From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752060AbdJ2VPO (ORCPT ); Sun, 29 Oct 2017 17:15:14 -0400 Received: from mail-by2nam01on0068.outbound.protection.outlook.com ([104.47.34.68]:1655 "EHLO NAM01-BY2-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1751666AbdJ2VPL (ORCPT ); Sun, 29 Oct 2017 17:15:11 -0400 Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=brijesh.singh@amd.com; Cc: brijesh.singh@amd.com, Paolo Bonzini , =?UTF-8?B?UmFkaW0gS3LEjW3DocWZ?= , Borislav Petkov , Herbert Xu , Gary Hook , Tom Lendacky , linux-crypto@vger.kernel.org, kvm@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [Part2 PATCH v6.1 16/38] crypto: ccp: Add Secure Encrypted Virtualization (SEV) command support To: bp@alien8.de References: <20171020023413.122280-14-brijesh.singh@amd.com> <20171029204825.18260-1-brijesh.singh@amd.com> From: Brijesh Singh Message-ID: Date: Sun, 29 Oct 2017 16:14:59 -0500 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.4.0 MIME-Version: 1.0 In-Reply-To: <20171029204825.18260-1-brijesh.singh@amd.com> Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit Content-Language: en-US X-Originating-IP: [165.204.77.1] X-ClientProxiedBy: BN6PR16CA0021.namprd16.prod.outlook.com (10.172.212.159) To SN1PR12MB0158.namprd12.prod.outlook.com (10.162.3.145) X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: 071d1100-1322-4f1c-7e83-08d51f122096 X-MS-Office365-Filtering-HT: Tenant X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001)(4534020)(4602075)(48565401081)(2017052603199);SRVR:SN1PR12MB0158; X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0158;3:yHs+skxdi33ovsmPJvuYrAUpX11+m3RidW/Efd4TrWYwXFI8dahtgvmMuly1yOCqviNLIq+abG3+/WLQTTDYQkKgZtZ+moToDt8bucF0wcpzbsCTuiiblskFNeIGxKFYTt/tI6XOOpABxrpOEhtP65vYHBKkFsSJvZ5S7TKBNSW5v9lhFDl8fDIt1BLpPt2l2fv1HexEE6SQbmVBZxBqiZAgW3BFr4Xs93K8Fzsnrm+Aplc8PsqTXqsIvsDSGBsP;25:RuUJbAhv4Vw8XHOzYIJWSrbRYUIyCIIRmAyzjBICWOXd1ht9YeN7gc4Y+enyN2Gjl+PNt9dvH8I9YkGKzBs6RPHuJEZbxdikTCqIfWV4BUFn8cSvsNegSaxBPQUQlwiSpHl8Bwns+VM7KBTY36/AThRMn2mSbsaGeoedP2ZA9eSE5MlZPBtyFFrKstfuwivkDivyLevVwRCcyzEzJoOB5kNTrNZvPKccxVdmdiqwesikFSGVfTXA8LIQLw8qcQaxK7KEe1dh5AfhcW6h1QphtpilfWxIsUH+/trjWDAgaA1suP05Z/REzpGsc5Xn81uazrW0tJQ1qtxm6r1HaBvmCw==;31:qrSihO+L5RqWq02A7ElclF148H7+JzoEpE29k5+6AWD6hKSdmvZu4+saZ13ooDvvI1uxfp4doTxksQ4NE471w1aXh7/JGdDDnfcg+K2yOYt8K7QHLGCNcd4GcAfbN5Cd2+3nxuQeevVQq1dkeTXgLKRjLWaKNfQqxFSVKVfsL9V3YyasLqv7rg9O67SQWHMzYR0I3kfyasSmD6rCA8wF2nvsVfChFKWSYP1GiXGpwDE= X-MS-TrafficTypeDiagnostic: SN1PR12MB0158: X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0158;20:dibaL7l7qvhoxfNReIJ4E1oR/lq7+4Rfc2h8aY/8ySyd77ApiTnZqXl7Ynic0VqsD3Ji8KsWBWIWdYkyFEzLJsAAXLotXh3Pl/5WTD8Fvf+Ih+7fIWtY5EeAUXmFogIsOa8bBEcypcWof7BdLuOWwIz+WFp3FDfoy3AhM/px0OcdRWBr/8x5dTDHEcUtVcMvhrwhMSsEajQcoUts5KFTyH1BhfxDacFJnggdtoQ9OE2BL1ozXjQFrOev2lRu3XgjXLki5rFQL5kqE/Uz94SA/3lHdl/o7DXmKqNe4mFipyXV2w3Ezt+p3B/5jO5QQicR8gPmOXRraO3qp9aqpIWrPmk52I5pwRBCF6ioWr+GxdLALz0g/R/6GTLwrcyqhL4Jf5Pzv4twRj0ErQy2pw1U1I1rhR4rmKj8augQL27FQkt8eZJXxor9hY6e5dfdyKpvH//+ie5lNUWDMQp+e2H/Ixz2HoLsPd0CSR44xNN9v65pzEkEmYWUSoojUMJhW7+u;4:xPlWEREMYQHCnMmJxFYEY8BUp3g7vzoEdgJ8r0q43QXHwMoZioGRPK/1Qnm22LFK07MUP7QRogvAs1EKa1F1ZyUrPMoYE72QIC2+DB3adtxsnHm98tduXS+meheFwlebVBapjI4bXfrkMggjJmTnNkfYQP3tGGF9WSdIVYJmJneVHAq2Q3e0+LrZ61RKV/0rw0sM90edA34KzFnY8xytrW07XgJKHN6pJlu+ZNzbE3x+U6j2RG8Uns8NjFYXezkTIZk92140bvp6E8dBGO01Gx+6HEmTFqyXOPeTYImtUoBIYCkO5oLcawpoec4Z2CzxoxppGxSp8V1ITBqsPgR12A== X-Exchange-Antispam-Report-Test: UriScan:(9452136761055)(767451399110); X-Microsoft-Antispam-PRVS: X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(5005006)(8121501046)(93006095)(93001095)(100000703101)(100105400095)(10201501046)(3231020)(3002001)(6055026)(6041248)(20161123562025)(20161123564025)(20161123558100)(20161123555025)(20161123560025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095);SRVR:SN1PR12MB0158;BCL:0;PCL:0;RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095);SRVR:SN1PR12MB0158; X-Forefront-PRVS: 0475418F50 X-Forefront-Antispam-Report: SFV:NSPM;SFS:(10009020)(6009001)(376002)(39830400002)(346002)(24454002)(189002)(199003)(478600001)(54906003)(25786009)(2906002)(966005)(47776003)(33646002)(50466002)(2361001)(2351001)(53546010)(81156014)(8676002)(6486002)(81166006)(229853002)(575784001)(86362001)(97736004)(68736007)(2870700001)(189998001)(31696002)(8936002)(7736002)(36756003)(305945005)(76176999)(50986999)(54356999)(83506002)(6306002)(101416001)(6116002)(3846002)(58126008)(53936002)(16526018)(4326008)(6246003)(316002)(65806001)(31686004)(53416004)(23676002)(106356001)(105586002)(65826007)(66066001)(65956001)(64126003)(5660300001)(6916009)(6666003)(2950100002)(134885004);DIR:OUT;SFP:1101;SCL:1;SRVR:SN1PR12MB0158;H:wsp101162wss.amd.com;FPR:;SPF:None;PTR:InfoNoRecords;MX:1;A:1;LANG:en; X-Microsoft-Exchange-Diagnostics: =?utf-8?B?MTtTTjFQUjEyTUIwMTU4OzIzOlZ5dkNqNWhvWURlTlNvaUtJZFNWZ0VPTE1G?= =?utf-8?B?VzNOaTQydU1JMUcyMXBWOWdjcU1tVS9KaHF1cGpzUWFhMmFlMkJPYnFXRlRZ?= =?utf-8?B?TnVRU3I1WGpnNVpXcUowczZ1UWswbmJjY1hZbTdFRUk1aUxqeGNnSkUrSzRw?= =?utf-8?B?cUdCZ2JWRUFwdVBBSUpJNkx2ZDBvNy81bW5tVWl1TmVjOTUvcG4rVTVmZ2ow?= =?utf-8?B?cVVmUytvZlAvTUlKTGQwdzFnNTJHd0pQcmdwVFFEOEdhYVFOTFp6VCt4UWx5?= =?utf-8?B?MTJ6amNsNlZFbjVwbHYvR3FOU0tiK0NNdnFDdlV6S0N0YVFvanVncm50TmRG?= =?utf-8?B?aWV3eDEyYmtGcWlLMkowcGVNb2RGNVNjRkI2dldZdGEzRGRBZmhyOThhYURQ?= =?utf-8?B?cjJxdms0VmF0MVl6Z1pHLzI5ODVkT0tLVjRTWDgxM3ZFMlpENisxbkFnSEsw?= =?utf-8?B?cWIvMGVDdVhTblo2b3p5STFlc0pwSlBsTW1ubEx0ZFZudzV6NE8xd0MvdGg3?= =?utf-8?B?T3ZQZjFGV3J1Z2wzVE9oMnNidmR1YWl5S0FNVUxoY0RIM2s1OVFpSVl4Tytj?= =?utf-8?B?WHZnSDludXVXbFNRUEdrcU11OGp5SFNUdXFTQll5dWhLQ1ZGdFZWeXV2eXd1?= =?utf-8?B?c1hoeUNxZzE1eDhWYmZubjJJNk9SbENWMXUwQnluOWFFb21FeC90MWRnbWxB?= =?utf-8?B?MGxqRzNMaE03TWhKb2VuQXNlWGVTak93aUZURGhHNGNQWTFBNENMandMWkl0?= =?utf-8?B?TXVvdVdIeW9DQzVxcEl1R29kaWVuMUxrSU0wWVdpYTIra0h6RndGWmJvNHZ3?= =?utf-8?B?NkpZU3Q4QTRQR1VUczRUeUtpdUU2Y2NDZFVocmd6b1hPczRBSUNGNU1jZnUr?= =?utf-8?B?dmVXdFVxRmR2U09hMnlHV3d3bit1OUVyTDBNSHFiWFloUjR4YVY5YlZwbTdo?= =?utf-8?B?ZVRPRVRzOWhGQjZtY0JDajFZTUwzN1BIQlhaS1FrNjF1RHArWGxEVDdERlVC?= =?utf-8?B?UURrdVF2RWpLWXI3UHJlSXJ3Q2pobFZNem9wNXAzYklPYzhxZysrZlNxOVl6?= =?utf-8?B?SWxIa0pYS2dqazZUbEJYMjROc1JjS3I0NFRPaE1NdkdZNzRkbG1aYkdlcnN4?= =?utf-8?B?enQrVE1mNndzOVg4MlhRZ0NOT1QzbkJjcUFWcXozbWkxMDZwcmFKVE9WS3Jl?= =?utf-8?B?bVhHeUlmRlgxeGYwb0UxcWs5ZlN1ai9Ea2NoS2pscFg5VmM5Q0JjdlRQQVN4?= =?utf-8?B?QmhMSVVZbW9XcDNmeU9UbzNlUjRtWk9VSWZtcERvK1V4bWszNU5BS2dEZnRn?= =?utf-8?B?SXQvcFJ6bGppZURlMVRmT2xRWWlxM2FUUlZtY0VtNmxrS2dBa3V2T25LdTdY?= =?utf-8?B?c0N3SjVDem4zT1huL0d2WnBaYzJKNVJ4ZnU4V1lPV1BzQ0QyTWljNnpBN0Q3?= =?utf-8?B?OHRXUm91M2h6WUg5RnVuemljRDhWMDY3dkpRNzdJQ2ZvODR3QXdLdjBaY21X?= =?utf-8?B?V0MrQnQvQmdPZ3BZa0Q0Y0QvRGRZUVR0VGRtVkRRMzMvMkxPb3hLelhKb3hi?= =?utf-8?B?a2FZRmRidzNuamNRWDZBeDVuUzRaUm1FUVptb2lKS3F5TFdzSWltYXBvelht?= =?utf-8?B?cDA5b3R6ejZwa3RsTUxLQUhZaUVqTlVGcjNONk5CRDZleGdERitFZHA2TnBO?= =?utf-8?B?VGE3UjQ1SWlFYXBHTmRJa3VLZ0kvNmhJUlNvRFA3N3V0Zmh4ZTdoK0hGcDQ3?= =?utf-8?B?cEo1Z0hhZXRERnVydWgwMlBhWi9TQ3FGQU5Ec2h1VkgzRXdGSkR5K1JTTkxD?= =?utf-8?B?QjNvWmN3dHNPcTB0cVpLWXlic0hlRG5XTEtkdTNGdFpFME5FeUlqeXZaUm1K?= =?utf-8?B?UWpvNHhnNGg0aU5CdG1sV1dBcXdMSlFLdUI1UFRnSDlqME9JeXV3U2R3Y1FQ?= =?utf-8?Q?Hezy6ZxkiNKN5opxpmeY85wShL/ZG8=3D?