From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from NAM05-CO1-obe.outbound.protection.outlook.com (NAM05-CO1-obe.outbound.protection.outlook.com [40.107.72.46]) by mx.groups.io with SMTP id smtpd.web11.26601.1574354932883891752 for ; Thu, 21 Nov 2019 08:48:53 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@amdcloud.onmicrosoft.com header.s=selector2-amdcloud-onmicrosoft-com header.b=nZ6g8bDb; spf=none, err=SPF record not found (domain: amd.com, ip: 40.107.72.46, mailfrom: thomas.lendacky@amd.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=MSS4xbUcowEG+cYHiF7dl6h3R1jmDBAtUo6d6szICh8DahCVlSgG+tWm+nMY4VlxBBjk7CLKR/UcQmSbydJvkmaDWeDs2PXVHKG/9JcAH37WKtRfKXIWb80H7czlUPB7aSGw6AlWDE+zz+Aylcksob46/fOm+K1YPX57kKBjKjCCM6kDgna8fU4KyfSFgRsRx437qWRlVLRTXIRjU3aGtClHBsHrdN4Rf2Q9DyROMgxvv50k/Y/tFI4T4lXQ0S7HWMQsUddgU+CB7r9Vn08w/ftPBmBlFrwCF/97ENhV6OQrCgduF36ihDPOkfHjmTWaHhngRyfVFDlAtqUWkhLNUQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=HaZ6qMSK0W18JCbCTByAMfwGDER9G9S6WK4Pj0z4SAA=; b=GfPUu4niyOWPDjU9V9ilP3noQ4seJmTvFhT3qibbeyRBfccpAWB5Tut3QjvZg0VZ+a/IEN12fSpe7WeQFmtgwZWql6R7F3eke/HYo/LYycaQy1tPsPsHcVpx7it/8ABM6Ky0yYK1DKrPyQm6LY0v2BL9MB4yEWs21v31IEUmtiXWhl8xIqKQJ942wHWdT0EYNYHIHUp8aN9AhZoDVQ4dpA/WFmVNK9nzd/1pXS7PvubiQpavzy6FNxuJAxf03oO6GHG84gnSZqlXTJUjrcJ9z7Sqj5vwOWjT28v6kS+/+HxFdnh5R8KXeEuh6BvY7KlnivoOyhQgCubj41ZuG/Rq8A== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amdcloud.onmicrosoft.com; s=selector2-amdcloud-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=HaZ6qMSK0W18JCbCTByAMfwGDER9G9S6WK4Pj0z4SAA=; b=nZ6g8bDb7QoACYlU0hXFdl+Vshv6BquBNDEHIj2BdxvMxjZ6L9NIGOZ0c74T+3C9rscgGDpAlRAL4jBpYavDI7+/HB41JZMvLlySQ7Aw0F0XQc2e1FBUuto2kF/DPUD23puT6O8laXG3YUoLkwmD94XFk0BKJxi7DZ+TfMaIKuA= Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Thomas.Lendacky@amd.com; Received: from DM6PR12MB3163.namprd12.prod.outlook.com (20.179.71.154) by DM6SPR01MB0093.namprd12.prod.outlook.com (10.141.107.136) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2474.16; Thu, 21 Nov 2019 16:48:51 +0000 Received: from DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::dd0c:8e53:4913:8ef4]) by DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::dd0c:8e53:4913:8ef4%5]) with mapi id 15.20.2474.019; Thu, 21 Nov 2019 16:48:51 +0000 Subject: Re: [edk2-devel] [RFC PATCH v3 07/43] UefiCpuPkg: Implement library support for VMGEXIT To: devel@edk2.groups.io, lersek@redhat.com Cc: Jordan Justen , Ard Biesheuvel , Michael D Kinney , Liming Gao , Eric Dong , Ray Ni , Brijesh Singh References: <5c8f36407e5ac7c7757ae5108cf861b36287a3ce.1574280425.git.thomas.lendacky@amd.com> <49c5bbb0-0b52-c528-c917-212b5a84f1f7@redhat.com> From: "Lendacky, Thomas" Openpgp: preference=signencrypt Message-ID: <478e29e6-f15a-2e74-1c3d-b166fc1395c8@amd.com> Date: Thu, 21 Nov 2019 10:48:49 -0600 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0 In-Reply-To: <49c5bbb0-0b52-c528-c917-212b5a84f1f7@redhat.com> X-ClientProxiedBy: SN6PR16CA0042.namprd16.prod.outlook.com (2603:10b6:805:ca::19) To DM6PR12MB3163.namprd12.prod.outlook.com (2603:10b6:5:15e::26) Return-Path: thomas.lendacky@amd.com MIME-Version: 1.0 X-Originating-IP: [165.204.77.1] X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-HT: Tenant X-MS-Office365-Filtering-Correlation-Id: 9f84663f-9685-43b1-a53d-08d76ea2afeb X-MS-TrafficTypeDiagnostic: DM6SPR01MB0093:|DM6SPR01MB0093: X-MS-Exchange-PUrlCount: 4 X-MS-Exchange-Transport-Forked: True X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:10000; X-Forefront-PRVS: 0228DDDDD7 X-Forefront-Antispam-Report: SFV:NSPM;SFS:(10009020)(4636009)(366004)(136003)(39860400002)(346002)(376002)(396003)(189003)(199004)(7736002)(47776003)(65806001)(65956001)(6436002)(14454004)(186003)(6486002)(6306002)(66066001)(2906002)(58126008)(316002)(2616005)(6512007)(5660300002)(6246003)(305945005)(14444005)(66556008)(66946007)(66476007)(50466002)(966005)(76176011)(31696002)(25786009)(26005)(52116002)(53546011)(6506007)(386003)(23746002)(6116002)(3846002)(31686004)(446003)(508600001)(11346002)(99286004)(8676002)(81156014)(229853002)(54906003)(30864003)(230700001)(86362001)(4326008)(36756003)(81166006)(8936002);DIR:OUT;SFP:1101;SCL:1;SRVR:DM6SPR01MB0093;H:DM6PR12MB3163.namprd12.prod.outlook.com;FPR:;SPF:None;LANG:en;PTR:InfoNoRecords;MX:1;A:1; Received-SPF: None (protection.outlook.com: amd.com does not designate permitted sender hosts) X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: H4uOBYfMtjLc547CAb+BhcfssGTL9z1XtLkdtUvj9VJmC6pWdaORcPuoE7hdyzNrDyf/q2iFYlpVFxRj4wVBtVul0hWXBydaZTGyGyC0EP8DTtm8tKIt+3jLkHLK8MzvtCDqZuLzNdhMEiiKby4mdU/+/b3O+q+2C+16NwXPUCUn673LwIW5AEE1nFeq3bxIPcDy/uOqV+yPRfiWSPxDyOg+ZnZIfCvzoyGAViNwlhXLoe8B05GMU2+XrDrXeGlI/19H17Lu4w+04+aBE4g6ca5RCkqaXhFYJIKwmDoAd2oCgEVYzGczzFH9n5AyZtk98urAvKeAxA66ooZqdb4oEZdaLhLXN1iRPF2nYiPO640aFk46/FEptvLctjbE9P5z7pQGNRUQ8pRSfenI8wvMLrJeV2FBmNy798uhEIytwj4yFI7qCmfAd402eA1zj2clPAKngDgKA4foCB0kap96Ne1oQp0DC2FsLRKu1xEobzo= X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: 9f84663f-9685-43b1-a53d-08d76ea2afeb X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Nov 2019 16:48:51.3876 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: U0eclG9lIJo9pprCzFo+eP75pThwFN+9q3gG01xX37jBeVvKP2vmnHKo4BlqrXlhdQ/Ir/3lNOlmBCZhULhUsg== X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6SPR01MB0093 Content-Type: text/plain; charset=windows-1252 Content-Language: en-US Content-Transfer-Encoding: 7bit On 11/21/19 5:15 AM, Laszlo Ersek via Groups.Io wrote: > On 11/20/19 21:06, Lendacky, Thomas wrote: >> BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=2198 >> >> To support issuing a VMGEXIT instruction, create a library that can be >> used to perform GHCB and VMGEXIT related operations and to issue the >> actual VMGEXIT instruction when using the GHCB. >> >> Additionally, two VMGEXIT / MMIO related functions are created to support >> flash emulation. Flash emulation currently is done by marking the flash >> area as read-only and taking a nested page fault to perform the emulation >> of the instruction. However, emulation cannot be performed because there >> is no instruction decode assist support when SEV-ES is enabled. Provide >> routines to initiate an MMIO