From: Alexey Kardashevskiy <aik@amd.com>
To: <x86@kernel.org>
Cc: linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
linux-crypto@vger.kernel.org, linux-pci@vger.kernel.org,
"Thomas Gleixner" <tglx@kernel.org>,
"Ingo Molnar" <mingo@redhat.com>,
"Borislav Petkov" <bp@alien8.de>,
"Dave Hansen" <dave.hansen@linux.intel.com>,
"H. Peter Anvin" <hpa@zytor.com>,
"Sean Christopherson" <seanjc@google.com>,
"Paolo Bonzini" <pbonzini@redhat.com>,
"Andy Lutomirski" <luto@kernel.org>,
"Peter Zijlstra" <peterz@infradead.org>,
"Ashish Kalra" <ashish.kalra@amd.com>,
"Tom Lendacky" <thomas.lendacky@amd.com>,
"Herbert Xu" <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
"Bjorn Helgaas" <bhelgaas@google.com>,
"Juergen Gross" <jgross@suse.com>,
"Stefano Stabellini" <sstabellini@kernel.org>,
"Oleksandr Tyshchenko" <oleksandr_tyshchenko@epam.com>,
"Marek Szyprowski" <m.szyprowski@samsung.com>,
"Robin Murphy" <robin.murphy@arm.com>,
"Andrew Morton" <akpm@linux-foundation.org>,
"David Hildenbrand" <david@kernel.org>,
"Lorenzo Stoakes" <ljs@kernel.org>,
"Liam R. Howlett" <liam@infradead.org>,
"Vlastimil Babka" <vbabka@kernel.org>,
"Mike Rapoport" <rppt@kernel.org>,
"Suren Baghdasaryan" <surenb@google.com>,
"Michal Hocko" <mhocko@suse.com>,
"Catalin Marinas" <catalin.marinas@arm.com>,
"Jini Susan George" <jinisusan.george@amd.com>,
"Kees Cook" <kees@kernel.org>,
"Michael Ellerman" <mpe@ellerman.id.au>,
"Nikunj A Dadhania" <nikunj@amd.com>,
"Ard Biesheuvel" <ardb@kernel.org>,
"Eric Biggers" <ebiggers@kernel.org>,
"Kim Phillips" <kim.phillips@amd.com>,
"Joerg Roedel" <jroedel@suse.de>,
"Ethan Nelson-Moore" <enelsonmoore@gmail.com>,
"Tycho Andersen (AMD)" <tycho@kernel.org>,
"Liam Merwick" <liam.merwick@oracle.com>,
"Michael Kerrisk" <mtk.manpages@gmail.com>,
"Suresh Siddha" <suresh.b.siddha@intel.com>,
"Xiaotian Feng" <dfeng@redhat.com>,
"Venkatesh Pallipadi" <venkatesh.pallipadi@intel.com>,
"Andi Kleen" <ak@linux.intel.com>,
"Kiryl Shutsemau" <kas@kernel.org>,
"Tony Luck" <tony.luck@intel.com>,
"Jason Gunthorpe" <jgg@ziepe.ca>,
"Lu Baolu" <baolu.lu@linux.intel.com>,
"Xu Yilun" <yilun.xu@linux.intel.com>,
"Carlos López" <clopez@suse.de>,
"Jonathan Cameron" <jic23@kernel.org>,
"Jori Koolstra" <jkoolstra@xs4all.nl>,
"Thomas Weißschuh" <thomas.weissschuh@linutronix.de>,
"Aneesh Kumar K.V (Arm)" <aneesh.kumar@kernel.org>,
"Ian Campbell" <ian.campbell@citrix.com>,
"Jeremy Fitzhardinge" <jeremy.fitzhardinge@citrix.com>,
"Petr Tesarik" <ptesarik@suse.com>,
"David Howells" <dhowells@redhat.com>,
"Haavard Skinnemoen" <hskinnemoen@atmel.com>,
"Kenji Kaneshige" <kaneshige.kenji@jp.fujitsu.com>,
"Ilpo Järvinen" <ilpo.jarvinen@linux.intel.com>,
"Christian Marangi" <ansuelsmth@gmail.com>,
"Dave Jiang" <dave.jiang@intel.com>,
"Michael Kelley" <mhklinux@outlook.com>,
"Ilias Stamatis" <ilstam@amazon.com>,
"Sumanth Korikkar" <sumanthk@linux.ibm.com>,
"Simona Vetter" <simona.vetter@ffwll.ch>,
"Toshi Kani" <toshi.kani@hp.com>,
"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
"Vinod Koul" <vkoul@kernel.org>,
"Jiang Liu" <jiang.liu@linux.intel.com>,
"Arnd Bergmann" <arnd@arndb.de>,
"Anshuman Khandual" <anshuman.khandual@arm.com>,
"Kefeng Wang" <wangkefeng.wang@huawei.com>,
"Palmer Dabbelt" <palmerdabbelt@google.com>,
linux-coco@lists.linux.dev, xen-devel@lists.xenproject.org,
iommu@lists.linux.dev, linux-mm@kvack.org,
"Alexey Kardashevskiy" <aik@amd.com>,