= X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0158;6:0+huGGVUfQsZSbu2W+xF+kYxQrDwy4lEhFF+DDP2f7ooe9fJ4vkVSD9zY7Q5Y6yn2Rwl86OJhXQdBFeHCEt2HFffPoi5ekmHXVaJk074lDu+fBvBHd/VmMUayfdU4OwgBk67G+APEHCZWheLYqDmbzRB4CQFdEZWJOYMtMnbLIjUxKb4+yo3wcTpZwfG404W/5MDe7OwBHHpgaOfwt9tI1fXnqJFplXzqUN4Xv3XNw3s+XQ2HjTrxJR1BqAJyMooxFsU88jKM2WwBp6zPDXPBn9gbzWRiUmiOeMu7z3KwKpSlNjpBFbQsJMEslGZY9thkoU73nJ4pPSfRjVR4oGtoWbNpw2hfYMD7g8A5wKyc2I=;5:My5leQAB05fDqIYjSKhVJ80waIR/CHhMxQet9KvdQwxR2NwULVpWNFkX92gc558aoSpJwd288QyLVziPlNkhAV7PfD+cY9DsWrUcRt0qrWC1RbErTFmN2E4A4fpfn/A3zxbjww1Dt3zSq34lQ9qGD/bcWZfPl3QSLe5rrSWGrcE=;24:jl1OAnAD9QNE3IdKmwfhhKr41zu0VbpvpS83GZufZ4r+ILK6F0Y0xM1Aek4TfGoZs9WcQCwDraPzCYxaLSSVU1Zl++utC4J2SMwDK+WFzdg=;7:i/HeJLWKjxnTHTAktAMLb/BpSPu7oX0UlaQ/7fx6zHbUDHtCv9HVPTZsplUuQmrJouo7Lke4UluC0lh7E8ZF8Jt4l2GyE6rFZ6lsMxmp19xyT/o7QeyC0wxWQZz04VVacdt3wrL/t+b7hM/CaekmlQfRBhq06PYKu08azrCndBvydkpsJeTDSyuoBK+EleD26LV0kSmYSRyJdzzDqd2ipDzyJy8M/DnDRJPGJkLJn7h3+h9pk31hxrFpuFJrAT3l SpamDiagnosticOutput: 1:99 SpamDiagnosticMetadata: NSPM X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0158;20:3VQJX1YbGzFXn3p4R4+FzQDPqxSZFT6sQm4oOkC+0J/RPplhVvMurT1bKCGLT1cyLnB2PRwVmlxk1qDUPcpdadm+86pjx4dTFKOmiJnSITEJUR/9+II5pL3YRNg+xdhxU7naJlXs1dxc1soQ9CRD3sQYMi54uQauaN3BOD/B7jcOdW0pbWdu3qwEWIeo9CpZPWdMyYp/M/JlwFnctE7KLAYAremt8jJp+rrkaKvYvLn/1nNYC9nAqbrJNEgN7UCb X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 29 Oct 2017 21:15:03.8149 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 071d1100-1322-4f1c-7e83-08d51f122096 X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN1PR12MB0158 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org I just realized that this should be marked as "PATCH v6.1 13/38 ...". I had some  debug patch before this hence it was pushed below in the stack. On 10/29/17 3:48 PM, Brijesh Singh wrote: > AMD's new Secure Encrypted Virtualization (SEV) feature allows the > memory contents of virtual machines to be transparently encrypted with a > key unique to the VM. The programming and management of the encryption > keys are handled by the AMD Secure Processor (AMD-SP) which exposes the > commands for these tasks. The complete spec is available at: > > http://support.amd.com/TechDocs/55766_SEV-KM%20API_Specification.pdf > > Extend the AMD-SP driver to provide the following support: > > - an in-kernel API to communicate with the SEV firmware. The API can be > used by the hypervisor to create encryption context for a SEV guest. > > - a userspace IOCTL to manage the platform certificates. > > Cc: Paolo Bonzini > Cc: "Radim Krčmář" > Cc: Borislav Petkov > Cc: Herbert Xu > Cc: Gary Hook > Cc: Tom Lendacky > Cc: linux-crypto@vger.kernel.org > Cc: kvm@vger.kernel.org > Cc: linux-kernel@vger.kernel.org > Improvements-by: Borislav Petkov > Signed-off-by: Brijesh Singh > --- > > Boris, > > I have tried to minimize the INIT -> SHUTDOWN transition by keeping state > information in sev_state variable. Since we INIT the platform during the > modprobe time hence we no longer need the kref count and init mutex. > Here are list of changes. > > Changes since v6: > * Add functions to init and shutdown firmware during modprobe > * Add sev_state variable in psp_device to keep track of the INIT and SHUTDOWN > state > * Don't allow caller to shutdown the FW because SHUTDOWN will be done during > the module removal. > * Drop the fw_init_mutex and init_refcount because we no longer allow apps to > INIT and UINIT the platform > > drivers/crypto/ccp/psp-dev.c | 360 +++++++++++++++++++++++++++++++++++++++++++ > drivers/crypto/ccp/psp-dev.h | 22 +++ > drivers/crypto/ccp/sp-dev.c | 9 ++ > drivers/crypto/ccp/sp-dev.h | 4 + > include/linux/psp-sev.h | 158 +++++++++++++++++++ > 5 files changed, 553 insertions(+) > > diff --git a/drivers/crypto/ccp/psp-dev.c b/drivers/crypto/ccp/psp-dev.c > index b5789f878560..060f57ac08b3 100644 > --- a/drivers/crypto/ccp/psp-dev.c > +++ b/drivers/crypto/ccp/psp-dev.c > @@ -26,6 +26,15 @@ > #include "sp-dev.h" > #include "psp-dev.h" > > +#define DEVICE_NAME "sev" > + > +static DEFINE_MUTEX(sev_cmd_mutex); > +static struct sev_misc_dev *misc_dev; > +static struct psp_device *psp_master; > + > +static int sev_platform_shutdown_locked(int *error); > +static int sev_platform_init_locked(struct sev_data_init *data, int *error); > + > static struct psp_device *psp_alloc_struct(struct sp_device *sp) > { > struct device *dev = sp->dev; > @@ -45,9 +54,304 @@ static struct psp_device *psp_alloc_struct(struct sp_device *sp) > > static irqreturn_t psp_irq_handler(int irq, void *data) > { > + struct psp_device *psp = data; > + unsigned int status; > + int reg; > + > + /* Read the interrupt status: */ > + status = ioread32(psp->io_regs + PSP_P2CMSG_INTSTS); > + > + /* Check if it is command completion: */ > + if (!(status & BIT(PSP_CMD_COMPLETE_REG))) > + goto done; > + > + /* Check if it is SEV command completion: */ > + reg = ioread32(psp->io_regs + PSP_CMDRESP); > + if (reg & PSP_CMDRESP_RESP) { > + psp->sev_int_rcvd = 1; > + wake_up(&psp->sev_int_queue); > + } > + > +done: > + /* Clear the interrupt status by writing the same value we read. */ > + iowrite32(status, psp->io_regs + PSP_P2CMSG_INTSTS); > + > return IRQ_HANDLED; > } > > +static void sev_wait_cmd_ioc(struct psp_device *psp, unsigned int *reg) > +{ > + psp->sev_int_rcvd = 0; > + > + wait_event(psp->sev_int_queue, psp->sev_int_rcvd); > + *reg = ioread32(psp->io_regs + PSP_CMDRESP); > +} > + > +static int sev_cmd_buffer_len(int cmd) > +{ > + switch (cmd) { > + case SEV_CMD_INIT: return sizeof(struct sev_data_init); > + case SEV_CMD_PLATFORM_STATUS: return sizeof(struct sev_user_data_status); > + case SEV_CMD_PEK_CSR: return sizeof(struct sev_data_pek_csr); > + case SEV_CMD_PEK_CERT_IMPORT: return sizeof(struct sev_data_pek_cert_import); > + case SEV_CMD_PDH_CERT_EXPORT: return sizeof(struct sev_data_pdh_cert_export); > + case SEV_CMD_LAUNCH_START: return sizeof(struct sev_data_launch_start); > + case SEV_CMD_LAUNCH_UPDATE_DATA: return sizeof(struct sev_data_launch_update_data); > + case SEV_CMD_LAUNCH_UPDATE_VMSA: return sizeof(struct sev_data_launch_update_vmsa); > + case SEV_CMD_LAUNCH_FINISH: return sizeof(struct sev_data_launch_finish); > + case SEV_CMD_LAUNCH_MEASURE: return sizeof(struct sev_data_launch_measure); > + case SEV_CMD_ACTIVATE: return sizeof(struct sev_data_activate); > + case SEV_CMD_DEACTIVATE: return sizeof(struct sev_data_deactivate); > + case SEV_CMD_DECOMMISSION: return sizeof(struct sev_data_decommission); > + case SEV_CMD_GUEST_STATUS: return sizeof(struct sev_data_guest_status); > + case SEV_CMD_DBG_DECRYPT: return sizeof(struct sev_data_dbg); > + case SEV_CMD_DBG_ENCRYPT: return sizeof(struct sev_data_dbg); > + case SEV_CMD_SEND_START: return sizeof(struct sev_data_send_start); > + case SEV_CMD_SEND_UPDATE_DATA: return sizeof(struct sev_data_send_update_data); > + case SEV_CMD_SEND_UPDATE_VMSA: return sizeof(struct sev_data_send_update_vmsa); > + case SEV_CMD_SEND_FINISH: return sizeof(struct sev_data_send_finish); > + case SEV_CMD_RECEIVE_START: return sizeof(struct sev_data_receive_start); > + case SEV_CMD_RECEIVE_FINISH: return sizeof(struct sev_data_receive_finish); > + case SEV_CMD_RECEIVE_UPDATE_DATA: return sizeof(struct sev_data_receive_update_data); > + case SEV_CMD_RECEIVE_UPDATE_VMSA: return sizeof(struct sev_data_receive_update_vmsa); > + case SEV_CMD_LAUNCH_UPDATE_SECRET: return sizeof(struct sev_data_launch_secret); > + default: return 0; > + } > + > + return 0; > +} > + > +static int sev_do_cmd_locked(int cmd, void *data, int *psp_ret) > +{ > + struct psp_device *psp = psp_master; > + unsigned int phys_lsb, phys_msb; > + unsigned int reg, ret = 0; > + > + if (!psp) > + return -ENODEV; > + > + /* Get the physical address of the command buffer */ > + phys_lsb = data ? lower_32_bits(__psp_pa(data)) : 0; > + phys_msb = data ? upper_32_bits(__psp_pa(data)) : 0; > + > + dev_dbg(psp->dev, "sev command id %#x buffer 0x%08x%08x\n", > + cmd, phys_msb, phys_lsb); > + > + print_hex_dump_debug("(in): ", DUMP_PREFIX_OFFSET, 