Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752089AbdFGTW6 (ORCPT ); Wed, 7 Jun 2017 15:22:58 -0400 Received: from mail-sn1nam01on0056.outbound.protection.outlook.com ([104.47.32.56]:15146 "EHLO NAM01-SN1-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1752480AbdFGTSC (ORCPT ); Wed, 7 Jun 2017 15:18:02 -0400 Authentication-Results: vger.kernel.org; dkim=none (message not signed) header.d=none;vger.kernel.org; dmarc=none action=none header.from=amd.com; From: Tom Lendacky Subject: [PATCH v6 27/34] x86, realmode: Check for memory encryption on the APs To: linux-arch@vger.kernel.org, linux-efi@vger.kernel.org, kvm@vger.kernel.org, linux-doc@vger.kernel.org, x86@kernel.org, kexec@lists.infradead.org, linux-kernel@vger.kernel.org, kasan-dev@googlegroups.com, linux-mm@kvack.org, iommu@lists.linux-foundation.org Cc: Rik van Riel , Radim =?utf-8?b?S3LEjW3DocWZ?= , Toshimitsu Kani , Arnd Bergmann , Jonathan Corbet , Matt Fleming , "Michael S. Tsirkin" , Joerg Roedel , Konrad Rzeszutek Wilk , Paolo Bonzini , Larry Woodman , Brijesh Singh , Ingo Molnar , Borislav Petkov , Andy Lutomirski , "H. Peter Anvin" , Andrey Ryabinin , Alexander Potapenko , Dave Young , Thomas Gleixner , Dmitry Vyukov Date: Wed, 07 Jun 2017 14:17:54 -0500 Message-ID: <20170607191754.28645.22939.stgit@tlendack-t1.amdoffice.net> In-Reply-To: <20170607191309.28645.15241.stgit@tlendack-t1.amdoffice.net> References: <20170607191309.28645.15241.stgit@tlendack-t1.amdoffice.net> User-Agent: StGit/0.17.1-dirty MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-Originating-IP: [165.204.77.1] X-ClientProxiedBy: CY4PR16CA0021.namprd16.prod.outlook.com (10.172.173.31) To MWHPR12MB1149.namprd12.prod.outlook.com (10.169.204.13) X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: MWHPR12MB1149: X-MS-Office365-Filtering-Correlation-Id: cbe74ddb-23c1-4105-a239-08d4add9e8a6 X-MS-Office365-Filtering-HT: Tenant X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001)(48565401081)(201703131423075)(201703031133081);SRVR:MWHPR12MB1149; X-Microsoft-Exchange-Diagnostics: 1;MWHPR12MB1149;3:JL2B4WQz4hRgdQW1i25mMKIqWTLbzVsYcVdNo5kkr3NjtFgUxihKmRmn1aLQh87Y2Ic19Keazt1NtTBBJ+SNU27uTo9o2WfsV2PM4IzL7FMpuc3TktChoyl4sQ64eGa0ypX5bwVcr78yDaHxefYYGsFIAFOVBDyTiasiU7w2Js/mD6A1lyc3KhOhsrZzYqIKPTTW3eNrmojLqTXx7Ng0MTtVmwGNdlaZmayI4uYSLBMB42AIVJFBJHl1igTMFCO8ArkLFG2uqLiPGxg+U7ER7+9i4RcMP9ABz3nMpE1YKPDwubZ/rfZaxhtmDCP5rBde/frUK98kYXfyYqJc2KBA9dK5IZUZ3M4PjiIR1Igb2Bc=;25:t1jBRI2MWk7Mnav/JlYfU/KKO/RQEkVGUiu8SLHX1OfiBbXhXM/aST5omMCHB5AibgTMYFxf2QcAaMP0Zv7aUmaagts1V3zit1ur9g21xDv+VATwRA7MkLCgjjpN/6L7xG+exWIZ1wOIEPOlDmvzUY1TtwSBML/GeWgJWSZQzLs0QpHfyJnRbtXzV5/P01ZBsFkPrqy9BL7jWMnfZ/UQP2TMN8X2EfWgm5lZIE006nBIZHT3CUnBXeOk59XhdDiTJzg6ufDGq9eeBR4T0HjTFsVTbbYpujGT7JyV5TPT6OGLRhI1gMIuddUi7hToWdZR6tixtLZA5mYD8FH6EjQiSTsfo65bgsFf1I3do4GTOG1DD0Wb5iCQJV0gywxBy+0MmTLWGZnNYGG6cfVjOE0eC/I7TXibCSYZL2KD32srNxaqDy2bDLm7TwiUk6NvX2wqG4rIF05mmBBxuqTduRqp6oH+4T0Ak5SasnUYmeY95k0= X-Microsoft-Exchange-Diagnostics: 1;MWHPR12MB1149;31:8/JMxQx0qctyZUb9cs9L/MKadQOEtIt5hRVyaltJFozu1AC4ApnWnwR5wAl6yFo25XlFuQrYhRFOBJx0d/Rtku2lsQ4D+V1C0lgrkm1FmbbaKbQftnGc/esUJJM+m72+UZZqXFuMgJkM4CgB+2vUV1e2CZtj0aqxt92vBgVh+Moq64srEEFPzjhiVkUDmHJRLSBXyT/EpCYUsQD0etrxkTzlsy/1iwnkxJCaY2MKUtY=;20:aljAui/SaWcSlen8qFjY052zAa3+ZDDf/B0LWtbdP++Ue3ruym8dLLEejq9286dTYM3oY8qF2w+7+XH9TvTpTH7xg/3F0lqzPUM8rRlzbaFtwR2uMPZ8dqswgAT7uWJwl9KEmQ720bj8hmJAw+LpBdUhTc/Hws3dyS9jlBowbA6NnYTjLTgdfkOJEdWNII+8nYNozQU/SyZUIrWpXeEFQXmiaUIs3zX0wtw5XXyftHbuEFk3o1/LbyYoKznwX8vhQPbYIMVp7RtaiXOnxgv+m/o41aS4QFt11XnlJhyUKQnJEIht/qoWGj4NbjeMStoOX0jv47avZqHtZZ/YysEhi3lUj6ExilBCAXdCRhTxnyCeAiJwGVv0IuGy/BITtnd1+FHaTS/chq4JUldxMY5pT6KnLtRfHVCWa6LqKd3jQYhPk3H6IqXBhWyXJO6C6ybhB0a1PVCwnPBU/ND6tUh3Vlg0CcU1JwXl0TWjZYCoF96TiHuYNTo+NejEHnsB0aGL X-Microsoft-Antispam-PRVS: X-Exchange-Antispam-Report-Test: UriScan:(767451399110); X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(601004)(2401047)(8121501046)(5005006)(93006095)(93001095)(3002001)(100000703101)(100105400095)(10201501046)(6055026)(6041248)(20161123555025)(20161123558100)(20161123564025)(20161123560025)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(6072148)(100000704101)(100105200095)(100000705101)(100105500095);SRVR:MWHPR12MB1149;BCL:0;PCL:0;RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095);SRVR:MWHPR12MB1149; X-Microsoft-Exchange-Diagnostics: =?utf-8?B?MTtNV0hQUjEyTUIxMTQ5OzQ6cm4yYjZ1Y1ZBWE9IMG13VHpIZDZCWklHODBC?= =?utf-8?B?QnF1T2VnQjVTM1JheGgxRjZxQllybkZMN2tmRTJOZmY1T3FiMGtCb3lHSW5R?= =?utf-8?B?OUpmT2ZXK0tudm9CVUNmSGphcWl3VDZuWWJmdUJQN0hDTytFNG9xYUJSMkZH?= =?utf-8?B?S0dwdUlsOVRiL2NSWnRZSlF0UDRQS3V6T3ZSZFBGM05BTHlMOW1ZUkJzVkQ3?= =?utf-8?B?WTlLa3BGNVg0RlUyN0NNZ3kyRFVNLzhzMnVyMzIzRkRsQWMyWHBJWmN5OEIy?= =?utf-8?B?WmRCVWdhRHhCNzFSUmg3U1RzdU9mS1F0eFNuN0xXeVJWREp3QVFHVHdFbjlD?= =?utf-8?B?czV1MzZ1bFU2UW1JRE5oVjRWdVdwUm1tUEwvRkpOTitudmQrM3o1NzJJd3hu?= =?utf-8?B?aXJJQVp5MTl1ZitOc1BBQlluelBhRC83UXFOVnNPcVY2YXZRYUtrVTA1YVly?= =?utf-8?B?eHU1dXRQV3duUTE5VEtsMnlLbVNqSjFqRlZBamdMMmxIUWo0MEZXQnBjUTQr?= =?utf-8?B?ck10bWdOOFUzQXROOGx3eStyazRTcDEwSGFGdVFTY2lmeFpaaTQyUnAyWmZj?= =?utf-8?B?Y1dwNC8xWWpCazVCUDZ1ei9xSEJUYk1GRnR2WmhtTHZ6Q2xoUlk2UkhQU1Ey?= =?utf-8?B?aVQveUg2eUxlZGcvYXdhUTJmVmRLZG4yeVhtZTlkZHc3YmVLR3RmK2hEY2J5?= =?utf-8?B?azZabVpIK3kyNUs5YkRnaTB1aERZOXYwWUEyK0MxRTJ6cmw3Q0ZXZ0tlc2p6?= =?utf-8?B?ZmxycERpRWRJQ202aHZCRG45ZktaeDJ1bVlOTWt0bGFvbjdOa1dPL3NmMm05?= =?utf-8?B?U09FdmJlSm5BUFlsYmhmd2htV0JPR0N4WjZMckpDQzY5VzFob0hjdHRCcWc0?= =?utf-8?B?c3VuNk95b0ZRY1Q3bFc2dmhERG41aisxd3ZEMzhyQnZtQ2Jnc0ZybGV4dDhL?= =?utf-8?B?eGpteXNaTFlwOUNIZVhydjVQRElmbWlMTk1iV0V0NFlzY2tDYVk4aUZmZHNl?= =?utf-8?B?UGJ3SHY5NjNpZ1FrZnYrUHp0M0o3Lzc1T1A4SnY3TmVnQW1PY1pXcGEyZnMw?= =?utf-8?B?WXFnVHRLRDJMeCtEb1NlbDBqRTNQeFdUUzFoWXFnTlNKd0xXWkNUejZNWDQ5?= =?utf-8?B?elhBa01LRkt6SWxNUkQyLzZwTHBpbTBVKzk1YjQwQ201T05IOGZOMml3TUJI?= =?utf-8?B?b21VN3ZPSnNvYUUvamFSRlVvRWZpWnJZd245Vm9TSEY0RVFteXE0ZkRnNm4z?= =?utf-8?B?dzdoV0V1YkxYcmtCVWVhaFYwcnhFbkV6S1RCUkRhWFg3VGp0aU9IendKcTg4?= =?utf-8?B?cEpxMEJrRkJsNnFwRkhETC9ydnA1dHY5dDlYemtOand3L1RmbDZtZGp0ZGp6?= =?utf-8?B?ZmdSMktXbjhMOXNiV1orelBhNDZGb0NBcDl4V2hsajYrR3dXamx3OHY5Yk50?= =?utf-8?B?RzFPSzZMbWNRMHVHMUZoajMzN1V2TlU2YmJ4cUdhNGpIWmpUVEZSQlhDaVVO?= =?utf-8?B?Z2RHY1NmK0czeVdEQjg4V3Bxekc1YzM4MkErNGl2MXVsT3AxTGI4RW85dk52?= =?utf-8?B?R2d3dmNIMGRseUJIaWtFR3AxaFhOYUFYRFNVWkZMWjlSNjRnN0JKQmtZeWlO?= =?utf-8?Q?1enLoi4xGMCrgKYxolL?= X-Forefront-PRVS: 03319F6FEF X-Forefront-Antispam-Report: SFV:NSPM;SFS:(10009020)(4630300001)(6009001)(39860400002)(39400400002)(39410400002)(39850400002)(39450400003)(39840400002)(6506006)(38730400002)(53416004)(478600001)(72206003)(54906002)(53936002)(66066001)(3846002)(9686003)(110136004)(6116002)(81166006)(54356999)(76176999)(50986999)(4001350100001)(4326008)(86362001)(1076002)(42186005)(97746001)(6666003)(2950100002)(189998001)(47776003)(83506001)(23676002)(33646002)(2906002)(7416002)(230700001)(305945005)(7406005)(50466002)(25786009)(5660300001)(8676002)(55016002)(7736002)(103116003)(921003)(1121003);DIR:OUT;SFP:1101;SCL:1;SRVR:MWHPR12MB1149;H:tlendack-t1.amdoffice.net;FPR:;SPF:None;MLV:sfv;LANG:en; X-Microsoft-Exchange-Diagnostics: =?utf-8?B?MTtNV0hQUjEyTUIxMTQ5OzIzOnBuOFFlKyswVGc4VmdMU1hzVVRlYnZua2xV?= =?utf-8?B?Nk5HbElqR2NGd0NXZHdZSkk4NkdKSEpKRncrQkIwaXJqTWVLdXZsRndINldn?= =?utf-8?B?aGUwdHh5RmpocEJxbzJWZDBqOUlIUXRtcStXdjczRUFNaFE5bUJFODFwTkZz?