request to perform actual writes to flash. >> >> Cc: Eric Dong >> Cc: Ray Ni >> Cc: Laszlo Ersek >> Signed-off-by: Tom Lendacky >> --- >> UefiCpuPkg/UefiCpuPkg.dec | 3 + >> UefiCpuPkg/UefiCpuPkg.dsc | 5 + >> UefiCpuPkg/Library/VmgExitLib/VmgExitLib.inf | 33 +++++ >> UefiCpuPkg/Include/Library/VmgExitLib.h | 96 ++++++++++++++ >> UefiCpuPkg/Library/VmgExitLib/VmgExitLib.c | 132 +++++++++++++++++++ >> UefiCpuPkg/Library/VmgExitLib/VmgExitLib.uni | 15 +++ >> 6 files changed, 284 insertions(+) >> create mode 100644 UefiCpuPkg/Library/VmgExitLib/VmgExitLib.inf >> create mode 100644 UefiCpuPkg/Include/Library/VmgExitLib.h >> create mode 100644 UefiCpuPkg/Library/VmgExitLib/VmgExitLib.c >> create mode 100644 UefiCpuPkg/Library/VmgExitLib/VmgExitLib.uni >> >> diff --git a/UefiCpuPkg/UefiCpuPkg.dec b/UefiCpuPkg/UefiCpuPkg.dec >> index 12f4413ea5b0..90feb9166dc8 100644 >> --- a/UefiCpuPkg/UefiCpuPkg.dec >> +++ b/UefiCpuPkg/UefiCpuPkg.dec >> @@ -53,6 +53,9 @@ [LibraryClasses.IA32, LibraryClasses.X64] >> ## >> MpInitLib|Include/Library/MpInitLib.h >> >> + ## @libraryclass Provides function to support VMGEXIT processing. >> + VmgExitLib|Include/Library/VmgExitLib.h >> + >> [Guids] >> gUefiCpuPkgTokenSpaceGuid = { 0xac05bf33, 0x995a, 0x4ed4, { 0xaa, 0xb8, 0xef, 0x7a, 0xe8, 0xf, 0x5c, 0xb0 }} >> gMsegSmramGuid = { 0x5802bce4, 0xeeee, 0x4e33, { 0xa1, 0x30, 0xeb, 0xad, 0x27, 0xf0, 0xe4, 0x39 }} >> diff --git a/UefiCpuPkg/UefiCpuPkg.dsc b/UefiCpuPkg/UefiCpuPkg.dsc >> index d28cb5cccb52..5ab7e423e8ab 100644 >> --- a/UefiCpuPkg/UefiCpuPkg.dsc >> +++ b/UefiCpuPkg/UefiCpuPkg.dsc >> @@ -63,6 +63,7 @@ [LibraryClasses.common.SEC] >> HobLib|MdePkg/Library/PeiHobLib/PeiHobLib.inf >> PeiServicesTablePointerLib|MdePkg/Library/PeiServicesTablePointerLibIdt/PeiServicesTablePointerLibIdt.inf >> MemoryAllocationLib|MdePkg/Library/PeiMemoryAllocationLib/PeiMemoryAllocationLib.inf >> + VmgExitLib|UefiCpuPkg/Library/VmgExitLib/VmgExitLib.inf >> >> [LibraryClasses.common.PEIM] >> MemoryAllocationLib|MdePkg/Library/PeiMemoryAllocationLib/PeiMemoryAllocationLib.inf >> @@ -74,6 +75,7 @@ [LibraryClasses.common.PEIM] >> [LibraryClasses.IA32.PEIM, LibraryClasses.X64.PEIM] >> PeiServicesTablePointerLib|MdePkg/Library/PeiServicesTablePointerLibIdt/PeiServicesTablePointerLibIdt.inf >> CpuExceptionHandlerLib|UefiCpuPkg/Library/CpuExceptionHandlerLib/PeiCpuExceptionHandlerLib.inf >> + VmgExitLib|UefiCpuPkg/Library/VmgExitLib/VmgExitLib.inf >> >> [LibraryClasses.common.DXE_DRIVER] >> MemoryAllocationLib|MdePkg/Library/UefiMemoryAllocationLib/UefiMemoryAllocationLib.inf >> @@ -81,12 +83,14 @@ [LibraryClasses.common.DXE_DRIVER] >> CpuExceptionHandlerLib|UefiCpuPkg/Library/CpuExceptionHandlerLib/DxeCpuExceptionHandlerLib.inf >> MpInitLib|UefiCpuPkg/Library/MpInitLib/DxeMpInitLib.inf >> RegisterCpuFeaturesLib|UefiCpuPkg/Library/RegisterCpuFeaturesLib/DxeRegisterCpuFeaturesLib.inf >> + VmgExitLib|UefiCpuPkg/Library/VmgExitLib/VmgExitLib.inf >> >> [LibraryClasses.common.DXE_SMM_DRIVER] >> SmmServicesTableLib|MdePkg/Library/SmmServicesTableLib/SmmServicesTableLib.inf >> MemoryAllocationLib|MdePkg/Library/SmmMemoryAllocationLib/SmmMemoryAllocationLib.inf >> HobLib|MdePkg/Library/DxeHobLib/DxeHobLib.inf >> CpuExceptionHandlerLib|UefiCpuPkg/Library/CpuExceptionHandlerLib/SmmCpuExceptionHandlerLib.inf >> + VmgExitLib|UefiCpuPkg/Library/VmgExitLib/VmgExitLib.inf >> >> [LibraryClasses.common.UEFI_APPLICATION] >> UefiApplicationEntryPoint|MdePkg/Library/UefiApplicationEntryPoint/UefiApplicationEntryPoint.inf >> @@ -136,6 +140,7 @@ [Components.IA32, Components.X64] >> UefiCpuPkg/Library/SmmCpuPlatformHookLibNull/SmmCpuPlatformHookLibNull.inf >> UefiCpuPkg/Library/SmmCpuFeaturesLib/SmmCpuFeaturesLib.inf >> UefiCpuPkg/Library/SmmCpuFeaturesLib/SmmCpuFeaturesLibStm.inf >> + UefiCpuPkg/Library/VmgExitLib/VmgExitLib.inf >> UefiCpuPkg/PiSmmCommunication/PiSmmCommunicationPei.inf >> UefiCpuPkg/PiSmmCommunication/PiSmmCommunicationSmm.inf >> UefiCpuPkg/SecCore/SecCore.inf >> diff --git a/UefiCpuPkg/Library/VmgExitLib/VmgExitLib.inf b/UefiCpuPkg/Library/VmgExitLib/VmgExitLib.inf >> new file mode 100644 >> index 000000000000..6acfa779e75a >> --- /dev/null >> +++ b/UefiCpuPkg/Library/VmgExitLib/VmgExitLib.inf >> @@ -0,0 +1,33 @@ >> +## @file >> +# VMGEXIT Support Library. >> +# >> +# Copyright (c) 2019, Advanced Micro Devices, Inc. All rights reserved.
>> +# SPDX-License-Identifier: BSD-2-Clause-Patent >> +# >> +## >> + >> +[Defines] >> + INF_VERSION = 0x00010005 >> + BASE_NAME = VmgExitLib >> + MODULE_UNI_FILE = VmgExitLib.uni >> + FILE_GUID = 3cd7368f-ef9b-4a9b-9571-2ed93813677e >> + MODULE_TYPE = BASE >> + VERSION_STRING = 1.0 >> + LIBRARY_CLASS = VmgExitLib >> + >> +# >> +# The following information is for reference only and not required by the build tools. >> +# >> +# VALID_ARCHITECTURES = IA32 X64 >> +# >> + >> +[Sources] >> + VmgExitLib.c >> + >> +[Packages] >> + MdePkg/MdePkg.dec >> + UefiCpuPkg/UefiCpuPkg.dec >> + >> +[LibraryClasses] >> + BaseLib >> + >> diff --git a/UefiCpuPkg/Include/Library/VmgExitLib.h b/UefiCpuPkg/Include/Library/VmgExitLib.h >> new file mode 100644 >> index 000000000000..b5639fbfa1a5 >> --- /dev/null >> +++ b/UefiCpuPkg/Include/Library/VmgExitLib.h >> @@ -0,0 +1,96 @@ >> +/** @file >> + Public header file for the VMGEXIT Support library class. >> + >> + This library class defines some routines used when invoking the VMGEXIT >> + instruction in support of SEV-ES. >> + >> + Copyright (c) 2019, Advanced Micro Devices, Inc. All rights reserved.
>> + SPDX-License-Identifier: BSD-2-Clause-Patent >> + >> +**/ >> + >> +#ifndef __VMG_EXIT_LIB_H__ >> +#define __VMG_EXIT_LIB_H__ >> + >> +#include >> + >> + >> +/** >> + Perform VMGEXIT. >> + >> + Sets the necessary fields of the GHCB, invokes the VMGEXIT instruction and >> + then handles the return actions. >> + >> + @param[in] GHCB A pointer to the GHCB >> + @param[in] ExitCode VMGEXIT code to be assigned to the SwExitCode field of >> + the GHCB. >> + @param[in] ExitInfo1 VMGEXIT information to be assigned to the SwExitInfo1 >> + field of the GHCB. >> + @param[in] ExitInfo2 VMGEXIT information to be assigned to the SwExitInfo2 >> + field of the GHCB. >> + >> + @retval 0 VMGEXIT