From: Tom Lendacky <thomas.lendacky@amd.com>
To: Borislav Petkov <bp@alien8.de>
Cc: Ard Biesheuvel <ardb+git@google.com>,
linux-kernel@vger.kernel.org, linux-efi@vger.kernel.org,
x86@kernel.org, Ard Biesheuvel <ardb@kernel.org>,
Ingo Molnar <mingo@kernel.org>,
Kevin Loughlin <kevinloughlin@google.com>,
Josh Poimboeuf <jpoimboe@kernel.org>,
Peter Zijlstra <peterz@infradead.org>,
Nikunj A Dadhania <nikunj@amd.com>,
Neeraj Upadhyay <Neeraj.Upadhyay@amd.com>
Subject: Re: [PATCH v6 21/22] x86/boot: Move startup code out of __head section
Date: Thu, 14 Aug 2025 12:17:40 -0500 [thread overview]
Message-ID: <38f6fa08-41fb-4717-9763-39ec5fa54075@amd.com> (raw)
In-Reply-To: <20250811190306.GAaJo-ai4M2aVod6_V@fat_crate.local>
On 8/11/25 14:03, Borislav Petkov wrote:
> On Mon, Aug 11, 2025 at 01:05:42PM -0500, Tom Lendacky wrote:
>> Yes, that works. Or just get rid of snp_abort() and call
>> sev_es_terminate() directly. Secure AVIC could even use an
>> SEV_TERM_SET_LINUX specific code instead of the generic failure code.
>
> I *love* deleting code. Here's something to start the debate:
>
> ---
> diff --git a/arch/x86/boot/startup/sev-startup.c b/arch/x86/boot/startup/sev-startup.c
> index 7a8128dc076e..19b23e6d2dbe 100644
> --- a/arch/x86/boot/startup/sev-startup.c
> +++ b/arch/x86/boot/startup/sev-startup.c
> @@ -135,7 +135,7 @@ static struct cc_blob_sev_info *__init find_cc_blob(struct boot_params *bp)
>
> found_cc_info:
> if (cc_info->magic != CC_BLOB_SEV_HDR_MAGIC)
> - snp_abort();
> + sev_es_terminate(SEV_TERM_SET_GEN, GHCB_SNP_UNSUPPORTED);
>
> return cc_info;
> }
> @@ -209,8 +209,3 @@ bool __init snp_init(struct boot_params *bp)
>
> return true;
> }
> -
> -void __init __noreturn snp_abort(void)
> -{
> - sev_es_terminate(SEV_TERM_SET_GEN, GHCB_SNP_UNSUPPORTED);
> -}
> diff --git a/arch/x86/boot/startup/sme.c b/arch/x86/boot/startup/sme.c
> index 39e7e9d18974..e389b39fa2a9 100644
> --- a/arch/x86/boot/startup/sme.c
> +++ b/arch/x86/boot/startup/sme.c
> @@ -531,7 +531,7 @@ void __init sme_enable(struct boot_params *bp)
> * enablement abort the guest.
> */
> if (snp_en ^ !!(msr & MSR_AMD64_SEV_SNP_ENABLED))
> - snp_abort();
> + sev_es_terminate(SEV_TERM_SET_GEN, GHCB_SNP_UNSUPPORTED);
>
> /* Check if memory encryption is enabled */
> if (feature_mask == AMD_SME_BIT) {
> diff --git a/arch/x86/include/asm/sev-common.h b/arch/x86/include/asm/sev-common.h
> index 0020d77a0800..01a6e4dbe423 100644
> --- a/arch/x86/include/asm/sev-common.h
> +++ b/arch/x86/include/asm/sev-common.h
> @@ -208,6 +208,7 @@ struct snp_psc_desc {
> #define GHCB_TERM_SVSM_CAA 9 /* SVSM is present but CAA is not page aligned */
> #define GHCB_TERM_SECURE_TSC 10 /* Secure TSC initialization failed */
> #define GHCB_TERM_SVSM_CA_REMAP_FAIL 11 /* SVSM is present but CA could not be remapped */
> +#define GHCB_TERM_SAVIC_FAIL 12 /* Secure AVIC-specific failure */
We can get specific if desired, e.g., GHCB_TERM_SAVIC_NO_X2APIC
Thanks,
Tom
>
> #define GHCB_RESP_CODE(v) ((v) & GHCB_MSR_INFO_MASK)
>
> diff --git a/arch/x86/include/asm/sev.h b/arch/x86/include/asm/sev.h
> index 2b8a779f1477..e907646b4e4b 100644
> --- a/arch/x86/include/asm/sev.h
> +++ b/arch/x86/include/asm/sev.h
> @@ -512,7 +512,6 @@ void snp_set_memory_shared(unsigned long vaddr, unsigned long npages);
> void snp_set_memory_private(unsigned long vaddr, unsigned long npages);
> void snp_set_wakeup_secondary_cpu(void);
> bool snp_init(struct boot_params *bp);
> -void __noreturn snp_abort(void);
> void snp_dmi_setup(void);
> int snp_issue_svsm_attest_req(u64 call_id, struct svsm_call *call, struct svsm_attest_call *input);
> void snp_accept_memory(phys_addr_t start, phys_addr_t end);
> @@ -590,7 +589,6 @@ static inline void snp_set_memory_shared(unsigned long vaddr, unsigned long npag
> static inline void snp_set_memory_private(unsigned long vaddr, unsigned long npages) { }
> static inline void snp_set_wakeup_secondary_cpu(void) { }
> static inline bool snp_init(struct boot_params *bp) { return false; }
> -static inline void snp_abort(void) { }
> static inline void snp_dmi_setup(void) { }
> static inline int snp_issue_svsm_attest_req(u64 call_id, struct svsm_call *call, struct svsm_attest_call *input)
> {
> diff --git a/arch/x86/kernel/apic/x2apic_savic.c b/arch/x86/kernel/apic/x2apic_savic.c
> index bea844f28192..f0270ce16e6c 100644
> --- a/arch/x86/kernel/apic/x2apic_savic.c
> +++ b/arch/x86/kernel/apic/x2apic_savic.c
