From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from NAM12-DM6-obe.outbound.protection.outlook.com (NAM12-DM6-obe.outbound.protection.outlook.com [40.107.243.67]) by mx.groups.io with SMTP id smtpd.web11.1226.1585071686106387436 for ; Tue, 24 Mar 2020 10:41:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@amdcloud.onmicrosoft.com header.s=selector2-amdcloud-onmicrosoft-com header.b=Y56R9i40; spf=none, err=SPF record not found (domain: amd.com, ip: 40.107.243.67, mailfrom: thomas.lendacky@amd.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=k7BzTcRxcg//WfRuK0nsxxzOFh4+eCuWOB6nD5iCKBJkFBrC6bI5UMFU6zgNCrTwWWteJVg/klKq/yi4yxjY7HrqeMxwWcbkfsS8ihqEiQtE9ZQ3SsG1PDIuROJvWS4iZZ+g5uou8PWdtsMYEJMyQ2Dom5ZAdlm6b68aEj6sJ2aiFxpsgb/EgEVtMnH4XW7vQm4A5c3wFnLl7bbjqfRZAN57zRbEfc6jkCc0yZ2NjVmxv9ZnQtvEw/zOT0ddo9PTQc4d0OyN894ww4U3NnWC9WhJqRIxv8fwvBUAMaPw8v6Vi4cT3wY4vfAVdXTaj61H4KtWzzZGeFn7FSLlG5dwVA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=jJlLQdGhCHbhU9GuxXyPZlDEUY2MSYZuTv3BBLs2ccs=; b=JTHQDj+FH98YreINDrFJTIsEdvLFjvM7fwgsjNGIhhw6J3mQmlJmp0x5f2ARSpth1Bw8rOIh2ZNdfVDmWYvixl3qaW6sI8kWrzwN6YDvqf+rILL9QPHnFllVAvQg0cCayougUdjf8XzI7ZidN9N037jVaBhtehFgqSNAeznTckqypXL9ORUDN9j24WYjy31rt2r/6aVCcM5x/mTHxziCOnvKdAZ5cM1N1RN7fy0oUW9jVNWkEnoQtizup+4eBHTzxyr6iwqMX7owZ+zpqxo3Xjm2Ouut/dml7LYn8FPk4IjBjLWBqbSNTielUsmftpJhqELktR2jtYr2XHJPekysUA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amdcloud.onmicrosoft.com; s=selector2-amdcloud-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=jJlLQdGhCHbhU9GuxXyPZlDEUY2MSYZuTv3BBLs2ccs=; b=Y56R9i40Gwolf4SpQ7ZsBE+aLrd3o2rm3uiCqhPZIW+clG75gftz+8U+/gQL3ANAtxm0hxC4wvYAILyMY3zG0QsuWtc6+ixKke1rv1GKkZbigSvMihCch/aT0b66GsPSBEaqE1c4y01fFaS+anfHmmJb56QcRQL3mimP7bZqaRI= Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Thomas.Lendacky@amd.com; Received: from DM6PR12MB3163.namprd12.prod.outlook.com (2603:10b6:5:15e::26) by DM6PR12MB3915.namprd12.prod.outlook.com (2603:10b6:5:1c4::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2835.22; Tue, 24 Mar 2020 17:41:24 +0000 Received: from DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::f0f9:a88f:f840:2733]) by DM6PR12MB3163.namprd12.prod.outlook.com ([fe80::f0f9:a88f:f840:2733%7]) with mapi id 15.20.2835.023; Tue, 24 Mar 2020 17:41:24 +0000 From: "Lendacky, Thomas" To: devel@edk2.groups.io Cc: Jordan Justen , Laszlo Ersek , Ard Biesheuvel , Michael D Kinney , Liming Gao , Eric Dong , Ray Ni , Brijesh Singh Subject: [PATCH v6 15/42] UefiCpuPkg/CpuExceptionHandler: Add support for NPF NAE events (MMIO) Date: Tue, 24 Mar 2020 12:40:29 -0500 Message-Id: <7c9a14e2515f6a41f9da0bce75770222f823ea4e.1585071656.git.thomas.lendacky@amd.