From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from NAM11-BN8-obe.outbound.protection.outlook.com (NAM11-BN8-obe.outbound.protection.outlook.com [40.107.236.40]) by mx.groups.io with SMTP id smtpd.web10.32749.1669862242038073726 for ; Wed, 30 Nov 2022 18:37:22 -0800 Authentication-Results: mx.groups.io; dkim=fail reason="body hash did not verify" header.i=@amd.com header.s=selector1 header.b=bzd8OM8Q; spf=permerror, err=parse error for token &{10 18 %{i}._ip.%{h}._ehlo.%{d}._spf.vali.email}: invalid domain name (domain: amd.com, ip: 40.107.236.40, mailfrom: alexey.kardashevskiy@amd.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=HfZ6eQMIPDkN37ygLL/4lpTQ9Lntdl96RGLnNUnGng9kO9gbIGa0tx3Vk7eg1kd59mth6kqBcwkXLsHxQPnH41TQf8cmGOAvN0N+mjD63cyMJezqiC0B9FcewcPvA0LJbyqrCac8FpNSjl0O2yp2RaW6Xwhl57Zfi8IWjtHnJGS9izPPe7Nxhyau34i8c22aL59OcEGYXciKBCUpa9WRUPmL2pQFeE5kXd4KRTnIq3uYLAcWBul+fjkXgBy9amC7+ce1oepxVZ59W9AqqUEVMeybeDH9bmTAsuO0CWgeJCPRROioZbEdALVgu2p2D4Q/P1sXcxkOwsoD/eX1EWgEwA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=8sfxmFi8q4ThKLJJwUWNTI/X9SQJnBKPzxpjvN/y2AY=; b=PBvNH01ABb3xcDctVj96ldC0Mn5VtV3KNEbpgraiBbWsEKeZthM+qrQBCxNPnHlu6Wr6V8O2Tg7k3axACO9n4IQvqPooTWDRi5ertOAmGwOZOlhTzZPmiz5PMJmIUjG14eIRn8qIaJTiuG09UK5G/snqg3pWEft3b05PkF+klCxFCTITwNhSLmce1Tdakb3Y7fYBRzKBcal02IeW56cOwduQgMibCSvWhERxTZYa73WjNvhwFteXpVhCR0wb6KFYAXIXqpfOn1/CF/KgPP7QIcFkqGh3nnNNcl//4y7//I601pdI5P2DGWeT8DGNOwvFwEJxJ5+7+2/h4zg6AP835g== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=edk2.groups.io smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8sfxmFi8q4ThKLJJwUWNTI/X9SQJnBKPzxpjvN/y2AY=; b=bzd8OM8QJDfrB6ax16QjU6FPLBYm3ntnPg0K9MMsWnmuIw1/aZRXwUVdKzTpJsP01PeLpf8cXezF3zK0jM69/BSKV4BSmZmYlrTc7Rj6hGUHlzqfQAOauy5BbmJBUgJW/Nq8yfxQx/YvwKbvTvuxi7ajjIFT96LyUb3ubu/BRjU= Received: from DM6PR06CA0018.namprd06.prod.outlook.com (2603:10b6:5:120::31) by BY5PR12MB4274.namprd12.prod.outlook.com (2603:10b6:a03:206::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5857.23; Thu, 1 Dec 2022 02:37:19 +0000 Received: from DS1PEPF0000B078.namprd05.prod.outlook.com (2603:10b6:5:120:cafe::fd) by DM6PR06CA0018.outlook.office365.com (2603:10b6:5:120::31) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5857.23 via Frontend Transport; Thu, 1 Dec 2022 02:37:18 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 165.204.84.17) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=amd.com; Received-SPF: Pass (protection.outlook.com: domain of amd.com designates 165.204.84.17 as permitted sender) receiver=protection.outlook.com; client-ip=165.204.84.17; helo=SATLEXMB04.amd.com; pr=C Received: from SATLEXMB04.amd.com (165.204.84.17) by DS1PEPF0000B078.mail.protection.outlook.com (10.167.17.9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.20.5880.8 via Frontend