From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752380AbdI2V2S (ORCPT ); Fri, 29 Sep 2017 17:28:18 -0400 Received: from mail-bn3nam01on0051.outbound.protection.outlook.com ([104.47.33.51]:40640 "EHLO NAM01-BN3-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1752103AbdI2V2R (ORCPT ); Fri, 29 Sep 2017 17:28:17 -0400 Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=brijesh.singh@amd.com; From: Brijesh Singh To: bp@suse.de Cc: Tom Lendacky , Thomas Gleixner , Ingo Molnar , "H. Peter Anvin" , Andy Lutomirski , linux-kernel@vger.kernel.org, x86@kernel.org, Brijesh Singh Subject: [Part1 PATCH v5.1 02/17] x86/mm: Add Secure Encrypted Virtualization (SEV) support Date: Fri, 29 Sep 2017 16:27:47 -0500 Message-Id: <20170929212747.3324-1-brijesh.singh@amd.com> X-Mailer: git-send-email 2.9.5 In-Reply-To: <20170928090242.ber7gynwaldinafa@pd.tnic> References: <20170928090242.ber7gynwaldinafa@pd.tnic> MIME-Version: 1.0 Content-Type: text/plain X-Originating-IP: [165.204.78.1] X-ClientProxiedBy: BN6PR03CA0066.namprd03.prod.outlook.com (10.173.137.28) To SN1PR12MB0159.namprd12.prod.outlook.com (10.162.3.146) X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: ef6e8045-13d0-489e-bd07-08d50780fd35 X-MS-Office365-Filtering-HT: Tenant X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001)(2017030254152)(48565401081)(2017052603199)(201703131423075)(201703031133081)(201702281549075);SRVR:SN1PR12MB0159; X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0159;3:3Rg4emgIwT24qjcI/m189s3XLzUf61CSv0xOhHRx5JGOxcZ0khodZum8GjZT7fFIr71YY95dMeO/DhK8fzZWDU2ip8X2eyTmjfo0isUiDQ1xo2oGep4bvggIBXDuro6ejxvha73widKodjPmYDDoCAGKLaP3mmlguEQQzv/GKHJv0oYySunovJGQjoNCuWvG0FieF7L9ogJlYj1nj5amuhP46tGPMRxQpC2QDf6DBoP83X6JUh8dzNC+yEOb55cr;25:6f8O7FJvlvpjBc0fZTDn9R6i51xEumZIHDW9XoEdLFEYf/0pVh3n/SYpqM47+8sxWGWkwYw8w1XXxJ1KLOlJ0G71tcMJxm9IamDmFOUIgzBhUvLJE1HRbO8qklOkIMiOqLPVVXZCbEjaZTNVLrBKg03hCrpd3ad6zIYCEA6Llxu/vbrFwdrfb++RHrc9U2++6St4s7Z5rpAqRcA+TQr7VE5eqNPgPuG+zf94CjvRiSoiy1nEfUdFWFaUGlpZ6Mg6F0DEw5rZHXyjTbt5ec4iWVH4pK5RUK3JRN+GdzRnFjhHSkt9688erIH4o80MKLTOLTZ/2SMo5dDkY5C2y33V7A==;31:hdk4xCGhc9AotF2PONZDp4dgWui2OhgGNtGU4YD0jpjOhr16lX/oGWSXdFafLtkI7BgCJ9GvvWgrrNCgiHjfONUcasObbInya5Wean2GZVrNwvH9jf/HN5osS8hWjmGQJ600HZ1UVxTBU7ay8Wc3nI4HrCKIa/35uvxzvVVPbWQum8q3UumxVsRotmXp6Q8tzB0+qz9DFe0px/ctPDIkyiEg9M6VqrA/cEbROvW5BfY= X-MS-TrafficTypeDiagnostic: SN1PR12MB0159: X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0159;20:rl2YMwBDVc5IaqzKmmt0uMP+4JPEb7IVqbGftvrLRT7yo4CHG0DsjrkfDe2Wnngm00xE8gc/S2HRGjsrA9I79mfVZv8NqlANiz4qT7/UGsE7+4k3AO+5HBh2VK89I2ONPmhASQGxXHALnHGK4IEnPZAHgZo/y2SAzv79ZAOzqi+y64UHOuJjqP7tYhadqBp9/yi9y/juTLeJy29ohAj9VMY3NK7Uak1/xANH3u1VSi1eSLpUX9waoEoZ4jj66juvrAtldnfAMvdAqgJBRPft333p4okF0ZsGJtSF/nIX0CUXAxg/DKMouIPSY/DidSV0IKWV+lDfeYkAqy0fZvu6e3+KEH/LJ+lOuUJICnIUj7zYYE9K7xam28kJKG5Icz5rnCcDbaG7OdzNPDY8a4YHNxHxfocP8pcvLB6hsv3f/rgPx0