16, 2, data, > + sev_cmd_buffer_len(cmd), false); > + > + iowrite32(phys_lsb, psp->io_regs + PSP_CMDBUFF_ADDR_LO); > + iowrite32(phys_msb, psp->io_regs + PSP_CMDBUFF_ADDR_HI); > + > + reg = cmd; > + reg <<= PSP_CMDRESP_CMD_SHIFT; > + reg |= PSP_CMDRESP_IOC; > + iowrite32(reg, psp->io_regs + PSP_CMDRESP); > + > + /* wait for command completion */ > + sev_wait_cmd_ioc(psp, ®); > + > + if (psp_ret) > + *psp_ret = reg & PSP_CMDRESP_ERR_MASK; > + > + if (reg & PSP_CMDRESP_ERR_MASK) { > + dev_dbg(psp->dev, "sev command %#x failed (%#010x)\n", > + cmd, reg & PSP_CMDRESP_ERR_MASK); > + ret = -EIO; > + } > + > + print_hex_dump_debug("(out): ", DUMP_PREFIX_OFFSET, 16, 2, data, > + sev_cmd_buffer_len(cmd), false); > + > + return ret; > +} > + > +static int sev_do_cmd(int cmd, void *data, int *psp_ret) > +{ > + int rc; > + > + mutex_lock(&sev_cmd_mutex); > + rc = sev_do_cmd_locked(cmd, data, psp_ret); > + mutex_unlock(&sev_cmd_mutex); > + > + return rc; > +} > + > +static long sev_ioctl(struct file *file, unsigned int ioctl, unsigned long arg) > +{ > + return -ENOTTY; > +} > + > +static const struct file_operations sev_fops = { > + .owner = THIS_MODULE, > + .unlocked_ioctl = sev_ioctl, > +}; > + > +static int sev_platform_init_locked(struct sev_data_init *data, int *error) > +{ > + struct psp_device *psp = psp_master; > + struct sev_data_init *input = NULL; > + int rc = 0; > + > + if (!psp) > + return -ENODEV; > + > + if (psp->sev_state == SEV_STATE_INIT) > + return 0; > + > + if (!data) { > + input = kzalloc(sizeof(*input), GFP_KERNEL); > + if (!input) > + return -ENOMEM; > + > + data = input; > + } > + > + rc = sev_do_cmd_locked(SEV_CMD_INIT, data, error); > + if (rc) > + goto e_free; > + > + psp->sev_state = SEV_STATE_INIT; > + dev_dbg(psp->dev, "SEV firmware intialized\n"); > + > +e_free: > + kfree(input); > + return rc; > +} > + > +int sev_platform_init(struct sev_data_init *data, int *error) > +{ > + int rc; > + > + mutex_lock(&sev_cmd_mutex); > + rc = sev_platform_init_locked(data, error); > + mutex_unlock(&sev_cmd_mutex); > + > + return rc; > +} > +EXPORT_SYMBOL_GPL(sev_platform_init); > + > +static int sev_platform_shutdown_locked(int *error) > +{ > + int ret; > + > + ret = sev_do_cmd_locked(SEV_CMD_SHUTDOWN, 0, error); > + if (ret) > + return ret; > + > + psp_master->sev_state = SEV_STATE_UNINIT; > + dev_dbg(psp_master->dev, "SEV firmware shutdown\n"); > + > + return ret; > +} > + > +int sev_platform_shutdown(int *error) > +{ > + if (error) > + *error = 0; > + > + return 0; > +} > +EXPORT_SYMBOL_GPL(sev_platform_shutdown); > + > +int sev_platform_status(struct sev_user_data_status *data, int *error) > +{ > + return sev_do_cmd(SEV_CMD_PLATFORM_STATUS, data, error); > +} > +EXPORT_SYMBOL_GPL(sev_platform_status); > + > +int sev_issue_cmd_external_user(struct file *filep, unsigned int cmd, > + void *data, int *error) > +{ > + if (!filep || filep->f_op != &sev_fops) > + return -EBADF; > + > + return sev_do_cmd(cmd, data, error); > +} > +EXPORT_SYMBOL_GPL(sev_issue_cmd_external_user); > + > +int sev_guest_deactivate(struct sev_data_deactivate *data, int *error) > +{ > + return sev_do_cmd(SEV_CMD_DEACTIVATE, data, error); > +} > +EXPORT_SYMBOL_GPL(sev_guest_deactivate); > + > +int sev_guest_activate(struct sev_data_activate *data, int *error) > +{ > + return sev_do_cmd(SEV_CMD_ACTIVATE, data, error); > +} > +EXPORT_SYMBOL_GPL(sev_guest_activate); > + > +int sev_guest_decommission(struct sev_data_decommission *data, int *error) > +{ > + return sev_do_cmd(SEV_CMD_DECOMMISSION, data, error); > +} > +EXPORT_SYMBOL_GPL(sev_guest_decommission); > + > +int sev_guest_df_flush(int *error) > +{ > + return sev_do_cmd(SEV_CMD_DF_FLUSH, 0, error); > +} > +EXPORT_SYMBOL_GPL(sev_guest_df_flush); > + > +static