From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from CH5PR02CU005.outbound.protection.outlook.com (mail-northcentralusazon11012006.outbound.protection.outlook.com [40.107.200.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 935ED367285 for ; Fri, 21 Aug 2026 03:19:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=40.107.200.6 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787282352; cv=fail; b=gLhA4tHp50VKSdWpbCme6bQJcg5DYgyQmaLCDwwUDyW7Tx9seasc+CPlN5Ble8y0pX6igCq9DvRFn/d+Bkt7hQSCQ2kCGCcIQaOvti0jhOaooTkOW9Qf28I6OXA2698KhvN+PICYuJMeN7G72x+0nWqHs6EtbDda4jCEuObq2jY= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787282352; c=relaxed/simple; bh=71uTDXpzFYXK1QfvywTzMSBWfIsmATu/x50NT95u9ow=; h=Message-ID:Date:Subject:To:Cc:References:From:In-Reply-To: Content-Type:MIME-Version; b=Pnk66Fe+91YMO9xi8+1dgYej7nVapnN1Le+5wWQ8veiBCsw/bdxOC10rhvjvmAnBRTq+dkhTyoSSkqNKkCYpmLKztkpMO6EI3dt3KBg/d3C5fb5X2tE7R2uKfxydp1KhiMAjI+EdmV83bW4Bf4Gd7Un2JiiaCZpCD0L+8oDj2K4= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=cYYzvY2Q; arc=fail smtp.client-ip=40.107.200.6 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="cYYzvY2Q" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=J5YgST6iBEYF8nwE0Wjgz49DBVtQBZmMRD0XfkAuikZkOKod5g8GUKqm8SaEKnHYB20v0QUQ96+v6vFaTbzvykSbUIzmpQTcAS1KefTPWErkFgt+J68N+/d3Ebp659y+rrqGmSg6qBR8NUDNya5Etm+k0qHz6yaS81zU+phuzWdG6k0ALBjYPaBYtliIaVoMIWnySywrCWtNDpjBu8WU1O5pbe6zLy5L8R1LdlCgOughv6m2thT3I7HAJPhvoykBGgmJc9eZp0w7iITKO2YmCHNZNh8S4VRcoQHyuGpAiuB4zs/6ahB0oaFPv2ehCurfJxH0ugNqEXRStzys47ceXA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=zqCMZw2EpTIks9bPrTKlhgfIfg+CB9wHL6ptI6MWBL4=; b=KNo2KseVUiX+oMCPj3ffRJrxJjmlve7HjuiaYtRikbik/wgnkuDQp7K++x0xac5WxFz7FZPViD8hwuvvVfQeHDBhDDAUZff47j2rj3jKT+5b7apLwWN6OklxnNxpzXZ9tpaVGUae2kLrsbOXBC4uqPPUzcNvupeAgDY3OpERRSDdWbPyrDdEfRvmA8X9Oi5+TLcmPz5Zyc3gAKONv0OM31sd7v+9i5ttL36mhsPSW/CYqjezh95iIRKrPo43zHj74Yr/4KXmkB/8cP74sEBxYT+2duhJnwpuezNSXiOdbnJtKJJFGRa4iqC+nrg2v356nC0u80Vwu3yFpVZr8NCmzw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=zqCMZw2EpTIks9bPrTKlhgfIfg+CB9wHL6ptI6MWBL4=; b=cYYzvY2QCTYRWPwxRr5E0NPnDijehGaHmb8CWvqYorn8CbxkWmgNeegGF85brFFpXpAFVFhLYmXak0UU8iz4GYJKheWTSx+kJOx4+PXIEIt5R+SBm9+m7N+4fFBwOhUogqdzX0M6rhVkaGbztWtz7BMhKpegzsW6JYdUsc/xkmw= Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=amd.com; Received: from CH1PR12MB9575.namprd12.prod.outlook.com (2603:10b6:610:2ad::12) by SJ0PR12MB7457.namprd12.prod.outlook.com (2603:10b6:a03:48d::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.339.10; Fri, 21 Aug 2026 03:19:04 +0000 Received: from CH1PR12MB9575.namprd12.prod.outlook.com ([fe80::2aab:a788:44ed:f4da]) by CH1PR12MB9575.namprd12.prod.outlook.com ([fe80::2aab:a788:44ed:f4da%5]) with