; + return 0; } EXPORT_SYMBOL_FOR_MODULES(snp_prepare, "ccp"); =20 @@ -567,6 +565,13 @@ void snp_shutdown(void) =20 clear_rmp(); on_each_cpu(mfd_reconfigure, NULL, 1); + + /* + * The firmware has disabled SNP (SnpEn is clear), so re-enable CPU + * hotplug. A legacy SNP shutdown returns above with SnpEn still set and + * leaves hotplug disabled. + */ + cpu_hotplug_enable(); } EXPORT_SYMBOL_FOR_MODULES(snp_shutdown, "ccp"); =20 @@ -577,6 +582,8 @@ EXPORT_SYMBOL_FOR_MODULES(snp_shutdown, "ccp"); */ int __init snp_rmptable_init(void) { + u64 val; + if (WARN_ON_ONCE(!cc_platform_has(CC_ATTR_HOST_SEV_SNP))) return -ENOSYS; =20 @@ -586,6 +593,15 @@ int __init snp_rmptable_init(void) if (!setup_rmptable()) return -ENOSYS; =20 + /* + * On a kexec boot SNP may already be enabled (legacy firmware leaves + * SnpEn set across shutdown), in which case snp_prepare() bails without + * disabling CPU hotplug, so disable it here. + */ + rdmsrq(MSR_AMD64_SYSCFG, val); + if (val & MSR_AMD64_SYSCFG_SNP_EN) + cpu_hotplug_disable(); + /* * Setting crash_kexec_post_notifiers to 'true' to ensure that SNP panic * notifier is invoked to do SNP IOMMU shutdown before kdump. --=20 2.43.0 From nobody Fri Sep 25 04:06:51 2026 Received: from MW6PR02CU001.outbound.protection.outlook.com (mail-westus2azon11012017.outbound.protection.outlook.com [52.101.48.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C3B284AD7ED; Wed, 16 Sep 2026 22:15:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.48.17 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789596930; cv=fail; b=l9OSwCDhxT8u57pwbsAwJEcef0ud6Hk6MIaG6dexF6umVyz8Ad852k/TjTysHG9vEHD/ODYYtxDvhVzoC/uP4mAQSzKiX0EqfJP/WzLBQXRxYcDuvs4+1o7s+6fdz1b/DP8BofuEZe1h/QwgBtol4SIm77gbkKS+II8dJk1+34c= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789596930; c=relaxed/simple; bh=HlQrOpdDntHcL3PW48X2DHVfGnTTAneOBtW7uJFZs44=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=IHJUuXiV0iK56FlUc8zT2AWCHulW83WsV1QP6OBXh5Sf3nubJA5JIOhQLSrKZHH+4VzZXAj1WFdCjxLdc77Sa/zZEpBonRxaholBCvG5gZkvVtkjkVllQzTve9rLN3HV2+3IlETiuouuTNmaQK9+BZRi0t0BVM7shVXyqfoZPe8= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=BvotpjDW; arc=fail smtp.client-ip=52.101.48.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="BvotpjDW" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=bPXFQoNsjHclw5FadI0DFpTtbw38Tphw+EZaYhVsFXjAfijMl9HI+yxA/xsqDj5MbPy2AqY3MwDi1Xhrgyqre4ThIRh0E+URPKii6nrfslLJAGUpikdd/bvf5NiL3B8hfXriQVn6LaUlp8Dg8rUN8WAmtXI/zhi0s3TGx8bbVCcFudSY5nBRMnraQ89slXxG12Pxtwg+lbM4XrKm47/NC+9z5jEzk77indSAJRHkDVKu3tRmKU2mQSx38oHMA16jM0mqvEJ3jpL6hBH46gH9FJXYzz49nsjvYFYw+hnS6tXWfO4rbyOFQnuV7jBB+BUOcKo/L6ozr4Z9CwJTGUtkmQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=eivRtoPiG2Xxrhl+/9BN56Kq3ffcWh2uUNtlTK302kY=; b=leF1TzW9MGm3/ESLchtqxxIX+tTOnxAVvRodFJnUTCF9N8kJCmi+T9IVjF0Q66xr5vq1dcsMHVNHQEfGqkRgHmh+rtjhQBNoNZpZCOluTRr5+PC6qhKwV7PtoVYjmmmmrJPjL64SBm/iMXwahYrYbwMkbzejhsJ7SOXf5ScqKhUfB7HBTzqR5WMMf0hm0sp1BwbAZEjOYjEN03dBr8NCfHtwIpJS755xnlzjhXmPnSKCz5IRM9fLyU7XE6Yblrc+x4WVYMFnuJgsG6/kaqgGCxoDb6ltmbFFAl9t0zSVOH3VR/KPjdMTrgCUaKrT8yBIZQCQj7LSUJgjW/us+gp/bw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=kernel.org smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=eivRtoPiG2Xxrhl+/9BN56Kq3ffcWh2uUNtlTK302kY=; b=BvotpjDW1JehTEeznJQTZOVVj1ReVumTvcC48hYCalQu5pgsKDHRoDepiJTlVDpQvp6QPP21od4hhN+JB+vqi+QSqM1NW2iV20tdnjr51Y6bEudIDandi3CASQjJ/pTDlUhlAphUJHP66kG/vPTmRG5lFhiEulGJXTrk4XnCPpg= Received: from YQZPR01CA0033.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:c01:86::19) by CH3PR12MB8658.namprd12.prod.outlook.com (2603:10b6:610:175::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.406.10; Wed, 16 Sep 2026 22:15:09 +0000 Received: from SJ5PEPF0000020A.namprd05.prod.outlook.com (2603:10b6:c01:86:cafe::39) by YQZPR01CA0033.outlook.office365.com (2603:10b6:c01:86::19) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.428.11 via Frontend Transport; Wed, 16 Sep 2026 22:15:09 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 165.204.84.17) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=amd.com; Received-SPF: Pass (protection.outlook.com: domain of amd.com designates 165.204.84.17 as permitted sender) receiver=protection.outlook.com; client-ip=165.204.84.17; helo=satlexmb07.amd.com; pr=C Received: from satlexmb07.amd.com (165.204.84.17) by SJ5PEPF0000020A.mail.protection.outlook.com (10.167.244.43) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.7 via Frontend Transport; Wed, 16 Sep 2026 22:15:08 +0000 Received: from nigeria-2635-os.