* [PATCH v4 0/2] nosnp sev command line support
@ 2024-09-22 3:36 Pavan Kumar Paluri
2024-09-22 3:36 ` [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm Pavan Kumar Paluri
2024-09-22 3:36 ` [PATCH v4 2/2] x86 KVM:SVM: Provide "nosnp" boot option for sev kernel command line Pavan Kumar Paluri
0 siblings, 2 replies; 5+ messages in thread
From: Pavan Kumar Paluri @ 2024-09-22 3:36 UTC (permalink / raw)
To: linux-kernel
Cc: linux-doc, Borislav Petkov, Thomas Gleixner, Ingo Molnar,
Dave Hansen, Eric Van Tassell, Tom Lendacky, Ashish Kalra,
Michael Roth, H . Peter Anvin, Peter Zijlstra,
Pavan Kumar Paluri
Provide "nosnp" boot option via "sev=nosnp" kernel command line to
prevent SEV-SNP[1] capable host kernel from enabling SEV-SNP and
initializing Reverse Map Table (RMP) [1].
On providing sev=nosnp via kernel command line:
cat /sys/module/kvm_amd/parameters/sev_snp should be "N".
This patchset is based on tip/master.
Reference:
[1] https://www.amd.com/content/dam/amd/en/documents/processor-tech-docs/programmer-references/24593.pdf
Changelog:
v3->v4:
* Remove an irrelevant header (Boris)
* Rebase on latest tip/master
v2->v3:
* Fix the build warning reported by kernel test robot
* https://lore.kernel.org/all/20240905143056.48216-1-papaluri@amd.com/
v1->v2:
* Pick R-b's from Tom.
* Include only those headers that provide the necessary definitions (Boris)
* Provide appropriate references to SEV, SNP and RMP (Matthew)
* https://lore.kernel.org/all/20240903003511.1530454-1-papaluri@amd.com/
Pavan Kumar Paluri (2):
x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm
x86 KVM:SVM: Provide "nosnp" boot option for sev kernel command line
.../arch/x86/x86_64/boot-options.rst | 3 ++
arch/x86/coco/sev/core.c | 44 -------------------
arch/x86/include/asm/sev-common.h | 29 ++++++++++++
arch/x86/virt/svm/Makefile | 1 +
arch/x86/virt/svm/cmdline.c | 39 ++++++++++++++++
5 files changed, 72 insertions(+), 44 deletions(-)
create mode 100644 arch/x86/virt/svm/cmdline.c
base-commit: 6d3e8e28e20d250d2f3ebb3f5afb63848a2aebf9
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm
2024-09-22 3:36 [PATCH v4 0/2] nosnp sev command line support Pavan Kumar Paluri
@ 2024-09-22 3:36 ` Pavan Kumar Paluri
2024-09-25 15:57 ` Tom Lendacky
2024-09-22 3:36 ` [PATCH v4 2/2] x86 KVM:SVM: Provide "nosnp" boot option for sev kernel command line Pavan Kumar Paluri
1 sibling, 1 reply; 5+ messages in thread
From: Pavan Kumar Paluri @ 2024-09-22 3:36 UTC (permalink / raw)
To: linux-kernel
Cc: linux-doc, Borislav Petkov, Thomas Gleixner, Ingo Molnar,
Dave Hansen, Eric Van Tassell, Tom Lendacky, Ashish Kalra,
Michael Roth, H . Peter Anvin, Peter Zijlstra,
Pavan Kumar Paluri
Move SEV specific kernel command line option parsing support from
arch/x86/coco/sev/core.c to arch/x86/virt/svm/cmdline.c so that both
host and guest related SEV command line options can be supported.
No functional changes intended.
Signed-off-by: Pavan Kumar Paluri <papaluri@amd.com>
Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
---
arch/x86/coco/sev/core.c | 44 -------------------------------
arch/x86/include/asm/sev-common.h | 29 ++++++++++++++++++++
arch/x86/virt/svm/Makefile | 1 +
arch/x86/virt/svm/cmdline.c | 32 ++++++++++++++++++++++
4 files changed, 62 insertions(+), 44 deletions(-)
create mode 100644 arch/x86/virt/svm/cmdline.c
diff --git a/arch/x86/coco/sev/core.c b/arch/x86/coco/sev/core.c
index de1df0cb45da..ff19e805e7a1 100644
--- a/arch/x86/coco/sev/core.c
+++ b/arch/x86/coco/sev/core.c
@@ -141,33 +141,6 @@ static DEFINE_PER_CPU(struct sev_es_save_area *, sev_vmsa);
static DEFINE_PER_CPU(struct svsm_ca *, svsm_caa);
static DEFINE_PER_CPU(u64, svsm_caa_pa);
-struct sev_config {
- __u64 debug : 1,
-
- /*
- * Indicates when the per-CPU GHCB has been created and registered
- * and thus can be used by the BSP instead of the early boot GHCB.