aik@ozlabs.ru, "Santosh Shukla" <santosh.shukla@amd.com>,
"Pratik R . Sampat" <prsampat@amd.com>,
"Scott Soule Cheloha" <scott.cheloha@amd.com>,
"Ackerley Tng" <ackerleytng@google.com>,
"Fuad Tabba" <tabba@google.com>
Subject: [RFC PATCH kernel 14/17] x86/sev: Add GHCB calls for SEV-TIO
Date: Wed, 16 Sep 2026 21:51:54 +1000 [thread overview]
Message-ID: <20260916115159.1938195-15-aik@amd.com> (raw)
In-Reply-To: <20260916115159.1938195-1-aik@amd.com>
SEV-TIO is a PSP protocol allowing PCI pass through of trusted devices
(TDI == TEE Device Interface) to an SNP VM. The VMM advertises
the support via HV_FEATURES and implements new calls:
1) TDI operation: the host executes on the guest behalf:
- TDI bind/unbind to/from the SNP VM in the PSP;
- TDI start/stop which translates to TDISP interface start/stop.
2) TIO guest request for an encrypted communication channel between
the SNP VM and the PSP, it follows the existing Extended Guest Request
pattern to read device evidence:
- get TDI status;
- validate MMIO ranges (a variant of the PVALIDATE instruction for
MMIO RMPs);
- configure sDTE (a secure IOMMU descriptor).
Extend snp_req_data to pass more parameters.
Signed-off-by: Alexey Kardashevskiy <aik@amd.com>
---
arch/x86/include/asm/sev-common.h | 1 +
arch/x86/include/asm/sev.h | 5 +++
arch/x86/include/uapi/asm/svm.h | 40 +++++++++++++++++++
arch/x86/coco/sev/core.c | 42 ++++++++++++++++++++
4 files changed, 88 insertions(+)
diff --git a/arch/x86/include/asm/sev-common.h b/arch/x86/include/asm/sev-common.h
index 01a6e4dbe423..ff763c3c5d63 100644
--- a/arch/x86/include/asm/sev-common.h
+++ b/arch/x86/include/asm/sev-common.h
@@ -137,6 +137,7 @@ enum psc_op {
#define GHCB_HV_FT_SNP BIT_ULL(0)
#define GHCB_HV_FT_SNP_AP_CREATION BIT_ULL(1)
#define GHCB_HV_FT_SNP_MULTI_VMPL BIT_ULL(5)
+#define GHCB_HV_FT_SNP_SEV_TIO BIT_ULL(7)
/*
* SNP Page State Change NAE event
diff --git a/arch/x86/include/asm/sev.h b/arch/x86/include/asm/sev.h
index 9e7a077c445d..89aaccb053ba 100644
--- a/arch/x86/include/asm/sev.h
+++ b/arch/x86/include/asm/sev.h
@@ -149,6 +149,9 @@ struct snp_req_data {
unsigned long resp_gpa;
unsigned long data_gpa;
unsigned int data_npages;
+ unsigned int guest_rid;
+ unsigned long npages;
+ unsigned long param;
};
#define MAX_AUTHTAG_LEN 32
@@ -597,6 +600,8 @@ static inline void sev_evict_cache(void *va, int npages)
}
}
+int sev_tio_op(u32 guest_rid, unsigned int op, u64 *fw_err, u64 *tdi_id);
+
#else /* !CONFIG_AMD_MEM_ENCRYPT */
#define snp_vmpl 0
diff --git a/arch/x86/include/uapi/asm/svm.h b/arch/x86/include/uapi/asm/svm.h
index 010a45c9f614..93597ad492bf 100644
--- a/arch/x86/include/uapi/asm/svm.h
+++ b/arch/x86/include/uapi/asm/svm.h
@@ -122,6 +122,44 @@
#define SVM_VMGEXIT_SAVIC_REGISTER_GPA 0
#define SVM_VMGEXIT_SAVIC_UNREGISTER_GPA 1
#define SVM_VMGEXIT_SAVIC_SELF_GPA ~0ULL
+#define SVM_VMGEXIT_SEV_TIO_GR 0x80000020ull
+#define SVM_VMGEXIT_SEV_TIO_GR_INFO_STATE BIT(0)
+#define SVM_VMGEXIT_SEV_TIO_GR_INFO_CERTS BIT(1)
+#define SVM_VMGEXIT_SEV_TIO_GR_INFO_MEAS BIT(2)
+#define SVM_VMGEXIT_SEV_TIO_GR_INFO_REPORT BIT(3)
+
+#define SVM_VMGEXIT_SEV_TIO_GR_SDTE_VALIDATE BIT(0)
+#define SVM_VMGEXIT_SEV_TIO_GR_SDTE_VTOM GENMASK_ULL(51, 21)
+
+/*
+ * TIO_GUEST_REQUEST's MMIO_VALIDATE_REQ/MMIO_CONFIG_REQ encoding for MMIO in RDX:
+ *
+ * T....... ....GGGG GGGGGGGG GGGGGGGG GGGGGGGG GGGGGGGG GGGG.... ........