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.49; Wed, 16 Sep 2026 17:15:07 -0500 From: Ashish Kalra To: , , , , , , , , , , , CC: , , , , , , , , , , , , , , , , , , , , Subject: [PATCH v16 3/5] x86/sev: Initialize RMPOPT configuration MSRs Date: Wed, 16 Sep 2026 22:14:52 +0000 Message-ID: <7fdf0f5b1be4b561c884c5200d6606a947cbc09d.1789594774.git.ashish.kalra@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb08.amd.com (10.181.42.217) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: SJ5PEPF0000020A:EE_|CH3PR12MB8658:EE_ X-MS-Office365-Filtering-Correlation-Id: 59a10a9c-d7d8-4142-58dd-08df143ff821 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|23010399003|36860700016|1800799024|82310400026|7416014|376014|5023799004|11063799006|10067099003|3023799007|56012099006|6133799003|18002099003|22082099003|921020; X-Microsoft-Antispam-Message-Info: ER2oaiWxFB+LDAwSXI8GK0KbsAY2anTUlm8MB2zlCc6Z+wi/9nAtSpqh0Uk/SbHCdmgw0sd31sbl+sO9/iDxWPohRhwxLSDPE8yXJP+Cwz7TSbJUD2Kq3dqAjXXY5sAjChl6FiNYGZUq3tgWwCK1AZ6kKSq/gViNnFKcL8X8jqr3irB0wRSXeAITfThinrNLGm9QcUTHIkn5QfZopbWrE36YfWbo+zPEr8FZ+Ns4240zIWr//coeJksuejDpqFgPRKFb5pqPlK6NH9AkznKKbjVYDvGfqwTtnnlLLhXiLiYVhPU5j3IyCx3E5xJoNmEMNaSOd3uAj60sTgapj1OXrDBYA/uzUIBJO/lc7gSrCpv7N1x+L0nvyH3ageCM/c32cy3ZzKyYPX4UAdHAkD4UyfOJ2vWqEzvpid+JeY1mb1B/kDA+ux9fc52AOilt8tPBYtYPJbf5PdAmTHVQRMQL/AKRVBIC8TQfViYeLbSPHzYczRoBIJ25lsTDnKw2e3RRoOO53q17uzHRTBCmwBXSFoNSn8YPNxN4S9/sQX3dg1zUJV5Sd/w7C2tRjc7A/VJNo3/JucIrJ2ASsImw+yT8XDnG1vvvBl1WQaiVxI4/hpKxgTx5L27e/zH8n49PKvPEnNCXerPSo3m2k0w/DErkud5F/uYy4lcebj9jcWHV2R5z8NjOX9Hza0eU7lMqQg+1zUr/eAREm+REbDmI4erbIGIicDbTgcFN9wywQtV3jEosu09gX/FZYV93w19Owr1O X-Forefront-Antispam-Report: CIP:165.204.84.17;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230040)(23010399003)(36860700016)(1800799024)(82310400026)(7416014)(376014)(5023799004)(11063799006)(10067099003)(3023799007)(56012099006)(6133799003)(18002099003)(22082099003)(921020);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: l5qQ7HEfCXVGD7OLC2n2kYPLSZ8lV2Sv7/mHroZm37sDChDJvcpyzIovUBUZ5yFcg3JVl5GWZ53iVj8xqgivBuRNMzXFUU8l/9TfBVKxtnJ7F6l4UG8NH5E3kISvX8+wEwtUgM7ZyvqL7klYU6RDBaayyXc8Z6Zcm0W9PnQCSmbFu4DVsN0W2hw4TcV7qDn2PHhFzYbskLjMA+uJwhAI4gicm8tga+tO3sHoyxKbhSoXgHmuPFP0UomGoKQCPs61HB35wvDzEDg5t6WwXcuB25iEtKcptr+iMtfVEp6qXnZCjdaAqYRRxDaajE390DpD7+vyp5kxeJlnKSHzv3ZlSdxZQqQyUUBqDZh8hUr/UfWhw1ZqnKvbNQp0la1GpAFalunVwv/ESaDIy9sn/Jy3qlObamzTwuYVE627tMtFHsu2OBv31/OEdp+f20xlQq34 X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 16 Sep 2026 22:15:08.7611 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 59a10a9c-d7d8-4142-58dd-08df143ff821 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[165.204.84.17];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: SJ5PEPF0000020A.namprd05.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: CH3PR12MB8658 Content-Type: text/plain; charset="utf-8" From: Ashish Kalra The new RMPOPT instruction helps manage per-CPU RMP optimization structures inside the CPU. It takes a 1GB-aligned physical address and either returns the status of the optimizations or tries to enable the optimizations. Per-CPU RMPOPT tables support at most 2 TB of addressable memory for RMP optimizations. Initialize the per-CPU RMPOPT table base to the starting physical address. This enables RMP optimization for up to 2 TB of system RAM on all CPUs. Add snp_enable_rmpopt() to program RMPOPT once SNP is enabled and initialized. Suggested-by: Thomas Lendacky Suggested-by: Dave Hansen Signed-off-by: Ashish Kalra --- Changes in v16: - Clear X86_FEATURE_RMPOPT when segmented RMP is enabled but its probe fails, so the initcall does not set up RMPOPT for a system that will not bring up SNP. - Program the RMPOPT_BASE MSRs (with wrmsrq_on_cpu()) only when RMPOPT_EN is not already set on the local CPU, so guest teardown skips reprogramming instead of reprogramming the MSRs on every teardown. Changes in v15: - Rename snp_setup_rmpopt() to snp_enable_rmpopt(). - Program each core's RMPOPT_BASE only when it is not already set. arch/x86/include/asm/msr-index.h | 3 ++ arch/x86/include/asm/sev.h | 2 + arch/x86/virt/svm/sev.c | 66 +++++++++++++++++++++++++++++--- drivers/crypto/ccp/sev-dev.c | 2 + 4 files changed, 68 insertions(+), 5 deletions(-) diff --git a/arch/x86/include/asm/msr-index.h b/arch/x86/include/asm/msr-in= dex.h index 3a8e51a0c9e8..1635e2e1c576 100644 --- a/arch/x86/include/asm/msr-index.h +++ b/arch/x86/include/asm/msr-index.h @@ -761,6 +761,9 @@ #define MSR_AMD64_SEG_RMP_ENABLED_BIT 0 #define MSR_AMD64_SEG_RMP_ENABLED BIT_ULL(MSR_AMD64_SEG_RMP_ENABLED_BIT) #define MSR_AMD64_RMP_SEGMENT_SHIFT(x) (((x) & GENMASK_ULL(13, 8)) >> 8) +#define MSR_AMD64_RMPOPT_BASE 0xc0010139 +#define MSR_AMD64_RMPOPT_ENABLE_BIT 0 +#define MSR_AMD64_RMPOPT_ENABLE BIT_ULL(MSR_AMD64_RMPOPT_ENABLE_BIT) =20 #define MSR_SVSM_CAA 0xc001f000 =20 diff --git a/arch/x86/include/asm/sev.h b/arch/x86/include/asm/sev.h index 9e7a077c445d..fa81aa004e8b 100644 --- a/arch/x86/include/asm/sev.h +++ b/arch/x86/include/asm/sev.h @@ -662,6 +662,7 @@ static inline void snp_leak_pages(u64 pfn, unsigned int= pages) __snp_leak_pages(pfn, pages, true); } int snp_prepare(void); +void snp_enable_rmpopt(void); void snp_shutdown(void); #else static inline bool snp_probe_rmptable_info(void) { return false; } @@ -680,6 +681,7 @@ static inline void snp_leak_pages(u64 pfn, unsigned int= npages) {} static inline void kdump_sev_callback(void) { } static inline void snp_fixup_e820_tables(void) {} static inline int snp_prepare(void) { return -ENODEV; } +static inline void snp_enable_rmpopt(void) {} static inline void snp_shutdown(void) {} #endif =20 diff --git a/arch/x86/virt/svm/sev.c b/arch/x86/virt/svm/sev.c index 558f7924a3f8..25cb486ff61b 100644 --- a/arch/x86/virt/svm/sev.c +++ b/arch/x86/virt/svm/sev.c @@ -124,6 +124,8 @@ static void *rmp_bookkeeping __ro_after_init; =20 static u64 probed_rmp_base, probed_rmp_size; =20 +static phys_addr_t rmpopt_pa_start; + static LIST_HEAD(snp_leaked_pages_list); static DEFINE_SPINLOCK(snp_leaked_pages_list_lock); =20 @@ -575,6 +577,42 @@ void snp_shutdown(void) } EXPORT_SYMBOL_FOR_MODULES(snp_shutdown, "ccp"); =20 +static bool rmpopt_capable(void) +{ + return cpu_feature_enabled(X86_FEATURE_RMPOPT) && + cc_platform_has(CC_ATTR_HOST_SEV_SNP); +} + +void snp_enable_rmpopt(void) +{ + u64 base; + int cpu; + + if (!rmpopt_capable()) + return; + + rmpopt_pa_start =3D ALIGN_DOWN(PFN_PHYS(min_low_pfn), SZ_1G); + + /* + * Per-CPU RMPOPT tables cover at most 2 TB. Program each core's + * RMPOPT_BASE with the start of RAM to optimize up to 2 TB. The MSR + * can only be written after SNP is enabled, so this runs from the ccp + * SNP init path (and again on guest teardown) rather than an initcall. + * + * The loop below programs RMPOPT_BASE on all primary threads. RMPOPT_EN + * cannot be cleared while SNP is enabled, and CPU hotplug is disabled + * while SNP is active, so once programmed the MSRs stay set on all CPUs + * until SNP is disabled. A set RMPOPT_EN on the local CPU therefore + * means the programming has already been done, so skip it. + */ + rdmsrq(MSR_AMD64_RMPOPT_BASE, base); + if (!(base & MSR_AMD64_RMPOPT_ENABLE)) + for_each_cpu(cpu, cpu_primary_thread_mask) + wrmsrq_on_cpu(cpu, MSR_AMD64_RMPOPT_BASE, + rmpopt_pa_start | MSR_AMD64_RMPOPT_ENABLE); +} +EXPORT_SYMBOL_FOR_MODULES(snp_enable_rmpopt, "ccp"); + /* * Do the necessary preparations which are verified by the firmware as * described in the SNP_INIT_EX firmware command description in the SNP @@ -699,13 +737,31 @@ static bool probe_segmented_rmptable_info(void) =20 bool snp_probe_rmptable_info(void) { - if (cpu_feature_enabled(X86_FEATURE_SEGMENTED_RMP)) + if (cpu_feature_enabled(X86_FEATURE_SEGMENTED_RMP)) { rdmsrq(MSR_AMD64_RMP_CFG, rmp_cfg); =20 - if (rmp_cfg & MSR_AMD64_SEG_RMP_ENABLED) - return probe_segmented_rmptable_info(); - else - return probe_contiguous_rmptable_info(); + if (rmp_cfg & MSR_AMD64_SEG_RMP_ENABLED) { + if (probe_segmented_rmptable_info()) + return true; + + /* + * Segmented RMP is enabled but misconfigured; RMPOPT is + * unusable, so drop the capability before it reaches the + * initcall. + */ + setup_clear_cpu_cap(X86_FEATURE_RMPOPT); + return false; + } + } + + /* + * Segmented RMP is either not supported on the platform or is + * disabled by the firmware. RMPOPT is not supported without + * segmented RMP. + */ + setup_clear_cpu_cap(X86_FEATURE_RMPOPT); + + return probe_contiguous_rmptable_info(); } =20 /* diff --git a/drivers/crypto/ccp/sev-dev.c b/drivers/crypto/ccp/sev-dev.c index f833cb7e4da3..5c996ab63895 100644 --- a/drivers/crypto/ccp/sev-dev.c +++ b/drivers/crypto/ccp/sev-dev.c @@ -1663,6 +1663,8 @@ static int __sev_snp_init_locked(int *error, unsigned= int max_snp_asid) =20 sev_es_tmr_size =3D SNP_TMR_SIZE; =20 + snp_enable_rmpopt(); + return 0; } =20 --=20 2.43.0 From nobody Fri Sep 25 04:06:51 2026 Received: from BN1PR04CU002.outbound.protection.outlook.com (mail-eastus2azon11010035.outbound.protection.outlook.com [52.101.56.35]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 766BC383310; Wed, 16 Sep 2026 22:15:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.56.35 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789596948; cv=fail; b=JDURg1SHUh5y9+bMmVq9fQV604q9NQJn+rGN4QNUfb+i9IstxqsC0gcEC8kmTdSar20a89HKzbMGB5qRUt/doD3sRDfax/mDUyjfU/b3jT34kBhlbHlMb1t45Wp7T/oPk+CvhSPlW1PcefYspI2JfmbzSopxprZQympZVNCtRl0= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789596948; c=relaxed/simple; bh=d60IauYdODcsis9hhOrvOk+23qHiahnv0YYkp4GY5wQ=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=NGcZJK4HVEfRq2B8fdZqQWWahy5WH3R8RpP7g2M8P2JONBjAmUoEcMmWyknFuxdpwRgLlTFq7tCx+1rGFWMRG6Pf4pLFA8JGi9RXItYFUQbtrfhOJtYkUjvTxiwyx0KEMQG4K3+MWTI7z0o0tmp37y5BlQLVepn0gifYcpF5CtM= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=NY1gTw4Y; arc=fail smtp.client-ip=52.101.56.35 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="NY1gTw4Y" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=eVXdZItu7GElnr/SZRZFiU0IWrv5BkAR1tdkMPCt4KSopU6e/GUslSclBT7zCerxNt1kYsFu7SbnSSDeQinapTX5WCm0c1Dt5nqMsQjlKtXzVFSOWxcoZnnkqXKGAfaP7m9Y/zO6od47IgGyRCxdAdqPr0z2N+QfE5P+g+K0C/Ogwr6jkUqeCqtzuolzML6SoAKzbMwGzzf6W+6JAhXkv2aPIneHEIDZUTUS0c/ruOf5cP4W6okFbK4801YPjREvjKL54jHSaEi5ko0IHUkmHkdXGbvsiWQcVkiHkxIjECdH1uQRsBR1cWTxvizN4z+JI0/Um/ThmIFwDO4hLxhL8w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=u8SWMy2t+AUZxijQA3o8GRGo5bDAXNNS4i3+xr6xK7Y=; b=wszBF6Qj0hwsZ2O7rcZSnLSGxkKT7gAtXih0/1yoN3wtrWauMcP5TmvGHfI925DX+pxdUF7tySPTzCbXKY5FcHI6Ove5lwnZvvzZZlupj2HhmltBK9SKIMsvLrs/fRgiEJ/V6jJ8IGYoDpDpuIPdmJyipxH9I6xaBAwkrlB+/gMXHZGRHDheQeB9mYBwOETuYYfmx1hw3dhDFqdZ9H6bLNBk4zhkoqlIZ/7VYISKxmHdeSAJ1455wDEL42lcvNQAgC94QQkOgiOuE6Kmd3th5RnNdtHp6wQnUPEL+JW2+d52YjzMSfVi0bytkN9qLfWHwU7VF8nd0mvL2iKj4NCNgg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=kernel.org smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=u8SWMy2t+AUZxijQA3o8GRGo5bDAXNNS4i3+xr6xK7Y=; b=NY1gTw4YzQzLlv4dYu42ZUr8Zy+hyfWpexrEvElq1NdM0EydouV7NAtQrHnwmXIkn+owYPUdH5Ewlv9epZouvNr7+HPbJp3dKcx0L2kKV1LM52gOaNZ+YpEIi4UE5YFE2fL6u60L6V462YgVeo9JQapkuyqZwNjyOESl2ygszKA= Received: from MW4PR03CA0221.namprd03.prod.outlook.com (2603:10b6:303:b9::16) by LV3PR12MB9356.namprd12.prod.outlook.com (2603:10b6:408:20c::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Wed, 16 Sep 2026 22:15:33 +0000 Received: from SJ5PEPF00000209.namprd05.prod.outlook.com (2603:10b6:303:b9:cafe::2d) by MW4PR03CA0221.outlook.office365.com (2603:10b6:303:b9::16) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.406.12 via Frontend Transport; Wed, 16 Sep 2026 22:15:33 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 165.204.84.17) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=amd.com; Received-SPF: Pass (protection.outlook.com: domain of amd.com designates 165.204.84.17 as permitted sender) receiver=protection.outlook.com; client-ip=165.204.84.17; helo=satlexmb07.amd.com; pr=C Received: from satlexmb07.amd.com (165.204.84.17) by SJ5PEPF00000209.mail.protection.outlook.com (10.167.244.42) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.7 via Frontend Transport; Wed, 16 Sep 2026 22:15:32 +0000 Received: from nigeria-2635-os.