succeeded. >> + @retval Others VMGEXIT processing did not succeed. Exception number to >> + be issued. >> + >> +**/ >> +UINTN >> +EFIAPI >> +VmgExit ( >> + GHCB *Ghcb, >> + UINT64 ExitCode, >> + UINT64 ExitInfo1, >> + UINT64 ExitInfo2 >> + ); >> + >> +/** >> + Perform pre-VMGEXIT initialization/preparation. >> + >> + Performs the necessary steps in preparation for invoking VMGEXIT. >> + >> + @param[in] GHCB A pointer to the GHCB >> + >> +**/ >> +VOID >> +EFIAPI >> +VmgInit ( >> + GHCB *Ghcb >> + ); >> + >> +/** >> + Perform post-VMGEXIT cleanup. >> + >> + Performs the necessary steps to cleanup after invoking VMGEXIT. >> + >> + @param[in] GHCB A pointer to the GHCB >> + >> +**/ >> +VOID >> +EFIAPI >> +VmgDone ( >> + GHCB *Ghcb >> + ); >> + >> +#define VMGMMIO_READ False >> +#define VMGMMIO_WRITE True >> + >> +/** >> + Perform MMIO write of a buffer to a non-MMIO marked range. >> + >> + Performs an MMIO write without taking a #VC. This is useful >> + for Flash devices, which are marked read-only. >> + >> + @param[in] UINT8 A pointer to the destination buffer >> + @param[in] UINTN The immediate value to write >> + @param[in] UINTN Number of bytes to write >> + >> +**/ >> +VOID >> +EFIAPI >> +VmgMmioWrite ( >> + UINT8 *Dest, >> + UINT8 *Src, >> + UINTN Bytes >> + ); >> + >> +#endif >> diff --git a/UefiCpuPkg/Library/VmgExitLib/VmgExitLib.c b/UefiCpuPkg/Library/VmgExitLib/VmgExitLib.c >> new file mode 100644 >> index 000000000000..23965b7ff022 >> --- /dev/null >> +++ b/UefiCpuPkg/Library/VmgExitLib/VmgExitLib.c >> @@ -0,0 +1,132 @@ >> +/** @file >> + VMGEXIT Support Library. >> + >> + Copyright (c) 2019, Advanced Micro Devices, Inc. All rights reserved.
>> + SPDX-License-Identifier: BSD-2-Clause-Patent >> + >> +**/ >> + >> +#include >> +#include >> +#include >> +#include >> +#include >> + >> +STATIC >> +UINTN >> +VmgExitErrorCheck ( >> + GHCB *Ghcb >> + ) >> +{ >> + GHCB_EXIT_INFO ExitInfo; >> + UINTN Reason, Action; >> + >> + if (!Ghcb->SaveArea.SwExitInfo1) { >> + return 0; >> + } >> + >> + ExitInfo.Uint64 = Ghcb->SaveArea.SwExitInfo1; >> + Action = ExitInfo.Elements.Lower32Bits; >> + if (Action == 1) { >> + Reason = ExitInfo.Elements.Upper32Bits; >> + >> + switch (Reason) { >> + case UD_EXCEPTION: >> + case GP_EXCEPTION: >> + return Reason; >> + } >> + } >> + >> + ASSERT (0); >> + return GP_EXCEPTION; >> +} >> + >> +UINTN >> +EFIAPI >> +VmgExit ( >> + GHCB *Ghcb, >> + UINT64 ExitCode, >> + UINT64 ExitInfo1, >> + UINT64 ExitInfo2 >> + ) >> +{ >> + Ghcb->SaveArea.SwExitCode = ExitCode; >> + Ghcb->SaveArea.SwExitInfo1 = ExitInfo1; >> + Ghcb->SaveArea.SwExitInfo2 = ExitInfo2; >> + AsmVmgExit (); > > This patch looks good to me (and, in general, I'd like to defer to Ray > and Eric on the UefiCpuPkg patches); just one comment: > > AsmVmgExit() orchestrates guest-host communication in guest RAM, and in > that sense, it is somewhat similar to virtio. In virtio (per spec), we > use MemoryFence() calls carefully. > > Now, if you check the MemoryFence() implementation in > "MdePkg/Library/BaseLib/X64/GccInline.c", it is only > > __asm__ __volatile__ ("":::"memory"); > > which is already part of AsmVmgExit(), from the previous patch: > > [edk2-devel] [RFC PATCH v3 06/43] > MdePkg/BaseLib: Add support for the VMGEXIT instruction > > __asm__ __volatile__ ("rep; vmmcall":::"memory"); > > So, I think it's not necessary *in practice* to add a MemoryFence() > ahead of the AsmVmgExit(). But, I think it is needed afterwards. > > The comment in "MdePkg/Library/BaseLib/X64/GccInline.c" says, "it is > more about the compiler that it is actually processor synchronization". > With that in mind, I'd like to suggest one of two alternatives: > > - modify the AsmVmgExit() documentation (function level comment in the > lib class header) so that it spell out that all barriers (before & > after) are contained within, > > - or please modify the call site so that it is both preceded and > succeeded by MemoryFence(). I'll update VmgExit() in VmgExitLib.c to add the MemoryFence() calls around the invocation of AsmVmgExit(). Thanks, Tom > > With either option implemented: > > Acked-by: Laszlo Ersek > > Thanks > Laszlo > > > >> + >> + return VmgExitErrorCheck (Ghcb); >> +} >> + >> +VOID >> +EFIAPI >> +VmgInit ( >> + GHCB *Ghcb >> + ) >> +{ >> + SetMem (&Ghcb->SaveArea, sizeof (Ghcb->SaveArea), 0); >> +} >> + >> +VOID >> +EFIAPI >> +VmgDone ( >> + GHCB *Ghcb >> + ) >> +{ >> +} >> + >> +UINTN >> +EFIAPI >> +VmgMmio ( >> + UINT8 *MmioAddress, >> + UINT8 *Buffer, >> + UINTN Bytes, >> + BOOLEAN Write >> + ) >> +{ >> + UINT64 MmioOp; >> + UINT64 ExitInfo1, ExitInfo2; >> + UINTN Status; >> + GHCB *Ghcb; >> + MSR_SEV_ES_GHCB_REGISTER Msr; >> + >> + Msr.GhcbPhysicalAddress = AsmReadMsr64 (MSR_SEV_ES_GHCB); >> + Ghcb = Msr.Ghcb; >> + >> + if (Write) { >> + MmioOp = SvmExitMmioWrite; >> + } else { >> + MmioOp = SvmExitMmioRead; >> + } >> + >> + ExitInfo1 = (UINT64) (UINTN) MmioAddress; >> + ExitInfo2 = Bytes; >> + >> + if (Write) { >> + CopyMem (Ghcb->SharedBuffer, Buffer, Bytes); >> + } >> + >> + Ghcb->SaveArea.SwScratch = (UINT64) (UINTN) Ghcb->SharedBuffer; >> + Status = VmgExit (Ghcb, MmioOp, ExitInfo1, ExitInfo2); >> + if (Status != 0) { >> + return Status; >> + } >> + >> + if (!Write) { >> + CopyMem (Buffer, Ghcb->SharedBuffer, Bytes); >> + } >> + >> + return 0; >> +} >> + >> +VOID >> +EFIAPI >> +VmgMmioWrite ( >> + UINT8 *Dest, >> + UINT8 *Src, >> + UINTN Bytes >> + ) >> +{ >> + VmgMmio (Dest, Src, Bytes, TRUE); >> +} >> + >> diff --git a/UefiCpuPkg/Library/VmgExitLib/VmgExitLib.uni b/UefiCpuPkg/Library/VmgExitLib/VmgExitLib.uni >> new file mode 100644 >> index 000000000000..e8656aae4726 >> --- /dev/null >> +++ b/UefiCpuPkg/Library/VmgExitLib/VmgExitLib.uni >> @@ -0,0 +1,15 @@ >> +// /** @file >> +// VMGEXIT support library instance. >> +// >> +// VMGEXIT support library instance. >> +// >> +// Copyright (c) 2019, Advanced Micro Devices, Inc. All rights reserved.
>> +// SPDX-License-Identifier: BSD-2-Clause-Patent >> +// >> +// **/ >> + >> + >> +#string STR_MODULE_ABSTRACT #language en-US "VMGEXIT Support Library." >> + >> +#string STR_MODULE_DESCRIPTION #language en-US "VMGEXIT Support Library." >> + >> > > > >