= =?utf-8?B?UlBGQ0JYaHo1WXZscHB1ek1WT3ZnU1BmZjR0Z1pXeGUrRmo1ODB4bGpNMUlt?= =?utf-8?B?a0ZKc0hENmZMSU9KUmNad0pXNWhRdGNHWjBrWnB3dUVaMHI5ZkZINWROYTZU?= =?utf-8?B?YldMVmNMV3FZRmVUQ3orMjJzOUM5c0xIUXVtcldwTDcyTFU4TjdMenp3Vklh?= =?utf-8?B?TTVjYlhteUtHRGZJVUYxeHg0eDBnVTZUSyt2Qll0ajdNeWp5VDk1UE9tR0ow?= =?utf-8?B?VStiNzZ6S0pJaGh2S3RpR0cydlgrTEl2V2ZVU2JYS3VPUFd2V0RLc3VYUlFB?= =?utf-8?B?UTJ5UTF3ZjNacVgwV2pDckErRXM3Mlc5TTRzbVVaNEhkdG52Qkd2dzJ3djJ2?= =?utf-8?B?WXpFaVFHMjBPSzBmUkgvL1NOc3FHSTNIaXo5NmtJVUVHcFhIeHp0UTNtbHFa?= =?utf-8?B?SXVPbkU3Q1JNbzQ1SlV1Q3BLZmVzbWVCRGs0L05wbjFMYVJrdjYyR3FIcjh0?= =?utf-8?B?dkROcUJscDRLSnBTbVo2WjFOZ3duOTJIZENDNnF2U2kvT21zcjhKL2JCd1FB?= =?utf-8?B?R2xjdWJvR3pkYU1FQzhvQ0xYZUhTYTZlZkc1cFUzYy9ZcExlMWpLK2JZWHM1?= =?utf-8?B?SXVJN1RtTnYzei9wYWM4UFN6U3JrRkR0SXJqQXFQbDllN1BHU0JhbGs0WkZE?= =?utf-8?B?UVF4T0h1S0JzTk1NSXpqWDN1WXFCWm9KaUg5L2svb3gyaUROS2NGMldDZ1Ny?= =?utf-8?B?VTBrQ0tMQmIrcjkwTlV4T0RpZDJkTjQwVktEZzRnZGtsblR2N0ljWGRndEZT?= =?utf-8?B?NnpKWi8wQmdIQW5vcThXa1VCRlhuemVMdDMrR3ZwbTlob0lteGZma3BrQnZF?= =?utf-8?B?cUw0cFJxbERoZWVqQjVEL3pIbnVRWllRdER3emo2TmpYUUFlZFlGanBkSE9W?= =?utf-8?B?Y3E0SkpNRmhIb2xsMEJ0QmlZU1B6YlU5ZVkvVWJOcXROdHdxemdSSTBRMXE0?= =?utf-8?B?aWVzd0VDRmI3NlpHWFRCU3grZTZkWUlrUE1YYWd0RlNmSTUrMVpDNDJ2dXZB?= =?utf-8?B?R1IvRWRsS1h2S1ZTcnNGVml5RkJIQmRMVDFHa2xkWkRvODMzT01yS2tHVDBz?= =?utf-8?B?eFRCL2l1MkRSaGlhaEdJTnJsbE5rQUN1QjVYTFk3ZEsxVlBtL1NyZlJEaWF2?= =?utf-8?B?cWZ5Ui9tYWxvT3hrL2F3eEdHTHNjTk43RVZXUkowc2QwMzlwQysrU2RnN3V2?= =?utf-8?B?YkszeTY3Z3ozSDZkeGE1cStQenFRMEF1SzFUVThITEVaRGt0Mi9hSm53OUZj?= =?utf-8?B?dFhLWGRSUUhDbUl4UmdDWjI3enpzQ29Hdk14NXJWajk4elF4KzJqampXTHhS?= =?utf-8?B?Y2krZkZLc1FablVKQktKZ29yWG83c09LeGw0YmE4Ymg3TWw0NEFqbVg3Rnh5?= =?utf-8?B?cWRNK3FrYXp3eGNLSC9WSWxna2k2M3dkMW5vQzFZYWdBNXNXcm05eVM5Y0xC?= =?utf-8?B?bjNOMm9BU3ZueEZqS1Y2Mlc4WVBJaVIwQ0s0a1lZWTQrM0NrZWZiNmxBeWRC?= =?utf-8?Q?2fJG1dh7T9CPmMbZao=3D?= X-Microsoft-Exchange-Diagnostics: 1;MWHPR12MB1149;6:gXL7ECZqw2ZiCel7GypQhdIv+GbyZjnQ9unsgISBMN9bcke/0WIrxWbJ8/zAUdHJnTD8fsK/7foaEM4XklPbnphaP2Ur5bq2HQh4he5VUPesw/DYwUmH8VyuKw7lLtUvpIJ8qY7LfPELQtz3nljGs58NR2DUEw9y93lQx5zMClw4AQpXlm9ztic9a4bhb5kgcgg1ZTRsQ+M2Sie/d0+ILhcP5Qs6p77oRzc0ufNCvYJs9N7E8S7eMyBgAlBLf/6vXAITTU4zghunB1JiFo4mvWeMmRqp7jLpxyjj5dK0kqHwFKcXa5pN0l9Ip6kgFI9+PuV2ZoW97VDSj6IE3QWQ8GZQpEhLDBvuGk4O6Dc6bMqXeH/PeCJ5IUEFeTXPXA6JJ4ZjMiwoBfE4ru5fvRblh4POia3SfGkX7EcQ24L0i2WhwiogwvcSp3d/ExdnU3rSn7m8fVbwapXr3WLTpuKDUg963VjRcLXgxJgJ34YuxwHCOA2vSu2xaUVkONAQjyMWGLpg/gAB2yR34Pt0LQMNLO4uAjsBme4OGRhn9Q0Mo9w= X-Microsoft-Exchange-Diagnostics: 