From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from NAM10-DM6-obe.outbound.protection.outlook.com (NAM10-DM6-obe.outbound.protection.outlook.com [40.107.93.75]) by mx.groups.io with SMTP id smtpd.web09.6449.1581089393985759648 for ; Fri, 07 Feb 2020 07:29:54 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@amdcloud.onmicrosoft.com header.s=selector2-amdcloud-onmicrosoft-com header.b=qOVvm2qW; spf=none, err=SPF record not found (domain: amd.com, ip: 40.107.93.75, mailfrom: thomas.lendacky@amd.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=PNhkpD4BnEsz+Hy3PKQ3DtQ5GggeFe+gh67ywOWAJZeaDjVaX6kXHXAxtM8nkaPi1vETp/O16hbsvfAdJQLw7Y939PRxhcpTc9CCuGsrH88Wa3Dwv364hNn90LWg0D6l09Hs7IMX9hb/vP3b3JMBGPpolg3qNOAtmwEspT+LPTGNUNyP7N7WNN2N2HjkXpswkiwi/FSU8X1Eorg23db+wNGJsvPzrzJUAc5szcjU3mVQqTiqSvBwzJ1gUDIqAiLk4C3awTf2gupaOnR+a2yOsGL5xCs/UQuJmf0GrXJwfxY2ttdSSP8AyMpC2n24rUcvKi6FGa9Cuzx/3E8CJtziTQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Glu4jHX0gOTFGbwxocR1NPKNU6WZ1Kty1MoZrVokrI4=; b=XedsBcQs4CpQeweZNyFi14NjoNP+hNystMvU3n4QBq+huu76I+mD/tOdyXJk7PYBOB0Mz6gLA2TjbMRcAPkLKEvzudbhZta8GFqazf+s2xAyUI95U7+WR+FhW+0qd0TmR+Vq7GESnf37hqhYyQh15IccF4YamHw1eZPnxHoG+65krAUz4h0I4VeNRuV+xghy9pccn0cZkxDjiMOhKyKzRtx0iUEl2vF+j85JBJWJcVRDQm6k5VSKwuXHl+BKN/BjmttmMwgQ2fqDk87onxObkCQPzKBYedAaWgMJ8gMTBGMPytFrlBSb32P7HjKtaLF1oQgpUiZyMUiBOjIyw5Bctw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amdcloud.onmicrosoft.com; s=selector2-amdcloud-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Glu4jHX0gOTFGbwxocR1NPKNU6WZ1Kty1MoZrVokrI4=; b=qOVvm2qW/elv+q3l4R1DN0WS0KZ37ENuV+iHeJ+McffXAGtZn4ea7SsFKkHzMOkg+YfY+tfRnhTkrObk4woUOejXKqo6Sv2+pUpTNeUjVLBARVR0pOzHxFhNCiSWP0587gzxM0Clcs1772FhXPAvnj5o0Ws7DzBnIs6Sn+JeSbI= Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Thomas.Lendacky@amd.com; Received: from DM6PR12MB3163.namprd12.prod.outlook.com (20.179.71.154) by DM6PR12MB3722.namprd12.prod.outlook.com (10.255.172.152) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2686.29; Fri, 7 Feb 2020 15:29:52 +0000 Received: from DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::a0cd:463:f444:c270]) by DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::a0cd:463:f444:c270%7]) with mapi id 15.20.2707.024; Fri, 7 Feb 2020 15:29:52 +0000 Subject: Re: [edk2-devel] [PATCH v4 23/40] OvmfPkg/MemEncryptSevLib: Add an SEV-ES guest indicator function To: devel@edk2.groups.io, lersek@redhat.com Cc: Jordan Justen , Ard Biesheuvel , Michael D Kinney , Liming Gao , Eric Dong , Ray Ni , Brijesh Singh References: <72fe7b157cad7782b81be256f7396aeb32fb04c5.1580857303.git.thomas.lendacky@amd.com> From: "Lendacky, Thomas" Message-ID: <15277aea-1aa0-2619-3aab-521cd4fff443@amd.com> Date: Fri, 7 Feb 2020 09:29:50 -0600 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.4.1 In-Reply-To: X-ClientProxiedBy: SN6PR2101CA0010.namprd21.prod.outlook.com (2603:10b6:805:106::20) To DM6PR12MB3163.namprd12.prod.outlook.com (2603:10b6:5:15e::26) Return-Path: thomas.lendacky@amd.com MIME-Version: 1.0 Received: from [10.236.30.74] (165.204.77.1) by SN6PR2101CA0010.namprd21.prod.outlook.com (2603:10b6:805:106::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2729.6 via Frontend Transport; Fri, 7 Feb 2020 15:29:52 +0000 X-Originating-IP: [165.204.77.1] X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-HT: Tenant X-MS-Office365-Filtering-Correlation-Id: f923027c-cb41-479b-d44d-08d7abe293bd X-MS-TrafficTypeDiagnostic: DM6PR12MB3722:|DM6PR12MB3722: X-MS-Exchange-Transport-Forked: True X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:7691; X-Forefront-PRVS: 0306EE2ED4 X-Forefront-Antispam-Report: SFV:NSPM;SFS:(10009020)(4636009)(366004)(346002)(376002)(39860400002)(136003)(396003)(189003)(199004)(316002)(5660300002)(8936002)(2906002)(31686004)(81156014)(81166006)(8676002)(86362001)(31696002)(66946007)(53546011)(4326008)(66476007)(66556008)(36756003)(6486002)(966005)(45080400002)(16576012)(16526019)(186003)(478600001)(52116002)(26005)(2616005)(956004)(54906003);DIR:OUT;SFP:1101;SCL:1;SRVR:DM6PR12MB3722;H:DM6PR12MB3163.namprd12.prod.outlook.com;FPR:;SPF:None;LANG:en;PTR:InfoNoRecords;MX:1;A:1; Received-SPF: None (protection.outlook.com: amd.com does not designate permitted sender hosts) X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: O7arb0qWx5MMSjhj4XvJsBSEAFe7Ntd/l7tmwabKl75VJuUNs5XtAiwkXEhx/WGXNclSw2ojIPdaHNaCpDpQVT7nTZrap8pW2xIdaU83Tj2ZSxnZidXrNWoow0SorxFwFuvXqSxZOYsanYTIFHydRCPbMISRvDuAoaFg5vpYdoxGiKwCKUgApoCjbnN6CkR5CayW+gJ8aXVe9cgt9gdZuNjD/s7XMMNzLsDUjeXYadUl5AXQuuyNsIBfBI6y23PNY2q4ldsItBPr5e6L7YfLNYQdMd1+s6tuQKug0/njh70lyuM3c5OqgEEwNAhzxrsMoGy11VXIlBobFf5Ywjh50lfIjexU38U6uQmsMqmN3rjFvDybpIhgVJby5ia7gZHCsVvSAhIr7NVnh1L9Qpr3o7toAY00SoD0Efz99hfrdwo7I35sXSgUPANVR2v2W8JZqrGs+qVs/9Eyw73E/5W6l7zWsY8e+ylQcFgt3wSqIUe2scgwc1/npqp/Ms0JxzIOFQzYS8mlw2jKvgMCb4Wxeg== X-MS-Exchange-AntiSpam-MessageData: BCrZVdBhBkMYu0Lh2LwXJ2FnsIac32ht9I4M1T/6Ovy9kLid0zju0iOPHx3bSCYLtCSWNiEk0RW6smDBM3cRcvDldDBHX5vO2z3HRVYS/4UHwq/kT8HRmdysvv5NeeAPEumde7bXt3d5N+pH/qZlFw== X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: f923027c-cb41-479b-d44d-08d7abe293bd X-MS-Exchange-CrossTenant-OriginalArrivalTime: 07 Feb 2020 15:29:52.7483 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: /viY4L6eqg8bXTKCHzoDQo83UQ/SaTD+VVIu2PZU3j5qNlinwOiwbrlkkvFjXCA6CfFA3MLvksB6+68RNN5qaw== X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR12MB3722 Content-Type: text/plain; charset=windows-1252 Content-Language: en-US Content-Transfer-Encoding: 7bit On 2/6/20 2:21 AM, Laszlo Ersek via Groups.Io wrote: > Hi Tom, > > On 02/05/20 00:01, Lendacky, Thomas wrote: >> BZ: https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fbugzilla.tianocore.org%2Fshow_bug.cgi%3Fid%3D2198&data=02%7C01%7Cthomas.lendacky%40amd.com%7Ce2df7232720d4a15b38208d7aadd8f51%7C3dd8961fe4884e608e11a82d994e183d%7C0%7C0%7C637165740882485307&sdata=CIU4UwRsJzE6qjKOkQOaOrwuPUe1EerzpYZJXc4Phvc%3D&reserved=0 >> >> Create a function that can be used to determine if the VM is running >> as an SEV-ES guest. >> >> Cc: Jordan Justen >> Cc: Laszlo Ersek >> Cc: Ard Biesheuvel >> Reviewed-by: Laszlo Ersek >> Signed-off-by: Tom Lendacky >> --- >> OvmfPkg/Include/Library/MemEncryptSevLib.h | 12 +++ >> .../MemEncryptSevLibInternal.c | 75 ++++++++++++------- >> 2 files changed, 60 insertions(+), 27 deletions(-) >> >> diff --git a/OvmfPkg/Include/Library/MemEncryptSevLib.h b/OvmfPkg/Include/Library/MemEncryptSevLib.h >> index 64dd6977b0f8..a50a0de9c870 100644 >> --- a/OvmfPkg/Include/Library/MemEncryptSevLib.h >> +++ b/OvmfPkg/Include/Library/MemEncryptSevLib.h >> @@ -13,6 +13,18 @@ >> >> #include >> >> +/** >> + Returns a boolean to indicate whether SEV-ES is enabled >> + >> + @retval TRUE SEV-ES is enabled >> + @retval FALSE SEV-ES is not enabled >> +**/ >> +BOOLEAN >> +EFIAPI >> +MemEncryptSevEsIsEnabled ( >> + VOID >> + ); >> + >> /** >> Returns a boolean