From: Tom Lendacky <thomas.lendacky@amd.com>
To: Dionna Amalie Glaze <dionnaglaze@google.com>
Cc: linux-kernel@vger.kernel.org, x86@kernel.org,
Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
"H. Peter Anvin" <hpa@zytor.com>,
Andy Lutomirski <luto@kernel.org>,
Peter Zijlstra <peterz@infradead.org>,
Dan Williams <dan.j.williams@intel.com>,
Michael Roth <michael.roth@amd.com>,
Ashish Kalra <ashish.kalra@amd.com>
Subject: Re: [PATCH 05/11] x86/sev: Perform PVALIDATE using the SVSM when not at VMPL0
Date: Sat, 27 Jan 2024 09:18:24 -0600 [thread overview]
Message-ID: <3399426b-57f3-17b2-9fa2-9244ee13542e@amd.com> (raw)
In-Reply-To: <CAAH4kHaX8T01wrA1XUUK5bJGKHHTw7GSY9ua0bVvo-6MkODUOw@mail.gmail.com>
On 1/26/24 18:59, Dionna Amalie Glaze wrote:
> On Fri, Jan 26, 2024 at 2:18 PM Tom Lendacky <thomas.lendacky@amd.com> wrote:
>>
>> The PVALIDATE instruction can only be performed at VMPL0. An SVSM will
>> be present when running at VMPL1 or a lower privilege level.
>>
>> When an SVSM is present, use the SVSM_CORE_PVALIDATE call to perform
>> memory validation instead of issuing the PVALIDATE instruction directly.
>>
>> The validation of a single 4K page is now explicitly identified as such
>> in the function name, pvalidate_4k_page(). The pvalidate_pages() function
>> is used for validating 1 or more pages at either 4K or 2M in size. Each
>> function, however, determines whether it can issue the PVALIDATE directly
>> or whether the SVSM needs to be invoked.
>>
>> Signed-off-by: Tom Lendacky <thomas.lendacky@amd.com>
>> ---
>> arch/x86/boot/compressed/sev.c | 42 +++++++-
>> arch/x86/include/asm/sev.h | 22 +++++
>> arch/x86/kernel/sev-shared.c | 176 ++++++++++++++++++++++++++++++++-
>> arch/x86/kernel/sev.c | 25 +++--
>> 4 files changed, 247 insertions(+), 18 deletions(-)
>>
>> diff --git a/arch/x86/boot/compressed/sev.c b/arch/x86/boot/compressed/sev.c
>> index 5d2403914ceb..3fbb614c31e0 100644
>> --- a/arch/x86/boot/compressed/sev.c
>> +++ b/arch/x86/boot/compressed/sev.c
>> +static int svsm_protocol(struct svsm_call *call)
>> +{
>> + struct ghcb *ghcb;
>> + int ret;
>> +
>> + if (boot_ghcb)
>> + ghcb = boot_ghcb;
>> + else
>> + ghcb = NULL;
>> +
>> + do {
>> + ret = ghcb ? __svsm_ghcb_protocol(ghcb, call)
>> + : __svsm_msr_protocol(call);
>> + } while (ret == SVSM_ERR_BUSY);
>
> Should this loop forever or eventually give up and panic?
The question becomes how many times before giving up. This would likely
only happen if the hypervisor is causing an issue for the SVSM, so it
would be similar to a DoS. I'm open to suggestions, though.
On a side not, that does remind that this should also be checking for
SVSM_ERR_INCOMPLETE.
>
>> void snp_set_page_private(unsigned long paddr)
>> @@ -261,6 +289,12 @@ void sev_es_shutdown_ghcb(void)
>> if (!sev_es_check_cpu_features())
>> error("SEV-ES CPU Features missing.");
>>
>> + /*
>> + * Ensure that the boot GHCB isn't used for the PVALIDATE when running
>
> Why the definite article? Which PVALIDATE is this referring to?
I'll clarify the comment, but it is specifically relates to the
set_page_encrypted() for the boot_ghcb_page that immediately follows.
Since the GHCB page is being changed to encrypted, we need to use the MSR
protocol by zeroing out the boot_ghcb variable. The comment should have
said for the Page State Change and not PVALIDATE.