+ * Where:
+ * G - guest physical address
+ * T - TEE
+ */
+#define SVM_VMGEXIT_SEV_TIO_GR_MMIO_GFN(r) (((r) & 0x000FFFFFFFFFF000ULL) >> PAGE_SHIFT)
+#define SVM_VMGEXIT_SEV_TIO_GR_MMIO_RESERVED(r) ((r) & 0x7FF0000000000FFFULL)
+#define SVM_VMGEXIT_SEV_TIO_GR_MMIO_PRIVATE(r) (!!((r) & BIT(63)))
+
+#define SVM_VMGEXIT_SEV_TIO_GR_MMIO_NUM(r) ((uint32_t)((r) >> 32))
+#define SVM_VMGEXIT_SEV_TIO_GR_MMIO_ADDR(r) ((uint32_t)((r) & 0xFFFFFFFF))
+
+#define SVM_VMGEXIT_SEV_TIO_GR_MMIO_MK_VALIDATE(start, private) \
+ ((SVM_VMGEXIT_SEV_TIO_GR_MMIO_GFN(start) << PAGE_SHIFT) | \
+ ((private) ? BIT(63) : 0))
+
+#define SVM_VMGEXIT_SEV_TIO_OP 0x80000021ull
+#define SVM_VMGEXIT_SEV_TIO_GR_MMIO_MK_NUM_BDFN(n, bdfn) (((uint64_t)(n) << 32) | (bdfn))
+
+#define SVM_VMGEXIT_SEV_TIO_OP_PARAM(guest_id, action) ((u64)(action)<<32|(guest_id))
+#define SVM_VMGEXIT_SEV_TIO_OP_ACTION(exitinfo1) ((exitinfo1)>>32)
+#define SVM_VMGEXIT_SEV_TIO_OP_GUEST_ID(exitinfo1) ((exitinfo1) & 0xFFFFFFFF)
+#define SVM_VMGEXIT_SEV_TIO_OP_BIND 0
+#define SVM_VMGEXIT_SEV_TIO_OP_UNBIND 1
+#define SVM_VMGEXIT_SEV_TIO_OP_RUN 2
+#define SVM_VMGEXIT_SEV_TIO_OP_STOP 3
#define SVM_VMGEXIT_HV_FEATURES 0x8000fffdull
#define SVM_VMGEXIT_TERM_REQUEST 0x8000fffeull
#define SVM_VMGEXIT_TERM_REASON(reason_set, reason_code) \
@@ -245,6 +283,8 @@
{ SVM_VMGEXIT_GUEST_REQUEST, "vmgexit_guest_request" }, \
{ SVM_VMGEXIT_EXT_GUEST_REQUEST, "vmgexit_ext_guest_request" }, \
{ SVM_VMGEXIT_AP_CREATION, "vmgexit_ap_creation" }, \
+ { SVM_VMGEXIT_SEV_TIO_GR, "vmgexit_sev_tio_guest_request" }, \
+ { SVM_VMGEXIT_SEV_TIO_OP, "vmgexit_sev_tio_op" }, \
{ SVM_VMGEXIT_HV_FEATURES, "vmgexit_hypervisor_feature" }, \
{ SVM_EXIT_ERR, "invalid_guest_state" }
diff --git a/arch/x86/coco/sev/core.c b/arch/x86/coco/sev/core.c
index 5b912f42f493..ed0e4546d5e5 100644
--- a/arch/x86/coco/sev/core.c
+++ b/arch/x86/coco/sev/core.c
@@ -104,6 +104,37 @@ static unsigned long snp_tsc_freq_khz __ro_after_init;
DEFINE_PER_CPU(struct sev_es_runtime_data*, runtime_data);
DEFINE_PER_CPU(struct sev_es_save_area *, sev_vmsa);
+int sev_tio_op(u32 guest_rid, unsigned int op, u64 *fw_err, u64 *tdi_id)
+{
+ struct ghcb_state state;
+ struct es_em_ctxt ctxt;
+ struct ghcb *ghcb;
+ int ret;
+
+ /* __sev_get_ghcb() needs IRQs disabled because it uses per-CPU GHCB. */
+ guard(irqsave)();
+
+ ghcb = __sev_get_ghcb(&state);
+ if (!ghcb)
+ return -EIO;
+
+ vc_ghcb_invalidate(ghcb);
+ ret = sev_es_ghcb_hv_call(ghcb, &ctxt, SVM_VMGEXIT_SEV_TIO_OP,
+ SVM_VMGEXIT_SEV_TIO_OP_PARAM(guest_rid, op), 0);
+
+ *fw_err = ghcb->save.sw_exit_info_2;
+ if (*fw_err)
+ ret = -EIO;
+
+ if (!ret && op == SVM_VMGEXIT_SEV_TIO_OP_BIND && tdi_id)
+ *tdi_id = ghcb_get_rcx(ghcb);
+
+ __sev_put_ghcb(&state);
+
+ return ret;
+}
+EXPORT_SYMBOL_GPL(sev_tio_op);
+
/*
* SVSM related information:
* When running under an SVSM, the VMPL that Linux is executing at must be
@@ -1345,6 +1376,11 @@ static int snp_issue_guest_request(struct snp_guest_req *req)
if (req->exit_code == SVM_VMGEXIT_EXT_GUEST_REQUEST) {
ghcb_set_rax(ghcb, input->data_gpa);
ghcb_set_rbx(ghcb, input->data_npages);
+ } else if (req->exit_code == SVM_VMGEXIT_SEV_TIO_GR) {
+ ghcb_set_rax(ghcb, input->data_gpa);
+ ghcb_set_rbx(ghcb, input->data_npages);
+ ghcb_set_rcx(ghcb, ((uint64_t)input->npages << 32) | input->guest_rid);
+ ghcb_set_rdx(ghcb, input->param);
}
ret = sev_es_ghcb_hv_call(ghcb, &ctxt, req->exit_code, input->req_gpa, input->resp_gpa);
@@ -1354,6 +1390,8 @@ static int snp_issue_guest_request(struct snp_guest_req *req)
req->exitinfo2 = ghcb->save.sw_exit_info_2;
switch (req->exitinfo2) {
case 0:
+ if (req->exit_code == SVM_VMGEXIT_SEV_TIO_GR)
+ input->param = ghcb_get_rdx(ghcb);
break;
case SNP_GUEST_VMM_ERR(SNP_GUEST_VMM_ERR_BUSY):
@@ -1366,6 +1404,10 @@ static int snp_issue_guest_request(struct snp_guest_req *req)
input->data_npages = ghcb_get_rbx(ghcb);
ret = -ENOSPC;
break;
+ } else if (req->exit_code == SVM_VMGEXIT_SEV_TIO_GR) {
+ input->data_npages = ghcb_get_rbx(ghcb);
+ ret = -ENOSPC;
+ break;
}
fallthrough;
default:
--
2.55.0
next prev parent reply other threads:[~2026-09-16 12:01 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 11:51 [RFC PATCH kernel 00/17] PCI/TSM: coco/sev-guest: Implement SEV-TIO PCIe TDISP (phase2) Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 01/17] pci/dma/tsm: Call disable DMA bus hook on cleanup Alexey Kardashevskiy
2026-09-16 17:49 ` Borislav Petkov
2026-09-16 11:51 ` [RFC PATCH kernel 02/17] pci/tsm: Fix stale comment about TDI report range start Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 03/17] tsm/core: Store range_id in pci_tsm_mmio_entry Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 04/17] crypto/ccp/tsm: Use TSM API for DOE Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 05/17] tsm-core: Register nevertheless Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 06/17] x86/io/tsm: Allow mixed ioremap for shared+private BARs Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 07/17] x86/dma: Revert "x86: Remove unnecessary architecture-specific <asm/device.h>" Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 08/17] x86/dma: Add ARCH_HAS_PHYS_TO_DMA Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 09/17] dma/swiotlb: Force shared DMA for allocatios from SWIOTLB Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 10/17] x86, dma: Allow accepted devices to map private memory Alexey Kardashevskiy
2026-09-16 12:48 ` Jason Gunthorpe
2026-09-16 11:51 ` [RFC PATCH kernel 11/17] tsm/core: Add TDI status Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 12/17] coco/sev-guest: Allow multiple source files in the driver Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 13/17] x86/sev: Pass HV features to sev-guest device via platform data Alexey Kardashevskiy
2026-09-16 11:51 ` Alexey Kardashevskiy [this message]
