mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Nikunj A. Dadhania" <nikunj@amd.com>
To: Peter Gonda <pgonda@google.com>
Cc: linux-kernel@vger.kernel.org, x86@kernel.org, bp@alien8.de,
	thomas.lendacky@amd.com, dionnaglaze@google.com,
	seanjc@google.com, pbonzini@redhat.com, michael.roth@amd.com,
	ketanch@iitk.ac.in
Subject: Re: [PATCH v2 08/11] x86/sev: Add Secure TSC support for SNP guests
Date: Fri, 14 Apr 2023 10:40:54 +0530	[thread overview]
Message-ID: <e99be091-8671-0ffd-ee87-1952d8302e43@amd.com> (raw)
In-Reply-To: <CAMkAt6rqsg6=Sx6Fqnf7KNOUB9YPMU6TUriZYZXbXQTvcoKzNw@mail.gmail.com>

On 4/10/2023 10:44 PM, Peter Gonda wrote:
>> +
>>  /* #VC handler runtime per-CPU data */
>>  struct sev_es_runtime_data {
>>         struct ghcb ghcb_page;
>> @@ -1107,7 +1111,7 @@ static void *alloc_shared_pages(size_t sz)
>>         return page_address(page);
>>  }
>>
>> -static int snp_setup_psp_messaging(struct sev_guest_platform_data *pdata)
>> +static int __init snp_setup_psp_messaging(struct sev_guest_platform_data *pdata)
>>  {
>>         u64 gpa;
>>         int ret;
>> @@ -1406,6 +1410,80 @@ bool snp_assign_vmpck(struct snp_guest_dev *dev, int vmpck_id)
>>  }
>>  EXPORT_SYMBOL_GPL(snp_assign_vmpck);
>>
>> +static int __init snp_get_tsc_info(void)
>> +{
>> +       u8 buf[SNP_TSC_INFO_REQ_SZ + AUTHTAG_LEN];
>> +       struct snp_tsc_info_resp tsc_resp = {0};
>> +       struct snp_tsc_info_req tsc_req;
>> +       struct snp_guest_req req;
>> +       struct snp_guest_dev dev;
>> +       int rc, resp_len;
>> +
>> +       /*
>> +        * The intermediate response buffer is used while decrypting the
>> +        * response payload. Make sure that it has enough space to cover the
>> +        * authtag.
>> +        */
>> +       resp_len = sizeof(tsc_resp) + AUTHTAG_LEN;
>> +       if (sizeof(buf) < resp_len)
>> +               return -EINVAL;
>> +
>> +       /* Zero the tsc_info_req */
>> +       memzero_explicit(&tsc_req, sizeof(tsc_req));
>> +       memzero_explicit(&req, sizeof(req));
> 
> Whats the guidance on when we should use memzero_explicit() vs just
> something like: `snp_tsc_info_resp tsc_resp = {0};`?

Going over the history of memzero_explicit, it seems it was introduce to 
explicitly zero sensitive information before the variable goes out of scope. 
GCC was optimizing out the memset in these cases:

d4c5efdb9777 ("random: add and use memzero_explicit() for clearing data")

https://bugzilla.kernel.org/show_bug.cgi?id=82041

With the above detail, IMHO, we do not need the memzero_explicit() for both case.

> 
>> +
>> +       dev.pdata = platform_data;
>> +       if (!snp_assign_vmpck(&dev, 0))
>> +               return -EINVAL;
>> +
>> +       req.msg_version = MSG_HDR_VER;
>> +       req.msg_type = SNP_MSG_TSC_INFO_REQ;
>> +       req.req_buf = &tsc_req;
>> +       req.req_sz = sizeof(tsc_req);
>> +       req.resp_buf = buf;
>> +       req.resp_sz = resp_len;
>> +       req.fw_err = NULL;
> 
> Why do we not want the FW error code?

I will add the FW error code.

Regards
Nikunj


  reply	other threads:[~2023-04-14  5:11 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-03-26 14:46 [PATCH v2 00/11] " Nikunj A Dadhania
2023-03-26 14:46 ` [PATCH v2 01/11] virt: sev-guest: Use AES GCM crypto library Nikunj A Dadhania
2023-04-03 19:09   ` Tom Lendacky
2023-04-05  5:10     ` Nikunj A. Dadhania
2023-03-26 14:46 ` [PATCH v2 02/11] virt: sev-guest: Move mutex to SNP guest device structure Nikunj A Dadhania
2023-04-03 19:13   ` Tom Lendacky
2023-04-05  5:23     ` Nikunj A. Dadhania
2023-03-26 14:46 ` [PATCH v2 03/11] virt: sev-guest: Add snp_guest_req structure Nikunj A Dadhania
2023-04-03 19:59   ` Tom Lendacky
2023-04-05  5:31     ` Nikunj A. Dadhania
2023-03-26 14:46 ` [PATCH v2 04/11] virt: sev-guest: Add simplified helper to assign vmpck Nikunj A Dadhania
2023-04-03 20:26   ` Tom Lendacky
2023-04-05  6:18     ` Nikunj A. Dadhania
2023-04-10 16:31   ` Peter Gonda
2023-04-14  4:51     ` Nikunj A. Dadhania
2023-03-26 14:46 ` [PATCH v2 05/11] x86/sev: Move and reorganize sev guest request api Nikunj A Dadhania
2023-04-03 21:01   ` Tom Lendacky
2023-04-05  7:11     ` Nikunj A. Dadhania
2023-03-26 14:46 ` [PATCH v2 06/11] x86/mm: Add generic guest initialization hook Nikunj A Dadhania
2023-03-26 14:46 ` [PATCH v2 07/11] x86/sev: Change TSC MSR behavior for Secure TSC enabled guests Nikunj A Dadhania
2023-04-03 21:15   ` Tom Lendacky
2023-03-26 14:46 ` [PATCH v2 08/11] x86/sev: Add Secure TSC support for SNP guests Nikunj A Dadhania
2023-04-03 21:41   ` Tom Lendacky
2023-04-05  7:37     ` Nikunj A. Dadhania
2023-04-05 13:24       ` Tom Lendacky
2023-04-05 14:37         ` Nikunj A. Dadhania
2023-04-10 17:14   ` Peter Gonda
2023-04-14  5:10     ` Nikunj A. Dadhania [this message]
2023-03-26 14:46 ` [PATCH v2 09/11] x86/kvmclock: Use Secure TSC as clock if available Nikunj A Dadhania
2023-04-03 21:45   ` Tom Lendacky
2023-04-05  8:16     ` Nikunj A. Dadhania
2023-03-26 14:47 ` [PATCH v2 10/11] x86/tsc: Mark Secure TSC as reliable clocksource Nikunj A Dadhania
2023-03-26 14:47 ` [PATCH v2 11/11] x86/sev: Enable Secure TSC for SNP guests Nikunj A Dadhania

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=e99be091-8671-0ffd-ee87-1952d8302e43@amd.com \
    --to=nikunj@amd.com \
    --cc=bp@alien8.de \
    --cc=dionnaglaze@google.com \
    --cc=ketanch@iitk.ac.in \
    --cc=linux-kernel@vger.kernel.org \
    --cc=michael.roth@amd.com \
    --cc=pbonzini@redhat.com \
    --cc=pgonda@google.com \
    --cc=seanjc@google.com \
    --cc=thomas.lendacky@amd.com \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®