> @@ -26,7 +26,7 @@ static int savic_probe(void)
>
> if (!x2apic_mode) {
> pr_err("Secure AVIC enabled in non x2APIC mode\n");
> - snp_abort();
> + sev_es_terminate(SEV_TERM_SET_LINUX, GHCB_TERM_SAVIC_FAIL);
> /* unreachable */
> }
>
> diff --git a/tools/objtool/noreturns.h b/tools/objtool/noreturns.h
> index 6a922d046b8e..802895fae3ca 100644
> --- a/tools/objtool/noreturns.h
> +++ b/tools/objtool/noreturns.h
> @@ -45,7 +45,6 @@ NORETURN(rewind_stack_and_make_dead)
> NORETURN(rust_begin_unwind)
> NORETURN(rust_helper_BUG)
> NORETURN(sev_es_terminate)
> -NORETURN(snp_abort)
> NORETURN(start_kernel)
> NORETURN(stop_this_cpu)
> NORETURN(usercopy_abort)
>
next prev parent reply other threads:[~2025-08-14 17:17 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-07-22 7:27 [PATCH v6 00/22] x86: strict separation of startup code Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 01/22] x86/sev: Separate MSR and GHCB based snp_cpuid() via a callback Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 02/22] x86/sev: Use MSR protocol for remapping SVSM calling area Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 03/22] x86/sev: Use MSR protocol only for early SVSM PVALIDATE call Ard Biesheuvel
2025-07-29 13:48 ` Tom Lendacky
2025-07-22 7:27 ` [PATCH v6 04/22] x86/sev: Run RMPADJUST on SVSM calling area page to test VMPL Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 05/22] x86/sev: Move GHCB page based HV communication out of startup code Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 06/22] x86/sev: Avoid global variable to store virtual address of SVSM area Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 07/22] x86/sev: Share implementation of MSR-based page state change Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 08/22] x86/sev: Pass SVSM calling area down to early page state change API Ard Biesheuvel
2025-08-10 20:36 ` Borislav Petkov
2025-07-22 7:27 ` [PATCH v6 09/22] x86/sev: Use boot SVSM CA for all startup and init code Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 10/22] x86/boot: Drop redundant RMPADJUST in SEV SVSM presence check Ard Biesheuvel
2025-08-11 6:30 ` Borislav Petkov
2025-08-28 7:36 ` Ard Biesheuvel
2025-08-28 14:47 ` Borislav Petkov
2025-07-22 7:27 ` [PATCH v6 11/22] x86/boot: Provide PIC aliases for 5-level paging related constants Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 12/22] x86/sev: Provide PIC aliases for SEV related data objects Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 13/22] x86/sev: Move __sev_[get|put]_ghcb() into separate noinstr object Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 14/22] x86/sev: Export startup routines for later use Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 15/22] objtool: Add action to check for absence of absolute relocations Ard Biesheuvel
2025-08-11 7:20 ` Borislav Petkov
2025-07-22 7:27 ` [PATCH v6 16/22] x86/boot: Check startup code " Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 17/22] x86/boot: Revert "Reject absolute references in .head.text" Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 18/22] x86/kbuild: Incorporate boot/startup/ via Kbuild makefile Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 19/22] x86/boot: Create a confined code area for startup code Ard Biesheuvel
2025-08-11 10:19 ` Borislav Petkov
2025-07-22 7:27 ` [PATCH v6 20/22] efistub/x86: Remap inittext read-execute when needed Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 21/22] x86/boot: Move startup code out of __head section Ard Biesheuvel
2025-08-11 17:40 ` Borislav Petkov
2025-08-11 18:05 ` Tom Lendacky
2025-08-11 19:03 ` Borislav Petkov
2025-08-14 17:17 ` Tom Lendacky [this message]
2025-08-28 6:50 ` Ard Biesheuvel
2025-08-28 6:55 ` Ard Biesheuvel
2025-07-22 7:27 ` [PATCH v6 22/22] x86/boot: Get rid of the .head.text section Ard Biesheuvel
2025-08-11 14:17 ` [PATCH v6 00/22] x86: strict separation of startup code Borislav Petkov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=38f6fa08-41fb-4717-9763-39ec5fa54075@amd.com \
--to=thomas.lendacky@amd.com \
--cc=Neeraj.Upadhyay@amd.com \
--cc=ardb+git@google.com \
--cc=ardb@kernel.org \
--cc=bp@alien8.de \
--cc=jpoimboe@kernel.org \
--cc=kevinloughlin@google.com \
--cc=linux-efi@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@kernel.org \
--cc=nikunj@amd.com \
--cc=peterz@infradead.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®