1;MWHPR12MB1149;5:x8qGJckbVDvnzvRd8kRAoEW89d+iNgGbIBr1i8XqzHvuki5RVKMVDo5LVXwc5zoA+3WKFwv/bURTRtS4K8pqBvNh5xoLGUnULdBwQKq4OjnfsUYWgPZ4ELHMcZ2KmIpqHbBDhqvNm3Ur4KRzwVvUpPT1usFirSCNgw8/ERzlEdo6xoF0K2X0UoUCOj6j5TPOcyzpWDGObZgRfByte4UyGoAeCAcgGLnrL2ajIb5VNvrv19vM9GW73HUWfyKQgD5h4N33fRBQs5YT8UVpNjJe6Rx/PkFPiZmrmpCzhd4+fpFIMfcVnXLOnd0+8r87f6FzndGe/KJ6cEVz0b3aI7GnIUXLpBlGVfuKCzy/VoYrdCSlX9x7STP55f/8A6bSbdrEV3H0LrKgsqwMBN9YzG268by1XtDphf/EwhzYZQln+DPiQ+CYEVMJKZ18TStB8fCkqSr+AmyO+VE+LfmcD9ZeenJrSQBVu/q9mgEPFYHaKiE1y0DxblJOQmzoVXIMeR3Q;24:jhkescqVYkUqroodieILQbhwcII73O18GC0AKB09xq8W3onO1m3WF1zNHWJYYU0DPWrRx7qj1dmmYbXOOI6yEWQl85VUYB80/O9AeFUbUbk= SpamDiagnosticOutput: 1:99 SpamDiagnosticMetadata: NSPM X-Microsoft-Exchange-Diagnostics: 1;MWHPR12MB1149;7:4vzZuAqTy3gM49V9k4OTQUjYZ3FydOZxjVhVXC5IoPXEHkDOLLMsyXtzzYy13METajVa5t2DIdjtpXYc0M/w8PJG8N9ryF8BAFMwTG8xptZq/nmm2968Rc9+yTRsIhuMWR1tdTj/igJYULmpgGvv1hBYWCpNNwUVsdtr4Gp/Z3mwSM68vORzrmw1/exh+2LlArsgDHUCb4JQxEjdg9MHVrOYRDCWu/Qseo4DLkUxfAH/106OHp6gAg/aeVm5BJNMvhzisFVWpseS+8Md49cbyTsDglLuQh3m3LCVJDRfntLV0xLcaEsLoQKV/YXWEfYNeGLacVIkWLAxNLVITRrJFg==;20:ZNzRgbDxubLsex4v9TLtGDOyjGjuMZAibbCbeWWOemzMlQUI0X6a1nYbJNeDqTL5SRydR3w06HBsi5UU8Ov3FYX9fV3xRSWTcLL0FqUd+yyuBB2z66vCCpJUARIGmbhMLG/LNyAHya0gD/g7R01lPIcNHWSBNj9FcO7Hdda5cEOWQzZXB4uTxumwt8W5K2EPUOftMZkiZUzJtrikAJaXrlxfFCxp4dVZw3JNPfZe14hOR5XIGEwwRx+jVVL3qN6S X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 07 Jun 2017 19:17:57.1160 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR12MB1149 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 3454 Lines: 112 Add support to check if memory encryption is active in the kernel and that it has been enabled on the AP. If memory encryption is active in the kernel but has not been enabled on the AP, then set the memory encryption bit (bit 23) of MSR_K8_SYSCFG to enable memory encryption on that AP and allow the AP to continue start up. Signed-off-by: Tom Lendacky --- arch/x86/include/asm/realmode.h | 12 ++++++++++++ arch/x86/realmode/init.c | 4 ++++ arch/x86/realmode/rm/trampoline_64.S | 24 ++++++++++++++++++++++++ 3 files changed, 40 insertions(+) diff --git a/arch/x86/include/asm/realmode.h b/arch/x86/include/asm/realmode.h index 230e190..90d9152 100644 --- a/arch/x86/include/asm/realmode.h +++ b/arch/x86/include/asm/realmode.h @@ -1,6 +1,15 @@ #ifndef _ARCH_X86_REALMODE_H #define _ARCH_X86_REALMODE_H +/* + * Flag bit definitions for use with the flags field of the trampoline header + * in the CONFIG_X86_64 variant. + */ +#define TH_FLAGS_SME_ACTIVE_BIT 0 +#define TH_FLAGS_SME_ACTIVE BIT(TH_FLAGS_SME_ACTIVE_BIT) + +#ifndef __ASSEMBLY__ + #include #include @@ -38,6 +47,7 @@ struct trampoline_header { u64 start; u64 efer; u32 cr4; + u32 flags; #endif }; @@ -69,4 +79,6 @@ static inline size_t real_mode_size_needed(void) void set_real_mode_mem(phys_addr_t mem, size_t size); void reserve_real_mode(void); +#endif /* __ASSEMBLY__ */ + #endif /* _ARCH_X86_REALMODE_H */ diff --git a/arch/x86/realmode/init.c b/arch/x86/realmode/init.c index 195ba29..60373d0 100644 --- a/arch/x86/realmode/init.c +++ b/arch/x86/realmode/init.c @@ -101,6 +101,10 @@ static void __init setup_real_mode(void) trampoline_cr4_features = &trampoline_header->cr4; *trampoline_cr4_features = mmu_cr4_features; + trampoline_header->flags = 0; + if (sme_active()) + trampoline_header->flags |= TH_FLAGS_SME_ACTIVE; + trampoline_pgd = (u64 *) __va(real_mode_header->trampoline_pgd); trampoline_pgd[0] = trampoline_pgd_entry.pgd; trampoline_pgd[511] = init_level4_pgt[511].pgd; diff --git a/arch/x86/realmode/rm/trampoline_64.S b/arch/x86/realmode/rm/trampoline_64.S index dac7b20..614fd70 100644 --- a/arch/x86/realmode/rm/trampoline_64.S +++ b/arch/x86/realmode/rm/trampoline_64.S @@ -30,6 +30,7 @@ #include #include #include +#include #include "realmode.h" .text @@ -92,6 +93,28 @@ ENTRY(startup_32) movl %edx, %fs movl %edx, %gs + /* + * Check for memory encryption support. This is a safety net in + * case BIOS hasn't done the necessary step of setting the bit in + * the MSR for this AP. If SME is active and we've gotten this far + * then it is safe for us to set the MSR bit and continue. If we + * don't we'll eventually crash trying to execute encrypted + * instructions. + */ + bt $TH_FLAGS_SME_ACTIVE_BIT, pa_tr_flags + jnc .Ldone + movl $MSR_K8_SYSCFG, %ecx + rdmsr + bts $MSR_K8_SYSCFG_MEM_ENCRYPT_BIT, %eax + jc .Ldone + + /* + * Memory encryption is enabled but the SME enable bit for this + * CPU has has not been set. It is safe to set it, so do so. + */ + wrmsr +.Ldone: + movl pa_tr_cr4, %eax movl %eax, %cr4 # Enable PAE mode @@ -147,6 +170,7 @@ GLOBAL(trampoline_header) tr_start: .space 8 GLOBAL(tr_efer) .space 8 GLOBAL(tr_cr4) .space 4 + GLOBAL(tr_flags) .space 4 END(trampoline_header) #include "trampoline_common.S"