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: References: X-ClientProxiedBy: DM5PR06CA0025.namprd06.prod.outlook.com (2603:10b6:3:5d::11) To DM6PR12MB3163.namprd12.prod.outlook.com (2603:10b6:5:15e::26) Return-Path: thomas.lendacky@amd.com MIME-Version: 1.0 X-MS-Exchange-MessageSentRepresentingType: 1 Received: from tlendack-t1.amd.com (165.204.77.1) by DM5PR06CA0025.namprd06.prod.outlook.com (2603:10b6:3:5d::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2835.19 via Frontend Transport; Tue, 24 Mar 2020 17:41:23 +0000 X-Mailer: git-send-email 2.17.1 X-Originating-IP: [165.204.77.1] X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-HT: Tenant X-MS-Office365-Filtering-Correlation-Id: e165969a-3399-431e-0570-08d7d01a9266 X-MS-TrafficTypeDiagnostic: DM6PR12MB3915:|DM6PR12MB3915: X-MS-Exchange-Transport-Forked: True X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:7219; X-Forefront-PRVS: 03524FBD26 X-Forefront-Antispam-Report: SFV:NSPM;SFS:(10009020)(4636009)(376002)(366004)(346002)(136003)(396003)(39860400002)(8676002)(8936002)(186003)(316002)(54906003)(16526019)(956004)(66476007)(36756003)(6486002)(19627235002)(66946007)(6916009)(66556008)(2616005)(26005)(4326008)(966005)(81156014)(478600001)(81166006)(5660300002)(2906002)(7696005)(52116002)(86362001)(136400200001);DIR:OUT;SFP:1101;SCL:1;SRVR:DM6PR12MB3915;H:DM6PR12MB3163.namprd12.prod.outlook.com;FPR:;SPF:None;LANG:en;PTR:InfoNoRecords; Received-SPF: None (protection.outlook.com: amd.com does not designate permitted sender hosts) X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: ZqQ3kO71OAPotXfyN8iI20VJ6DAxo0EuojZxEfvIIetiR9+GpPv1V0JPGBf8CCPXDTogWCossoGIT5vRIptbl0XTMyc9YEwEBz+ZIlN2TpYkQoQX/oodFyRDWHx27mT2idbS6niMkul6MSPJ+aYGPLavb7gcWUC0/nG4CJcuHLdtwaHe/G+Xs5oJEZMFGtMEjfxCvRoImQ28bYeFK75WATRzSljwy/UEa19FRcutz9k9rux60DmiHyKLcNjS0ygDWV9Fngdtk5V7PLa/lrzS/L9L7uorEUcOhC2chOJw0ACcwr1fkZExpWvpNZeQseyhMxxBLkgoPyuo9oOev31tKgz9qHO5cjLGDt7qkVlVvlEvyp1lGHsOvCvR9aCPAQuE0pNDf3+WoAMdDzmujatJAM773DJeVGqQhTCBN+SG6mFLEbw4neOTXFaV4CoBd7e/Nk0msWvje6yXNuwoeXXYNKbX0zEsSOpS3aUmtEk+QzM/rrNUpGk+BNvYnT9XetNp3fiY/2rBVLS4TqDmbYXfrE66JcG3IFQSpYGLFpxZC7yhI0U2X8OSh8ywkm3rNx0y5o8BSvIec4sqyzS2sp6v/g== X-MS-Exchange-AntiSpam-MessageData: QcpcVJt5DkinOEUWRvD1rKoQtN8NA114Yz5vuS+YfMiOHZ7+s+LzUcPgsTEEi32CHha8w5D3Aft1rdDkCSqWWxAwJOJRWnn82ldNbaJABkr9OJmLDGe9w8wYRIKMyuQKfziDjS/lk6d5W2nmfzjdHA== X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: e165969a-3399-431e-0570-08d7d01a9266 X-MS-Exchange-CrossTenant-OriginalArrivalTime: 24 Mar 2020 17:41:24.1970 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: QGkieb+JZJQ4+sC8cL13gV0EqHnZtkMHG912PYrv25bMglLJybtgwAPxfhFVUiiboBlsnH7Uhlurd5oWmJJZAg== X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR12MB3915 Content-Type: text/plain BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=2198 Under SEV-ES, a NPF intercept