Thanks,
Tom
>
next prev parent reply other threads:[~2024-01-27 15:18 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-01-26 22:15 [PATCH 00/11] Provide SEV-SNP support for running under an SVSM Tom Lendacky
2024-01-26 22:15 ` [PATCH 01/11] x86/sev: Rename snp_init() in the boot/compressed/sev.c file Tom Lendacky
2024-01-27 0:05 ` Dionna Amalie Glaze
2024-01-27 14:38 ` Tom Lendacky
2024-01-26 22:15 ` [PATCH 02/11] x86/sev: Make the VMPL0 checking function more generic Tom Lendacky
2024-01-26 22:15 ` [PATCH 03/11] x86/sev: Check for the presence of an SVSM in the SNP Secrets page Tom Lendacky
2024-01-26 22:15 ` [PATCH 04/11] x86/sev: Use kernel provided SVSM Calling Areas Tom Lendacky
2024-01-27 0:45 ` Dionna Amalie Glaze
2024-01-27 14:43 ` Tom Lendacky
2024-01-26 22:15 ` [PATCH 05/11] x86/sev: Perform PVALIDATE using the SVSM when not at VMPL0 Tom Lendacky
2024-01-27 0:59 ` Dionna Amalie Glaze
2024-01-27 15:18 ` Tom Lendacky [this message]
2024-01-26 22:15 ` [PATCH 06/11] x86/sev: Use the SVSM to create a vCPU when not in VMPL0 Tom Lendacky
2024-01-26 22:16 ` [PATCH 07/11] x86/sev: Provide SVSM discovery support Tom Lendacky
2024-01-29 10:41 ` Jeremi Piotrowski
2024-01-29 15:18 ` Tom Lendacky
2024-01-26 22:16 ` [PATCH 08/11] x86/sev: Provide guest VMPL level to userspace Tom Lendacky
2024-01-27 1:06 ` Dionna Amalie Glaze
2024-01-27 15:43 ` Tom Lendacky
2024-01-26 22:16 ` [PATCH 09/11] virt: sev-guest: Choose the VMPCK key based on executing VMPL Tom Lendacky
2024-01-26 22:16 ` [PATCH 10/11] x86/sev: Extend the config-fs attestation support for an SVSM Tom Lendacky
2024-01-27 1:27 ` Dionna Amalie Glaze
2024-01-29 15:02 ` Tom Lendacky
2024-01-29 20:04 ` Dionna Amalie Glaze
2024-02-01 21:14 ` Tom Lendacky
2024-02-02 7:10 ` Dan Williams
2024-02-05 23:29 ` Kuppuswamy, Sathyanarayanan
2024-02-06 18:53 ` Tom Lendacky
2024-02-06 18:48 ` Tom Lendacky
2024-02-13 2:34 ` Dan Williams
2024-02-16 19:07 ` Tom Lendacky
2024-02-16 20:46 ` Dan Williams
2024-02-23 20:41 ` Tom Lendacky
2024-02-24 0:02 ` Dan Williams
2024-02-26 14:42 ` Tom Lendacky
2024-01-26 22:16 ` [PATCH 11/11] x86/sev: Allow non-VMPL0 execution when an SVSM is present Tom Lendacky
2024-02-12 10:40 ` [PATCH 00/11] Provide SEV-SNP support for running under an SVSM Reshetova, Elena
2024-02-16 19:46 ` Tom Lendacky
2024-02-19 16:57 ` Shutemov, Kirill
2024-02-19 17:54 ` Reshetova, Elena
2024-02-23 20:23 ` Tom Lendacky
2024-02-27 14:56 ` Reshetova, Elena
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3399426b-57f3-17b2-9fa2-9244ee13542e@amd.com \
--to=thomas.lendacky@amd.com \
--cc=ashish.kalra@amd.com \
--cc=bp@alien8.de \
--cc=dan.j.williams@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=dionnaglaze@google.com \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@kernel.org \
--cc=michael.roth@amd.com \
--cc=mingo@redhat.com \
--cc=peterz@infradead.org \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome