From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received-SPF: Pass (sender SPF authorized) identity=helo; client-ip=104.47.38.71; helo=nam02-bl2-obe.outbound.protection.outlook.com; envelope-from=brijesh.singh@amd.com; receiver=edk2-devel@lists.01.org Received: from NAM02-BL2-obe.outbound.protection.outlook.com (mail-bl2nam02on0071.outbound.protection.outlook.com [104.47.38.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ml01.01.org (Postfix) with ESMTPS id CD8D62257C2DD for ; Mon, 5 Mar 2018 06:37:57 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amdcloud.onmicrosoft.com; s=selector1-amd-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=ZblajmnTUp/PnZQB22qqYVg2elrLoxp3hEaJhaAH4OQ=; b=Bgll4Riq1jeJxqL03Xq+WuI1EH23qDo26pq0x+gxOjsRyO5JDcDxIuzk1rVBsIyU2inAzylK90rmPeXw5Wzrbd0iGVVmiywjwb97N+LGHHQ8/8oyVcLo4+JBRkAeaGIX8x8nSZt2M25uZX6k8kaE+dvo6HqtEXdJf7ngyOhpC2M= Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=brijesh.singh@amd.com; Received: from [10.236.136.62] (165.204.77.1) by CY1PR12MB0151.namprd12.prod.outlook.com (10.161.173.21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.548.13; Mon, 5 Mar 2018 14:44:08 +0000 Cc: brijesh.singh@amd.com, Ard Biesheuvel , Jordan Justen To: Laszlo Ersek , edk2-devel-01 References: <20180302000408.14201-1-lersek@redhat.com> <2d6e37a5-fdfa-330d-d7ef-51e0350afdad@amd.com> <6be3c2e4-0269-7743-d14d-4cf1f2935342@redhat.com> <45c6adcc-57a1-c7c4-3474-b33b7323ea17@amd.com> From: Brijesh Singh Message-ID: <43e0c837-3f1d-691b-f701-10c2777b721a@amd.com> Date: Mon, 5 Mar 2018 08:44:03 -0600 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.6.0 MIME-Version: 1.0 In-Reply-To: X-Originating-IP: [165.204.77.1] X-ClientProxiedBy: BN6PR21CA0009.namprd21.prod.outlook.com (10.173.197.19) To CY1PR12MB0151.namprd12.prod.outlook.com (10.161.173.21) X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-HT: Tenant X-MS-Office365-Filtering-Correlation-Id: 06273bc2-5a63-449f-e314-08d582a78d8a X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(48565401081)(5600026)(4604075)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603307)(7153060)(7193020); SRVR:CY1PR12MB0151; X-Microsoft-Exchange-Diagnostics: 1; CY1PR12MB0151; 3:YINfEgFHJ36MRt9aEl0YlqwHmYtMg3J0+sSXNcY7Ezafny0WXRfEdGYWkJlLWR5i2iJBd9j7ieZMvv6UczGsUZV3js0hxkXwpmiCKyyV3QlUJQMoNsKQJfXVg6o9dM/Cr48iszX6qXLJ/kZtaehiSTypLRJ/eu/d9LEVeIZQU5TbHm3ha13Cj0tR46WpnRXRARswaEu3DiJ/8+kPwcsrYoulxeVqcWl2f989Q1vFMet3gb8O5jmKU/5Oh37dMQ7a; 