for an NPT entry with a reserved bit set generates a #VC exception. This condition is assumed to be an MMIO access. VMGEXIT must be used to allow the hypervisor to handle this intercept. Add support to construct the required GHCB values to support a NPF NAE event for MMIO. Parse the instruction that generated the #VC exception, setting the required register values in the GHCB and creating the proper SW_EXIT_INFO1, SW_EXITINFO2 and SW_SCRATCH values in the GHCB. Cc: Eric Dong Cc: Ray Ni Cc: Laszlo Ersek Signed-off-by: Tom Lendacky --- .../X64/ArchAMDSevVcHandler.c | 305 +++++++++++++++++- 1 file changed, 303 insertions(+), 2 deletions(-) diff --git a/UefiCpuPkg/Library/CpuExceptionHandlerLib/X64/ArchAMDSevVcHandler.c b/UefiCpuPkg/Library/CpuExceptionHandlerLib/X64/ArchAMDSevVcHandler.c index 26de6304a176..3cac613c8889 100644 --- a/UefiCpuPkg/Library/CpuExceptionHandlerLib/X64/ArchAMDSevVcHandler.c +++ b/UefiCpuPkg/Library/CpuExceptionHandlerLib/X64/ArchAMDSevVcHandler.c @@ -86,8 +86,8 @@ typedef struct { UINT8 Scale; } Sib; - UINTN RegData; - UINTN RmData; + INTN RegData; + INTN RmData; } SEV_ES_INSTRUCTION_OPCODE_EXT; typedef struct { @@ -159,6 +159,198 @@ GhcbSetRegValid ( Ghcb->SaveArea.ValidBitmap[RegIndex] |= (1 << RegBit); } +STATIC +INT64 * +GetRegisterPointer ( + EFI_SYSTEM_CONTEXT_X64 *Regs, + UINT8 Register + ) +{ + UINT64 *Reg; + + switch (Register) { + case 0: + Reg = &Regs->Rax; + break; + case 1: + Reg = &Regs->Rcx; + break; + case 2: + Reg = &Regs->Rdx; + break; + case 3: + Reg = &Regs->Rbx; + break; + case 4: + Reg = &Regs->Rsp; + break; + case 5: + Reg = &Regs->Rbp; + break; + case 6: + Reg = &Regs->Rsi; + break; + case 7: + Reg = &Regs->Rdi; + break; + case 8: + Reg = &Regs->R8; + break; + case 9: + Reg = &Regs->R9; + break; + case 10: + Reg = &Regs->R10; + break; + case 11: + Reg = &Regs->R11; + break; + case 12: + Reg = &Regs->R12; + break; + case 13: + Reg = &Regs->R13; + break; + case 14: + Reg = &Regs->R14; + break; + case 15: + Reg = &Regs->R15; + break; + default: + Reg = NULL; + } + ASSERT (Reg != NULL); + + return (INT64 *) Reg; +} + +STATIC +VOID +UpdateForDisplacement ( + SEV_ES_INSTRUCTION_DATA *InstructionData, + UINTN Size + ) +{ + InstructionData->DisplacementSize = Size; + InstructionData->Immediate += Size; + InstructionData->End += Size; +} + +STATIC +BOOLEAN +IsRipRelative ( + SEV_ES_INSTRUCTION_DATA *InstructionData + ) +{ + SEV_ES_INSTRUCTION_OPCODE_EXT *Ext = &InstructionData->Ext; + + return ((InstructionData == LongMode64Bit) && + (Ext->ModRm.Mod == 0) && + (Ext->ModRm.Rm == 5) && + (InstructionData->SibPresent == FALSE)); +} + +STATIC +UINTN +GetEffectiveMemoryAddress ( + EFI_SYSTEM_CONTEXT_X64 *Regs, + SEV_ES_INSTRUCTION_DATA *InstructionData + ) +{ + SEV_ES_INSTRUCTION_OPCODE_EXT *Ext = &InstructionData->Ext; + INTN EffectiveAddress = 0; + + if (IsRipRelative (InstructionData)) { + /* RIP-relative displacement is a 32-bit signed value */ + INT32 RipRelative = *(INT32 *) InstructionData->Displacement; + + UpdateForDisplacement (InstructionData, 4); + return (UINTN) ((INTN) Regs->Rip + RipRelative); + } + + switch (Ext->ModRm.Mod) { + case 1: + UpdateForDisplacement (InstructionData, 1); + EffectiveAddress += (INT8) (*(INT8 *) (InstructionData->Displacement)); + break; + case 2: + switch (InstructionData->AddrSize) { + case Size16Bits: + UpdateForDisplacement (InstructionData, 2); + EffectiveAddress += (INT16) (*(INT16 *) (InstructionData->Displacement)); + break; + default: + UpdateForDisplacement (InstructionData, 4); + EffectiveAddress += (INT32) (*(INT32 *) (InstructionData->Displacement)); + break; + } + break; + } + + if (InstructionData->SibPresent) { + if (Ext->Sib.Index != 4) { + EffectiveAddress += (*GetRegisterPointer (Regs, Ext->Sib.Index) << Ext->Sib.Scale); + } + + if ((Ext->Sib.Base != 5) || Ext->ModRm.Mod) { + EffectiveAddress += *GetRegisterPointer (Regs, Ext->Sib.Base); + } else { + UpdateForDisplacement (InstructionData, 4); + EffectiveAddress += (INT32) (*(INT32 *) (InstructionData->Displacement)); + } + } else { + EffectiveAddress += *GetRegisterPointer (Regs, Ext->ModRm.Rm); + } + + return (UINTN) EffectiveAddress; +} + +STATIC +VOID +DecodeModRm ( + EFI_SYSTEM_CONTEXT_X64 *Regs, + SEV_ES_INSTRUCTION_DATA *InstructionData + ) +{ + SEV_ES_INSTRUCTION_REX_PREFIX *RexPrefix = &InstructionData->RexPrefix; + SEV_ES_INSTRUCTION_OPCODE_EXT *Ext = &InstructionData->Ext; + SEV_ES_INSTRUCTION_MODRM *ModRm = &InstructionData->ModRm; + SEV_ES_INSTRUCTION_SIB *Sib = &InstructionData->Sib; + + InstructionData->ModRmPresent = TRUE; + ModRm->Uint8 = *(InstructionData->End); + + InstructionData->Displacement++; + InstructionData->Immediate++; + InstructionData->End++; + + Ext->ModRm.Mod = ModRm->Bits.Mod; + Ext->ModRm.Reg = (RexPrefix->Bits.R << 3) | ModRm->Bits.Reg; + Ext->ModRm.Rm = (RexPrefix->Bits.B << 3) | ModRm->Bits.Rm; + + Ext->RegData = *GetRegisterPointer (Regs, Ext->ModRm.Reg); + + if (Ext->ModRm.Mod == 3) { + Ext->RmData = *GetRegisterPointer (Regs, Ext->ModRm.Rm); + } else { + if (ModRm->Bits.Rm == 4) { + InstructionData->SibPresent = TRUE; + Sib->Uint8 = *(InstructionData->End); + + InstructionData->Displacement++; + InstructionData->Immediate++; + InstructionData->End++; + + Ext->Sib.Scale = Sib->Bits.Scale; + Ext->Sib.Index = (RexPrefix->Bits.X << 3) | Sib->Bits.Index; + Ext->Sib.Base = (RexPrefix->Bits.B << 3) | Sib->Bits.Base; + } + + Ext->RmData = GetEffectiveMemoryAddress (Regs, InstructionData); + } +} + STATIC VOID DecodePrefixes ( @@ -294,6 +486,111 @@ UnsupportedExit ( return Status; } +STATIC +UINT64 +MmioExit ( + GHCB *Ghcb, + EFI_SYSTEM_CONTEXT_X64 *Regs, + SEV_ES_INSTRUCTION_DATA *InstructionData + ) +{ + UINT64 ExitInfo1, ExitInfo2, Status; + UINTN Bytes; + INTN *Register; + + Bytes = 0; + + switch (*(InstructionData->OpCodes)) { + /* MMIO write */ + case 0x88: + Bytes = 1; + case 0x89: + DecodeModRm (Regs, InstructionData); + Bytes = (Bytes) ? Bytes + : (InstructionData->DataSize == Size16Bits) ? 2 + : (InstructionData->DataSize == Size32Bits) ? 4 + : (InstructionData->DataSize == Size64Bits) ? 8 + : 0; + + if (InstructionData->Ext.ModRm.Mod == 3) { + /* NPF on two register operands??? */ + return UnsupportedExit (Ghcb, Regs, InstructionData); + } + + ExitInfo1 = InstructionData->Ext.RmData; + ExitInfo2 = Bytes; + CopyMem (Ghcb->SharedBuffer, &InstructionData->Ext.RegData, Bytes); + + Ghcb->SaveArea.SwScratch = (UINT64) Ghcb->SharedBuffer; + Status = VmgExit (Ghcb, SvmExitMmioWrite, ExitInfo1, ExitInfo2); + if (Status) { + return Status; + } + break; + + case 0xC6: + Bytes = 1; + case 0xC7: + DecodeModRm (Regs, InstructionData); + Bytes = (Bytes) ? Bytes + : (InstructionData->DataSize == Size16Bits) ? 2 + : (InstructionData->DataSize == Size32Bits) ? 4 + : 0; + + InstructionData->ImmediateSize = Bytes; + InstructionData->End += Bytes; + + ExitInfo1 = InstructionData->Ext.RmData; + ExitInfo2 = Bytes; + CopyMem (Ghcb->SharedBuffer, InstructionData->Immediate, Bytes); + + Ghcb->SaveArea.SwScratch = (UINT64) Ghcb->SharedBuffer; + Status = VmgExit (Ghcb, SvmExitMmioWrite, ExitInfo1, ExitInfo2); + if (Status) { + return Status; + } + break; + + /* MMIO read */ + case 0x8A: + Bytes = 1; + case 0x8B: + DecodeModRm (Regs, InstructionData); + Bytes = (Bytes) ? Bytes + : (InstructionData->DataSize == Size16Bits) ? 2 + : (InstructionData->DataSize == Size32Bits) ? 4 + : (InstructionData->DataSize == Size64Bits) ? 8 + : 0; + if (InstructionData->Ext.ModRm.Mod == 3) { + /* NPF on two register operands??? */ + return UnsupportedExit (Ghcb, Regs, InstructionData); + } + + ExitInfo1 = InstructionData->Ext.RmData; + ExitInfo2 = Bytes; + + Ghcb->SaveArea.SwScratch = (UINT64) Ghcb->SharedBuffer; + Status = VmgExit (Ghcb, SvmExitMmioRead, ExitInfo1, ExitInfo2); + if (Status) { + return Status; + } + + Register = GetRegisterPointer (Regs, InstructionData->Ext.ModRm.Reg); + if (Bytes == 4) { + /* Zero-extend for 32-bit operation */ + *Register = 0; + } + CopyMem (Register, Ghcb->SharedBuffer, Bytes); + break; + + default: + Status = GP_EXCEPTION; + ASSERT (FALSE); + } + + return Status; +} + STATIC UINT64 MsrExit ( @@ -607,6 +904,10 @@ DoVcCommon ( NaeExit = MsrExit; break; + case SvmExitNpf: + NaeExit = MmioExit; + break; + default: NaeExit = UnsupportedExit; } -- 2.17.1