mapi id 15.21.0339.008; Fri, 21 Aug 2026 03:19:04 +0000 Message-ID: <3829c69d-53f8-438d-a8cb-c49d6958c73f@amd.com> Date: Thu, 20 Aug 2026 20:19:02 -0700 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH 2/7] x86/apic: Add an SVSM APIC driver To: Tom Lendacky Cc: LKML , x86@kernel.org References: <7c4f962cb0c993f0cb136a9abcbd4f3e4759282c.1785375271.git.huibo.wang@amd.com> <0514ffca-89a3-42e9-bc30-50c317aa7bd9@amd.com> <1bd358fe-39f8-4a95-bf87-24a4a34d5b64@amd.com> Content-Language: en-US From: Melody Wang In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-ClientProxiedBy: PH7P221CA0057.NAMP221.PROD.OUTLOOK.COM (2603:10b6:510:33c::20) To CH1PR12MB9575.namprd12.prod.outlook.com (2603:10b6:610:2ad::12) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: CH1PR12MB9575:EE_|SJ0PR12MB7457:EE_ X-MS-Office365-Filtering-Correlation-Id: 96f18679-893a-458b-8398-08deff32f41a X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|376014|1800799024|23010399003|5023799004|11063799006|4143699003|22082099003|18002099003|10067099003|3023799007|56012099006|6133799003; X-Microsoft-Antispam-Message-Info: PcxgkT/O7juRilIHhlG1gFlgBw+jj58jayOiQ161qidijMAl5vb1eh8L6VV9WbxpkcvdNGrOr4DywsYS6AJVS+f3w0aeXsGL/JAcz97UVN+CXlFD5B/M7t3hzjyTfwcXsyj+eaEvsSmNi8uNmrcc+M+xVxlW6r0RRC/ZCYEvIs2EM3Mn4yUjIX7Dp90h38ih5bHYq5UfB/IBU2jsJmy3l4FqWJK2KCmuRC/XeDm2hYqdVHnF6+WCfPJ3z9oLVCHvyOF34/7EyMoqlWSmZveXbhEwrobajvZs1zUlM8uhJSHfqvrIKrVt92ReS0En4eayQ/ZvjsRytKwVnrC8qYYrGN7K2XBWohwggktV8GS52W6WD7/mM9qc6dpgROrwiBAPglmPCI0BKP6DF/4zzkwVg4opnVFtOc365tlbQodQAcliGdg9lRPUt8DVIySsng3IvkjQ19yOi6wNlk6h/GEzZgOpMW0eRKfhT5xSJn/BP8MMwYQgX+nRbGqqAJNib6A1pVIq/Wkgde03tjMBYDcPuMtW9gj8Y9FIrNxqEmPnJuH0N4OWMGj15/lYqLjiJE5KiDDrUb3Jkp/YJQk5ojUBNMlHxcj/IcZ1CjOdLA32oKB6rFpyyvm7n/eW8DqNCvcJIxYNHoe9ar88AgM2Oiu3SbRN9fSbVgPKxopSaXoxZB4= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:CH1PR12MB9575.namprd12.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(366016)(376014)(1800799024)(23010399003)(5023799004)(11063799006)(4143699003)(22082099003)(18002099003)(10067099003)(3023799007)(56012099006)(6133799003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?B?dVZVNno0VE9UeE9meEsrZkhyci9Pd29Bdlg4YmxBdzQzamhLYmd5RWZCaGx5?= =?utf-8?B?KzhaekJnUzVyT3gydjFmcGFLU0xUUUloQzhrRWF0cHIwMzJEa2hXT3FTTlFX?= =?utf-8?B?MVd1bUJQenAzemM3K09pbENocGltOUdCWGJjelc5dzNtR1dWZ2dCT2JuS0xt?= =?utf-8?B?aHJsbmd5VW9rcXFPckJCWHcyK2xzeG9pYi9XanJKNmt3VklaNnUvMjlFUngx?= =?utf-8?B?Qm82dmM1WUJtTlRNL0lzSG5DQTd6ZXRzbnNaTkJQaFZCQkdUeUMyMWIycVVX?= =?utf-8?B?cUZMbUxNOVlMcHJiTFRGOFBzQ0psUU0xellTdk9CaWcrTjVxSjBNUDZQd2l4?= =?utf-8?B?ZC9zMHNGbXRxWndSRkt0NVYvRFFjVE1GTEhQQVEyWGF0OHBkeUhlK21WZFhB?= =?utf-8?B?ODdRV0U4dXhXcjFqNHBnQmJJbDJXYXRIVDYzWmhwQXNGZ2g5MGFaaVVXMXNr?