25:PLCdcojB0b1lvTpAybctvaC2QgsGQL1EeWaNPKCsJ8RMP1kCWD2Os9PpSMUQtp+9S/ffb8y2MtMjWnPk16AhKccUo97ySEiVEDvYFA7Wc35sWz7cNYPDINRPbgynul4hjgWcUEPs0+PcYX5gcykSiA7nSx/tQ9pHfgmilaQPJdarOKKOb/edmIrvWrRG2Fbb8SFGPSUHRlUsvv/2pdEjbI3JXsvwE+wthkuR3SUi7uWf4+hDfXfbVhrfRKAUTaSEdMm3FOF/Il7LPhuUoIImfsrSNelTkdLVuz80tPUd27FHj+K+CTAO/UxMn3pqnfNWF6q6D/MhaPS2849CJJsWAg==; 31:0E9ZSDeajPFA+DAycO1l/sa1JAxSRh88a5Qs81hSGjTQ1/lVMNbNEuyGEn1onRZMGkU3rnjjdGDup8pAc4muSMWleHMSwMoy2j7bsWQY02mYCLjGfX/WxMNaN7pMKLX5LyNCWGGA3oyKhYR1UWH7udjQYDAN8l9PqVXOjHg3zaYAh+SkAAs7I+CkAYfueq3pFwqnr3nI72n7PD+Djff8PKfF6EC8UzYWGsarUN2g5T4= X-MS-TrafficTypeDiagnostic: CY1PR12MB0151: X-Microsoft-Exchange-Diagnostics: 1; CY1PR12MB0151; 20:t9Fc6tob8eiTmOniF41/xX2y8PiMHJDV8aNulzW6yzaZ1rdA92Ds5eI2DvTQjQlAH5GIcPHTZhJR5EiyjZqwvJdOrH+ezbafDwIA5qZm1Fz9Zd64bEy1uIRQ0/XXcBm3h6h/PvrfUgXOgTWP9pTVelDTe6QE8zcAwxl5ea6hhZEVKhL7h+08eo79+wa9Yuh3LmDGv0JigETzaU9L++QfcTcVb9loYGb8p4Ly7SKJWM2qUtBPgfQT97+MeL+D/CBTB8ELuJJBW8g23cWVhywwxkbXkSf4J1DQP+gJ/yUj9dx1YOZBPmY4eacIfzJ0ht+CKWlWdhHJ8AL2Vdsm8M05aqaasuceFK4fOJ+b1S+md2RykF6wVw0BzuDeHpwmGeUzaRc7aBXwXcBNi1MuywxKkCFVqKeC8fOBlYAgXiCWUmkGStOsV3TnEPr/Esg43sO+8HG2hb2v0yTg/kcsrzLFQdU/v1gNLo/F6X7hFJkAs/AkntLq1otheEuzN/mUptjA; 4:0Xqbu3S+wVOaFMhgSYB/Y1kK2+h8bqm7JDfVyiiylnw8SfnbZRXVZDkrNYUzWaZmBh/3BaDTQbF9SnZe8A7MOv8FcAneKgtPe4GA/3oFMeUERC8tmptaPD1ut0RV+F/9zeEDmaFEK72c7zdwwInMaXAQokoXntmiyGiOzsoAsDcC0Dev57LW7u3TFLWJDrTwu8X/Z2H3oV/c1PDLbpT5ns05LCrebwAFAHapQmPDy8tpJvUGadQa+X9stNNT5CjE4YQMfOPeUmiOLK17fmqTUQuIHD+4AZDVMCG4I4yUZzAjD8txaHO7cW7D/UV3kBZ8 X-Microsoft-Antispam-PRVS: X-Exchange-Antispam-Report-Test: UriScan:(166708455590820); X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(8211001083)(6040501)(2401047)(8121501046)(5005006)(93006095)(93001095)(10201501046)(3231220)(944501244)(52105095)(3002001)(6055026)(6041288)(20161123562045)(20161123558120)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123564045)(20161123560045)(6072148)(201708071742011); SRVR:CY1PR12MB0151; BCL:0; PCL:0; RULEID:; SRVR:CY1PR12MB0151; X-Forefront-PRVS: 06022AA85F X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10009020)(6049001)(376002)(346002)(366004)(396003)(39850400004)(39380400002)(189003)(199004)(90366009)(8936002)(81166006)(6486002)(2906002)(6116002)(305945005)(47776003)(6246003)(7736002)(2870700001)(67846002)(65956001)(66066001)(97736004)(6306002)(106356001)(3846002)(65806001)(316002)(53936002)(966005)(31696002)(2950100002)(16576012)(68736007)(54906003)(110136005)(478600001)(65826007)(36756003)(81156014)(6666003)(229853002)(58126008)(4326008)(31686004)(53546011)(25786009)(76176011)(64126003)(105586002)(5660300001)(59450400001)(386003)(26005)(93886005)(52116002)(77096007)(50466002)(52146003)(23676004)(2486003)(186003)(16526019)(8676002)(86362001); DIR:OUT; SFP:1101; SCL:1; SRVR:CY1PR12MB0151; H:[10.236.136.62]; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en; Received-SPF: None (protection.outlook.com: amd.com does not designate permitted sender hosts) X-Microsoft-Exchange-Diagnostics: =?utf-8?B?MTtDWTFQUjEyTUIwMTUxOzIzOlpUaXpGSU94dmZHVDVWVjlsbTgrY1FqUWtT?= =?utf-8?B?ZEZrZHMxLzlKK2R5bzNORTNFaG1RM1NMdStsNzZIU21weTVnYnlHOW1KVTdm?= =?utf-8?B?cURpOHBkV3Z1L1IwZEVOTlI3eFZ1dlpjQVgvd1l4UmswcW9RMjRFOTh0TWEr?= =?utf-8?B?dWtjTmROa3dJYytia295TXJRalF0RE5TTk1Tck1aMXRsdE4zeTQ0RTZHMG5O?= =?utf-8?B?Z25EQ2VES3RQcGdLUE1YV3IwT2ZoVW1lemJzcUg3Q1lpdm9lNTFiem9mRVNa?= =?utf-8?B?bDlaNjAzWUFPMndZUWJwbUJQUjlHbHZ3emM3aFlZTjZ2d0puSmljNUkxWFpr?= =?utf-8?B?c0t2cFpVQTdCVW9GbHVnSk00aEZWZWo3c2Z5cUs5bEFiUGhJUEkwMW5wNnh2?= =?utf-8?B?UThmSDYzU3BOWW0yVmdodGN4dDZvbzBac2dMZE81bjBySlQxU3BzT0U4SmhL?= =?utf-8?B?NTkvZ2F4Ti91OGZqSU14cFpneU1wOEI5TGxURnZVaUZES1hmdlpxUXRqRWVM?= =?utf-8?B?dUV4a3FHUzlTOTRla213VzloSlF3akUyV3dsd25hY2o2WUF5N3c3elRIVndT?= =?utf-8?B?cFZiMFg3b0hZb21yU2daditZM0RwN08rRVR0Q0w3bjRZSXlVbURTc0xxOFlU?= =?utf-8?B?WG0zMU9WNmxFSi9RdnZtQ0E5WHgvZXpDdWR0a1N4emdpZWhlamx4NkNIVFFB?= =?utf-8?B?UzlYb0NuWC9BMWlwakxST0VTNVpHMDY3Ti84ZnZ1YVNiYUxjMEZ1N0o5Ukw1?= =?utf-8?B?QUd5cGtYbmlnN0s2VVBSMnRhKzJxS1lib0ZBc09EUVJSM0g1WllBcVpXZmFI?= =?utf-8?B?WCtJdmZ2S0FRVmtzemVFK2FFMXQ0dmlLOCtHQ2J3UllLR1Qvb1hVZW9aQ3Nq?= =?utf-8?B?R2daTTROV1ZKVmQweVJZMkE1a2tQVHdsODE5K1A3L2xUbVRacEEwU3h2aHcz?= =?utf-8?B?S1kvUWd1bU5oOHVGRVBGTDBZVTFjUEI4OXZRdXFpVTNkS1g0eit0Zno5ZlBk?= =?utf-8?B?dVB0djJXVG5oWFpHMlpHUXFPTVBjTUQ4Q2k2Umc2QUxTeURBVEJ6ckNOSTI4?= =?utf-8?B?blhSR0UrVFh2MUFDT0Fkam9GNDlGT2dhUDA1Wml3NjZJeU4vUWF2SXlrWUdW?= =?utf-8?B?QmhBb1AzUFROTWgvTVdLeG92QXcxdExpTmhjVkg0bFF5SkVPVHU0SnlaOHNo?= =?utf-8?B?SHhlTlF5RFpwbSt6akRDM2FRMjBiTWExcE81VVdldHdHeTRqUGJ5VTFFZjRv?= =?utf-8?B?cjU3M3RvZzMzVGJITGtydG9oZWc0MFArb3NySWh2QWhZbU1ZeXpyanFaamVX?= =?utf-8?B?M0JYWUUrWERWaE93RzNTNE04Wkx3OHBVeTZLd1JvUlRra3VpeW40emJ3Ym45?= =?utf-8?B?aWptWFJwdFBNR2JYODQ1OHU5RTFyckdOMVNkdWsyckVubTkzNzkyT3JGM1RF?= =?utf-8?B?YUxFczZwcFBtdTF0TmZVdktadXkvNWc5WWxBL1pPNmJRSHJjWU5wM2EzWWJN?= =?utf-8?B?R3F4bkZsK3NSVGg4TFp1ZVBRMVhmTkdlRjJHdVlBcGwvRlp6TVliOE12ak01?= =?utf-8?B?aStkK1l3VnRoVTNGKzUrYW4zZ2dCSEdaZGdyOEZUcy9ieFA0UmJTeGlGWW9P?= =?utf-8?B?Y052dDArVHgzME96NENIY3ErZ2ovY0NGWE9kdFdvSlU1QzlIdmViM05CLzNl?