From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from DM5PR21CU001.outbound.protection.outlook.com (mail-centralusazon11011061.outbound.protection.outlook.com [52.101.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 99455368D46 for ; Thu, 30 Jul 2026 01:50:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.62.61 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785376220; cv=fail; b=LxThxGFWCJhLXmkLwqwj3OyARN5UofFx+H1CMs9bJxwtTUZpfxTsmekUGPAUb1JnCpKXiaCcbn/iDisWYX+B3fi9VBHl4znPGdy2RnCIm0PVtKjxCSXa95wDlzRmurGAoBdlUPhsyLoeGlbbMALNcAGJzDIc8ayt4jMVYHk3LOU= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785376220; c=relaxed/simple; bh=VJ6Pwjs0HWWoBW+TfUphVinZtTueAAvDEZQFNNbJnv0=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=f3qTZJ7PUltyr2XLbMwEDTUJdxw1HN5Ty8gUORv8rhnJaG0vrwMsLq6+X4wSI/ymlrJsKlXnAKwQ7wbh9cnGjP9670Eb10v+3GlCtEXH3ucPIAsXiaRhiZxUvgHt8bDN/BgLYmIT2NsX1NcFsjcQydCXGQiIXIKrq/cBU1Ms7ks= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=AVTA2RF+; arc=fail smtp.client-ip=52.101.62.61 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="AVTA2RF+" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=VpzVLfixOfE8w9DZMjA2rbzGXMgMr2A5hBaB8/Tl3RouwoKEJVnDf9c+mGWphYpIBjWoh5tErY43+JFu5f7qdH3aYw+LQIG2G6Ow8tM7ZiKXCMWvxXMPAfS0JYVWC37yMboEZLqftFW4CflSuP10YmjkMvp4n26AxZE8ZK/lKcilNUwpKgtMQV79inIMr5QLshHG+US9ZKakX+jrMRIaIcNq5gHD0mBeY2JS6wct33aRW5RzLLaQjfY2H0yw4Y5v6tE03l66sSd8Aoi7N53RH4fA9sNthLU2a3jtBppMSY3OvVzMGIuUVpQK1r+TpvE1Z7g72GTIr6W110+/vfX40w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=JXlPFKQW3rMFcrQIiVYR3iFAjqSUfv9TwmFMhPAoDMU=; b=rpqD0FndsoqDqG4zPiIi8HVw+xsQGhkmnPFP0PdlpDMl0Zg5OEgrCUVLl38KCCij74i3iimJmIfF1VJ9c1E8wbwJh0+F9Z91b6en8Kblvl+TqQtbQY8x6C5S6jXlmw8gKxAn+KtA040o1CdNBRQXWoYZqoJFZy4+7cdKAvC5BpIL9opAJSoYctblNGwCSfMttWRc98vPdbLLmgQvMg12WRYLQm/6LsykCVPWQHb+Qk4LQJOEMO8KBBqe0H0yK90eSO1kIOgaZnmBpj3SAfvAd34U0Fk6tT8JMmcQYp1ldAHFK9RQPFLBnO3n4STw4cf5wpYHDHv6O7/Cr5P2VvE39g== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=kernel.org smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=JXlPFKQW3rMFcrQIiVYR3iFAjqSUfv9TwmFMhPAoDMU=; b=AVTA2RF+IqkeLrU7myOEDdvm2/vuIyYcELmZpft9QywYFIvsGPHYGmQvy6zqTkXDMqzh+riOnoyoivGerPlwpx1NhP4xJ4B9kuraSp5IcO8xsGlnJHlMjOZ0fiVm44r5fEGN7ll593Z37bYj/ah29sggnHWCEdLORh767+lSOB4= Received: from CH2PR17CA0009.namprd17.prod.outlook.com (2603:10b6:610:53::19) by BN5PR12MB9540.namprd12.prod.outlook.com (2603:10b6:408:2a8::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.270.14; Thu, 30 Jul 2026 01:50:14 +0000 Received: from CH2PEPF0000013B.namprd02.prod.outlook.com (2603:10b6:610:53:cafe::37) by CH2PR17CA0009.outlook.office365.com (2603:10b6:610:53::19) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.270.13 via Frontend Transport; Thu, 30 Jul 2026 01:50:13 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 165.204.84.17) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=amd.com; Received-SPF: Pass (protection.outlook.com: domain of amd.com designates 165.204.84.17 as permitted sender) receiver=protection.outlook.com; client-ip=165.204.84.17; helo=satlexmb07.amd.com; pr=C Received: from satlexmb07.amd.com (165.204.84.17) by CH2PEPF0000013B.mail.protection.outlook.com (10.167.244.68) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.292.8 via Frontend Transport; Thu, 30 Jul 2026 01:50:13 +0000 Received: from purico-9dcchost.