From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from NAM12-MW2-obe.outbound.protection.outlook.com (NAM12-MW2-obe.outbound.protection.outlook.com [40.107.244.78]) by mx.groups.io with SMTP id smtpd.web12.47510.1624283800634677996 for ; Mon, 21 Jun 2021 06:56:44 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@amd.com header.s=selector1 header.b=QI46i/4I; spf=permerror, err=parse error for token &{10 18 %{i}._ip.%{h}._ehlo.%{d}._spf.vali.email}: invalid domain name (domain: amd.com, ip: 40.107.244.78, mailfrom: ashish.kalra@amd.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=LoIh+aLhcXsKgc20Z7dsaBgByLot+Rh1iKTsPLtcY1A/4X//ezK9PSJQw06XJ5kaKeWi9llPU0cC+/Kefmf+SqbqFK4KlcseT+Q83gda8+o75ZB3EaTUgpGxLYI97iUFjqF+1X6MWlNZzJvIidMfZZffgsBUs9ioQBkQ2ywXAjzDREeYEl22zk7hsIJlC2trYT7NWaiMrZp9qi9vdtMHwxnTaZ8y2p/9OZED1WZ89/LIyA2IRQnnRwxvQ0UhvgStgvLqJPEf6XeuM2W5Ca1xdZgFFGzw61Fu9m5uQ+QXSVcwSBgSX6LfslggDRui9OkAGkXa9fif/BqLWBB4NocL0w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=KpTPaQeMR4siNN36YXcG30YhNIlj8aM3j3RoSwHHgTg=; b=CRysbi0vTmzxxVoV8nq9I6Nx7c35YvVGkaQHXN+sZpg+2DCxziiJMSmzes6LFtdMPRqB5kPpfQ/l4qbitr+8cvzm8RBh9fKiOYJ0WsLcRo+Pf+C6ygUZCiLwqeTmgNo0hLi5+6Tq7JJteBGWsp4HLx77BO7gEwPlUdeXd5FPZyLlHc74rgOIvDgHmj4DQxDn8/bd7FtWYYOcLQDTVr94tomQXXvmSLvz3dB7H9d8csgLi80CUnyP1ToyadvTcoFxsYHzKQUTgELrjzazUNiV7ZYRCOFXoLcBkbmz4df1641OLIb2VaSdsyz2lcC+SAy9wr5yAvcQvLhtPdHFy0qVOQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=KpTPaQeMR4siNN36YXcG30YhNIlj8aM3j3RoSwHHgTg=; b=QI46i/4IbCTOiUx+Zvmr0SCq/rDghyCqXyBUmz/wfpVK9aeazMOLOyczyP+UPJdUCoz8DNOpD0xUCAZHLcn45kkl4gWmIfCni67rOGfQ18TLSYbtF2VnSlICXbVWPBiUU4IqEVLHTUOZV93qMQQxg1fUpYQTeIcF3idUku/a6pI= Authentication-Results: edk2.groups.io; dkim=none (message not signed) header.d=none;edk2.groups.io; dmarc=none action=none header.from=amd.com; Received: from SN6PR12MB2767.namprd12.prod.outlook.com (2603:10b6:805:75::23) by SA0PR12MB4509.namprd12.prod.outlook.com (2603:10b6:806:9e::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4242.19; Mon, 21 Jun 2021 13:56:39 +0000 Received: from SN6PR12MB2767.namprd12.prod.outlook.com ([fe80::958d:2e44:518c:744c]) by SN6PR12MB2767.namprd12.prod.outlook.com ([fe80::958d:2e44:518c:744c%7]) with mapi id 15.20.4242.023; Mon, 21 Jun 2021 13:56:39 +0000 From: "Ashish Kalra" To: devel@edk2.groups.io Cc: brijesh.singh@amd.com, Thomas.Lendacky@amd.com, jejb@linux.ibm.com, erdemaktas@google.com, jiewen.yao@intel.com, min.m.xu@intel.com, lersek@redhat.com, jordan.l.justen@intel.com, ard.biesheuvel@arm.com Subject: [PATCH v4 0/4] SEV Live Migration