Transport; Thu, 1 Dec 2022 02:37:18 +0000 Received: from aiemdeew.1.ozlabs.ru (10.180.168.240) by SATLEXMB04.amd.com (10.181.40.145) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2375.34; Wed, 30 Nov 2022 20:37:13 -0600 From: "Alexey Kardashevskiy" To: CC: Ard Biesheuvel , Jiewen Yao , Jordan Justen , "Gerd Hoffmann" , Brijesh Singh , "Erdem Aktas" , James Bottomley , Min Xu , Tom Lendacky , "Alexey Kardashevskiy" Subject: [PATCH ovmf 3/5] OvmfPkg: Add AMD SEV-ES DebugSwap feature support Date: Thu, 1 Dec 2022 13:35:19 +1100 Message-ID: <20221201023521.10028-4-aik@amd.com> X-Mailer: git-send-email 2.38.1 In-Reply-To: <20221201023521.10028-1-aik@amd.com> References: <20221201023521.10028-1-aik@amd.com> MIME-Version: 1.0 Return-Path: Alexey.Kardashevskiy@amd.com X-Originating-IP: [10.180.168.240] X-ClientProxiedBy: SATLEXMB04.amd.com (10.181.40.145) To SATLEXMB04.amd.com (10.181.40.145) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DS1PEPF0000B078:EE_|BY5PR12MB4274:EE_ X-MS-Office365-Filtering-Correlation-Id: 2547e020-6137-474f-eec7-08dad344f768 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: 1tLZkjNApDOD4HAv/Q9K2KrGOD3Ha19aug0RBCeMIs//sU4++ZkmoIk7W2IZR2omCKUzvvFM1eH7eb4wuY+HuqVaMAh+uBTwQYxJSWXr0VvPVy8gE0FXF2OJxDh7+8MnlyRoBVr59o8Xak5Tt+dYQ+Zrm5KXxwt1HtClsCy1wKfNLn6w4Q+dbj3syTxSeQgCIoWM9/5ITDy+/2Sqn4ANiErqjB5HD84tRB7Be/5kALzbtDZGMq5VDdz8v4eE7JYqaiL7DGg2WkuH1aa03kK1xq1PSxFhzj41+X7e4JWvFviwDYPNL08B4UiVnayHOq5Qp4DaWxoiyHrpkWXwnLI6rLwo5r7sUMpsSLwoxSkDFphDjbZ/e1KlKsLTEdET9VsgAuZpu5bXpfmglGnjrEJlmbfUFe8oktuY6Wp3glMUt4oMfnrq8HTKwIUSuW/DCp4IHCU9vYbBqwaw7xyyEGGJVgXzWp0uYyUhol1yGRiS6PL/yanQ9Vl/aDr0xcTdS0i7uwkem+7R5dm8/pnQLyRT4wuq7vQz9MvIZRj/OalCb1OM81t69jB9rDqbV8OYxOJ+Cc7Jjw19XNsydmqOZj/q/HUzXt+RAJ9igNfBoAh7YTH/GzQ3FDVGqNqYxVKQ448ziO7/XCP69nuLrZlUGns7XxHuKrahR28CWcF7W/Y6OCRBuTQHXYinjtZrVzNal7MCDFgpshCMDgRJsBqlAUcTcXdGIOYfX+a4JcJqe988WVA= X-Forefront-Antispam-Report: CIP:165.204.84.17;CTRY:US;LANG:en;SCL:1;SRV:;IPV:CAL;SFV:NSPM;H:SATLEXMB04.amd.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230022)(4636009)(376002)(39860400002)(136003)(346002)(396003)(451199015)(46966006)(40470700004)(36840700001)(426003)(336012)(47076005)(83380400001)(40460700003)(6916009)(54906003)(82310400005)(356005)(40480700001)(81166007)(26005)(36756003)(82740400003)(1076003)(2616005)(8676002)(36860700001)(16526019)(186003)(5660300002)(70206006)(478600001)(41300700001)(4326008)(8936002)(316002)(70586007)(2906002)(36900700001);DIR:OUT;SFP:1101; X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 01 Dec 2022 02:37:18.7651 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 2547e020-6137-474f-eec7-08dad344f768 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[165.204.84.17];Helo=[SATLEXMB04.amd.com] X-MS-Exchange-CrossTenant-AuthSource: DS1PEPF0000B078.namprd05.