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.41; Wed, 29 Jul 2026 20:50:11 -0500 From: Melody Wang To: CC: LKML , Tom Lendacky , Melody Wang , Ard Biesheuvel Subject: [PATCH 5/7] x86/sev: Add a function to contain all SEV-specific setup operations Date: Thu, 30 Jul 2026 01:48:45 +0000 Message-ID: <47df4ef41f05f465d00011e9644780d90d08c6a0.1785375271.git.huibo.wang@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: satlexmb08.amd.com (10.181.42.217) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: CH2PEPF0000013B:EE_|BN5PR12MB9540:EE_ X-MS-Office365-Filtering-Correlation-Id: db0487d2-515d-4e76-3b86-08deeddce5e1 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|36860700016|23010399003|376014|82310400026|1800799024|56012099006|11063799006|10067099003|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: IPtsGDc3oEuaJRnh8s/IdRcPR5HflQae/ABEjAnWjXgKYyryl9lt2IHSwEfu2bzq0+2hVRTSu6IzIHFwuhPGJP4Cp0dtp18czRcf1M6ONdxR8dUk1YzmGgI1MekmuGb0dCy2osfOZbQdCCfe4mJDgh1hpVLQKQHSkW0A/MEnh+i99iPQtzJHdpfdi53O+nBqlixi7xx3C9SjCHLPPBKSuWXhero7OvbB7g3jkAjoO6mND6xNalsjZ+3owE7jEObDyG5QYGHnSBMlSMaYVQ7w/OIggvGs5BC1TbdQd7iMxnLwsqomi/9VS20ZcGXnrPZxKl3qzfSE1Gvf50V4o69buyL3ybWXKMKhikCCB/hggGJHto/I1YWpD2NVf3tCv8myuGevPwbCNmZqKv++vmpuI/E320n40uD+MzTijC3/dKbyiSR4QWVH6qYFXURxbnZCvLyD4Kp+bbG8V08941H7vTgfENSVUcDUyZ5HStTiPIroMKpKghF8g1X8f6dGr6PtCL/0ZI1f8jbQE8VIPoKsZluLQ9+iLHHnUb5lDQtIXcFFec8iQiLff6ThXBVpdvaTKa8YaCkjgQ+oqbfe8MJKRI/ppQSKX4p/f1tZnSfr/CsxPbBcNVX7o4+G8Qb7n5vkTkvSJE06kmXEl1QZRb8qS/7Rork6xZLG/faVe5z6hDGUCfBz3TH2h9S7wgLVRWs+o8LY87w+YMTIaE8c5+7uGA== X-Forefront-Antispam-Report: CIP:165.204.84.17;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230040)(36860700016)(23010399003)(376014)(82310400026)(1800799024)(56012099006)(11063799006)(10067099003)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: 4EN4MGYkMByAvwaDVX366EBZXYnQIEWe6Zpuy1sCt4B11GbTicCouuK99VbmchwlyWHBqaUCN3lPRMX9OUxml+1+8sYmoPD1NcEYZkbbv/hcxd1IHjZ86iyxXz/C5D8nfPMpa3/5o4fBUDFBSrdDPDYqkFlN+Z81P8lWHqS0HxFz+Pp5Jd8AnIktzARCFIBJXcEPxEJX61RjhDjazmxNjF3j4NTd2BMPcRQEcapwOvw4Jn4bJvrPkeE9O5UyCZAZImY3zdBeaDaSr5412OOlbO4b7zjuLz6T+S3jhn6IjDdGae4YZiyNeb4Dn5+w64XdjEuz82ZzoeNyUFUjUYvL7xebF8PfMtxjGmCyrdxFUSk4agDYflRm0Ouh37O81lSu01I+Lc+dZg12KpPez7QXbMX5a0uMo1J40Km2o1BQC8O44qn34TjjdXsqy0h6G1e9 X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 30 Jul 2026 01:50:13.7973 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: db0487d2-515d-4e76-3b86-08deeddce5e1 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[165.204.84.17];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: CH2PEPF0000013B.namprd02.