- *
- * For APs, the per-CPU GHCB is created before they are started
- * and registered upon startup, so this flag can be used globally
- * for the BSP and APs.
- */
- ghcbs_initialized : 1,
-
- /*
- * Indicates when the per-CPU SVSM CA is to be used instead of the
- * boot SVSM CA.
- *
- * For APs, the per-CPU SVSM CA is created as part of the AP
- * bringup, so this flag can be used globally for the BSP and APs.
- */
- use_cas : 1,
-
- __reserved : 61;
-};
-
-static struct sev_config sev_cfg __read_mostly;
-
static __always_inline bool on_vc_stack(struct pt_regs *regs)
{
unsigned long sp = regs->sp;
@@ -2374,23 +2347,6 @@ static int __init report_snp_info(void)
}
arch_initcall(report_snp_info);
-static int __init init_sev_config(char *str)
-{
- char *s;
-
- while ((s = strsep(&str, ","))) {
- if (!strcmp(s, "debug")) {
- sev_cfg.debug = true;
- continue;
- }
-
- pr_info("SEV command-line option '%s' was not recognized\n", s);
- }
-
- return 1;
-}
-__setup("sev=", init_sev_config);
-
static void update_attest_input(struct svsm_call *call, struct svsm_attest_call *input)
{
/* If (new) lengths have been returned, propagate them up */
diff --git a/arch/x86/include/asm/sev-common.h b/arch/x86/include/asm/sev-common.h
index 98726c2b04f8..adddcf3edaf0 100644
--- a/arch/x86/include/asm/sev-common.h
+++ b/arch/x86/include/asm/sev-common.h
@@ -8,6 +8,8 @@
#ifndef __ASM_X86_SEV_COMMON_H
#define __ASM_X86_SEV_COMMON_H
+#include <asm/cache.h>
+
#define GHCB_MSR_INFO_POS 0
#define GHCB_DATA_LOW 12
#define GHCB_MSR_INFO_MASK (BIT_ULL(GHCB_DATA_LOW) - 1)
@@ -220,4 +222,31 @@ struct snp_psc_desc {
#define GHCB_ERR_INVALID_INPUT 5
#define GHCB_ERR_INVALID_EVENT 6
+struct sev_config {
+ __u64 debug : 1,
+
+ /*
+ * Indicates when the per-CPU GHCB has been created and registered
+ * and thus can be used by the BSP instead of the early boot GHCB.
+ *
+ * For APs, the per-CPU GHCB is created before they are started
+ * and registered upon startup, so this flag can be used globally
+ * for the BSP and APs.
+ */
+ ghcbs_initialized : 1,
+
+ /*
+ * Indicates when the per-CPU SVSM CA is to be used instead of the
+ * boot SVSM CA.
+ *
+ * For APs, the per-CPU SVSM CA is created as part of the AP
+ * bringup, so this flag can be used globally for the BSP and APs.
+ */
+ use_cas : 1,
+
+ __reserved : 61;
+};
+
+extern struct sev_config sev_cfg __read_mostly;
+
#endif
diff --git a/arch/x86/virt/svm/Makefile b/arch/x86/virt/svm/Makefile
index ef2a31bdcc70..eca6d71355fa 100644
--- a/arch/x86/virt/svm/Makefile
+++ b/arch/x86/virt/svm/Makefile
@@ -1,3 +1,4 @@
# SPDX-License-Identifier: GPL-2.0
obj-$(CONFIG_KVM_AMD_SEV) += sev.o
+obj-$(CONFIG_CPU_SUP_AMD) += cmdline.o
diff --git a/arch/x86/virt/svm/cmdline.c b/arch/x86/virt/svm/cmdline.c
new file mode 100644
index 000000000000..964677ab02d6
--- /dev/null
+++ b/arch/x86/virt/svm/cmdline.c
@@ -0,0 +1,32 @@
+// SPDX-License-Identifier: GPL-2.0-only
+/*
+ * AMD SVM-SEV command line parsing support
+ *
+ * Copyright (C) 2023 - 2024 Advanced Micro Devices, Inc.
