* [PATCH v4 0/2] nosnp sev command line support @ 2024-09-22 3:36 Pavan Kumar Paluri 2024-09-22 3:36 ` [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm Pavan Kumar Paluri 2024-09-22 3:36 ` [PATCH v4 2/2] x86 KVM:SVM: Provide "nosnp" boot option for sev kernel command line Pavan Kumar Paluri 0 siblings, 2 replies; 5+ messages in thread From: Pavan Kumar Paluri @ 2024-09-22 3:36 UTC (permalink / raw) To: linux-kernel Cc: linux-doc, Borislav Petkov, Thomas Gleixner, Ingo Molnar, Dave Hansen, Eric Van Tassell, Tom Lendacky, Ashish Kalra, Michael Roth, H . Peter Anvin, Peter Zijlstra, Pavan Kumar Paluri Provide "nosnp" boot option via "sev=nosnp" kernel command line to prevent SEV-SNP[1] capable host kernel from enabling SEV-SNP and initializing Reverse Map Table (RMP) [1]. On providing sev=nosnp via kernel command line: cat /sys/module/kvm_amd/parameters/sev_snp should be "N". This patchset is based on tip/master. Reference: [1] https://www.amd.com/content/dam/amd/en/documents/processor-tech-docs/programmer-references/24593.pdf Changelog: v3->v4: * Remove an irrelevant header (Boris) * Rebase on latest tip/master v2->v3: * Fix the build warning reported by kernel test robot * https://lore.kernel.org/all/20240905143056.48216-1-papaluri@amd.com/ v1->v2: * Pick R-b's from Tom. * Include only those headers that provide the necessary definitions (Boris) * Provide appropriate references to SEV, SNP and RMP (Matthew) * https://lore.kernel.org/all/20240903003511.1530454-1-papaluri@amd.com/ Pavan Kumar Paluri (2): x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm x86 KVM:SVM: Provide "nosnp" boot option for sev kernel command line .../arch/x86/x86_64/boot-options.rst | 3 ++ arch/x86/coco/sev/core.c | 44 ------------------- arch/x86/include/asm/sev-common.h | 29 ++++++++++++ arch/x86/virt/svm/Makefile | 1 + arch/x86/virt/svm/cmdline.c | 39 ++++++++++++++++ 5 files changed, 72 insertions(+), 44 deletions(-) create mode 100644 arch/x86/virt/svm/cmdline.c base-commit: 6d3e8e28e20d250d2f3ebb3f5afb63848a2aebf9 -- 2.34.1 ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm 2024-09-22 3:36 [PATCH v4 0/2] nosnp sev command line support Pavan Kumar Paluri @ 2024-09-22 3:36 ` Pavan Kumar Paluri 2024-09-25 15:57 ` Tom Lendacky 2024-09-22 3:36 ` [PATCH v4 2/2] x86 KVM:SVM: Provide "nosnp" boot option for sev kernel command line Pavan Kumar Paluri 1 sibling, 1 reply; 5+ messages in thread From: Pavan Kumar Paluri @ 2024-09-22 3:36 UTC (permalink / raw) To: linux-kernel Cc: linux-doc, Borislav Petkov, Thomas Gleixner, Ingo Molnar, Dave Hansen, Eric Van Tassell, Tom Lendacky, Ashish Kalra, Michael Roth, H . Peter Anvin, Peter Zijlstra, Pavan Kumar Paluri Move SEV specific kernel command line option parsing support from arch/x86/coco/sev/core.c to arch/x86/virt/svm/cmdline.c so that both host and guest related SEV command line options can be supported. No functional changes intended. Signed-off-by: Pavan Kumar Paluri <papaluri@amd.com> Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com> --- arch/x86/coco/sev/core.c | 44 ------------------------------- arch/x86/include/asm/sev-common.h | 29 ++++++++++++++++++++ arch/x86/virt/svm/Makefile | 1 + arch/x86/virt/svm/cmdline.c | 32 ++++++++++++++++++++++ 4 files changed, 62 insertions(+), 44 deletions(-) create mode 100644 arch/x86/virt/svm/cmdline.c diff --git a/arch/x86/coco/sev/core.c b/arch/x86/coco/sev/core.c index de1df0cb45da..ff19e805e7a1 