= =?utf-8?B?SEFEcUZlcllmNnNCMmhZYlRYcHF6M1pqM2dhbmFELzdsRURvKzh3N1dtVll4?= =?utf-8?B?dGhmbDVCSFdBeHI1bENZWUFYeWFvTXlKek4xazZWM2lhRnlRenZhbGpETlk2?= =?utf-8?B?aStoRVBDRlY0V01NbWlNYzMwMEdOZHo3SFRBbll4bHN3R25PRDluc0lNVDh4?= =?utf-8?B?YTI2YnBTbTFhemwzWFZTVnduWWpqVU5WTmZubzhOZVNOai9ZNGFMaE9ERkps?= =?utf-8?B?VTNUZy9hdmZFZStMODlJQ1E0WTZJenRHc09LL01YQzZwSXlVS0J6WUFhUVdT?= =?utf-8?B?alptalZBQktkQm1SVzc0cUNOMkNHSXlwUHIydlkyd2FxU05naWFKS3B3dlJk?= =?utf-8?B?U2VvTUZmaXk2RVY0ZlpLMGFDMVJubk56UWd4Wkp5ZyswME5YYnlsK2orUDJi?= =?utf-8?B?T0g4YWFMMUNKL1BUd1lVMUtxVFUwQkZZcFB5SkJhSGxXS29DWnNRTmJEaDdO?= =?utf-8?B?SWwxMnQ3YXBnWTVJYlRaZldoR2pGNUpwczIyaFpXZzJNZUYvQXV0OStUdXda?= =?utf-8?B?OENaanhyZUVKZlhrbUNEUTV3RnhIMmhaZDR4WXYzZGtvZnkvK1VTNURmejFN?= =?utf-8?B?N2x1alBQVk1tL0RRMDZodko3blRrYUFGTHVBTlQ5SGRua3diY3U5dnVhM2No?= =?utf-8?B?TklYQkQ1ZVdDY3VGQ2oxakdLUWxUa1FzWTdWNUpTa1NMcTlYOFNjamx5L2hV?= =?utf-8?B?TTdhamZtWFRYYmRBeVFxTE9mM0pPdzc3UmxrMmxudUNOQ3JlaXdoR1lncjZM?= =?utf-8?B?SHEyTlBvVDAwWFM5ZGR6VXJmMHNWbFR3eVd2Ulc0RVdwelV6SGtpa2tHZ3Qy?= =?utf-8?B?OWFVVXVESHdXRld1UnFkUG94dmJFbEo1ZjF6S1lFYmNjRmVXR2FZRU5wWjJO?= =?utf-8?B?MDhSSTNzMHFPRWRHbE9JYldHcmxrTDJLS3ZMUlVmMDlSdFZUWVVzMnRqS2Mx?= =?utf-8?B?TnJqMXRNaDVwY3pnaXhWODdsRjBPTTNJd2ZVcFlzaUppWHpwOWh6NUN5N2RL?= =?utf-8?B?UmZ6SXB4NnZrSTlTYk15MHBVcTQ3NnZUWitGaTFiQkhET3B4Nit5Y1FFa1pG?= =?utf-8?B?UVBnWUgvMGxGdEJaWGc0MC9sVURRVkpDOXFFRm94eDFpYnRtNi9hai9maUxm?= =?utf-8?B?M2ZCZ295MXNKVlNYR1pFUm1FV3NIeTlLcWNmOXZTa1FmNjFSTXVDTXhuUU1G?= =?utf-8?B?MTlSTFU3WTZNZ1ZBMnl3WGQxZmJneC8zYTB6OE1JUTBnSXBsSmM5V1o1V282?= =?utf-8?B?ZzkyRExsZEJkOU43MWdWaER3bzYzVGM2QXZ2VXpPZlJldjBSTVRQQWtLK1Va?= =?utf-8?B?ck5kOG5mSFl4MDJXcHZoVHU0Vm9FN0dRakpwaXlXaEdqL1BrdUtXMU13VjI0?= =?utf-8?B?WUZlbWRrWWhtSktJV01KckF5Q2k4ZWxHVTZLdVNqQUxRSXJONjJpbzRxTjVu?= =?utf-8?B?NHBzRm9YRVNoY2JsbUF3OGJGT0F0WEJrSmZ6eXpKL0VLeGN2L1hyWWdRNzF1?= =?utf-8?B?alQ1ZTlTL0dWWERFTlp0UmhkTkFEUEFXME1WY1ZmUitrenNnL0NqK0cwSXpT?= =?utf-8?B?S3BNd3MwNVdaQVoyLzJRZnl6aTVaWUwvWmZPcUo3OVBjcUJiYm9mRHFIZWFF?= =?utf-8?B?ME9LVk1WNUx6ZGlzU1dvSVpmOEZ5TkNPRDlqLzFqUWV4L0szY01RL3FSMWhQ?= =?utf-8?B?ZTk5TGhOOFhWblJvbkhlbXZ2RUR0cTZzL2tsVFZIcTJjWEs3V0I1TjNTVU5Q?= =?utf-8?B?RStyY3YyeTVsbWJjSDdTRFpUTnMxTXcwZmVOTVBDVXdKaXRkVVQ2NldsSDZV?= =?utf-8?B?c2xhbE1DNDhUK3JNYVdxbUFBRVFuWEpHalRjUXcrS0oyakRYM2Vadz09?= X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: 96f18679-893a-458b-8398-08deff32f41a X-MS-Exchange-CrossTenant-AuthSource: CH1PR12MB9575.namprd12.