int sev_ops_init(struct psp_device *psp) > +{ > + struct device *dev = psp->dev; > + int ret; > + > + /* > + * SEV feature support can be detected on multiple devices but the SEV > + * FW commands must be issued on the master. During probe, we do not > + * know the master hence we create /dev/sev on the first device probe. > + * sev_do_cmd() finds the right master device to which to issue the > + * command to the firmware. > + */ > + if (!misc_dev) { > + struct miscdevice *misc; > + > + misc_dev = devm_kzalloc(dev, sizeof(*misc_dev), GFP_KERNEL); > + if (!misc_dev) > + return -ENOMEM; > + > + misc = &misc_dev->misc; > + misc->minor = MISC_DYNAMIC_MINOR; > + misc->name = DEVICE_NAME; > + misc->fops = &sev_fops; > + > + ret = misc_register(misc); > + if (ret) > + return ret; > + > + kref_init(&misc_dev->refcount); > + } else { > + kref_get(&misc_dev->refcount); > + } > + > + init_waitqueue_head(&psp->sev_int_queue); > + psp->sev_misc = misc_dev; > + dev_dbg(dev, "registered SEV device\n"); > + > + return 0; > +} > + > +static int sev_init(struct psp_device *psp) > +{ > + /* Check if device supports SEV feature */ > + if (!(ioread32(psp->io_regs + PSP_FEATURE_REG) & 1)) { > + dev_dbg(psp->dev, "device does not support SEV\n"); > + return 1; > + } > + > + return sev_ops_init(psp); > +} > + > +static void sev_exit(struct kref *ref) > +{ > + struct sev_misc_dev *misc_dev = container_of(ref, struct sev_misc_dev, refcount); > + > + misc_deregister(&misc_dev->misc); > +} > + > int psp_dev_init(struct sp_device *sp) > { > struct device *dev = sp->dev; > @@ -84,11 +388,17 @@ int psp_dev_init(struct sp_device *sp) > if (sp->set_psp_master_device) > sp->set_psp_master_device(sp); > > + ret = sev_init(psp); > + if (ret) > + goto e_irq; > + > /* Enable interrupt */ > iowrite32(-1, psp->io_regs + PSP_P2CMSG_INTEN); > > return 0; > > +e_irq: > + sp_free_psp_irq(psp->sp, psp); > e_err: > sp->psp_data = NULL; > > @@ -101,5 +411,55 @@ void psp_dev_destroy(struct sp_device *sp) > { > struct psp_device *psp = sp->psp_data; > > + if (psp->sev_misc) > + kref_put(&misc_dev->refcount, sev_exit); > + > sp_free_psp_irq(sp, psp); > } > + > +void psp_pci_init(void) > +{ > + struct sev_user_data_status *data; > + struct sp_device *sp; > + int error, rc; > + > + sp = sp_get_psp_master_device(); > + if (!sp) > + return; > + > + psp_master = sp->psp_data; > + > + /* Initialize the platform */ > + rc = sev_platform_init(NULL, &error); > + if (rc) { > + dev_err(sp->dev, "SEV: failed to INIT error %#x\n", error); > + return; > + } > + > + /* Display SEV firmware version */ > + data = kzalloc(sizeof (*data), GFP_KERNEL); > + if (!data) > + return; > + > + rc = sev_platform_status(data, &error); > + if (rc) { > + dev_err(sp->dev, "SEV: failed to get status error %#x\n", error); > + goto e_free; > + } > + > + dev_info(sp->dev, "SEV API:%d.%d build:%d\n", > + data->api_major, data->api_minor, data->build); > + > +e_free: > + kfree(data); > +} > + > +void psp_pci_exit(void) > +{ > + if (!psp_master) > + return; > + > + mutex_lock(&sev_cmd_mutex); > + sev_platform_shutdown_locked(NULL); > + mutex_unlock(&sev_cmd_mutex); > +} > diff --git a/drivers/crypto/ccp/psp-dev.h b/drivers/crypto/ccp/psp-dev.h > index 55b7808367c3..98889b721904 100644 > --- a/drivers/crypto/ccp/psp-dev.h > +++ b/drivers/crypto/ccp/psp-dev.h > @@ -25,9 +25,21 @@ > #include > #include > #include > +#include > +#include > > #include "sp-dev.h" > > +#define PSP_C2PMSG(_num) ((_num) << 2) > +#define PSP_CMDRESP PSP_C2PMSG(32) > +#define PSP_CMDBUFF_ADDR_LO PSP_C2PMSG(56) > +#define PSP_CMDBUFF_ADDR_HI PSP_C2PMSG(57) > +#define PSP_FEATURE_REG PSP_C2PMSG(63) > + > +#define PSP_P2CMSG(_num) ((_num) << 2) > +#define PSP_CMD_COMPLETE_REG 1 > +#define PSP_CMD_COMPLETE PSP_P2CMSG(PSP_CMD_COMPLETE_REG) > + > #define