100644 --- a/arch/x86/coco/sev/core.c +++ b/arch/x86/coco/sev/core.c @@ -141,33 +141,6 @@ static DEFINE_PER_CPU(struct sev_es_save_area *, sev_vmsa); static DEFINE_PER_CPU(struct svsm_ca *, svsm_caa); static DEFINE_PER_CPU(u64, svsm_caa_pa); -struct sev_config { - __u64 debug : 1, - - /* - * Indicates when the per-CPU GHCB has been created and registered - * and thus can be used by the BSP instead of the early boot GHCB. - * - * For APs, the per-CPU GHCB is created before they are started - * and registered upon startup, so this flag can be used globally - * for the BSP and APs. - */ - ghcbs_initialized : 1, - - /* - * Indicates when the per-CPU SVSM CA is to be used instead of the - * boot SVSM CA. - * - * For APs, the per-CPU SVSM CA is created as part of the AP - * bringup, so this flag can be used globally for the BSP and APs. - */ - use_cas : 1, - - __reserved : 61; -}; - -static struct sev_config sev_cfg __read_mostly; - static __always_inline bool on_vc_stack(struct pt_regs *regs) { unsigned long sp = regs->sp; @@ -2374,23 +2347,6 @@ static int __init report_snp_info(void) } arch_initcall(report_snp_info); -static int __init init_sev_config(char *str) -{ - char *s; - - while ((s = strsep(&str, ","))) { - if (!strcmp(s, "debug")) { - sev_cfg.debug = true; - continue; - } - - pr_info("SEV command-line option '%s' was not recognized\n", s); - } - - return 1; -} -__setup("sev=", init_sev_config); - static void update_attest_input(struct svsm_call *call, struct svsm_attest_call *input) { /* If (new) lengths have been returned, propagate them up */ diff --git a/arch/x86/include/asm/sev-common.h b/arch/x86/include/asm/sev-common.h index 98726c2b04f8..adddcf3edaf0 100644 --- a/arch/x86/include/asm/sev-common.h +++ b/arch/x86/include/asm/sev-common.h @@ -8,6 +8,8 @@ #ifndef __ASM_X86_SEV_COMMON_H #define __ASM_X86_SEV_COMMON_H +#include <asm/cache.h> + #define GHCB_MSR_INFO_POS 0 #define GHCB_DATA_LOW 12 #define GHCB_MSR_INFO_MASK (BIT_ULL(GHCB_DATA_LOW) - 1) @@ -220,4 +222,31 @@ struct snp_psc_desc { #define GHCB_ERR_INVALID_INPUT 5 #define GHCB_ERR_INVALID_EVENT 6 +struct sev_config { + __u64 debug : 1, + + /* + * Indicates when the per-CPU GHCB has been created and registered + * and thus can be used by the BSP instead of the early boot GHCB. + * + * For APs, the per-CPU GHCB is created before they are started + * and registered upon startup, so this flag can be used globally + * for the BSP and APs. + */ + ghcbs_initialized : 1, + + /* + * Indicates when the per-CPU SVSM CA is to be used instead of the + * boot SVSM CA. + * + * For APs, the per-CPU SVSM CA is created as part of the AP + * bringup, so this flag can be used globally for the BSP and APs. + */ + use_cas : 1, + + __reserved : 61; +}; + +extern struct sev_config sev_cfg __read_mostly; + #endif diff --git a/arch/x86/virt/svm/Makefile b/arch/x86/virt/svm/Makefile index ef2a31bdcc70..eca6d71355fa 100644 --- a/arch/x86/virt/svm/Makefile +++ b/arch/x86/virt/svm/Makefile @@ -1,3 +1,4 @@ # SPDX-License-Identifier: GPL-2.0 obj-$(CONFIG_KVM_AMD_SEV) += sev.o +obj-$(CONFIG_CPU_SUP_AMD) += cmdline.o diff --git a/arch/x86/virt/svm/cmdline.c b/arch/x86/virt/svm/cmdline.c new file mode 100644 index 000000000000..964677ab02d6 --- /dev/null +++ b/arch/x86/virt/svm/cmdline.c @@ -0,0 +1,32 @@ +// SPDX-License-Identifier: GPL-2.0-only +/* + * AMD SVM-SEV command line parsing support + * + * Copyright (C) 2023 - 2024 Advanced