+ *
+ * Author: Michael Roth <michael.roth@amd.com>
+ */
+
+#include <linux/string.h>
+#include <linux/printk.h>
+
+#include <asm/sev-common.h>
+
+struct sev_config sev_cfg;
+
+static int __init init_sev_config(char *str)
+{
+ char *s;
+
+ while ((s = strsep(&str, ","))) {
+ if (!strcmp(s, "debug")) {
+ sev_cfg.debug = true;
+ continue;
+ }
+
+ pr_info("SEV command-line option '%s' was not recognized\n", s);
+ }
+
+ return 1;
+}
+__setup("sev=", init_sev_config);
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v4 2/2] x86 KVM:SVM: Provide "nosnp" boot option for sev kernel command line
2024-09-22 3:36 [PATCH v4 0/2] nosnp sev command line support Pavan Kumar Paluri
2024-09-22 3:36 ` [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm Pavan Kumar Paluri
@ 2024-09-22 3:36 ` Pavan Kumar Paluri
1 sibling, 0 replies; 5+ messages in thread
From: Pavan Kumar Paluri @ 2024-09-22 3:36 UTC (permalink / raw)
To: linux-kernel
Cc: linux-doc, Borislav Petkov, Thomas Gleixner, Ingo Molnar,
Dave Hansen, Eric Van Tassell, Tom Lendacky, Ashish Kalra,
Michael Roth, H . Peter Anvin, Peter Zijlstra,
Pavan Kumar Paluri
Provide a "nosnp" kernel command line option to prevent enabling of the
RMP and SEV-SNP features in the host/hypervisor. Not initializing the
RMP removes system overhead associated with RMP checks.
Co-developed-by: Eric Van Tassell <Eric.VanTassell@amd.com>
Signed-off-by: Eric Van Tassell <Eric.VanTassell@amd.com>
Signed-off-by: Pavan Kumar Paluri <papaluri@amd.com>
Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
---
Documentation/arch/x86/x86_64/boot-options.rst | 3 +++
arch/x86/virt/svm/cmdline.c | 7 +++++++
2 files changed, 10 insertions(+)
diff --git a/Documentation/arch/x86/x86_64/boot-options.rst b/Documentation/arch/x86/x86_64/boot-options.rst
index 137432d34109..3d4e9a7dccf2 100644
--- a/Documentation/arch/x86/x86_64/boot-options.rst
+++ b/Documentation/arch/x86/x86_64/boot-options.rst
@@ -317,3 +317,6 @@ The available options are:
debug
Enable debug messages.
+
+ nosnp
+ Do not enable SEV-SNP (applies to host/hypervisor only).
diff --git a/arch/x86/virt/svm/cmdline.c b/arch/x86/virt/svm/cmdline.c
index 964677ab02d6..454574539c49 100644
--- a/arch/x86/virt/svm/cmdline.c
+++ b/arch/x86/virt/svm/cmdline.c
@@ -11,6 +11,7 @@
#include <linux/printk.h>
#include <asm/sev-common.h>
+#include <asm/cpufeature.h>
struct sev_config sev_cfg;
@@ -24,6 +25,12 @@ static int __init init_sev_config(char *str)
continue;
}
+ if (!strcmp(s, "nosnp")) {
+ setup_clear_cpu_cap(X86_FEATURE_SEV_SNP);
+ cc_platform_clear(CC_ATTR_HOST_SEV_SNP);
+ continue;
+ }
+
pr_info("SEV command-line option '%s' was not recognized\n", s);
}
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm
2024-09-22 3:36 ` [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm Pavan Kumar Paluri
@ 2024-09-25 15:57 ` Tom Lendacky
2024-09-26 17:06 ` Paluri, PavanKumar
0 siblings, 1 reply; 5+ messages in thread
From: Tom Lendacky @ 2024-09-25 15:57 UTC (permalink / raw)
To: Pavan Kumar Paluri, linux-kernel
Cc: linux-doc, Borislav Petkov, Thomas Gleixner, Ingo Molnar,
Dave Hansen, Eric Van Tassell, Ashish Kalra, Michael Roth,
H . Peter Anvin, Peter Zijlstra
On 9/21/24 22:36, Pavan Kumar Paluri wrote:
> Move SEV specific kernel command line option parsing support from
> arch/x86/coco/sev/core.c to arch/x86/virt/svm/cmdline.c so that both
> host and guest related SEV command line options can be supported.
>
> No functional changes intended.
>
> Signed-off-by: Pavan Kumar Paluri <papaluri@amd.com>
> Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
> ---
> arch/x86/coco/sev/core.c | 44 -------------------------------
> arch/x86/include/asm/sev-common.h | 29 ++++++++++++++++++++
> arch/x86/virt/svm/Makefile | 1 +
> arch/x86/virt/svm/cmdline.c | 32 ++++++++++++++++++++++
> 4 files changed, 62 insertions(+), 44 deletions(-)
> create mode 100644 arch/x86/virt/svm/cmdline.c
>
...
> diff --git a/arch/x86/include/asm/sev-common.h b/arch/x86/include/asm/sev-common.h
> index 98726c2b04f8..adddcf3edaf0 100644
> --- a/arch/x86/include/asm/sev-common.h
> +++ b/arch/x86/include/asm/sev-common.h
> @@ -8,6 +8,8 @@
> #ifndef __ASM_X86_SEV_COMMON_H
> #define __ASM_X86_SEV_COMMON_H
>
> +#include <asm/cache.h>
> +
> #define GHCB_MSR_INFO_POS 0
> #define GHCB_DATA_LOW 12
> #define GHCB_MSR_INFO_MASK (BIT_ULL(GHCB_DATA_LOW) - 1)
> @@ -220,4 +222,31 @@ struct snp_psc_desc {
> #define GHCB_ERR_INVALID_INPUT 5
> #define GHCB_ERR_INVALID_EVENT 6
>
> +struct sev_config {
> + __u64 debug : 1,
> +
> + /*
> + * Indicates when the per-CPU GHCB has been created and registered
> + * and thus can be used by the BSP instead of the early boot GHCB.
> + *
> + * For APs, the per-CPU GHCB is created before they are started
> + * and registered upon startup, so this flag can be used globally
> + * for the BSP and APs.
> + */
> + ghcbs_initialized : 1,
> +
> + /*
> + * Indicates when the per-CPU SVSM CA is to be used instead of the
> + * boot SVSM CA.
> + *
> + * For APs, the per-CPU SVSM CA is created as part of the AP
> + * bringup, so this flag can be used globally for the BSP and APs.
> + */
> + use_cas : 1,
> +
> + __reserved : 61;
> +};
> +
> +extern struct sev_config sev_cfg __read_mostly;
So I believe the "__read_mostly" attribute really needs to be on the
actual declaration of the struct, below, in cmdline.c, right?
You can check and see which section the sev_cfg struct ends up being
placed after a build to verify.
Thanks,
Tom
> +
> #endif
> diff --git a/arch/x86/virt/svm/Makefile b/arch/x86/virt/svm/Makefile
> index ef2a31bdcc70..eca6d71355fa 100644
> --- a/arch/x86/virt/svm/Makefile
> +++ b/arch/x86/virt/svm/Makefile
> @@ -1,3 +1,4 @@
> # SPDX-License-Identifier: GPL-2.0
>
> obj-$(CONFIG_KVM_AMD_SEV) += sev.o
> +obj-$(CONFIG_CPU_SUP_AMD) += cmdline.o
> diff --git a/arch/x86/virt/svm/cmdline.c b/arch/x86/virt/svm/cmdline.c
> new file mode 100644
> index 000000000000..964677ab02d6
> --- /dev/null
> +++ b/arch/x86/virt/svm/cmdline.c
> @@ -0,0 +1,32 @@
> +// SPDX-License-Identifier: GPL-2.0-only
> +/*
> + * AMD SVM-SEV command line parsing support
> + *
> + * Copyright (C) 2023 - 2024 Advanced Micro Devices, Inc.