PSP_P2CMSG_INTEN 0x0110 > #define PSP_P2CMSG_INTSTS 0x0114 > > @@ -44,6 +56,11 @@ > > #define MAX_PSP_NAME_LEN 16 > > +struct sev_misc_dev { > + struct kref refcount; > + struct miscdevice misc; > +}; > + > struct psp_device { > struct list_head entry; > > @@ -54,6 +71,11 @@ struct psp_device { > struct sp_device *sp; > > void __iomem *io_regs; > + > + int sev_state; > + unsigned int sev_int_rcvd; > + wait_queue_head_t sev_int_queue; > + struct sev_misc_dev *sev_misc; > }; > > #endif /* __PSP_DEV_H */ > diff --git a/drivers/crypto/ccp/sp-dev.c b/drivers/crypto/ccp/sp-dev.c > index cf101c039c8f..eb0da6572720 100644 > --- a/drivers/crypto/ccp/sp-dev.c > +++ b/drivers/crypto/ccp/sp-dev.c > @@ -272,6 +272,10 @@ static int __init sp_mod_init(void) > if (ret) > return ret; > > +#ifdef CONFIG_CRYPTO_DEV_SP_PSP > + psp_pci_init(); > +#endif > + > return 0; > #endif > > @@ -291,6 +295,11 @@ static int __init sp_mod_init(void) > static void __exit sp_mod_exit(void) > { > #ifdef CONFIG_X86 > + > +#ifdef CONFIG_CRYPTO_DEV_SP_PSP > + psp_pci_exit(); > +#endif > + > sp_pci_exit(); > #endif > > diff --git a/drivers/crypto/ccp/sp-dev.h b/drivers/crypto/ccp/sp-dev.h > index 909cf3e436b4..acb197b66ced 100644 > --- a/drivers/crypto/ccp/sp-dev.h > +++ b/drivers/crypto/ccp/sp-dev.h > @@ -143,12 +143,16 @@ static inline int ccp_dev_resume(struct sp_device *sp) > #ifdef CONFIG_CRYPTO_DEV_SP_PSP > > int psp_dev_init(struct sp_device *sp); > +void psp_pci_init(void); > void psp_dev_destroy(struct sp_device *sp); > +void psp_pci_exit(void); > > #else /* !CONFIG_CRYPTO_DEV_SP_PSP */ > > static inline int psp_dev_init(struct sp_device *sp) { return 0; } > +static inline void psp_pci_init(void) { } > static inline void psp_dev_destroy(struct sp_device *sp) { } > +static inline void psp_pci_exit(void) { } > > #endif /* CONFIG_CRYPTO_DEV_SP_PSP */ > > diff --git a/include/linux/psp-sev.h b/include/linux/psp-sev.h > index 15bda519538e..7ddce7dec464 100644 > --- a/include/linux/psp-sev.h > +++ b/include/linux/psp-sev.h > @@ -491,4 +491,162 @@ struct sev_data_dbg { > u32 len; /* In */ > } __packed; > > +#ifdef CONFIG_CRYPTO_DEV_SP_PSP > + > +/** > + * sev_platform_init - perform SEV INIT command > + * > + * @init: sev_data_init structure to be processed > + * @error: SEV command return code > + * > + * Returns: > + * 0 if the SEV successfully processed the command > + * -%ENODEV if the SEV device is not available > + * -%ENOTSUPP if the SEV does not support SEV > + * -%ETIMEDOUT if the SEV command timed out > + * -%EIO if the SEV returned a non-zero return code > + */ > +int sev_platform_init(struct sev_data_init *init, int *error); > + > +/** > + * sev_platform_shutdown - perform SEV SHUTDOWN command > + * @error: SEV command return code > + * > + * Returns: > + * 0 if the SEV successfully processed the command > + * -%ENODEV if the SEV device is not available > + * -%ENOTSUPP if the SEV does not support SEV > + * -%ETIMEDOUT if the SEV command timed out > + * -%EIO if the SEV returned a non-zero return code > + */ > +int sev_platform_shutdown(int *error); > + > +/** > + * sev_platform_status - perform SEV PLATFORM_STATUS command > + * > + * @status: sev_user_data_status structure to be processed > + * @error: SEV command return code > + * > + * Returns: > + * 0 if the SEV successfully processed the command > + * -%ENODEV if the SEV device is not available > + * -%ENOTSUPP if the SEV does not support SEV > + * -%ETIMEDOUT if the SEV command timed out > + * -%EIO if the SEV returned a non-zero return code > + */ > +int sev_platform_status(struct sev_user_data_status *status, int *error); > + > +/** > + * sev_issue_cmd_external_user - issue SEV command by other driver with a file > + * handle. > + * > + * This function can be used by other