= =?utf-8?B?dG1STE14Q2ZEcU1xYTVDRkNlY3BwL2FMT1VrQk1NZXdINC9aWjRGUGhiaHBX?= =?utf-8?B?ZGo1ME1FRzBPUWpmNHRaRFY5d0I2bE1pVTdIM1JrMDdySHgyQkp5ZWlTdWVR?= =?utf-8?B?RnpJWWNQNWxZaXFtKytud1hkWkVoeUNxQlVaSlE4VHNUSjh0OE02MGFVM2V5?= =?utf-8?B?Q1pUbVMvN3JVQkN6YmhzZjJNRUJUbkVjSitzTTBsbEJOUWowWHFId2M3a2NO?= =?utf-8?B?RE1LdHZGSklyRm5lcXhGUlF5Tk56cS9QdHh1L3BGQ2JrUEMrZWRuaEZTTjVF?= =?utf-8?B?ejhKRE1mL0dINVFVRkZ2TEEzTjd4bTlzWmNFdz09?= X-Microsoft-Antispam-Message-Info: 0A0pY5fu/IxFa4k3mzar+9EEGMYV6E9tEqSJ4V7jvJqoVU5yI+SoFVQFs4/+sK3DsgOWm1v/QLK9IsZRXNVVQHtlx03CajK06mmoE7FLt4K18m96ZAb3J63hKYA5oFgNLJoy5Xa+WNQ5tqMw9NHqEpvSyD1nXF4CW3A3T0PuUnG0CtCG9MUL8JsPZqADwl+E X-Microsoft-Exchange-Diagnostics: 1; CY1PR12MB0151; 6:6lIRG9eUX9NVHms6DWKWluvLIUU9JVfDdzX1sY9na2NJXO2wJsh32s2h6f9Pak3WHpw0JyOBW1GwTgbpiZi/RsVSieZw6NbKh2MmkfDSwYmIkYWtDY1ijhwsx1c1EeeNYA4RslrUIgBVSXPBwVN0+yOqYssHP86gQ3SGc1840Qk1x4YnD05hx5CLPV/TxyLRJn75r8M29Jz9n5X5myRJhfPc1opn9Hd11Gh4CZtW7AgKY/t5gx37Anntppt1q31a5Cvl2WlCrx/rOfgyqR/o/k9CyzQGipHE1Qsp2IY2EcNwa4D5p+8Et1dxTTBEQ9wKnxqQI3MOEKFIkKz7sBv7P2wC0oSMgOTpmimLhni1rHE=; 5:z1IybfirQGzoczcPVarEgx0m/5zjsq0JJtA1nzwG0EJuWoct14h6ugkiE+ZrVZRIo4hTplVDBmyosJehuc9wV6hJhqyMlLIT6WH0rxDKc5Hw62xpeuLhOk+b6Cyku53IPTgr+tQQeXEPs7cvaHarWFjbesF2IDX3mXs+l3XPPb4=; 24:AN2avLlrI5Km8o8lq472r1gBQtet0N9WiLvwvy4yE5ru26Gh7qjvTtg0EKxz0FCdXjPj1hASMEl+N8D56p+tG5B7Xgj9yIkCeWdYiaxfr5M=; 7:6ReAh9bQoxSt2AsZV5zwLh3Cfuc0Cni19z4ZIslJMli6/ldZJcOyTKJQyhidbkaXG6OHqCkkMCh0YX6RsG1lVReYSlwwIMDps59mDj6v2YAoY/ODYNRkDq9kwVZmxCbNDxOI1OJZFu8jchpEvIFs+zCxOyiljQjplHuGSvJjiJenR/84ZnUafN9LmeeE1qgVCF50Uykzzj+9h/+tcJAb6NnYivrwl72zrRvhWTS3XLwheNUluC6PTctx6Pffvjcj SpamDiagnosticOutput: 1:99 SpamDiagnosticMetadata: NSPM X-Microsoft-Exchange-Diagnostics: 1; CY1PR12MB0151; 20:eIXKbUc/8oqQ3SRF88Kh2DOE8qAUV9uwUIJGaU2HezJVuAT5+roFVd3YUDp641lUVCQuV9pTyelAuec3iQ68VXpC2bZyxrzxTT7C0784bFcEyFyXimmLOw3cDNvk02vi2hZSYcW/+KyNi46GmuoGSP7J6iVsEGum620zj+hFhGI7crL+94IeushqFPVf5j9ReqaiT2PVl8IAcieiJh2pZRCmmWHYfngeVXy5exwJRdIWbf3nO5McIvsl4cCmhbMa X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 05 Mar 2018 14:44:08.1600 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 06273bc2-5a63-449f-e314-08d582a78d8a X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY1PR12MB0151 Subject: Re: [PATCH 00/20] OvmfPkg: SEV: decrypt the initial SMRAM save state map for SMBASE relocation X-BeenThere: edk2-devel@lists.01.