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.49; Wed, 16 Sep 2026 17:15:28 -0500 From: Ashish Kalra To: , , , , , , , , , , , CC: , , , , , , , , , , , , , , , , , , , , Subject: [PATCH v16 4/5] x86/sev: Perform RMP optimizations asynchronously Date: Wed, 16 Sep 2026 22:15:14 +0000 Message-ID: X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb08.amd.com (10.181.42.217) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: SJ5PEPF00000209:EE_|LV3PR12MB9356:EE_ X-MS-Office365-Filtering-Correlation-Id: ee3be194-e89d-4eba-2bf8-08df1440068f X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|7416014|376014|36860700016|1800799024|23010399003|82310400026|921020|6133799003|3023799007|10067099003|11063799006|56012099006|5023799004|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: Z/xdttY77EkHoFA3JdTM44zqW5YwlonICpV+eh74Ac8yrdimA7jjxfLPMcqD4WIZFX/iTVDNhBl95IAYoPfskWqh6UAgjfIRq16qKFwOMf/J4gYko0qldUthQDBwELkpGSN5mSZMKWsKqSLZ6vqBiG4cr/b28TeGC+Mblop0qpL1+egLylSi6ZQ/4rtBmx1uR1TvyHUSiKzRwXltyPeQIs01qajYSNEyUQ+VqaFDVuKzIAxLAWRcN04kC0BFfc+bTq3Dyn4Pa7eEzSk4O2tM468J6TCQR4I4yyoYs+/8RWzMTQ0AP0BCXRKCR2NBpbvZ5vLuf/DuvY23mkjpt8CUCJdIyHLYNTDsaDmdlnKmKiSN+4X7wyqVctPXVMXO3Eq5+5v9gjGHMLkqwVNTlx7cBW0d0nkady9gIlGyFamgGjftEn0ZJliiHI4DLjEX2/RzNBvjrJOksr/BCL5/so9Xodrue9lqga+FKFnmfkv6qa92wIIDvivizTocU2vIZDHWiNroPRwnks1n86kxzrZDkd3FxvWspaZHhaagymdVSvHj9UIE821Bji2hFzLALAfUbkpF8FkoDqMgByQScry97XcOklzXNeP/lUfq4I9bfY7zvzWvQ7I8a1a5LgEbwij+mWyJnk9BchZKR7fiJV4bb5bOydYY0lFXkLIUS1WOGvc/KAUUxgDa29FQsdspzzYyIWPN8OsmCSUS3HWvqPdwL922oYhUXnV9hLnSxUewIYzFMgtXl6FntHUdujXo46l4 X-Forefront-Antispam-Report: CIP:165.204.84.17;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230040)(7416014)(376014)(36860700016)(1800799024)(23010399003)(82310400026)(921020)(6133799003)(3023799007)(10067099003)(11063799006)(56012099006)(5023799004)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: Uk3RrTgXARtB4Da0CHVmd8fLhdN+b5KGpvLv4WqxyLAhFO57C5tZSbitXERW0v9ELI18CVDa/0L4yciekgauVeY81MU+HpQmPTMFc2FwmxM66rUx8uDPhkd7bwxF+eeCZH9tl5r3CBAJDdLgOh9YZ70WMsMd42gIbirIThiUKzO2aE7ip5xh2kvlhpILwLtKr3yxZ0dfYBZSfnLkMdzkGvxH/cGZkEh6IXScIFo40kbUWD+NP61lC875hIMblBxGXzoN5WdFAd7XPjccskGZWH/sypPhrRU09ju/1rppHk657FX6WLaX3x5x1T3/6zBDcJ/cXFSdg8b3A1ptBAIcrUd9n5tBEII4ab/1ZsfAwpBBYGAlB87Ax2SWlFG0G5aSwW2UpFz5xpS73DGhcsFJ4/8gLlwKnZDmOMewFOTDAl4t/tJCvSsn720vHyZCuxE5 X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 16 Sep 2026 22:15:32.9730 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: ee3be194-e89d-4eba-2bf8-08df1440068f X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[165.204.84.17];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: SJ5PEPF00000209.namprd05.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: LV3PR12MB9356 Content-Type: text/plain; charset="utf-8" From: Ashish Kalra When SNP is enabled, all writes to memory are checked to ensure memory integrity. This imposes performance overhead on the whole system. RMPOPT is a new instruction that minimizes the performance overhead of RMP checks on the hypervisor and on non-SNP guests by allowing RMP checks to be skipped for 1GB regions of memory that are known not to contain any SNP guest memory. Add support for performing RMP optimizations asynchronously using a dedicated per-CPU workqueue. The workqueue is allocated from an initcall, and snp_enable_rmpopt() queues the optimization pass. Shortly after SNP initialization, run an optimization pass over all physical memory (up to 2TB of system RAM, starting from the lowest physical memory address aligned down to a 1GB boundary), skipping RMP checks for 1GB regions that do not contain SNP guest memory (excluding preassigned pages such as the RMP table and firmware pages). As SNP guests are launched, RMPUPDATE assigns their private pages to guest-owned state; when such a page falls within an optimized 1GB region, the hardware clears that region's RMPOPT optimization and RMP checks resume there to protect the guest memory. Since launching SNP guests clears these optimizations, perform them again asynchronously using the dedicated workqueue. Suggested-by: Thomas Lendacky Suggested-by: Dave Hansen Signed-off-by: Ashish Kalra --- Changes in v15: - Move the workqueue allocation and the (fixed) optimization range computation to an initcall; snp_enable_rmpopt() now only programs the RMPOPT_BASE MSRs and queues the optimization pass. - Gate rmpopt_capable() on a static rmpopt_enabled bool set when the workqueue is allocated, instead of an if (rmpopt_wq) check, and drop rmpopt_wq_mutex. - Queue both the initial and the teardown pass with mod_delayed_work(). arch/x86/virt/svm/sev.c | 99 +++++++++++++++++++++++++++++++++++++++-- 1 file changed, 95 insertions(+), 4 deletions(-) diff --git a/arch/x86/virt/svm/sev.c b/arch/x86/virt/svm/sev.c index 25cb486ff61b..bd97135cacc2 100644 --- a/arch/x86/virt/svm/sev.c +++ b/arch/x86/virt/svm/sev.c @@ -19,6 +19,7 @@ #include #include #include +#include =20 #include #include @@ -124,7 +125,25 @@ static void *rmp_bookkeeping __ro_after_init; =20 static u64 probed_rmp_base, probed_rmp_size; =20 -static phys_addr_t rmpopt_pa_start; +static u64 rmpopt_pa_start, rmpopt_pa_end; + +enum rmpopt_op_type { + RMPOPT_OP_VERIFY_AND_REPORT_STATUS, + RMPOPT_OP_REPORT_STATUS +}; + +static struct workqueue_struct *rmpopt_wq; +static struct delayed_work rmpopt_delayed_work; +static bool rmpopt_enabled; + +/* + * Delay, in milliseconds, before the RMP re-optimization pass runs after = an SNP + * guest is torn down, passed as the delay to mod_delayed_work(). This co= alesces + * a burst of teardowns into a single scan and gives each guest's pages ti= me to + * be converted back to the shared, hypervisor-owned state. The 10 second= value + * is a heuristic trading re-optimization latency against scanning too eag= erly. + */ +#define RMPOPT_WORK_TIMEOUT (10 * MSEC_PER_SEC) =20 static LIST_HEAD(snp_leaked_pages_list); static DEFINE_SPINLOCK(snp_leaked_pages_list_lock); @@ -557,6 +576,12 @@ int snp_prepare(void) } EXPORT_SYMBOL_FOR_MODULES(snp_prepare, "ccp"); =20 +static void rmpopt_disable(void) +{ + if (rmpopt_wq) + cancel_delayed_work_sync(&rmpopt_delayed_work); +} + void snp_shutdown(void) { u64 syscfg; @@ -565,6 +590,8 @@ void snp_shutdown(void) if (syscfg & MSR_AMD64_SYSCFG_SNP_EN) return; =20 + rmpopt_disable(); + clear_rmp(); on_each_cpu(mfd_reconfigure, NULL, 1); =20 @@ -580,8 +607,69 @@ EXPORT_SYMBOL_FOR_MODULES(snp_shutdown, "ccp"); static bool rmpopt_capable(void) { return cpu_feature_enabled(X86_FEATURE_RMPOPT) && - cc_platform_has(CC_ATTR_HOST_SEV_SNP); + cc_platform_has(CC_ATTR_HOST_SEV_SNP) && rmpopt_enabled; +} + +/* + * RMPOPT optimizations skip RMP checks at 1GB granularity if this range of + * memory does not contain any SNP guest memory. + * + * @pa is a system physical address; RMPOPT operates on the containing 1GB. + */ +static void rmpopt(u64 pa) +{ + enum rmpopt_op_type op =3D RMPOPT_OP_VERIFY_AND_REPORT_STATUS; + u64 pa_start =3D ALIGN_DOWN(pa, SZ_1G); + + /* Supported by binutils 2.48+ */ + asm volatile(".byte 0xf2, 0x0f, 0x01, 0xfc" + :: "a" (pa_start), "c" (op) + : "memory", "cc"); +} + +static void rmpopt_scan_range(void *arg) +{ + u64 pa; + + for (pa =3D rmpopt_pa_start; pa < rmpopt_pa_end; pa +=3D SZ_1G) + rmpopt(pa); +} + +static void do_rmpopt_work(struct work_struct *work) +{ + /* + * Warm up the RMPOPT cache on this pinned per-CPU worker with interrupts + * enabled, so the IRQ-disabled fan-out below only issues cache-hit RMPOP= Ts. + */ + rmpopt_scan_range(NULL); + + on_each_cpu_mask(cpu_primary_thread_mask, rmpopt_scan_range, NULL, true); +} + +static int __init rmpopt_init(void) +{ + if (!cpu_feature_enabled(X86_FEATURE_RMPOPT)) + return 0; + + rmpopt_wq =3D alloc_workqueue("rmpopt_wq", WQ_PERCPU, 1); + if (!rmpopt_wq) { + pr_err("Failed to allocate RMPOPT workqueue\n"); + return 0; + } + + INIT_DELAYED_WORK(&rmpopt_delayed_work, do_rmpopt_work); + + /* The optimization range is fixed at boot; compute it once. */ + rmpopt_pa_start =3D ALIGN_DOWN(PFN_PHYS(min_low_pfn), SZ_1G); + rmpopt_pa_end =3D ALIGN(PFN_PHYS(max_pfn), SZ_1G); + if ((rmpopt_pa_end - rmpopt_pa_start) > SZ_2T) + rmpopt_pa_end =3D rmpopt_pa_start + SZ_2T; + + rmpopt_enabled =3D true; + + return 0; } +device_initcall(rmpopt_init); =20 void snp_enable_rmpopt(void) { @@ -591,8 +679,6 @@ void snp_enable_rmpopt(void) if (!rmpopt_capable()) return; =20 - rmpopt_pa_start =3D ALIGN_DOWN(PFN_PHYS(min_low_pfn), SZ_1G); - /* * Per-CPU RMPOPT tables cover at most 2 TB. Program each core's * RMPOPT_BASE with the start of RAM to optimize up to 2 TB. The MSR @@ -610,6 +696,11 @@ void snp_enable_rmpopt(void) for_each_cpu(cpu, cpu_primary_thread_mask) wrmsrq_on_cpu(cpu, MSR_AMD64_RMPOPT_BASE, rmpopt_pa_start | MSR_AMD64_RMPOPT_ENABLE); + + mod_delayed_work(rmpopt_wq, &rmpopt_delayed_work, + msecs_to_jiffies(RMPOPT_WORK_TIMEOUT)); + + pr_info_once("RMPOPT optimizations enabled\n"); } EXPORT_SYMBOL_FOR_MODULES(snp_enable_rmpopt, "ccp"); =20 --=20 2.43.0 From nobody Fri Sep 25 04:06:51 2026 Received: from PH7PR06CU001.outbound.protection.outlook.com (mail-westus3azon11010024.outbound.protection.outlook.com [52.101.201.24]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7EB914657C2; Wed, 16 Sep 2026 22:16:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.201.24 