From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail.alien8.de (mail.alien8.de [65.109.113.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2B108328625 for ; Mon, 17 Nov 2025 21:11:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=65.109.113.108 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1763413886; cv=none; b=lzKfzXMBUFLDG2YTyPrbU1LJq22So76f9rMcpwWAa7qGS9Keti2hjAVuk8htmOO7VIOnnTtDQ0ONO5QfsdyQIagJB3EixsfGoI+Vzuy5dT1WtoNzJC2Cp6U6fWUf12ctsM7R9cbtxYnKOKpeuZwcHwMHSeMhPsAveGnPoGGFYYQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1763413886; c=relaxed/simple; bh=1wGQGI4C5+CqlCjjE7owjZTgIq1prRAadC+aqWm0lm8=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=Mqw6y2QE/Rp3g9nNYNQlYwviYsueOWYbnU5BMdOt1kz4rI/X1bBkrgwO1q4a1DwhrCc6yDbsHE2ho/TBrAKS2AtAGykqeGEjSf0aSC79Kg5mZ/yBoscDN7TDjC2/XGz9amlOYmDKTQ9W09MKA0DdZzEo5/4/ziw6iLkFZBt7Xnw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=alien8.de; spf=pass smtp.mailfrom=alien8.de; dkim=pass (4096-bit key) header.d=alien8.de header.i=@alien8.de header.b=OFowDoAz; arc=none smtp.client-ip=65.109.113.108 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=alien8.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=alien8.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (4096-bit key) header.d=alien8.de header.i=@alien8.de header.b="OFowDoAz" Received: from localhost (localhost.localdomain [127.0.0.1]) by mail.alien8.de (SuperMail on ZX Spectrum 128k) with ESMTP id E780440E0258; Mon, 17 Nov 2025 21:11:19 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at mail.alien8.de Authentication-Results: mail.alien8.de (amavisd-new); dkim=pass (4096-bit key) header.d=alien8.de Received: from mail.alien8.de ([127.0.0.1]) by localhost (mail.alien8.de [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id VdeT-iqnp0Xj; Mon, 17 Nov 2025 21:11:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alien8.de; s=alien8; t=1763413874; bh=kN/ZP+AETUYMxSbztTJq36lxsjO5fcsgKZuFEA2bpDE=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=OFowDoAzB42/RXfJGFzs4fMWo5AgZGdHbl02Sxfh9HjnW6od+JSzKEbtyqsJPsOtv PhSv3cxkajGFV48WjSdWBMrws2vvKq1Ub/68U3rPeRtoZiG91BoL6o+wcGqp2i6qK5 YQVpcNK04NRTZjCWpCGZT4Xs8uiYaJVHPbWhiwNoR47Dyo5SSfuILuB+5jCEhZVhyW G+ly3wvyQxxHK/yp+nowogInAIUQfbfJc09QLWvcx2/bgNphul5dggn8XyWa4qQjPr Kp8UCQMTzM3H3CRMhHh8btDh8qKftgVXwZrLcyUgwu79NdbWV4wdEN9VTtwTu4OO2t JrNJA+OE36Y66koMfV4BLwOABkdbrf761dChWjISBCs+4tiEopbJ2o1nAFSaQmQgnc fd4c2eeIgpWhL8Rl1HRZFq+2gTWq7ytVgv3SAIbQ+fH7qxdFnThElRAeyMj39X/ViC UQzKJRIo0KKNrcH76uNlFZgxrLXvrZjkuNYg32V2zrgxCEcBQ0m1AixxAqYaXGA0r2 BMW6CCqGdB3zDipczS6u+9f48WraiBmVpxlo579uVZFQ0gCMc3EVxsYXGLEIfUuwVZ MAcA6V+si2nAR24NOmqQedBNc+97+b+V0XTpPbCHT/nh74k2lcx5au5lm0SQsFa42o 4LAmLeU5pz5/2steBAlUD6yM= Received: from zn.tnic (pd9530da1.dip0.t-ipconnect.de [217.83.13.161]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail.alien8.de (SuperMail on ZX Spectrum 128k) with UTF8SMTPSA id 141B440E022E; Mon, 17 Nov 2025 21:11:07 +0000 (UTC) Date: Mon, 17 Nov 2025 22:11:01 +0100 From: Borislav Petkov To: Waiman Long Cc: Thomas Gleixner , Ingo Molnar , Dave Hansen , "H. Peter Anvin" , x86@kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH tip] x86/microcode/AMD: Read from MSR_AMD64_PATCH_LEVEL to get base_rev if not defined Message-ID: <20251117211101.GGaRuPZQQ2InlyRbk9@fat_crate.local> References: <20251117191527.1487774-1-longman@redhat.com> <20251117193750.GAaRt5jpu9XSHEawSM@fat_crate.local> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: On Mon, Nov 17, 2025 at 02:58:30PM -0500, Waiman Long wrote: > when CONFIG_MICROCODE_DBG is