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN5PR12MB9540 To make the code clean in the boot phase, add a sev_prepare() wrapper which contains early SEV-specific checks in order to have all that code in a single place. No functional changes. Signed-off-by: Melody Wang Cc: Ard Biesheuvel --- arch/x86/boot/compressed/sev.c | 9 +++++++++ arch/x86/include/asm/sev.h | 3 +++ drivers/firmware/efi/libstub/x86-stub.c | 20 ++++++-------------- 3 files changed, 18 insertions(+), 14 deletions(-) diff --git a/arch/x86/boot/compressed/sev.c b/arch/x86/boot/compressed/sev.c index fc2029746c50..655291a03dcc 100644 --- a/arch/x86/boot/compressed/sev.c +++ b/arch/x86/boot/compressed/sev.c @@ -511,3 +511,12 @@ bool early_is_sevsnp_guest(void) } return true; } + +u64 sev_prepare(void) +{ + u64 unsupported = snp_get_unsupported_features(sev_get_status()); + if (unsupported) + return unsupported; + + return 0; +} diff --git a/arch/x86/include/asm/sev.h b/arch/x86/include/asm/sev.h index 491a891a7694..b430c1aab403 100644 --- a/arch/x86/include/asm/sev.h +++ b/arch/x86/include/asm/sev.h @@ -613,6 +613,8 @@ static inline void sev_evict_cache(void *va, int npages) } } +u64 sev_prepare(void); + #else /* !CONFIG_AMD_MEM_ENCRYPT */ #define snp_vmpl 0 @@ -661,6 +663,7 @@ static inline enum es_result savic_register_gpa(u64 gpa) { return ES_UNSUPPORTED static inline enum es_result savic_unregister_gpa(u64 *gpa) { return ES_UNSUPPORTED; } static inline void hvs_ghcb_msr_write(u32 reg, u64 value) { } static inline u64 hvs_ghcb_msr_read(u32 reg) { return 0; } +static inline u64 sev_prepare(void) { return 0; } #endif /* CONFIG_AMD_MEM_ENCRYPT */ diff --git a/drivers/firmware/efi/libstub/x86-stub.c b/drivers/firmware/efi/libstub/x86-stub.c index cef32e2c82d8..95fa16fc9887 100644 --- a/drivers/firmware/efi/libstub/x86-stub.c +++ b/drivers/firmware/efi/libstub/x86-stub.c @@ -783,19 +783,6 @@ static efi_status_t exit_boot(struct boot_params *boot_params, void *handle) return EFI_SUCCESS; } -static bool have_unsupported_snp_features(void) -{ - u64 unsupported; - - unsupported = snp_get_unsupported_features(sev_get_status()); - if (unsupported) { - efi_err("Unsupported SEV-SNP features detected: 0x%llx\n", - unsupported); - return true; - } - return false; -} - static void efi_get_seed(void *seed, int size) { efi_get_random_bytes(size, seed); @@ -919,6 +906,7 @@ void __noreturn efi_stub_entry(efi_handle_t handle, unsigned long kernel_entry; struct setup_header *hdr; efi_status_t status; + u64 unsup_feats; efi_system_table = sys_table_arg; /* Check if we were booted by the EFI firmware */ @@ -933,8 +921,12 @@ void __noreturn efi_stub_entry(efi_handle_t handle, hdr = &boot_params->hdr; - if (have_unsupported_snp_features()) + unsup_feats = sev_prepare(); + if (unsup_feats) { + efi_err("Unsupported SEV-SNP features detected: 0x%llx\n", + unsup_feats); efi_exit(handle, EFI_UNSUPPORTED); + } if (IS_ENABLED(CONFIG_EFI_DXE_MEM_ATTRIBUTES)) { efi_dxe_table = get_efi_config_table(EFI_DXE_SERVICES_TABLE_GUID); -- 2.43.0