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789596977; cv=fail; b=taWH7xW6dAXDMP+vpftVn38EQYbCAKFYRzm5bt7QrX59YZxrIOxHOFwcjCdpC68/wCo1lrZfXAWElsQriOvFnZdhFWb+0NmAFOFBhqEGiXY/L23Yr3I5W7aB+tJtfBYlDmLObjam1Qptzy8LgD4LBxJIdraQcRrBoBSpTFbzWLE= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789596977; c=relaxed/simple; bh=JiEsn2nFiNy96AhW93+Ovn5MdyQxmZ6vj4Z/C/JnbRU=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Xt36uQzVtp0tP2gpiKvsbwkHwssTg517VInQGltVluLA769/pXQFw4zF47Tg7uhrio3MpJZ2sG9lqmDylhuhLvAcNu2lkVlqYzRxJ5jQq14wNmbwo9+yB7iC2qIYtPIYEZZJoWtyJB2mj9TH70wzhAIQN2OpRuv6WeLO//kbp6Y= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=kENMo65b; arc=fail smtp.client-ip=52.101.201.24 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="kENMo65b" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=o1Pz6cK9WWefhD9XUw1TXNyAOo+Dq+yaiENB40+xMVA0hcl9GpH8gp6BPEuZk1bFivEwcPQdGKuMtKr6BLzxcpMaHOxLwtLfi9ueym8+jNWLUeYfFi+RFbgzkLDbvLrJilVosHGHFpGXEK84LsU8Q6h0fNI3pVHMicMf1uC3NJPbXH5CNQw/TY6Tf8yeesgPhLabk8INT/PN7Gg19ETY14swofki1V6BmMmJzBo/mfhVXWO6hUUS1FcZHInjfjOce4SubzlWBoIZfW/G7l+6UXiUjmcvxJetgDpmB1AqTS3PrbkV7qoYIaQ2wrc9DZawO8OEDlYGYGOqqcRnkDHkeg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=mw4iglQk0dlTUyHTRW1lm9fP8hCwuZuT1/2sS4LzHcY=; b=gYIdnjUYugMOX9KGW9m8lFzsTDNutRp9lRiVh8QHQOF0TG8Em/MQVRgseazHkJcw9zE4w00SkUdLnGPDo9RnUJ6lzgSuVf7mbi9Dbd8QLo7vuweNLAgRsSYCDauDhE0LpWC7KEmLYOwxm0z3thy1Iv4boVGsFr/Z10hdBKsY0bgQsyOhFWOfbXWRl5hz1cj4e0KcZw02IaJ04XVfcm++A0IXsTNgcrY6nBVMcudqrypI+9wRHf7s+gygMy7MUPtBEiaSsdqULeXYkGGkcP2EHJBGpTubYj4C7s/qgVbajg5fyZuiH9RAkRveC/1NdGRUEWEP9x1Ts0JoK4t2kZt/og== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=kernel.org smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=mw4iglQk0dlTUyHTRW1lm9fP8hCwuZuT1/2sS4LzHcY=; b=kENMo65boqtztoy0GPUzilln9xQjqKh9CzpnlQCFpccn8X+e0JdmNudBcHE9OAxSPoYAxE98z+KcA73goiF5tZcPJ26EyR7pXqI7+w9lUtkEQEixJJLmKhnoYyOY5q6F0zYzvd5uZV5CCfvsIlKvxwP001SG2utN2XPnQPQBHeg= Received: from SJ0PR13CA0191.namprd13.prod.outlook.com (2603:10b6:a03:2c3::16) by PH7PR12MB9203.namprd12.prod.outlook.com (2603:10b6:510:2f2::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.406.12; Wed, 16 Sep 2026 22:15:56 +0000 Received: from SJ5PEPF00000203.namprd05.prod.outlook.com (2603:10b6:a03:2c3:cafe::40) by SJ0PR13CA0191.outlook.office365.com (2603:10b6:a03:2c3::16) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.451.7 via Frontend Transport; Wed, 16 Sep 2026 22:15:56 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 165.204.84.17) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=amd.com; Received-SPF: Pass (protection.outlook.com: domain of amd.com designates 165.204.84.17 as permitted sender) receiver=protection.outlook.com; client-ip=165.204.84.17; helo=satlexmb07.amd.com; pr=C Received: from satlexmb07.amd.com (165.204.84.17) by SJ5PEPF00000203.mail.protection.outlook.com (10.167.244.36) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.7 via Frontend Transport; Wed, 16 Sep 2026 22:15:56 +0000 Received: from nigeria-2635-os.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.49; Wed, 16 Sep 2026 17:15:51 -0500 From: Ashish Kalra To: , , , , , , , , , , , CC: , , , , , , , , , , , , , , , , , , , , Subject: [PATCH v16 5/5] x86/sev: Re-enable RMP optimizations on SNP guest shutdown Date: Wed, 16 Sep 2026 22:15:37 +0000 Message-ID: <7a15a880ea6b6d53b3702def3b3434307656afd7.1789594774.git.ashish.kalra@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb08.amd.com (10.181.42.217) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: SJ5PEPF00000203:EE_|PH7PR12MB9203:EE_ X-MS-Office365-Filtering-Correlation-Id: 3cff6f0c-80f7-45d5-00fd-08df14401460 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|376014|36860700016|23010399003|7416014|82310400026|1800799024|921020|56012099006|11063799006|10067099003|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: Os+Bif6SkLROewAw+GGh33upxyh5ilhfrgTa6H71Y4Hx4cb02Cvk8aD0RUKny7/zLM3YUEtaHGkY+0/RHx6QiX3q3fPIfAk4Mp9BsxZIjLfdz2atuzfTS8xFq6iVY4Vl9qmAel2bFvItHwJ65mbCgeBkRMJh5VY2G6AAyjIRZ2DOoghulb6XxPf0K5IEZYPsvrRAtjv686ehze27JaWnyvLGPjczP43fj9ip//yiL1elXzc9qU1Htg8xHflrKfWqgcrdG7hUwILa09WTvkqamLgYp6DobH9kYFbhajA0n7DXvI6pY1ER2HLh75J6zQmhR4qfCOPxQFq1Znioy2OcRKv69GHUeSJ/LSDjnKcXgx27oBIgyl4HZ+Lm/IdsaUKl2D5sjc6cBOV4g7ZPJt2FK86r5NUeLb2c3MNKijFuEeAvIwycmJ2AQ8csIY9OGuBM+/ISnK2zpMzwOZ+QKaYhLdmqtzVxmflNTHWPj4k8tiHxpYqe6hbWOg4T+ym5MnUrNtDy0fTGR7RF6GRTkHSErZY18PQ4NvWPLggKJZmEZZ3E2Zm8pYsMVSNrrQIiWWZe3rhmEH7jA3zPgWRnJ0W0MFJLOToJliHkykA4Yq33byjVxwwnsVqf9DrEOAgYOBD+g5be6ZAQv36K6PyoVxPd/LuJNIpA28BoJbXUJDCo8ebH38tWt7JTf6RpL7EjQBIPVc7pIV9HoWDyI9dN4q0LtvdV4rh+fdoVd9SRbFfAtg8/avkjWVMQ2g/zR2NGtuO5 