on. Again, CONFIG_MICROCODE_DBG is only to be used in a guest. Like the help text says. For now at least. I have tried to extend it to debugging on baremetal - see below - but this is unfinished. --- Author: Borislav Petkov (AMD) Date: Mon Oct 6 17:50:10 2025 +0200 Host debugging Signed-off-by: Borislav Petkov (AMD) diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig index fa3b616af03a..c213e00ea963 100644 --- a/arch/x86/Kconfig +++ b/arch/x86/Kconfig @@ -1362,10 +1362,12 @@ config MICROCODE_DBG default n depends on MICROCODE help - Enable code which allows for debugging the microcode loader in - a guest. Meaning the patch loading is simulated but everything else + Enable code which allows to debug the microcode loader. When running + in a guest the patch loading is simulated but everything else related to patch parsing and handling is done as on baremetal with - the purpose of debugging solely the software side of things. + the purpose of debugging solely the software side of things. On + baremetal, it simply dumps additional debugging information as it + goes. You almost certainly want to say n here. diff --git a/arch/x86/kernel/cpu/microcode/amd.c b/arch/x86/kernel/cpu/microcode/amd.c index a584f9cbf9a3..c25db0d40629 100644 --- a/arch/x86/kernel/cpu/microcode/amd.c +++ b/arch/x86/kernel/cpu/microcode/amd.c @@ -301,7 +301,7 @@ static u32 get_patch_level(void) { u32 rev, dummy __always_unused; - if (IS_ENABLED(CONFIG_MICROCODE_DBG)) { + if (IS_ENABLED(CONFIG_MICROCODE_DBG) && hypervisor_present) { int cpu = smp_processor_id(); if (!microcode_rev[cpu]) { @@ -694,7 +694,7 @@ static bool __apply_microcode_amd(struct microcode_amd *mc, u32 *cur_rev, invlpg(p_addr_end); } - if (IS_ENABLED(CONFIG_MICROCODE_DBG)) + if (IS_ENABLED(CONFIG_MICROCODE_DBG) && hypervisor_present) microcode_rev[smp_processor_id()] = mc->hdr.patch_id; /* verify patch application was successful */ diff --git a/arch/x86/kernel/cpu/microcode/core.c b/arch/x86/kernel/cpu/microcode/core.c index f75c140906d0..ae0ba9df501b 100644 --- a/arch/x86/kernel/cpu/microcode/core.c +++ b/arch/x86/kernel/cpu/microcode/core.c @@ -57,6 +57,8 @@ bool force_minrev = IS_ENABLED(CONFIG_MICROCODE_LATE_FORCE_MINREV); u32 base_rev; u32 microcode_rev[NR_CPUS] = {}; +bool hypervisor_present; + /* * Synchronization. * @@ -117,6 +119,13 @@ bool __init microcode_loader_disabled(void) * Disable when: * * 1) The CPU does not support CPUID. + */ + if (!cpuid_feature()) { + dis_ucode_ldr = true; + return dis_ucode_ldr; + } + + /* * * 2) Bit 31 in CPUID[1]:ECX is clear * The bit is reserved for hypervisor use. This is still not @@ -127,9 +136,9 @@ bool __init microcode_loader_disabled(void) * 3) Certain AMD patch levels are not allowed to be * overwritten. */ - if (!cpuid_feature() || - ((native_cpuid_ecx(1) & BIT(31)) && - !IS_ENABLED(CONFIG_MICROCODE_DBG)) || + hypervisor_present = native_cpuid_ecx(1) & BIT(31); + + if ((hypervisor_present && !IS_ENABLED(CONFIG_MICROCODE_DBG)) || amd_check_current_patch_level()) dis_ucode_ldr = true; diff --git a/arch/x86/kernel/cpu/microcode/internal.h b/arch/x86/kernel/cpu/microcode/internal.h index ae8dbc2b908d..f084aac6c839 100644 --- a/arch/x86/kernel/cpu/microcode/internal.h +++ b/arch/x86/kernel/cpu/microcode/internal.h @@ -46,6 +46,7 @@ extern struct early_load_data early_data; extern struct ucode_cpu_info ucode_cpu_info[]; extern u32 microcode_rev[NR_CPUS]; extern u32 base_rev; +extern bool hypervisor_present; struct cpio_data find_microcode_in_initrd(const char *path); -- Regards/Gruss, Boris. https://people.kernel.org/tglx/notes-about-netiquette