From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: mx.groups.io; dkim=pass header.i=@amdcloud.onmicrosoft.com header.s=selector2-amdcloud-onmicrosoft-com header.b=C/MxqhEF; spf=none, err=SPF record not found (domain: amd.com, ip: , mailfrom: thomas.lendacky@amd.com) Received: from NAM02-SN1-obe.outbound.protection.outlook.com (NAM02-SN1-obe.outbound.protection.outlook.com []) by groups.io with SMTP; Mon, 19 Aug 2019 14:35:58 -0700 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=K3G9P7LlUYm5KUME/FVyHQE7BeR0nE2Y116xDZmrOXE/PE0+iHYrYq7DI2pDfkydqutwmu0FD6+LINziskfsX0nYqBzdbKiY4cpwJjm6Qq+TNXYtYLfL3wfItt4cZATLprWVcBjrK2+S44StWYj6xW2Zzv7K1rXVpm/Dav3watzcWcyc7vykf1uJBE4NfGVh8QpsFQmC3Jq3bc4dXN59sy9dNfz63zpIk/2cSWuCyrQE0XVyeTwO8nZHeVTSLbZDgbgDFiBpyLhCT4ztuLnK4evTCWbpQE++k3mqpni5j4UOeWPtXn/91b+ImOCejrLC7e+h0vmM/RjeaGZ8LGimeA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=eBNu9cI2kiYnFdSGqYg51XXLaJpdHpfAO8W+UzHTCGU=; b=cjvusd8bpX8QthkDUWq9/UMvPF3OK/Qef6eoxQsIB52lOjXUKxe4TSd0HlHABIKT13Lg53yipjRjt8tuuKlq42p7yaD8My0ZbJ1+hBv1giXwhZYrCdguL1mb7lMNFQF4qyFqeSrTxBKDVl0Bs8i51vLwogYcyHeExim5sfq7klq1XTSme5ItwnhwGIGwuhvZRiFH19omg+Xz0m3f40bWjjYqvL7y1Z1eaqeEUwIPjB1giVTkz+HIovrEwTz/BCyt0KSw5aEicZNUuGsiOLZbvV4lsE3L0P/YCc6CLbsVcvchc9bOdwVcS6CTNmcP6yS6tKO+soDxHsnuXRNtXRliwQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amdcloud.onmicrosoft.com; s=selector2-amdcloud-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=eBNu9cI2kiYnFdSGqYg51XXLaJpdHpfAO8W+UzHTCGU=; b=C/MxqhEF/RTjvLbI0D0+q0WsJ9v1nHi4zbiy3zug3W5oR+xO2DYOvQa4T1eR29GxA5wNPtiaUr0Gg9DfduPE3ozea4bXMDlE2Fgg7JtcQRgZ9Zx1++fm7x8BhofBJ8wHYOK9X461vOXNo+OgGws/KjZ2CQvG1S1OJIqZ3y4h3fs= Received: from BYAPR12MB3158.namprd12.prod.outlook.com (20.179.92.19) by BYAPR12MB2965.namprd12.prod.outlook.com (20.178.52.214) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2178.18; Mon, 19 Aug 2019 21:35:55 +0000 Received: from BYAPR12MB3158.namprd12.prod.outlook.com ([fe80::39b9:76bd:a491:1f27]) by BYAPR12MB3158.namprd12.prod.outlook.com ([fe80::39b9:76bd:a491:1f27%6]) with mapi id 15.20.2157.022; Mon, 19 Aug 2019 21:35:55 +0000 From: "Lendacky, Thomas" To: "devel@edk2.groups.io" CC: Jordan Justen , Laszlo Ersek , Ard Biesheuvel , Michael D Kinney , Liming Gao , Eric Dong , Ray Ni , "Singh, Brijesh" Subject: [RFC PATCH 07/28] OvmfPkg/PlatformPei: Move early GDT into ram when SEV-ES is enabled Thread-Topic: [RFC PATCH 07/28] OvmfPkg/PlatformPei: Move early GDT into ram when SEV-ES is enabled Thread-Index: AQHVVtYVQwjttoEikE67yaNazZWrMg== Date: Mon, 19 Aug 2019 21:35:55 +0000 Message-ID: <79bac50e4cea5e261c694a2b875cc2eff32bea68.1566250534.git.thomas.lendacky@amd.com> References: In-Reply-To: Accept-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-mailer: git-send-email 2.17.1 x-clientproxiedby: SN2PR01CA0031.prod.exchangelabs.com (2603:10b6:804:2::41) To BYAPR12MB3158.namprd12.prod.outlook.com (2603:10b6:a03:132::19) authentication-results: spf=none (sender IP is ) smtp.mailfrom=Thomas.Lendacky@amd.com; x-ms-exchange-messagesentrepresentingtype: 1 x-originating-ip: [165.204.77.1] x-ms-publictraffictype: Email x-ms-office365-filtering-correlation-id: 2fa6bec7-4dd2-485d-8469-08d724ed378b x-ms-office365-filtering-ht: Tenant x-microsoft-antispam: BCL:0;PCL:0;RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600148)(711020)(4605104)(1401327)(4618075)(2017052603328)(7193020);SRVR:BYAPR12MB2965; x-ms-traffictypediagnostic: BYAPR12MB2965: x-ms-exchange-transport-forked: True x-microsoft-antispam-prvs: x-ms-oob-tlc-oobclassifiers: OLM:9508; x-forefront-prvs: 0134AD334F x-forefront-antispam-report: SFV:NSPM;SFS:(10009020)(4636009)(346002)(366004)(376002)(396003)(136003)(39860400002)(189003)(199004)(50226002)(53936002)(316002)(5660300002)(2351001)(52116002)(76176011)(36756003)(6436002)(71200400001)(6512007)(7736002)(256004)(14444005)(86362001)(14454004)(478600001)(305945005)(2906002)(71190400001)(2501003)(64756008)(186003)(118296001)(4326008)(26005)(6486002)(99286004)(1730700003)(386003)(6506007)(66066001)(66476007)(66556008)(8676002)(102836004)(81166006)(25786009)(66446008)(6916009)(54906003)(3846002)(6116002)(486006)(5640700003)(476003)(2616005)(11346002)(446003)(81156014)(66946007)(8936002);DIR:OUT;SFP:1101;SCL:1;SRVR:BYAPR12MB2965;H:BYAPR12MB3158.namprd12.prod.outlook.com;FPR:;SPF:None;LANG:en;PTR:InfoNoRecords;MX:1;A:1; received-spf: None (protection.outlook.com: amd.com does not designate permitted sender hosts) x-ms-exchange-senderadcheck: 1 x-microsoft-antispam-message-info: S6j5gbIClAaa9R+2hfXO3+Xq+dMhl1bOmCuwunthFkpDwljI2rjPLiBbYqzYrauy9cwkzyXE7465YA18SxGqbhkBN1M6A1VNE+5vQRSFcaFMeGW3jO7UVe7VwvjGURmE3w3Jy7gfxHWlaYPzfAqtGzA2+dks9ka8f8m9kzdzEjR0l8QD0xFgf+nmU7chShBA7mTllyQt3K8g9Q2tO1KYyN+howwMOQj274Waae1qaw1NL44O1stUibc68gt5U3pBVs2HaKNbbOVh+Unx/gwpqWv5LmhR/INVwjDk9Za4MgIogfJF2m9YR0tD5x0sKTI2j54czvp/93BAe700rNRDI0GdThfKlOQUEnYi3K0aRjKTHYrHFbPRA5KEWGTcDlo0yVRwEJdrwotOnqSnqFulJnD4hWgtLyCUwqOC1w0Qczw= MIME-Version: 1.0 X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: 2fa6bec7-4dd2-485d-8469-08d724ed378b X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Aug 2019 21:35:55.6442 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: ovF80LpqZYXHYtYcIdrmsmfuln5gMo3mRenC2R0KZwSz1XhvPNOfQcJ6DFXwPt/I478V5UaKntsBT8Kvof8ROQ== X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR12MB2965 Content-Language: en-US Content-Type: text/plain; charset="us-ascii" Content-ID: Content-Transfer-Encoding: quoted-printable From: Tom Lendacky The SEV support will clear the C-bit from non-RAM areas. The early GDT lives in a non-RAM area, so when an exception occurs (like a #VC) the GDT will be read as un-encrypted even though it is encrypted. This will result in a failure to be able to handle the exception. Move the GDT into RAM so it can be accessed without error when running as an SEV-ES guest. Signed-off-by: Tom Lendacky --- OvmfPkg/PlatformPei/AmdSev.c | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/OvmfPkg/PlatformPei/AmdSev.c b/OvmfPkg/PlatformPei/AmdSev.c index 87ac842a1590..5f4983fd36d8 100644 --- a/OvmfPkg/PlatformPei/AmdSev.c +++ b/OvmfPkg/PlatformPei/AmdSev.c @@ -37,6 +37,8 @@ AmdSevEsInitialize ( PHYSICAL_ADDRESS GhcbBasePa; UINTN GhcbPageCount; RETURN_STATUS DecryptStatus, PcdStatus; + IA32_DESCRIPTOR Gdtr; + VOID *Gdt; =20 if (!MemEncryptSevEsIsEnabled ()) { return; @@ -76,6 +78,20 @@ AmdSevEsInitialize ( DEBUG ((DEBUG_INFO, "SEV-ES is enabled, %u GHCB pages allocated starting= at 0x%lx\n", GhcbPageCount, GhcbBase)); =20 AsmWriteMsr64 (MSR_SEV_ES_GHCB, (UINT64)GhcbBasePa); + + // + // The SEV support will clear the C-bit from the non-RAM areas. Since + // the GDT initially lives in that area and it will be read when a #VC + // exception happens, it needs to be moved to RAM for an SEV-ES guest. + // + AsmReadGdtr (&Gdtr); + + Gdt =3D AllocatePool (Gdtr.Limit + 1); + ASSERT (Gdt); + + CopyMem (Gdt, (VOID *) Gdtr.Base, Gdtr.Limit + 1); + Gdtr.Base =3D (UINTN) Gdt; + AsmWriteGdtr (&Gdtr); } =20 /** --=20 2.17.1