From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: mx.groups.io; dkim=pass header.i=@amdcloud.onmicrosoft.com header.s=selector2-amdcloud-onmicrosoft-com header.b=KVrCCQM+; spf=none, err=SPF record not found (domain: amd.com, ip: 40.107.76.70, mailfrom: thomas.lendacky@amd.com) Received: from NAM02-CY1-obe.outbound.protection.outlook.com (NAM02-CY1-obe.outbound.protection.outlook.com [40.107.76.70]) by groups.io with SMTP; Thu, 19 Sep 2019 12:52:45 -0700 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=icRzi7fkVN3lnrGzhoPK5lhYw0DytxqsVxo4rRgPH2l/B6NmvSa2H4aGZyNS0XnNjq34c8BKVYZrU723Ndj1K7JTtAiwNSgZljeeWhTtMDp3uJI+HClNMzmOm5s+Wo1lKpbb36aDrly84qU/6AIMpPmvcae137PFYIgl8I5KVGONg1IWqPhzSQ0rjdKjcpMnISrbPiMF5RN0JSMohXdnDAebFzljBUf5r7d0LLWMDtGMOCJCvgFXnVVNG/OWEBEIyxqqULgAOL247wFqSCPXvf3kMsTlqelN8WOHVqeBSP2Ps4LzhzjKfm8imB2k2sBIUS6Gs99fGvhR2n2f1YsxCw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Igq3h4zG4I52crtTqr+i3x9mev1jnumlgMYG+0qQxmM=; b=gqFw9TMYm4X83v6jgEZOhmDcLO7JKv2H9J38iZm+D51AMTYNxxVZ5cMu2aOXpP3JXrrt/vaL1HQt2XkMIxR3AojYzs8CaEC6hoUbkadWuqFNv82q3mjJCBkhxY4IdCne8Jvi0R2qyfLyG1ZlFwBTbDtiJvMSlFXSlGNBV1p0o328ywnDzIggqTgaIZNwpckCWfefn4sZ+M2xVHKoMKih7l6gv8BX98CA1LBNoAwqNhyhyiOBCblxrKFVxxaH4wQMnfRIv17Rwrq42P5TNSpZKovx1QNOwyNnZGNoh1rqkyE3EtF2ntfHoAzffcH2rTp4UTqROt5MggO4MBHr0p7udg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amdcloud.onmicrosoft.com; s=selector2-amdcloud-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Igq3h4zG4I52crtTqr+i3x9mev1jnumlgMYG+0qQxmM=; b=KVrCCQM+7v6+MyTTdIYV25ZhSNwlcxH92/YDdlXsmwRxaeQqbLKCPzLo/U1vtM1qSf4JZEtAFjSKAHg7JQPPQLMbaItbYc6sJ7hYztK/HOX7fiHCkcm4zaziegMlL3k2CKxPG2+yY86gB2PebUoW8lCptokTEF6tQpymERq9vL0= Received: from DM6PR12MB3163.namprd12.prod.outlook.com (20.179.104.150) by DM6PR12MB3228.namprd12.prod.outlook.com (20.179.105.96) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2263.13; Thu, 19 Sep 2019 19:52:37 +0000 Received: from DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::400e:f0c3:7ca:2fcc]) by DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::400e:f0c3:7ca:2fcc%6]) with mapi id 15.20.2284.009; Thu, 19 Sep 2019 19:52:36 +0000 From: "Lendacky, Thomas" To: "devel@edk2.groups.io" CC: Jordan Justen , Laszlo Ersek , Ard Biesheuvel , Michael D Kinney , Liming Gao , Eric Dong , Ray Ni , "Singh, Brijesh" Subject: [RFC PATCH v2 11/44] OvmfPkg/PlatformPei: Move early GDT into ram when SEV-ES is enabled Thread-Topic: [RFC PATCH v2 11/44] OvmfPkg/PlatformPei: Move early GDT into ram when SEV-ES is enabled Thread-Index: AQHVbyPJn+3R7DBBt0GZRRCSMmsIBQ== Date: Thu, 19 Sep 2019 19:52:36 +0000 Message-ID: <457424fdcd5ba463dbbc198c1018cedd3857a9b7.1568922728.git.thomas.lendacky@amd.com> References: In-Reply-To: Accept-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-mailer: git-send-email 2.17.1 x-clientproxiedby: SN4PR0501CA0146.namprd05.prod.outlook.com (2603:10b6:803:2c::24) To DM6PR12MB3163.namprd12.prod.outlook.com (2603:10b6:5:182::22) authentication-results: spf=none (sender IP is ) smtp.mailfrom=Thomas.Lendacky@amd.com; x-ms-exchange-messagesentrepresentingtype: 1 x-originating-ip: [165.204.78.1] x-ms-publictraffictype: Email x-ms-office365-filtering-correlation-id: f0886c32-5b81-4bc3-2b39-08d73d3aeb96 x-ms-office365-filtering-ht: Tenant x-microsoft-antispam: BCL:0;PCL:0;RULEID:(2390118)(7020095)(4652040)(8989299)(5600167)(711020)(4605104)(1401327)(4618075)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(2017052603328)(7193020);SRVR:DM6PR12MB3228; x-ms-traffictypediagnostic: DM6PR12MB3228: x-ms-exchange-purlcount: 1 x-ms-exchange-transport-forked: True x-microsoft-antispam-prvs: x-ms-oob-tlc-oobclassifiers: OLM:9508; x-forefront-prvs: 016572D96D x-forefront-antispam-report: SFV:NSPM;SFS:(10009020)(4636009)(366004)(376002)(396003)(136003)(39860400002)(346002)(189003)(199004)(4326008)(26005)(446003)(25786009)(52116002)(14444005)(71200400001)(71190400001)(8936002)(81156014)(81166006)(256004)(8676002)(186003)(50226002)(2351001)(2616005)(102836004)(486006)(11346002)(476003)(66066001)(386003)(6506007)(66446008)(14454004)(76176011)(99286004)(6486002)(36756003)(5640700003)(66556008)(118296001)(3846002)(316002)(7736002)(2501003)(1730700003)(6116002)(5660300002)(478600001)(54906003)(6916009)(966005)(6436002)(2906002)(64756008)(305945005)(86362001)(6512007)(6306002)(66476007)(66946007);DIR:OUT;SFP:1101;SCL:1;SRVR:DM6PR12MB3228;H:DM6PR12MB3163.namprd12.prod.outlook.com;FPR:;SPF:None;LANG:en;PTR:InfoNoRecords;MX:1;A:1; received-spf: None (protection.outlook.com: amd.com does not designate permitted sender hosts) x-ms-exchange-senderadcheck: 1 x-microsoft-antispam-message-info: VIzKiKHT/DOdRX1TaTXbTJech3xyzq8scNeeLtoth0Chjvsj2Ngvw/P3JEflr7yIKTRkm93t7dTtryQCiSn65XusFDmt9445Q4/NsWqYzadX9Y5SrhSx3i2U9SHWiTLtWLmRQOOPb/9i2jR9aVVJm+CieKJQAHIewEnITfsOjPiQzF0XSxHdpuQb1VNpuj+bGksOVxuz/kPX89kQpdjmEuYkZkQlgE/TtbEL2hYKRNzA8KhN7KEgsNJs+eg41vFWZJlsNe/S4sLt9Yeoi5CnOPdi2T+rF4fU73+uRZScCCrJtAh3msfI9AaO3CIHP9cKK+eoT7RMfJjjdz5rsNDiWIfSx+uBIY+asj1AST4ZLjaq+Hv9KhuaaNpV3X2qn6t42ieW4hAOIs+x5GRcfToe5vLo3DrOfz3kxfY2L5UsZA8= MIME-Version: 1.0 X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: f0886c32-5b81-4bc3-2b39-08d73d3aeb96 X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Sep 2019 19:52:36.8058 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: w9DqEP4eXv0SICPuW6Ic53Y0CPCqaQU8YrQqt48Lwuyn668MSOcixKrIQcg/uyZCjVW20UIZRP12i6CXdXZcWA== X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR12MB3228 Content-Language: en-US Content-Type: text/plain; charset="us-ascii" Content-ID: Content-Transfer-Encoding: quoted-printable From: Tom Lendacky BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=3D2198 The SEV support will clear the C-bit from non-RAM areas. The early GDT lives in a non-RAM area, so when an exception occurs (like a #VC) the GDT will be read as un-encrypted even though it is encrypted. This will result in a failure to be able to handle the exception. Move the GDT into RAM so it can be accessed without error when running as an SEV-ES guest. Cc: Jordan Justen Cc: Laszlo Ersek Cc: Ard Biesheuvel Signed-off-by: Tom Lendacky --- OvmfPkg/PlatformPei/AmdSev.c | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/OvmfPkg/PlatformPei/AmdSev.c b/OvmfPkg/PlatformPei/AmdSev.c index 699bb8b11557..d6733447bdf2 100644 --- a/OvmfPkg/PlatformPei/AmdSev.c +++ b/OvmfPkg/PlatformPei/AmdSev.c @@ -37,6 +37,8 @@ AmdSevEsInitialize ( PHYSICAL_ADDRESS GhcbBasePa; UINTN GhcbPageCount; RETURN_STATUS PcdStatus, DecryptStatus; + IA32_DESCRIPTOR Gdtr; + VOID *Gdt; =20 if (!MemEncryptSevEsIsEnabled ()) { return; @@ -72,6 +74,20 @@ AmdSevEsInitialize ( DEBUG ((DEBUG_INFO, "SEV-ES is enabled, %u GHCB pages allocated starting= at 0x%lx\n", GhcbPageCount, GhcbBase)); =20 AsmWriteMsr64 (MSR_SEV_ES_GHCB, (UINT64)GhcbBasePa); + + // + // The SEV support will clear the C-bit from the non-RAM areas. Since + // the GDT initially lives in that area and it will be read when a #VC + // exception happens, it needs to be moved to RAM for an SEV-ES guest. + // + AsmReadGdtr (&Gdtr); + + Gdt =3D AllocatePages (EFI_SIZE_TO_PAGES (Gdtr.Limit + 1)); + ASSERT (Gdt); + + CopyMem (Gdt, (VOID *) Gdtr.Base, Gdtr.Limit + 1); + Gdtr.Base =3D (UINTN) Gdt; + AsmWriteGdtr (&Gdtr); } =20 /** --=20 2.17.1