to indicate whether SEV is enabled >> >> diff --git a/OvmfPkg/Library/BaseMemEncryptSevLib/MemEncryptSevLibInternal.c b/OvmfPkg/Library/BaseMemEncryptSevLib/MemEncryptSevLibInternal.c >> index 96a66e373f11..c859bb141963 100644 >> --- a/OvmfPkg/Library/BaseMemEncryptSevLib/MemEncryptSevLibInternal.c >> +++ b/OvmfPkg/Library/BaseMemEncryptSevLib/MemEncryptSevLibInternal.c >> @@ -20,19 +20,17 @@ >> #include >> >> STATIC BOOLEAN mSevStatus = FALSE; >> +STATIC BOOLEAN mSevEsStatus = FALSE; >> STATIC BOOLEAN mSevStatusChecked = FALSE; >> >> /** >> >> - Returns a boolean to indicate whether SEV is enabled >> - >> - @retval TRUE SEV is enabled >> - @retval FALSE SEV is not enabled >> + Reads and sets the status of SEV features >> **/ >> STATIC >> -BOOLEAN >> +VOID >> EFIAPI >> -InternalMemEncryptSevIsEnabled ( >> +InternalMemEncryptSevStatus ( >> VOID >> ) >> { >> @@ -56,32 +54,55 @@ InternalMemEncryptSevIsEnabled ( >> // >> Msr.Uint32 = AsmReadMsr32 (MSR_SEV_STATUS); >> if (Msr.Bits.SevBit) { >> - return TRUE; >> + mSevStatus = TRUE; >> + } >> + >> + // >> + // Check MSR_0xC0010131 Bit 1 (Sev-Es Enabled) >> + // >> + if (Msr.Bits.SevEsBit) { > > In the previous version this was also gated by a check on > "Eax.Bits.SevEsBit". What's the reason for removing that check? > > Is it simply superfluous to rely on that output of the CPUID because the > MSR tells us anyway? IOW, > > - if "Eax.Bits.SevEsBit" is clear, then "Msr.Bits.SevEsBit" will always > be clear (i.e. "no support" implies "not enabled"), > > - if "Msr.Bits.SevEsBit" is set, then "Eax.Bits.SevEsBit" is always set > (i.e. "enabled" implies "supported")? Correct, it's not needed. The only reason for the check is to verify that the proper level of support is present so that the (non-interceptable) RDMSR of MSR 0xC0010131 can be safely issued. The MSR value indicates the SEV-ES support regardless of what is set in the CPUID function, so they are not tied together in that way. The MSR value is based on, among other things, the SEV/SEV-ES setting in the VMCB used for the VMRUN. The GHCB spec calls for the SEV bit to be set as an indication that there is SEV support before issuing the RDMSR (in case that CPUID function is used in the future by others for some reason). Thanks, Tom > > Thanks > Laszlo > >> + mSevEsStatus = TRUE; >> } >> } >> } >> >> - return FALSE; >> -} >> - >> -/** >> - Returns a boolean to indicate whether SEV is enabled >> - >> - @retval TRUE SEV is enabled >> - @retval FALSE SEV is not enabled >> -**/ >> -BOOLEAN >> -EFIAPI >> -MemEncryptSevIsEnabled ( >> - VOID >> - ) >> -{ >> - if (mSevStatusChecked) { >> - return mSevStatus; >> - } >> - >> - mSevStatus = InternalMemEncryptSevIsEnabled(); >> mSevStatusChecked = TRUE; >> +} >> + >> +/** >> + Returns a boolean to indicate whether SEV-ES is enabled >> + >> + @retval TRUE SEV-ES is enabled >> + @retval FALSE SEV-ES is not enabled >> +**/ >> +BOOLEAN >> +EFIAPI >> +MemEncryptSevEsIsEnabled ( >> + VOID >> + ) >> +{ >> + if (!mSevStatusChecked) { >> + InternalMemEncryptSevStatus(); >> + } >> + >> + return mSevEsStatus; >> +} >> + >> +/** >> + Returns a boolean to indicate whether SEV is enabled >> + >> + @retval TRUE SEV is enabled >> + @retval FALSE SEV is not enabled >> +**/ >> +BOOLEAN >> +EFIAPI >> +MemEncryptSevIsEnabled ( >> + VOID >> + ) >> +{ >> + if (!mSevStatusChecked) { >> + InternalMemEncryptSevStatus(); >> + } >> >> return mSevStatus; >> } >> > > > >