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: EDK II Development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 05 Mar 2018 14:37:59 -0000 Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 8bit Hi Laszlo, On 03/05/2018 08:00 AM, Laszlo Ersek wrote: > On 03/02/18 14:17, Brijesh Singh wrote: >> On 3/2/18 5:53 AM, Laszlo Ersek wrote: > >>> Do you have (maybe updated) instructions for setting up the SEV host? >>> What are the latest bits that are expected to work together? > >> For host kernel: >> - use recent kvm/master >> - make sure following kernel config is enabled >>   CONFIG_KVM_AMD_SEV >>   CONFIG_CRYPTO_DEV_SP_PSP >>   CONFIG_AMD_MEM_ENCRYPT >>   CONFIG_AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT >> >> For guest kernel: >>  - you can use host kernel or anything >=4.15 >>     make sure you have following config enabled in kernel: >>       CONFIG_AMD_MEM_ENCRYPT >> >> For qemu: >> - v10 patches from this branch >> https://github.com/codomania/qemu/tree/v10 > > QEMU exits with the following error for me: > > 2018-03-05T13:40:12.478835Z qemu-system-x86_64: sev_ram_block_added: failed to register region (0x7f3df3e00000+0x200000000) > 2018-03-05T13:40:12.489183Z qemu-system-x86_64: sev_ram_block_added: failed to register region (0x7f3ffaa00000+0x37c000) > 2018-03-05T13:40:12.497580Z qemu-system-x86_64: sev_ram_block_added: failed to register region (0x7f3ffa800000+0x20000) > 2018-03-05T13:40:12.504485Z qemu-system-x86_64: sev_launch_update_data: LAUNCH_UPDATE ret=-12 fw_error=0 '' > 2018-03-05T13:40:12.504493Z qemu-system-x86_64: failed to encrypt pflash rom > > Here's my full QEMU command line (started by libvirt) -- this command line does not restrict pflash access to guest code that runs in SMM, and correspondingly, the OVMF build lacks SMM_REQUIRE: > Are you launching guest as a normal users or root ? If you are launching guest as normal user then please make sure you have increased the 'max locked memory' limit. The register region function will try to pin the memory, while doing so we check the limit and if requested size is greater than ulimit then we fail. # ulimit -a core file size (blocks, -c) unlimited data seg size (kbytes, -d) unlimited scheduling priority (-e) 0 file size (blocks, -f) unlimited pending signals (-i) 966418 max locked memory (kbytes, -l) 10240000 max memory size (kbytes, -m) unlimited open files (-n) 1024 pipe size (512 bytes, -p) 8 POSIX message queues (bytes, -q) 819200 real-time priority (-r) 0 stack size (kbytes, -s) 8192 cpu time (seconds, -t) unlimited max user processes (-u) 966418 virtual