drivers to issue a SEV command on > + * behalf of userspace. The caller must pass a valid SEV file descriptor > + * so that we know that it has access to SEV device. > + * > + * @filep - SEV device file pointer > + * @cmd - command to issue > + * @data - command buffer > + * @error: SEV command return code > + * > + * Returns: > + * 0 if the SEV successfully processed the command > + * -%ENODEV if the SEV device is not available > + * -%ENOTSUPP if the SEV does not support SEV > + * -%ETIMEDOUT if the SEV command timed out > + * -%EIO if the SEV returned a non-zero return code > + * -%EINVAL if the SEV file descriptor is not valid > + */ > +int sev_issue_cmd_external_user(struct file *filep, unsigned int id, > + void *data, int *error); > + > +/** > + * sev_guest_deactivate - perform SEV DEACTIVATE command > + * > + * @deactivate: sev_data_deactivate structure to be processed > + * @sev_ret: sev command return code > + * > + * Returns: > + * 0 if the sev successfully processed the command > + * -%ENODEV if the sev device is not available > + * -%ENOTSUPP if the sev does not support SEV > + * -%ETIMEDOUT if the sev command timed out > + * -%EIO if the sev returned a non-zero return code > + */ > +int sev_guest_deactivate(struct sev_data_deactivate *data, int *error); > + > +/** > + * sev_guest_activate - perform SEV ACTIVATE command > + * > + * @activate: sev_data_activate structure to be processed > + * @sev_ret: sev command return code > + * > + * Returns: > + * 0 if the sev successfully processed the command > + * -%ENODEV if the sev device is not available > + * -%ENOTSUPP if the sev does not support SEV > + * -%ETIMEDOUT if the sev command timed out > + * -%EIO if the sev returned a non-zero return code > + */ > +int sev_guest_activate(struct sev_data_activate *data, int *error); > + > +/** > + * sev_guest_df_flush - perform SEV DF_FLUSH command > + * > + * @sev_ret: sev command return code > + * > + * Returns: > + * 0 if the sev successfully processed the command > + * -%ENODEV if the sev device is not available > + * -%ENOTSUPP if the sev does not support SEV > + * -%ETIMEDOUT if the sev command timed out > + * -%EIO if the sev returned a non-zero return code > + */ > +int sev_guest_df_flush(int *error); > + > +/** > + * sev_guest_decommission - perform SEV DECOMMISSION command > + * > + * @decommission: sev_data_decommission structure to be processed > + * @sev_ret: sev command return code > + * > + * Returns: > + * 0 if the sev successfully processed the command > + * -%ENODEV if the sev device is not available > + * -%ENOTSUPP if the sev does not support SEV > + * -%ETIMEDOUT if the sev command timed out > + * -%EIO if the sev returned a non-zero return code > + */ > +int sev_guest_decommission(struct sev_data_decommission *data, int *error); > + > +#else /* !CONFIG_CRYPTO_DEV_SP_PSP */ > + > +static inline int > +sev_platform_status(struct sev_user_data_status *status, int *error) { return -ENODEV; } > + > +static inline int > +sev_platform_init(struct sev_data_init *init, int *error) { return -ENODEV; } > + > +static inline int sev_platform_shutdown(int *error) { return -ENODEV; } > + > +static inline int > +sev_guest_deactivate(struct sev_data_deactivate *data, int *error) { return -ENODEV; } > + > +static inline int > +sev_guest_decommission(struct sev_data_decommission *data, int *error) { return -ENODEV; } > + > +static inline int > +sev_guest_activate(struct sev_data_activate *data, int *error) { return -ENODEV; } > + > +static inline int sev_guest_df_flush(int *error) { return -ENODEV; } > + > +static inline int > +sev_issue_cmd_external_user(struct file *filep, > + unsigned int id, void *data, int *error) > +{ > + return -ENODEV; > +} > + > +#endif /* CONFIG_CRYPTO_DEV_SP_PSP */ > + > #endif /* __PSP_SEV_H__ */