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY5PR12MB4274 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain The SEV-ES DebugSwap feature enables type B swaping of debug registers on #VMEXIT and makes #DB and DR7 intercepts unnecessary and unwanted. When DebugSwap is enabled, this stops booting if #VC for #DB or DB7 read/write occurs as this signals unwanted interaction from the HV. This adds new API which uses SEV-ES working area in PEI and SEC. This does not change the existing behavour for DXE just yet but soon. Signed-off-by: Alexey Kardashevskiy --- OvmfPkg/Include/Library/MemEncryptSevLib.h | 12 ++= ++++++++ OvmfPkg/Library/BaseMemEncryptSevLib/DxeMemEncryptSevLibInternal.c | 25 ++= +++++++++++++++--- OvmfPkg/Library/BaseMemEncryptSevLib/PeiMemEncryptSevLibInternal.c | 19 ++= +++++++++++++ OvmfPkg/Library/BaseMemEncryptSevLib/SecMemEncryptSevLibInternal.c | 20 ++= ++++++++++++++ OvmfPkg/Library/CcExitLib/CcExitVcHandler.c | 8 ++= +++++ 5 files changed, 81 insertions(+), 3 deletions(-) diff --git a/OvmfPkg/Include/Library/MemEncryptSevLib.h b/OvmfPkg/Include/L= ibrary/MemEncryptSevLib.h index 4fa9c0d70083..0fa86aecc38c 100644 --- a/OvmfPkg/Include/Library/MemEncryptSevLib.h +++ b/OvmfPkg/Include/Library/MemEncryptSevLib.h @@ -166,6 +166,18 @@ MemEncryptSevGetEncryptionMask ( VOID ); =20 +/** + Returns a boolean to indicate whether DebugSwap is enabled. + + @retval TRUE DebugSwap is enabled + @retval FALSE DebugSwap is not enabled +**/ +BOOLEAN +EFIAPI +MemEncryptSevEsDebugSwapIsEnabled ( + VOID + ); + /** Returns the encryption state of the specified virtual address range. =20 diff --git a/OvmfPkg/Library/BaseMemEncryptSevLib/DxeMemEncryptSevLibIntern= al.c b/OvmfPkg/Library/BaseMemEncryptSevLib/DxeMemEncryptSevLibInternal.c index 4aba0075b9e2..ffe5399c73ca 100644 --- a/OvmfPkg/Library/BaseMemEncryptSevLib/DxeMemEncryptSevLibInternal.c +++ b/OvmfPkg/Library/BaseMemEncryptSevLib/DxeMemEncryptSevLibInternal.c @@ -40,19 +40,23 @@ AmdMemEncryptionAttrCheck ( IN CONFIDENTIAL_COMPUTING_GUEST_ATTR Attr ) { + UINT64 CurrentLevel =3D CurrentAttr & ~CCAttrAmdSevFeatureMask; + switch (Attr) { case CCAttrAmdSev: // // SEV is automatically enabled if SEV-ES or SEV-SNP is active. // - return CurrentAttr >=3D CCAttrAmdSev; + return CurrentLevel >=3D CCAttrAmdSev; case CCAttrAmdSevEs: // // SEV-ES is automatically enabled if SEV-SNP is active. // - return CurrentAttr >=3D CCAttrAmdSevEs; + return CurrentLevel >=3D CCAttrAmdSevEs; case CCAttrAmdSevSnp: - return CurrentAttr =3D=3D CCAttrAmdSevSnp; + return CurrentLevel =3D=3D CCAttrAmdSevSnp; + case CCAttrAmdSevFeatureDebugSwap: + return !!