2026-09-16 11:51 ` [RFC PATCH kernel 15/17] x86/sev: Implement guest TSM driver for SEV-TIO (phase2, DMA) Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 16/17] x86/sev: Enable secure MMIO (phase2) Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 17/17] x86/sev: Flush IOMMU TLB for trusted devices Alexey Kardashevskiy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916115159.1938195-15-aik@amd.com \
--to=aik@amd.com \
--cc=ackerleytng@google.com \
--cc=aik@ozlabs.ru \
--cc=ak@linux.intel.com \
--cc=akpm@linux-foundation.org \
--cc=aneesh.kumar@kernel.org \
--cc=anshuman.khandual@arm.com \
--cc=ansuelsmth@gmail.com \
--cc=ardb@kernel.org \
--cc=arnd@arndb.de \
--cc=ashish.kalra@amd.com \
--cc=baolu.lu@linux.intel.com \
--cc=bhelgaas@google.com \
--cc=bp@alien8.de \
--cc=catalin.marinas@arm.com \
--cc=clopez@suse.de \
--cc=dave.hansen@linux.intel.com \
--cc=dave.jiang@intel.com \
--cc=davem@davemloft.net \
--cc=david@kernel.org \
--cc=dfeng@redhat.com \
--cc=dhowells@redhat.com \
--cc=ebiggers@kernel.org \
--cc=enelsonmoore@gmail.com \
--cc=gregkh@linuxfoundation.org \
--cc=herbert@gondor.apana.org.au \
--cc=hpa@zytor.com \
--cc=hskinnemoen@atmel.com \
--cc=ian.campbell@citrix.com \
--cc=ilpo.jarvinen@linux.intel.com \
--cc=ilstam@amazon.com \
--cc=iommu@lists.linux.dev \
--cc=jeremy.fitzhardinge@citrix.com \
--cc=jgg@ziepe.ca \
--cc=jgross@suse.com \
--cc=jiang.liu@linux.intel.com \
--cc=jic23@kernel.org \
--cc=jinisusan.george@amd.com \
--cc=jkoolstra@xs4all.nl \
--cc=jroedel@suse.de \
--cc=kaneshige.kenji@jp.fujitsu.com \
--cc=kas@kernel.org \
--cc=kees@kernel.org \
--cc=kim.phillips@amd.com \
--cc=kvm@vger.kernel.org \
--cc=liam.merwick@oracle.com \
--cc=liam@infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-pci@vger.kernel.org \
--cc=ljs@kernel.org \
--cc=luto@kernel.org \
--cc=m.szyprowski@samsung.com \
--cc=mhklinux@outlook.com \
--cc=mhocko@suse.com \
--cc=mingo@redhat.com \
--cc=mpe@ellerman.id.au \
--cc=mtk.manpages@gmail.com \
--cc=nikunj@amd.com \
--cc=oleksandr_tyshchenko@epam.com \
--cc=palmerdabbelt@google.com \
--cc=pbonzini@redhat.com \
--cc=peterz@infradead.org \
--cc=prsampat@amd.com \
--cc=ptesarik@suse.com \
--cc=robin.murphy@arm.com \
--cc=rppt@kernel.org \
--cc=santosh.shukla@amd.com \
--cc=scott.cheloha@amd.com \
--cc=seanjc@google.com \
--cc=simona.vetter@ffwll.ch \
--cc=sstabellini@kernel.org \
--cc=sumanthk@linux.ibm.com \
--cc=surenb@google.com \
--cc=suresh.b.siddha@intel.com \
--cc=tabba@google.com \
--cc=tglx@kernel.org \
--cc=thomas.lendacky@amd.com \
--cc=thomas.weissschuh@linutronix.de \
--cc=tony.luck@intel.com \
--cc=toshi.kani@hp.com \
--cc=tycho@kernel.org \
--cc=vbabka@kernel.org \
--cc=venkatesh.pallipadi@intel.com \
--cc=vkoul@kernel.org \
--cc=wangkefeng.wang@huawei.com \
--cc=x86@kernel.org \
--cc=xen-devel@lists.xenproject.org \
--cc=yilun.xu@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®