From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751436AbdJARQ4 (ORCPT ); Sun, 1 Oct 2017 13:16:56 -0400 Received: from mx2.suse.de ([195.135.220.15]:57850 "EHLO mx1.suse.de" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1751093AbdJARQy (ORCPT ); Sun, 1 Oct 2017 13:16:54 -0400 Date: Sun, 1 Oct 2017 19:16:17 +0200 From: Borislav Petkov To: Brijesh Singh Cc: Tom Lendacky , Thomas Gleixner , Ingo Molnar , "H. Peter Anvin" , Paolo Bonzini , Radim =?utf-8?B?S3LEjW3DocWZ?= , kvm@vger.kernel.org, x86@kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH] x86/CPU/AMD, mm: Extend with mem_encrypt=sme option Message-ID: <20171001171617.uzwfzps7sxowfram@pd.tnic> References: <20170928090242.ber7gynwaldinafa@pd.tnic> <20170929230652.37821-1-brijesh.singh@amd.com> <20170930115604.w4g3oplmyo5oyjeq@pd.tnic> <26bdd83f-f4a0-dbfc-e6f9-fc3780ce0080@amd.com> <20170930214124.74w44yel3gijwlxj@pd.tnic> <6f50eb4c-f2bb-f125-196f-c1456dd6c601@amd.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <6f50eb4c-f2bb-f125-196f-c1456dd6c601@amd.com> User-Agent: NeoMutt/20170113 (1.7.2) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sun, Oct 01, 2017 at 12:00:31PM -0500, Brijesh Singh wrote: > When SEV feature is disabled, KVM will not be able to launch any SEV > guests.  When SEV support is available, KVM can enable it in a specific > VM by setting SEV bit before executing the VMRUN instruction. So I want to be able to disable SEV and the whole code that comes with it in the *host*. > Guest OS: > -------- > Checks the MSR_AMD64_SEV to determine if SEV feature is enabled. Please > note that the MSR is a read-only. IOW, MSR is not intercepted by the > hypervisor. > > Currently, mem_encrypt=xxx and CONFIG_AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT > is don't care. We can not depend on the command line because when SEV is > enabled in a VM then instruction fetch will be decrypted by the > hardware. If we want then we can perform the comparison between the SEV > state obtained through MSR with user supplied command line and trigger > BUG() if they don't match. And when we have supplied mem_encrypt=sme to the *host* cmdline, it should be impossible to start SEV guests. IOW, that feature mask test should not happen and I should do instead: } else if (!strncmp(buffer, cmd_sme, sizeof(buffer))) { sme_only = true; sev_enabled = false; } Or, respectively, not set it here as it is false already but set it at the end of the function like this: if (sme_only) return; sev_enabled = true; } Hmmm? -- Regards/Gruss, Boris. SUSE Linux GmbH, GF: Felix Imendörffer, Jane Smithard, Graham Norton, HRB 21284 (AG Nürnberg) --