Micro Devices, Inc. + * + * Author: Michael Roth <michael.roth@amd.com> + */ + +#include <linux/string.h> +#include <linux/printk.h> + +#include <asm/sev-common.h> + +struct sev_config sev_cfg; + +static int __init init_sev_config(char *str) +{ + char *s; + + while ((s = strsep(&str, ","))) { + if (!strcmp(s, "debug")) { + sev_cfg.debug = true; + continue; + } + + pr_info("SEV command-line option '%s' was not recognized\n", s); + } + + return 1; +} +__setup("sev=", init_sev_config); -- 2.34.1 ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm 2024-09-22 3:36 ` [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm Pavan Kumar Paluri @ 2024-09-25 15:57 ` Tom Lendacky 2024-09-26 17:06 ` Paluri, PavanKumar 0 siblings, 1 reply; 5+ messages in thread From: Tom Lendacky @ 2024-09-25 15:57 UTC (permalink / raw) To: Pavan Kumar Paluri, linux-kernel Cc: linux-doc, Borislav Petkov, Thomas Gleixner, Ingo Molnar, Dave Hansen, Eric Van Tassell, Ashish Kalra, Michael Roth, H . Peter Anvin, Peter Zijlstra On 9/21/24 22:36, Pavan Kumar Paluri wrote: > Move SEV specific kernel command line option parsing support from > arch/x86/coco/sev/core.c to arch/x86/virt/svm/cmdline.c so that both > host and guest related SEV command line options can be supported. > > No functional changes intended. > > Signed-off-by: Pavan Kumar Paluri <papaluri@amd.com> > Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com> > --- > arch/x86/coco/sev/core.c | 44 ------------------------------- > arch/x86/include/asm/sev-common.h | 29 ++++++++++++++++++++ > arch/x86/virt/svm/Makefile | 1 + > arch/x86/virt/svm/cmdline.c | 32 ++++++++++++++++++++++ > 4 files changed, 62 insertions(+), 44 deletions(-) > create mode 100644 arch/x86/virt/svm/cmdline.c > ... > diff --git a/arch/x86/include/asm/sev-common.h b/arch/x86/include/asm/sev-common.h > index 98726c2b04f8..adddcf3edaf0 100644 > --- a/arch/x86/include/asm/sev-common.h > +++ b/arch/x86/include/asm/sev-common.h > @@ -8,6 +8,8 @@ > #ifndef __ASM_X86_SEV_COMMON_H > #define __ASM_X86_SEV_COMMON_H > > +#include <asm/cache.h> > + > #define GHCB_MSR_INFO_POS 0 > #define GHCB_DATA_LOW 12 > #define GHCB_MSR_INFO_MASK (BIT_ULL(GHCB_DATA_LOW) - 1) > @@ -220,4 +222,31 @@ struct snp_psc_desc { > #define GHCB_ERR_INVALID_INPUT 5 > #define GHCB_ERR_INVALID_EVENT 6 > > +struct sev_config { > + __u64 debug : 1, > + > + /* > + * Indicates when the per-CPU GHCB has been created and registered > + * and thus can be used by the BSP instead of the early boot GHCB. > + * > + * For APs, the per-CPU GHCB is created before they are started > + * and registered upon startup, so this flag can be used globally > + * for the BSP and APs. > + */ > + ghcbs_initialized : 1, > + > + /* > + * Indicates when the per-CPU SVSM CA is to be used instead of the > + * boot SVSM CA. > + * > + * For APs, the per-CPU SVSM CA is created as part of the AP > + * bringup, so this flag can be used globally for the BSP and APs. > + */ > + use_cas : 1, > + > + __reserved : 61; > +}; > + > +extern struct sev_config sev_cfg __read_mostly; So I believe the "__read_mostly" attribute really needs to be on the actual declaration of the struct, below, in cmdline.c, right? You can check and see which section the sev_cfg struct ends up being placed after a build to verify. Thanks, Tom > + > #endif > diff --git a/arch/x86/virt/svm/Makefile b/arch/x86/virt/svm/Makefile > index ef2a31bdcc70..eca6d71355fa 100644 > --- a/arch/x86/virt/svm/Makefile > +++ b/arch/x86/virt/svm/Makefile > @@ -1,3 +1,4 @@ > # SPDX-License-Identifier: GPL-2.0 > > obj-$(CONFIG_KVM_AMD_SEV) += sev.o > +obj-$(CONFIG_CPU_SUP_AMD) += cmdline.o > diff --git a/arch/x86/virt/svm/cmdline.c b/arch/x86/virt/svm/cmdline.c > new file mode 100644 > index 000000000000..964677ab02d6 > --- /dev/null > +++ b/arch/x86/virt/svm/cmdline.c > @@ -0,0 +1,32 @@ > +// SPDX-License-Identifier: GPL-2.0-only > +/* > + * AMD SVM-SEV command line parsing support > + * > + * Copyright (C) 2023 - 2024 Advanced Micro Devices, Inc. > + * > + * Author: Michael Roth <michael.roth@amd.com> > + */ > + > +#include <linux/string.h> > +#include <linux/printk.h> > + > +#include <asm/sev-common.h> > + > +struct sev_config sev_cfg; > + > +static int __init init_sev_config(char *str) > +{ > + char *s; > + > + while ((s = strsep(&str, ","))) { > + if (!strcmp(s, "debug")) { > + sev_cfg.debug = true; > + continue; > + } > + > + pr_info("SEV command-line option '%s' was not recognized\n", s); > + } > + > + return 1; > +} > +__setup("sev=", init_sev_config); ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm 2024-09-25 15:57 ` Tom Lendacky @ 2024-09-26 17:06 ` Paluri, PavanKumar 0 siblings, 0 replies; 5+ messages in thread From: Paluri, PavanKumar @ 2024-09-26 17:06 UTC (permalink / raw) To: Tom Lendacky, linux-kernel Cc: linux-doc, Borislav Petkov, Thomas Gleixner, Ingo Molnar, Dave Hansen, Eric Van Tassell, Ashish Kalra, Michael Roth, H . Peter Anvin, Peter Zijlstra Hello Tom, On 9/25/2024 10:57 AM, Tom Lendacky wrote: > On 9/21/24 22:36, Pavan Kumar Paluri wrote: >> Move SEV specific kernel command line option parsing support from >> arch/x86/coco/sev/core.c to arch/x86/virt/svm/cmdline.c so that both >> host and guest related SEV command line options can be supported. >> >> No functional changes intended. >> >> Signed-off-by: Pavan Kumar Paluri <papaluri@amd.com> >> Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com> >> --- >> arch/x86/coco/sev/core.c | 44 ------------------------------- >> arch/x86/include/asm/sev-common.h | 29 ++++++++++++++++++++ >> arch/x86/virt/svm/Makefile | 1 + >> arch/x86/virt/svm/cmdline.c | 32 ++++++++++++++++++++++ >> 4 files changed, 62 insertions(+), 44 deletions(-) >> create mode 100644 arch/x86/virt/svm/cmdline.c >> > ... >> +extern struct sev_config sev_cfg __read_mostly; > > So I believe the "__read_mostly" attribute really needs to be on the > actual declaration of the struct, below, in cmdline.c, right? > Yes, I will move this attribute to cmdline.c > You can check and see which section the sev_cfg struct ends up being > placed after a build to verify. > It is placed in .data.readmostly section. 0000000000000000 g O .data..read_mostly 0000000000000008 sev_cfg > Thanks, > Tom > Thanks for the review, Pavan >> + >> #endif >> diff --git a/arch/x86/virt/svm/Makefile b/arch/x86/virt/svm/Makefile >> index ef2a31bdcc70..eca6d71355fa 100644 >> --- a/arch/x86/virt/svm/Makefile >> +++ b/arch/x86/virt/svm/Makefile >> @@ -1,3 +1,4 @@ >> # SPDX-License-Identifier: GPL-2.0 >> >> obj-$(CONFIG_KVM_AMD_SEV) += sev.o >> +obj-$(CONFIG_CPU_SUP_AMD) += cmdline.o >> diff --git a/arch/x86/virt/svm/cmdline.c b/arch/x86/virt/svm/cmdline.c >> new file mode 100644 >> index 000000000000..964677ab02d6 >> --- /dev/null >> +++ b/arch/x86/virt/svm/cmdline.c >> @@ -0,0 +1,32 @@ >> +// SPDX-License-Identifier: GPL-2.0-only >> +/* >> + * AMD SVM-SEV