support for OVMF. Date: Mon, 21 Jun 2021 13:56:26 +0000 Message-Id: X-Mailer: git-send-email 2.17.1 X-Originating-IP: [165.204.77.1] X-ClientProxiedBy: SA9PR13CA0140.namprd13.prod.outlook.com (2603:10b6:806:27::25) To SN6PR12MB2767.namprd12.prod.outlook.com (2603:10b6:805:75::23) Return-Path: Ashish.Kalra@amd.com MIME-Version: 1.0 X-MS-Exchange-MessageSentRepresentingType: 1 Received: from ashkalra_ubuntu_server.amd.com (165.204.77.1) by SA9PR13CA0140.namprd13.prod.outlook.com (2603:10b6:806:27::25) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4264.7 via Frontend Transport; Mon, 21 Jun 2021 13:56:38 +0000 X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: 3cb64452-ca34-482a-7ac9-08d934bc6428 X-MS-TrafficTypeDiagnostic: SA0PR12MB4509: X-MS-Exchange-Transport-Forked: True X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:8882; X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: Nw37lXuQpv9+eaWhW7L4YlYkweRS4QAusVAZPN4V3Tgm+uJCCT/IG28It36QKGPfD/aezzkJqBect+DQAps3ZLqjq+9ZyszHjju+IQF+Vub/ZQlk18vuySvqU34N0IJZ/u/HxVyuXUUq7OIEPrXUWE53jP63CtS85zOVpXVln1J4+jYxoiuam0pXNJIbCF6TBnkO0QOdF36VhJk5s7Z6pja9zPHhMujTtHj4giS5yNj5qpaeE7It0RasY2MbvMePcP2NxwAH6dIpu6AQoYk4JFA8EfIqV8x1PZUOnu6G4mHOnOBF/jZJgkHCQ611hbIk2hYbRrkk5beOtEDaCE0FWDNw+jEkvkMi5VLhgbHPuqI4vsEqm1C+dY1SvaWZjYlIO9xsZ0yWynRK/w/pPri1ITHBsWO1yAmVNPbIa5RgFM+jPvJ+akEXvJ8U5ibMZpMh2+OMh5LnEvZfjfKipP9FEfrbXzXVsJ//BLjDBR9JJmoeZzxmT+JaNFUntGtgm+dyS9nDg0CIBECJe6BZ37fK+p4rIqJtL5diOCukLVaW5SLeFmtTa4K9zW5kOqPaX6EJGioGdr95Rs/HB3XcZBJzia0Htdkwk2kLaa5+qbRISCNJm44WpP1bQyzIpBWL1nPL4gEJshsSKVxFPz3bNpTqCo2UoKrIX26ZLilPvMfoVkvwMMPdYW1FcyOFtlfJGKjz/XLFESB/k77k5cRZjWLPmiHDVoWM8z66FkDDsAgHm2VwQCit8Zk8SHub4jfqV3TjORPZeHlpimOPyW1nPPqqHg== X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:SN6PR12MB2767.namprd12.prod.outlook.com;PTR:;CAT:NONE;SFS:(4636009)(39860400002)(366004)(376002)(346002)(136003)(396003)(66556008)(316002)(8936002)(66476007)(6916009)(52116002)(7696005)(956004)(83380400001)(966005)(2906002)(478600001)(2616005)(6666004)(66946007)(5660300002)(6486002)(26005)(8676002)(36756003)(186003)(4326008)(16526019)(19627235002)(38350700002)(38100700002)(86362001);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?UhWRD0AAqYsdgjxDBefo2KRHXAG9YpRGZHxVb6yz4YyXibc8UUrnIQs6LX4A?= =?us-ascii?Q?R0fr461nucRc/G82zkiQ7+r4SCXn3dyzFHbG/RfiXn9rcZtHWc/cQFu7XGIR?= =?us-ascii?Q?RVidz2zRzLaPekfYlJ+aopBHSqAdS85phku6V4L6hXlhGve9tdP1/iKXCmQG?= =?us-ascii?Q?1Y8FaR995E40F58CONxGRmQMxCiyiCdqDDXvfdyctM/8XVbOc4t2++eaTKP+?= =?us-ascii?Q?mJpg3wmhccDOxbJP9p3s7eEAbb+glxKJ5spSuJoUGl1R7gaLwyck+hgvErf8?