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Aug 2026 03:19:04.4334 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: rU6sKIXJrqTRXORIUACEPyqz9lg77GllHoAqGFQmk3KUEdzdUUul4lN48f06alXVwU/DxNX7na6fM2FsyqnQaA== X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR12MB7457 Hi Tom, On 8/20/26 8:43 AM, Tom Lendacky wrote: > Why not move svsm_get_caa() and svsm_perform_call_protocol() from > internal.h then and make them available? Or create a callable function > that lives in arch/x86/coco/sev/svsm.c that builds the svsm_call struct > and performs the SVSM call? The current svsm_do_call() actually is a callable function living in arch/x86/coco/sev/svsm.c except it doesn't build the call struct inside. I feel this way it is more clear. What would be the advantage of building the svsm call? > Isn't that all that is needed? If the attribute is set none of the other > injection methods can be used. If anything, you should terminate if > alternate injection is enabled and you are running at VMPL0, because > nothing can update the VMSA to set the injection/irq fields. Ok, agreed. > If the VMRUN fails because both are set, how can you possibly be running > in the guest with both set? So I see no need to check for Secure AVIC. Do you mean there are already enough places to prevent this fault, so the guest does not need to enforce it too? I feel it does not hurt to do it there too, in the probe function. That belongs there anyway. > What if the version of the SVSM that is running doesn't have the APIC > emulation protocol? The Alternate Injection spec says: "The APIC Protocol is supported only as long as Alternate Injection is enabled." To me, this reads like the APIC protocol is always there when Alternate Injection is enabled so I can assume it's present in that case. So I don't need to query it. Or am I misreading the spec? >> needed to query the APIC protocol now. In the future, when the SVSM code >> changes with different set, we can adjust the guest code accordingly. >> >>> The read and write are very similar. Can you have a common function that >>> takes a reg paramter, value parameter (that is input and output), and a >>> mode parameter (read/write) and then have small read and write functions? >> >> Yes, and Sashiko pointed that I need to prevent preemption for the caa >> call, I agree with it, but I think I should prevent interrupts here - I >> should do native_local_irq_save(), because there should not be any >> interrupts during a caa call as those things are not reentrant. Thoughts? > > svsm_perform_call_protocol() already disables interrupts. The problem is in svsm_get_caa(), when the task is preempted and migrated to a different CPU after fetching the per-CPU caa. Since this is preemptible code, after migration it is already wrong. The hypercall will execute on the new CPU but use the original CPU's caa. This was found by Sashiko's review, I think this is a problem, so I need to disable preemption until svsm_perform_call_protocol() is finished. -- Thanks, Melody