command line parsing support >> + * >> + * Copyright (C) 2023 - 2024 Advanced Micro Devices, Inc. >> + * >> + * Author: Michael Roth <michael.roth@amd.com> >> + */ >> + >> +#include <linux/string.h> >> +#include <linux/printk.h> >> + >> +#include <asm/sev-common.h> >> + >> +struct sev_config sev_cfg; >> + >> +static int __init init_sev_config(char *str) >> +{ >> + char *s; >> + >> + while ((s = strsep(&str, ","))) { >> + if (!strcmp(s, "debug")) { >> + sev_cfg.debug = true; >> + continue; >> + } >> + >> + pr_info("SEV command-line option '%s' was not recognized\n", s); >> + } >> + >> + return 1; >> +} >> +__setup("sev=", init_sev_config); ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v4 2/2] x86 KVM:SVM: Provide "nosnp" boot option for sev kernel command line 2024-09-22 3:36 [PATCH v4 0/2] nosnp sev command line support Pavan Kumar Paluri 2024-09-22 3:36 ` [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm Pavan Kumar Paluri @ 2024-09-22 3:36 ` Pavan Kumar Paluri 1 sibling, 0 replies; 5+ messages in thread From: Pavan Kumar Paluri @ 2024-09-22 3:36 UTC (permalink / raw) To: linux-kernel Cc: linux-doc, Borislav Petkov, Thomas Gleixner, Ingo Molnar, Dave Hansen, Eric Van Tassell, Tom Lendacky, Ashish Kalra, Michael Roth, H . Peter Anvin, Peter Zijlstra, Pavan Kumar Paluri Provide a "nosnp" kernel command line option to prevent enabling of the RMP and SEV-SNP features in the host/hypervisor. Not initializing the RMP removes system overhead associated with RMP checks. Co-developed-by: Eric Van Tassell <Eric.VanTassell@amd.com> Signed-off-by: Eric Van Tassell <Eric.VanTassell@amd.com> Signed-off-by: Pavan Kumar Paluri <papaluri@amd.com> Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com> --- Documentation/arch/x86/x86_64/boot-options.rst | 3 +++ arch/x86/virt/svm/cmdline.c | 7 +++++++ 2 files changed, 10 insertions(+) diff --git a/Documentation/arch/x86/x86_64/boot-options.rst b/Documentation/arch/x86/x86_64/boot-options.rst index 137432d34109..3d4e9a7dccf2 100644 --- a/Documentation/arch/x86/x86_64/boot-options.rst +++ b/Documentation/arch/x86/x86_64/boot-options.rst @@ -317,3 +317,6 @@ The available options are: debug Enable debug messages. + + nosnp + Do not enable SEV-SNP (applies to host/hypervisor only). diff --git a/arch/x86/virt/svm/cmdline.c b/arch/x86/virt/svm/cmdline.c index 964677ab02d6..454574539c49 100644 --- a/arch/x86/virt/svm/cmdline.c +++ b/arch/x86/virt/svm/cmdline.c @@ -11,6 +11,7 @@ #include <linux/printk.h> #include <asm/sev-common.h> +#include <asm/cpufeature.h> struct sev_config sev_cfg; @@ -24,6 +25,12 @@ static int __init init_sev_config(char *str) continue; } + if (!strcmp(s, "nosnp")) { + setup_clear_cpu_cap(X86_FEATURE_SEV_SNP); + cc_platform_clear(CC_ATTR_HOST_SEV_SNP); + continue; + } + pr_info("SEV command-line option '%s' was not recognized\n", s); } -- 2.34.1 ^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2024-09-26 17:06 UTC | newest] Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2024-09-22 3:36 [PATCH v4 0/2] nosnp sev command line support Pavan Kumar Paluri 2024-09-22 3:36 ` [PATCH v4 1/2] x86, KVM:SVM: Move sev specific parsing into arch/x86/virt/svm Pavan Kumar Paluri 2024-09-25 15:57 ` Tom Lendacky 2024-09-26 17:06 ` Paluri, PavanKumar 2024-09-22 3:36 ` [PATCH v4 2/2] x86 KVM:SVM: Provide "nosnp" boot option for sev kernel command line Pavan Kumar Paluri
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®