memory (kbytes, -v) unlimited file locks (-x) unlimited If QEMU command is still failing for you then can you please share your kernel dmesg. thanks > /opt/qemu-installed/bin/qemu-system-x86_64 \ > -name guest=from-brijesh,debug-threads=on \ > -S \ > -object secret,id=masterKey0,format=raw,file=/var/lib/libvirt/qemu/domain-4-from-brijesh/master-key.aes \ > -machine pc-q35-2.10,accel=kvm,usb=off,smm=on,dump-guest-core=off \ > -cpu host \ > -drive file=/home/virt-images/OVMF_CODE.4m.fd,if=pflash,format=raw,unit=0,readonly=on \ > -drive file=/var/lib/libvirt/qemu/nvram/from-brijesh_VARS.fd,if=pflash,format=raw,unit=1 \ > -m 8192 \ > -realtime mlock=off \ > -smp 1,sockets=1,cores=1,threads=1 \ > -uuid e2373f13-f481-4008-88d0-d61fa9da16fe \ > -no-user-config \ > -nodefaults \ > -chardev socket,id=charmonitor,path=/var/lib/libvirt/qemu/domain-4-from-brijesh/monitor.sock,server,nowait \ > -mon chardev=charmonitor,id=monitor,mode=control \ > -rtc base=utc \ > -no-shutdown \ > -boot strict=on \ > -device pcie-root-port,port=0x10,chassis=1,id=pci.1,bus=pcie.0,multifunction=on,addr=0x2 \ > -device pcie-root-port,port=0x11,chassis=2,id=pci.2,bus=pcie.0,addr=0x2.0x1 \ > -device pcie-root-port,port=0x12,chassis=3,id=pci.3,bus=pcie.0,addr=0x2.0x2 \ > -device pcie-root-port,port=0x13,chassis=4,id=pci.4,bus=pcie.0,addr=0x2.0x3 \ > -device nec-usb-xhci,id=usb,bus=pci.1,addr=0x0 \ > -device virtio-scsi-pci,iommu_platform=on,ats=on,id=scsi0,bus=pci.3,addr=0x0 \ > -drive file=/var/lib/libvirt/images/rhel-7-server.qcow2,format=qcow2,if=none,id=drive-scsi0-0-0-0,cache=writeback,discard=unmap,werror=enospc \ > -device scsi-hd,bus=scsi0.0,channel=0,scsi-id=0,lun=0,drive=drive-scsi0-0-0-0,id=scsi0-0-0-0,bootindex=1 \ > -netdev tap,fd=26,id=hostnet0,vhost=on,vhostfd=28 \ > -device virtio-net-pci,netdev=hostnet0,id=net0,mac=52:54:00:65:f7:fb,bus=pci.4,addr=0x0,rombar=0 \ > -chardev pty,id=charserial0 \ > -device isa-serial,chardev=charserial0,id=serial0 \ > -device usb-tablet,id=input2,bus=usb.0,port=1 \ > -spice port=5900,addr=127.0.0.1,disable-ticketing,seamless-migration=on \ > -device cirrus-vga,id=video0,bus=pcie.0,addr=0x1 \ > -device virtio-balloon-pci,id=balloon0,bus=pci.2,addr=0x0 \ > -global isa-debugcon.iobase=0x402 \ > -debugcon file:/tmp/from-brijesh.log \ > -fw_cfg name=opt/ovmf/PcdResizeXterm,string=y \ > -s \ > -object sev-guest,id=sev0,policy=0x0,cbitpos=47,reduced-phys-bits=5 \ > -machine memory-encryption=sev0 \ > -msg timestamp=on > > Thanks, > Laszlo >