(CurrentAttr & CCAttrAmdSevFeatureDebugSwap); default: return FALSE; } @@ -159,3 +163,18 @@ MemEncryptSevGetEncryptionMask ( =20 return mSevEncryptionMask; } + +/** + Returns a boolean to indicate whether DebugSwap is enabled. + + @retval TRUE DebugSwap is enabled + @retval FALSE DebugSwap is not enabled +**/ +BOOLEAN +EFIAPI +MemEncryptSevEsDebugSwapIsEnabled ( + VOID + ) +{ + return ConfidentialComputingGuestHas (CCAttrAmdSevFeatureDebugSwap); +} diff --git a/OvmfPkg/Library/BaseMemEncryptSevLib/PeiMemEncryptSevLibIntern= al.c b/OvmfPkg/Library/BaseMemEncryptSevLib/PeiMemEncryptSevLibInternal.c index 41d1246a5b31..e2ebc8afcaee 100644 --- a/OvmfPkg/Library/BaseMemEncryptSevLib/PeiMemEncryptSevLibInternal.c +++ b/OvmfPkg/Library/BaseMemEncryptSevLib/PeiMemEncryptSevLibInternal.c @@ -141,3 +141,22 @@ MemEncryptSevGetEncryptionMask ( =20 return SevEsWorkArea->EncryptionMask; } + +/** + Returns a boolean to indicate whether DebugSwap is enabled. + + @retval TRUE DebugSwap is enabled + @retval FALSE DebugSwap is not enabled +**/ +BOOLEAN +EFIAPI +MemEncryptSevEsDebugSwapIsEnabled ( + VOID + ) +{ + MSR_SEV_STATUS_REGISTER Msr; + + Msr.Uint32 =3D InternalMemEncryptSevStatus (); + + return Msr.Bits.DebugSwap ? TRUE : FALSE; +} diff --git a/OvmfPkg/Library/BaseMemEncryptSevLib/SecMemEncryptSevLibIntern= al.c b/OvmfPkg/Library/BaseMemEncryptSevLib/SecMemEncryptSevLibInternal.c index 27148c7e337a..974be9555296 100644 --- a/OvmfPkg/Library/BaseMemEncryptSevLib/SecMemEncryptSevLibInternal.c +++ b/OvmfPkg/Library/BaseMemEncryptSevLib/SecMemEncryptSevLibInternal.c @@ -142,6 +142,26 @@ MemEncryptSevGetEncryptionMask ( return SevEsWorkArea->EncryptionMask; } =20 + +/** + Returns a boolean to indicate whether DebugSwap is enabled. + + @retval TRUE DebugSwap is enabled + @retval FALSE DebugSwap is not enabled +**/ +BOOLEAN +EFIAPI +MemEncryptSevEsDebugSwapIsEnabled ( + VOID + ) +{ + MSR_SEV_STATUS_REGISTER Msr; + + Msr.Uint32 =3D InternalMemEncryptSevStatus (); + + return Msr.Bits.DebugSwap ? TRUE : FALSE; +} + /** Locate the page range that covers the initial (pre-SMBASE-relocation) SM= RAM Save State Map. diff --git a/OvmfPkg/Library/CcExitLib/CcExitVcHandler.c b/OvmfPkg/Library/= CcExitLib/CcExitVcHandler.c index 985e5479775c..811cad164ea2 100644 --- a/OvmfPkg/Library/CcExitLib/CcExitVcHandler.c +++ b/OvmfPkg/Library/CcExitLib/CcExitVcHandler.c @@ -2136,6 +2136,10 @@ Dr7WriteExit ( UINT64 *Register; UINT64 Status; =20 + if (MemEncryptSevEsDebugSwapIsEnabled ()) { + return UnsupportedExit (Ghcb, Regs, InstructionData); + } + Ext =3D &InstructionData->Ext; SevEsData =3D (SEV_ES_PER_CPU_DATA *)(Ghcb + 1); =20 @@ -2188,6 +2192,10 @@ Dr7ReadExit ( SEV_ES_PER_CPU_DATA *SevEsData; UINT64 *Register; =20 + if (MemEncryptSevEsDebugSwapIsEnabled ()) { + return UnsupportedExit (Ghcb, Regs, InstructionData); + } + Ext =3D &InstructionData->Ext; SevEsData =3D (SEV_ES_PER_CPU_DATA *)(Ghcb + 1); =20 --=20 2.38.1