WCfxO9siSa9Sxc7fqFuAALbgVeawIpKhJ2Xvp14i8rGF45QNqfC1U8o2xjtFZAe9cbgge0wgE9KvMNNzGd;4:E17rGCZI2OnMKXXvAiOZ0lKsrT0gTrY5rTNeRTx68IiAyLr/axpcbimt7jJX7FYC91UhEjfW262SiM4iIuoZdHdIpfijQhw7y6PlGUtsJims3OhIpg8SB5YP5X821T92Pv5m1F8yjqJqYEGNyKXCKcEl4784wxRnyQ0iaLz6IFCupfeKq0Vq6y8BYLP1kuQSsx3Gk8E26fC+ZNjq7PAb5TdkkH/1orxpd7m+3oPSt2eJgWPZnoT0blju/YT2vVjMlmsgMFoMSRU+mfr5X+PyqM1pvOk008kkcHvcnTizoXwBpOpsPJOWOUSSkdzUld6vv4gaGs7IDF91ltcrDoqmng== X-Exchange-Antispam-Report-Test: UriScan:(9452136761055)(767451399110); X-Microsoft-Antispam-PRVS: X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(5005006)(8121501046)(100000703101)(100105400095)(10201501046)(93006095)(93001095)(3002001)(6055026)(6041248)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123558100)(20161123564025)(20161123562025)(20161123560025)(20161123555025)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095);SRVR:SN1PR12MB0159;BCL:0;PCL:0;RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095);SRVR:SN1PR12MB0159; X-Forefront-PRVS: 0445A82F82 X-Forefront-Antispam-Report: SFV:NSPM;SFS:(10009020)(6009001)(346002)(39860400002)(376002)(189002)(199003)(8936002)(53416004)(16586007)(54906003)(1076002)(97736004)(8676002)(6116002)(81156014)(16526017)(3846002)(316002)(81166006)(6486002)(48376002)(6916009)(5003940100001)(7736002)(6666003)(50466002)(36756003)(53936002)(305945005)(2351001)(2361001)(105586002)(101416001)(478600001)(2906002)(47776003)(2950100002)(4326008)(25786009)(50986999)(76176999)(106356001)(50226002)(66066001)(68736007)(86362001)(33646002)(189998001)(5660300001)(309714004);DIR:OUT;SFP:1101;SCL:1;SRVR:SN1PR12MB0159;H:ubuntu-010236106000.amd.com;FPR:;SPF:None;PTR:InfoNoRecords;MX:1;A:1;LANG:en; X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1;SN1PR12MB0159;23:aiem4RrlLSIRKF+Mr+il+mZl5GQk3cKmuHhtDo6KH?= =?us-ascii?Q?gUB/79bovE1sON3v0JDBrQ+2+3y1LWwpA3C42yuYEQxR2dWhHAHAGUQvGkzt?= =?us-ascii?Q?g85eAKqLiWJO+EgnKEuWRJRHQgROe/iq4eaiGKpvakvru2PSODkHZa4j+ss7?= =?us-ascii?Q?RP2XhitYtIgqabFC8UzGnDumyIpsFnZdAkXJBUsmbewyttdZ7qrSscFBHxyn?= =?us-ascii?Q?B/3pDMnmZSxZrcGbmtTkM+XRnMdmj/jCnC9L6SgiuACaaZWZRg0k9amW00kX?= =?us-ascii?Q?hXPabMEeGldz5EmjQ7ibZ6rJ2jWomhOz24ZvNMdMWA7vticpBpY2r8lullj1?= =?us-ascii?Q?AW3ds9bbOWepMRM7+eazmTFvbnGlp7XmiOZAx9N9GFz9SYp415WVzgyJDcI3?= =?us-ascii?Q?Zv5NdeGatBbrAdK+mIYmsW2Zwu0/dR1o8naOsjgZHQiZoVLrPzeJcPu5peEt?= =?us-ascii?Q?6MhjLrqVSmpoGd9SC7UON1sloQTWD4gqkp9zjlPiDLlSrX5P82zNAuUEtv1a?= =?us-ascii?Q?Od5bnhluiitF+UpiIUg2DN9i9I+4kO05uk1imquhxf1Df8W6dRW7kWueVmfq?= =?us-ascii?Q?cayG/2NXfuO68i+RvWyg44ahWwxZIma9l7dv1wGSdbdt9vwaLTBxRCIvnYRn?= =?us-ascii?Q?gZWah6PgekDuSrIKoVvOVRN1ZmI5vf+J836t8zOu6RTmMxFEGJpL06k0gODF?= =?us-ascii?Q?N4w+F8baGJrF1YDSu6+0BHDOiD6Aad+bp7oH4e554YSZMwHtxk7pX6mLiFug?= =?us-ascii?Q?53Zd78MeVWFoDY2V91XF0/KWmu1rajq93N9doV8bfmupKyZiebp49DdBbYzV?= =?us-ascii?Q?Cwcua+4tctWAIXt/tLT2CvvnNZ/bM2geRAELjVV75pTpwAjbj/uc4C2a/2l8?