= =?us-ascii?Q?fiW/2CTsPaOY67hTsX5C+smdkPb2kjz33GFh2Xryp2g0as2XGYipdAJHYr6H?= =?us-ascii?Q?Q7GrJIvygOK0hBKVpo/0zydb+B6vg79TKDSqmtcqTxM6cpfPBAjhAsuHMcXm?= =?us-ascii?Q?FMiRq0bFUTkxqXF3w0C6kMKyZKUDHnwReI4f+JTZJUwYdo90zN3pkMs2Oxsw?= =?us-ascii?Q?3strA/seOR9JxYhCSfCdL9CgW/XUcFOgUI78aLxlCfBJPvynYtvFOk36CWhY?= =?us-ascii?Q?s4HU6gfzy2YrGyKzsa+uo3+xEVhD6xi1eRCJW8CocUyfvsimfuNGnxNj3lMH?= =?us-ascii?Q?YfJNsQQPFd+F9N/VrzktiDQc4gdhQ/QgNIux2/7xmu0KAdXoGko12FXJKwTZ?= =?us-ascii?Q?XXBx1FvJwy3M1XLfaiuKCuWrh/Ot5ZhcLWo52Stzt/H0qQOy4BFwLcHs2gzP?= =?us-ascii?Q?9vrJqd3QcTeuXg7CQ7/yQcg0Bqul3pRtdlaYjESQeKEP9GXfm8LuDJJetw6x?= =?us-ascii?Q?+ZbGIgSuf0IH2QgMWbjoUCSHBYYjc/b1HqroEM/rlkUIu5U0hKr5j2musW9O?= =?us-ascii?Q?IZcCJ6EIroW+Q/uZUnPtnM2NNUE57lo1gbFj508Q6Q5DD+JXNcy5jyH/gLkW?= =?us-ascii?Q?LzFTlaO0UPbyCldWhSmSOlvlHipk04ue7RN4rU60fSZZZnYyYOqmC3MR2eb7?= =?us-ascii?Q?4RwumZRqCpU5yNz1B+3FZf9OXvyWKog72WTlLxjiV8K1KBvpKf9foKfLHgbD?= =?us-ascii?Q?yQ5VNd8WzINH8yXZOCj51x6FpV30U2XzPfvNCCCU/iB9lW2MN3AM8fdq8i0e?= =?us-ascii?Q?L8ecqyIGKGoy+y0xH1N34287nUivj5NArJ9Knt5kM4e3UaNr8wfuoGXXj75H?= =?us-ascii?Q?io1z+2RfnNMEiKCcqpxVXOuId9fFGGErr3C5ge89muXsuRCPiwOz2f9hGOk5?= =?us-ascii?Q?L4PegboriJdmYFmp4B3oqAtYPb6mWfJV4e9pA3CcRonEr7Y9Oi1PxbAE6UZH?= =?us-ascii?Q?VYsN8Qq3/lhkg6dYt31+6G6BEBeOynWBAK1nP3sdkHst/+reVlwAdq6RPwS7?= =?us-ascii?Q?IHD94caPuRAE/zqiaBCf+DiA?= X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: 3cb64452-ca34-482a-7ac9-08d934bc6428 X-MS-Exchange-CrossTenant-AuthSource: SN6PR12MB2767.namprd12.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Jun 2021 13:56:39.0635 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: qpuxmaPSR3KpwxPFGKCt1W94P3DIJSplXeVZWg4Eg3tFICPGP4OfJ8tecHgGWh7nZsdvTQI95l8yii3rctQK6g== X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA0PR12MB4509 Content-Type: text/plain From: Ashish Kalra By default all the SEV guest memory regions are considered encrypted, if a guest changes the encryption attribute of the page (e.g mark a page as decrypted) then notify hypervisor. Hypervisor will need to track the unencrypted pages. The information will be used during guest live migration, guest page migration and guest debugging. The patch-set adds a new SEV and SEV-ES hypercall abstraction library to support SEV Page encryption/decryption status hypercalls for SEV and SEV-ES guests. BaseMemEncryptSevLib invokes hypercalls via this new hypercall library. The patch-set detects if it is running under KVM hypervisor and then checks for SEV live migration feature support via KVM_FEATURE_CPUID, if detected setup a new UEFI