From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from NAM10-BN7-obe.outbound.protection.outlook.com (NAM10-BN7-obe.outbound.protection.outlook.com [40.107.92.61]) by mx.groups.io with SMTP id smtpd.web11.1675.1580857385855360254 for ; Tue, 04 Feb 2020 15:03:06 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@amdcloud.onmicrosoft.com header.s=selector2-amdcloud-onmicrosoft-com header.b=URE/P4iE; spf=none, err=SPF record not found (domain: amd.com, ip: 40.107.92.61, mailfrom: thomas.lendacky@amd.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=RLOOmaoGHBN8l6MyRXanWbNgN6uzJdb2DmL9WrPBtmJXEz2hUw170U7LtVA8qiP21PORdvw3dweGI0/Z6tyvKkA4KbqMF5Z5xnbKX5l4ZX6+Ox+kZHAPiWfCl5m01oex9v0ZtD+wS8hhs1diponm9+9u1/2sZ1Qszv6awbiKlHENu18ufc0QzDWJS9lSocwVF+KJh0DOLrBSTs8YPweZXFHvPVuRRePB3pMHiEsWAZEyro3i1YrvZvP0P3katDrwAs4bSfi90IBCwy+Bbjdn86QRm6i0tViyWx+hykkqe7QEMKvi/fC2gr+YqlKd9yP4aPB5x1pk7OS9SGGDGh6doA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=nGiLjub4Kcd3bv+BZa5LhJ1SpytHwE/xhHEJdf9iMkk=; b=SfnI+mmzVf7girm5TsQSYBm6gmCV1/Z9mm7gmr+FM+aAfsJmn3lr68VguBJV3PJ75vpFR09fQ0+10Omk3V/6mSPFLOKF2vLYiDxZagMRHcYeoKJzh1H9dmgfc5cOitRKyVKalr8DPqKYcl003g1H0ogXxhszLZT0EMoj2PBTW4x6o+ryyFY8Xb1P0iBqo4St8vH+U97aMhVjF9qtriWJyvYysBwlqslr1pUNwS7m2ZdJFG9LK7xoBljT3wIW48Aj1N/Gmir2jc+jo3/4Z6jx3AMzP6bto4G91eti9YhkreEUunKdQPMpqG9BiPDWYlu0qwIFTl0M5Lv1BU74mW/VoQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amdcloud.onmicrosoft.com; s=selector2-amdcloud-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=nGiLjub4Kcd3bv+BZa5LhJ1SpytHwE/xhHEJdf9iMkk=; b=URE/P4iEiBTL2DqQy3ggg+yyP8Yp8DsYDoeGW7wShTE9creFNvsm9W77NBbGjKa9h8zQVb8L9NFQpHC9kcfJz3nyyHbRHdo9uFxD6QggIs6sQ0gSQHtBvKvHZ/2Kc+RNwa/SQTbzSgGSEOhJWoW/uAoqmlXKfLV8YuDmxmmFQ7U= Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Thomas.Lendacky@amd.com; Received: from DM6PR12MB3163.namprd12.prod.outlook.com (20.179.71.154) by DM6PR12MB3930.namprd12.prod.outlook.com (10.255.174.19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2686.29; Tue, 4 Feb 2020 23:03:04 +0000 Received: from DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::a0cd:463:f444:c270]) by DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::a0cd:463:f444:c270%7]) with mapi id 15.20.2707.020; Tue, 4 Feb 2020 23:03:04 +0000 From: "Lendacky, Thomas" To: devel@edk2.groups.io Cc: Jordan Justen , Laszlo Ersek , Ard Biesheuvel , Michael D Kinney , Liming Gao , Eric Dong , Ray Ni , Brijesh Singh Subject: [PATCH v4 30/40] OvmfPkg: Reserve a page in memory for the SEV-ES usage Date: Tue, 4 Feb 2020 17:01:34 -0600 Message-Id: <0e6bf397c276117bfca51f574870a4927c05c173.1580857303.git.thomas.lendacky@amd.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: References: X-ClientProxiedBy: SN6PR16CA0062.namprd16.prod.outlook.com (2603:10b6:805:ca::39) To DM6PR12MB3163.namprd12.prod.outlook.com (2603:10b6:5:15e::26) Return-Path: thomas.lendacky@amd.com MIME-Version: 1.0 Received: from tlendack-t1.amd.com (165.204.77.1) by SN6PR16CA0062.namprd16.prod.outlook.com (2603:10b6:805:ca::39) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2686.32 via Frontend Transport; Tue, 4 Feb 2020 23:02:33 +0000 X-Mailer: git-send-email 2.17.1 X-Originating-IP: [165.204.77.1] X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-HT: Tenant X-MS-Office365-Filtering-Correlation-Id: c4eec5ac-1183-4bab-eb6e-08d7a9c6520a X-MS-TrafficTypeDiagnostic: DM6PR12MB3930:|DM6PR12MB3930: X-MS-Exchange-Transport-Forked: True X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:8882; X-Forefront-PRVS: 03030B9493 X-Forefront-Antispam-Report: SFV:NSPM;SFS:(10009020)(4636009)(39860400002)(366004)(376002)(136003)(396003)(346002)(199004)(189003)(4326008)(478600001)(6916009)(81156014)(2616005)(956004)(81166006)(8676002)(966005)(316002)(54906003)(19627235002)(2906002)(6486002)(66476007)(66556008)(52116002)(7696005)(186003)(26005)(16526019)(5660300002)(86362001)(36756003)(66946007)(8936002);DIR:OUT;SFP:1101;SCL:1;SRVR:DM6PR12MB3930;H:DM6PR12MB3163.namprd12.prod.outlook.com;FPR:;SPF:None;LANG:en;PTR:InfoNoRecords;A:1;MX:1; Received-SPF: None (protection.outlook.com: amd.com does not designate permitted sender hosts) X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: /3Q7U1LsOGhXOM8JLdbFLqNqFpXSwTPkKARwvIY9E2P027DFoxqEfnnRvt9DDVny4QTA6pgM9160xDjqGKN7H/7cRG3qQF80igMruG0lGseMv5eB+qpJf5v8mR24TStyJ8fvad4zio6EZDWN2GnH/BKPV4C81oX3jHfPrGPr5FQsT+jgk8EVoXrNzUhRRblerg/MEdJN2sjE7+eBXuxqm3ICHpWik039YVzfAA1TSUPF2CuLXpOLOX42JW6JVtGKRPwZczzeGSvS2x+ieFT0Mf7fY86GoDx2gPJSK+QtZdcej+rMlo8dgNZ7/0bSahL0G2fRNlRZxS59fUirVqffa6LwvBxlcDqjhD+77cAsFnDX8jMbDX07PwX3mvis0q3UZE4uQZ1jiD2PiGdZWIrcYNRBbBzs4iiSpm0XjFvXPl/6F/2zWTMKLPvdlJZXSh6pozYKJLOeI6q908ODZYm43R9kMkkzGAh99lxaIb0kttHzgeiKBmwdOk0OTUEdDcKmVN9Vn5et5Z4A7Yp/MUKL0A== X-MS-Exchange-AntiSpam-MessageData: lueP1raoaZOxaz6RF4SyZv5TRAZGUuCOlVvnb2CFR+T7VPrbh0sfqBeFdCEHI5uuP4wQI2mIZbxQ++hWrigWLOXOkjecVUOic0+fPL5lLWQ8qtbzI1qu94ukXdNx47jv1XtSFEtaKuDreR79lg4xSw== X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: c4eec5ac-1183-4bab-eb6e-08d7a9c6520a X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Feb 2020 23:02:34.3879 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: ONP917vjW51TLO7NBMaT1PHmFMzy0+qXPfJ+RUkkfqr7kWvWrz8/USStwjzYmPtmOt8vBninO7ZHbrbSSuotCA== X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR12MB3930 Content-Type: text/plain BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=2198 Reserve a fixed area of memory for SEV-ES use and set a fixed PCD, PcdSevEsWorkAreaBase, to this value. This area will be used by SEV-ES support for two purposes: 1. Communicating the SEV-ES status during BSP boot to SEC: Using a byte of memory from the page, the BSP reset vector code can communicate the SEV-ES status to SEC for use before exception handling can be enabled in SEC. After SEC, this field is no longer valid and the standard way of determine if SEV-ES is active should be used. 2. Establishing an area of memory for AP boot support: A hypervisor is not allowed to update an SEV-ES guest's register state, so when booting an SEV-ES guest AP, the hypervisor is not allowed to set the RIP to the guest requested value. Instead an SEV-ES AP must be re-directed from within the guest to the actual requested staring location as specified in the INIT-SIPI-SIPI sequence. Use this memory for reset vector code that can be programmed to have the AP jump to the desired RIP location after starting the AP. This is required for only the very first AP reset. Cc: Jordan Justen Cc: Laszlo Ersek Cc: Ard Biesheuvel Signed-off-by: Tom Lendacky --- OvmfPkg/OvmfPkgX64.fdf | 3 +++ 1 file changed, 3 insertions(+) diff --git a/OvmfPkg/OvmfPkgX64.fdf b/OvmfPkg/OvmfPkgX64.fdf index f541481dc95c..3504aa35dc37 100644 --- a/OvmfPkg/OvmfPkgX64.fdf +++ b/OvmfPkg/OvmfPkgX64.fdf @@ -82,6 +82,9 @@ [FD.MEMFD] 0x009000|0x002000 gUefiCpuPkgTokenSpaceGuid.PcdSecGhcbBase|gUefiCpuPkgTokenSpaceGuid.PcdSecGhcbSize +0x00B000|0x001000 +gUefiCpuPkgTokenSpaceGuid.PcdSevEsWorkAreaBase|gUefiCpuPkgTokenSpaceGuid.PcdSevEsWorkAreaSize + 0x010000|0x010000 gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecPeiTempRamBase|gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecPeiTempRamSize -- 2.17.1