= =?us-ascii?Q?n1XnLNhjdWil2m8L3MEO9vh/mcJBgsRsvo4B4sddLKcd8xEkLAbWrkSqo+w4?= =?us-ascii?Q?qpFGcjI2FgqDrsMzTUNfiwWLTzRc0pWcmokwtnEaSkhJ/o5NuN1KbYPNf/hI?= =?us-ascii?Q?nbi5vSdIdL87FdMz9cMsUAYLSbCWgayN4KFPw1ARZ84Juj1m0jUoggfQnJBP?= =?us-ascii?Q?Ik4oo7x3yvF/C0u4kQJmkxq7TvAFbnBPQZkFH23dyv2HNexfmz1VDEnzyuMA?= =?us-ascii?Q?2dB8sxSdp2NCmLMOxxUJacFcx4+/ORQWMhsiaysLExkXTKglinlqVh77/ivP?= =?us-ascii?Q?wPiAsWuN7ZE7Do=3D?= X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0159;6:YcMnWumGjXXcyf5gakfnE6y2TURLyWxxFsj4H1hQxR8arbbRD5hlMvHr4ccVD3oJTvRlCY6WTf/yfWFa+H5yUAYPqxyjzqQU+XK8UOUM6ip72fN1HhreT/5DKvfSr198xo9dNXI8yHY9jGqcOF/BpYtC7EUu+yLnMJ2CpzsgqS9w2x8syWGX0cvq6f1niFf3HlPc8jHFU5M6nOXC4+WUi1D7XrYDcGu/lmMXMMRH7skJ92GBg2KA0fPL8NUmlVIADaGe2XPZBrkZgUVhmkLRs63NjhiTmkKGS2KnFqP41U5cma3HbDP8jRCtnjM6dAjBjjUcjL2fRM+NSHHagDwizg==;5:8ZIfqjN35TAZP7lQT7UeQZv4XBXr041jokMgNgN6pRiUgDPSzfXtCcckDGmnNwQ25aoS9cyga0uI0SJh3J+b56HsEa0CDQBoI5W3X6oiSmpLo2D4sPW6Wo2iNO1iGXlGFiwVrZQ0wq44EwMPZBTHD0Agy5t1/yFFjzK7HE8F/N8=;24:GdD1YzsZK+Ie6F6/q7lkqJCHuIMVfO9bGCExthrq20rJbcGkHDODFA9zkxYAajHLMCoc49t/t/5mLnlt5S1dyeeqslRo7y121Z/1hli1a0k=;7:l0GuMtAvU/9dCFHL+6yQJoneTmy7EGyAfOrtibDilrKnioLG5YuRt5gvrzxpijrpsW2at7xJK120oP7Z5lvx+xbWPYfSO5sOF3Vfxa+oPSGdB0wwrOdHuXY2uR/baL5rLQHmwixpe12E+6eSbIYMj5m+bb0KeBV56ZYDouu6e64o//JeF04gSn72BQoEJMGlEpJVnhO6s1sv2Qng4H2u6SiWL0jIGU6d2IN4myjA6iU= SpamDiagnosticOutput: 1:99 SpamDiagnosticMetadata: NSPM X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0159;20:BPRjwYf9d0oVtNHMnDD04ZJG9hTBVXFbP5kPzkg/+TWem36nFk9XkMMtfbiDExLJqe30bzwW/doxv3FeAXBF8lnGC6M1U/bMXQihskLOyU3049q0K80tvf05kk02uuAgmpngiBKwB6gXx8/hL/VbPf4gpb8kbLorTz+Jitln4DmofVDoU4ZUUWo3he0+Qyxw3EFfDkwkYen18uVusWy9CBtCvYcT1T37Qg2jwj9RUjq5yd0l0/tDoL1tv8zG2pS7 X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 29 Sep 2017 21:28:12.0346 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN1PR12MB0159 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Tom Lendacky Provide support for Secure Encrypted Virtualization (SEV). This initial support defines a flag that is used by the kernel to determine if it is running with SEV active. Cc: Thomas Gleixner Cc: Ingo Molnar Cc: "H. Peter Anvin" Cc: Borislav Petkov Cc: Andy Lutomirski Cc: linux-kernel@vger.kernel.org Cc: x86@kernel.org Signed-off-by: Tom Lendacky Signed-off-by: Brijesh Singh --- Hi Boris, Similar to the sme_me_mask, sev_enabled must live in .data section otherwise it will get zero'ed in clear_bss() and we will loose the value. I have encountered this issue when booting SEV guest using qemu's -kernel option. I have removed your R-b since was not sure if you are still okay with the change. Changes: * move sev_enabled in .data section arch/x86/include/asm/mem_encrypt.h | 6 ++++++ arch/x86/mm/mem_encrypt.c | 26 ++++++++++++++++++++++++++ include/linux/mem_encrypt.h | 7 +++++-- 3 files changed, 37 insertions(+), 2 deletions(-) diff --git a/arch/x86/include/asm/mem_encrypt.h b/arch/x86/include/asm/mem_encrypt.h index 6a77c63540f7..2b024741bce9 100644 --- a/arch/x86/include/asm/mem_encrypt.h +++ b/arch/x86/include/asm/mem_encrypt.h @@ -47,6 +47,9 @@ void __init mem_encrypt_init(void); void swiotlb_set_mem_attributes(void *vaddr, unsigned long size); +bool sme_active(void); +bool sev_active(void); + #else /* !CONFIG_AMD_MEM_ENCRYPT */ #define sme_me_mask 0ULL @@ -64,6 +67,9 @@ static inline void __init sme_early_init(void) { } static inline void __init sme_encrypt_kernel(void) { } static inline void __init sme_enable(struct boot_params *bp) { } +static inline bool sme_active(void) { return false; } +static inline bool sev_active(void) { return false; } + #endif /* CONFIG_AMD_MEM_ENCRYPT */ /* diff --git a/arch/x86/mm/mem_encrypt.c b/arch/x86/mm/mem_encrypt.c index 3fcc8e01683b..b84c9a52df18 100644 --- a/arch/x86/mm/mem_encrypt.c +++ b/arch/x86/mm/mem_encrypt.c @@ -40,6 +40,8 @@ static char sme_cmdline_off[] __initdata = "off"; u64 sme_me_mask __section(.data) = 0; EXPORT_SYMBOL_GPL(sme_me_mask); +static bool sev_enabled __section(.data) = false; + /* Buffer used for early in-place encryption by BSP, no locking needed */ static char sme_early_buffer[PAGE_SIZE] __aligned(PAGE_SIZE); @@ -190,6 +192,30 @@ void __init sme_early_init(void) protection_map[i] = pgprot_encrypted(protection_map[i]); } +/* + * SME and SEV are very similar but they are not the same, so there are + * times that the kernel will need to distinguish between SME and SEV. The + * sme_active() and sev_active() functions are used for this. When a + * distinction isn't needed, the mem_encrypt_active() function can be used. + * + * The trampoline code is a good example for this requirement. Before + * paging is activated, SME will access all memory as decrypted, but SEV + * will access all memory as encrypted. So, when APs are being brought + * up under SME the trampoline area cannot be encrypted, whereas under SEV + * the trampoline area must be encrypted. + */ +bool sme_active(void) +{ + return sme_me_mask && !sev_enabled; +} +EXPORT_SYMBOL_GPL(sme_active); + +bool sev_active(void) +{ + return sme_me_mask && sev_enabled; +} +EXPORT_SYMBOL_GPL(sev_active); + /* Architecture __weak replacement functions */ void __init mem_encrypt_init(void) { diff --git a/include/linux/mem_encrypt.h b/include/linux/mem_encrypt.h index 265a9cd21cb4..b310a9c18113 100644 --- a/include/linux/mem_encrypt.h +++ b/include/linux/mem_encrypt.h @@ -23,11 +23,14 @@ #define sme_me_mask 0ULL +static inline bool sme_active(void) { return false; } +static inline bool sev_active(void) { return false; } + #endif /* CONFIG_ARCH_HAS_MEM_ENCRYPT */ -static inline bool sme_active(void) +static inline bool mem_encrypt_active(void) { - return !!sme_me_mask; + return sme_me_mask; } static inline u64 sme_get_me_mask(void) -- 2.9.5