enviroment variable to indicate OVMF support for SEV live migration. A branch containing these patches is available here: https://github.com/ashkalra/edk2/tree/sev_live_migration_v4 Changes since v3: - Fix all DSC files under OvmfPkg except X64 to add support for BaseMemEncryptLib and add NULL instance of BaseMemEncryptLib for 32 bit platforms. - Add the MemEncryptHypercallLib-related files to Maintainers.txt, in section "OvmfPkg: Confidential Computing". - Add support for the new KVM_HC_MAP_GPA_RANGE hypercall interface. - Add patch for SEV live migration support. Changes since v2: - GHCB_BASE setup during reset-vector as decrypted is marked explicitly in the hypervisor page encryption bitmap after setting the PcdSevEsIsEnabled PCD. Changes since v1: - Mark GHCB_BASE setup during reset-vector as decrypted explicitly in the hypervisor page encryption bitmap. - Resending the series with correct shallow threading. Ashish Kalra (3): OvmfPkg/MemEncryptHypercallLib: add library to support SEV hypercalls. OvmfPkg/PlatformPei: Mark SEC GHCB page as unencrypted via hypercall OvmfPkg/PlatformDxe: Add support for SEV live migration. Brijesh Singh (1): OvmfPkg/BaseMemEncryptLib: Support to issue unencrypted hypercall Maintainers.txt | 2 + OvmfPkg/Include/Guid/MemEncryptLib.h | 20 ++++ .../Include/Library/MemEncryptHypercallLib.h | 43 +++++++ .../DxeMemEncryptSevLib.inf | 1 + .../PeiMemEncryptSevLib.inf | 1 + .../X64/PeiDxeVirtualMemory.c | 22 ++++ .../Ia32/MemEncryptHypercallLib.c | 37 ++++++ .../MemEncryptHypercallLib.inf | 42 +++++++ .../X64/AsmHelperStub.nasm | 28 +++++ .../X64/MemEncryptHypercallLib.c | 105 +++++++++++++++++ OvmfPkg/OvmfPkg.dec | 1 + OvmfPkg/OvmfPkgIa32.dsc | 1 + OvmfPkg/OvmfPkgIa32X64.dsc | 1 + OvmfPkg/OvmfPkgX64.dsc | 1 + OvmfPkg/OvmfXen.dsc | 1 + OvmfPkg/PlatformDxe/AmdSev.c | 108 ++++++++++++++++++ OvmfPkg/PlatformDxe/Platform.c | 5 + OvmfPkg/PlatformDxe/Platform.inf | 2 + OvmfPkg/PlatformDxe/PlatformConfig.h | 5 + OvmfPkg/PlatformPei/AmdSev.c | 10 ++ 20 files changed, 436 insertions(+) create mode 100644 OvmfPkg/Include/Guid/MemEncryptLib.h create mode 100644 OvmfPkg/Include/Library/MemEncryptHypercallLib.h create mode 100644 OvmfPkg/Library/MemEncryptHypercallLib/Ia32/MemEncryptHypercallLib.c create mode 100644 OvmfPkg/Library/MemEncryptHypercallLib/MemEncryptHypercallLib.inf create mode 100644 OvmfPkg/Library/MemEncryptHypercallLib/X64/AsmHelperStub.nasm create mode 100644 OvmfPkg/Library/MemEncryptHypercallLib/X64/MemEncryptHypercallLib.c create mode 100644 OvmfPkg/PlatformDxe/AmdSev.c -- 2.17.1