X-Forefront-Antispam-Report: CIP:165.204.84.17;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230040)(376014)(36860700016)(23010399003)(7416014)(82310400026)(1800799024)(921020)(56012099006)(11063799006)(10067099003)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: FrJyJCRmZzB0IzVRME4vrjDF5jhEJ0WMGzeeD25NO5yN5TgOvJ+jRXOPdIZrXMqrc0KuCOBV8CVm1E0ad8M6jGQXm7SrpQ2T+fXqnc85JCh+xvRbqtzHk7hcf0nrZH7i9icZaRPR2TYCqnOMCKJqvOxi4applASRNJRsjxGqJT0uFQRwX9PexlAtYyBhzHQJ1EIvltsHiiAV/wQfoPfnpqRtG9rreZbcRTG1G8kmt3q01Hx07Y6XOKQEF3kGGjzelksveJZiEY6pCq8FvpJI2rtxNOj8pSwU9eoC3YbUnTef9SAifz9XJgXDgw+Q2oRTdcXW/0UOL5RXbimHTzwMa13R75HSpNnAWd89oiMv6ZE7tyFRxbeRQtBddm3om5f8iWnparuVuys0bD0nqGwUdpgEa2657GvsqRyqHpFvhdcCvlWgi78hQiTiZ9m7ShVb X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 16 Sep 2026 22:15:56.0907 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 3cff6f0c-80f7-45d5-00fd-08df14401460 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[165.204.84.17];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: SJ5PEPF00000203.namprd05.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH7PR12MB9203 Content-Type: text/plain; charset="utf-8" From: Ashish Kalra The RMPOPT table is a per-CPU table which indicates whether 1GB regions of physical memory are entirely hypervisor-owned. When performing host memory accesses in hypervisor mode as well as non-SNP guest mode, the processor may consult the RMPOPT table to potentially skip an RMP access and improve performance. Normal guest events disable RMP optimizations: pages are converted from shared to private as SNP guests are launched, and large pages are split and collapsed during guest operation -- both disable the RMPOPT optimizations for the affected 1GB regions. When guests are torn down, their pages are converted back to shared, so those regions may become eligible for RMPOPT optimization again. Without some intervention, all RMP optimizations would eventually be lost, so re-optimize all of physical memory on SNP guest teardown by calling snp_enable_rmpopt(). snp_enable_rmpopt() performs the re-optimization after a delay, using mod_delayed_work() so that the delay timer is reset on each call. This batches multiple guest terminations into a single pass: the re-optimization runs 10 seconds after the *last* termination rather than after the first. mod_delayed_work() also re-queues work that is already in-flight, so a re-scan request during an active scan is not silently dropped. Guest teardown is currently the only event that returns guest memory to hypervisor ownership: SNP guests do not support ballooning or memory hotplug, so pages freed during a guest's lifetime remain guest-owned. It is therefore the only point at which memory becomes eligible for RMP re-optimization, which is why re-optimization is driven by guest teardown rather than by a periodic scan. Reviewed-by: Ackerley Tng Reviewed-by: Tom Lendacky Reviewed-by: Dave Hansen Signed-off-by: Ashish Kalra --- Changes in v15: - Call snp_enable_rmpopt() on guest teardown instead of a separate snp_rmpopt_all_physmem(); the delayed re-optimization now lives in snp_enable_rmpopt(). arch/x86/kvm/svm/sev.c | 2 ++ arch/x86/virt/svm/sev.c | 2 +- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 5705723f1f41..4d5e30af1ade 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -3032,6 +3032,8 @@ void sev_vm_destroy(struct kvm *kvm) */ if (snp_decommission_context(kvm)) return; + + snp_enable_rmpopt(); } else { sev_unbind_asid(kvm, sev->handle); } diff --git a/arch/x86/virt/svm/sev.c b/arch/x86/virt/svm/sev.c index bd97135cacc2..13d9acb319aa 100644 --- a/arch/x86/virt/svm/sev.c +++ b/arch/x86/virt/svm/sev.c @@ -702,7 +702,7 @@ void snp_enable_rmpopt(void) =20 pr_info_once("RMPOPT optimizations enabled\n"); } -EXPORT_SYMBOL_FOR_MODULES(snp_enable_rmpopt, "ccp"); +EXPORT_SYMBOL_FOR_MODULES(snp_enable_rmpopt, "ccp,kvm-amd"); =20 /* * Do the necessary preparations which are verified by the firmware as --=20 2.43.0