> + *
> + * Author: Michael Roth <michael.roth@amd.com>
> + */
> +
> +#include <linux/string.h>
> +#include <linux/printk.h>
> +
> +#include <asm/sev-common.h>
> +
> +struct sev_config sev_cfg;
> +
> +static int __init init_sev_config(char *str)
> +{
> + char *s;
> +
> + while ((s = strsep(&str, ","))) {
> + if (!strcmp(s, "debug")) {
> + sev_cfg.debug = true;
> + continue;
> + }
> +
> + pr_info("SEV command-line option '%s' was not recognized\n", s);
> + }
> +
> + return 1;
> +}
> +__setup("sev=", init_sev_config);
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm
2024-09-25 15:57 ` Tom Lendacky
@ 2024-09-26 17:06 ` Paluri, PavanKumar
0 siblings, 0 replies; 5+ messages in thread
From: Paluri, PavanKumar @ 2024-09-26 17:06 UTC (permalink / raw)
To: Tom Lendacky, linux-kernel
Cc: linux-doc, Borislav Petkov, Thomas Gleixner, Ingo Molnar,
Dave Hansen, Eric Van Tassell, Ashish Kalra, Michael Roth,
H . Peter Anvin, Peter Zijlstra
Hello Tom,
On 9/25/2024 10:57 AM, Tom Lendacky wrote:
> On 9/21/24 22:36, Pavan Kumar Paluri wrote:
>> Move SEV specific kernel command line option parsing support from
>> arch/x86/coco/sev/core.c to arch/x86/virt/svm/cmdline.c so that both
>> host and guest related SEV command line options can be supported.
>>
>> No functional changes intended.
>>
>> Signed-off-by: Pavan Kumar Paluri <papaluri@amd.com>
>> Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
>> ---
>> arch/x86/coco/sev/core.c | 44 -------------------------------
>> arch/x86/include/asm/sev-common.h | 29 ++++++++++++++++++++
>> arch/x86/virt/svm/Makefile | 1 +
>> arch/x86/virt/svm/cmdline.c | 32 ++++++++++++++++++++++
>> 4 files changed, 62 insertions(+), 44 deletions(-)
>> create mode 100644 arch/x86/virt/svm/cmdline.c
>>
>
...
>> +extern struct sev_config sev_cfg __read_mostly;
>
> So I believe the "__read_mostly" attribute really needs to be on the
> actual declaration of the struct, below, in cmdline.c, right?
>
Yes, I will move this attribute to cmdline.c
> You can check and see which section the sev_cfg struct ends up being
> placed after a build to verify.
>
It is placed in .data.readmostly section.
0000000000000000 g O .data..read_mostly 0000000000000008 sev_cfg
> Thanks,
> Tom
>
Thanks for the review,
Pavan
>> +
>> #endif
>> diff --git a/arch/x86/virt/svm/Makefile b/arch/x86/virt/svm/Makefile
>> index ef2a31bdcc70..eca6d71355fa 100644
>> --- a/arch/x86/virt/svm/Makefile
>> +++ b/arch/x86/virt/svm/Makefile
>> @@ -1,3 +1,4 @@
>> # SPDX-License-Identifier: GPL-2.0
>>
>> obj-$(CONFIG_KVM_AMD_SEV) += sev.o
>> +obj-$(CONFIG_CPU_SUP_AMD) += cmdline.o
>> diff --git a/arch/x86/virt/svm/cmdline.c b/arch/x86/virt/svm/cmdline.c
>> new file mode 100644
>> index 000000000000..964677ab02d6
>> --- /dev/null
>> +++ b/arch/x86/virt/svm/cmdline.c
>> @@ -0,0 +1,32 @@
>> +// SPDX-License-Identifier: GPL-2.0-only
>> +/*
>> + * AMD SVM-SEV command line parsing support
>> + *
>> + * Copyright (C) 2023 - 2024 Advanced Micro Devices, Inc.
>> + *
>> + * Author: Michael Roth <michael.roth@amd.com>
>> + */
>> +
>> +#include <linux/string.h>
>> +#include <linux/printk.h>
>> +
>> +#include <asm/sev-common.h>
>> +
>> +struct sev_config sev_cfg;
>> +
>> +static int __init init_sev_config(char *str)
>> +{
>> + char *s;
>> +
>> + while ((s = strsep(&str, ","))) {
>> + if (!strcmp(s, "debug")) {
>> + sev_cfg.debug = true;
>> + continue;
>> + }
>> +
>> + pr_info("SEV command-line option '%s' was not recognized\n", s);
>> + }
>> +
>> + return 1;
>> +}
>> +__setup("sev=", init_sev_config);
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2024-09-26 17:06 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-09-22 3:36 [PATCH v4 0/2] nosnp sev command line support Pavan Kumar Paluri
2024-09-22 3:36 ` [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm Pavan Kumar Paluri
2024-09-25 15:57 ` Tom Lendacky
2024-09-26 17:06 ` Paluri, PavanKumar
2024-09-22 3:36 ` [PATCH v4 2/2] x86 KVM:SVM: Provide "nosnp" boot option for sev kernel command line Pavan Kumar Paluri
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®