Received: by 2002:a25:e74b:0:0:0:0:0 with SMTP id e72csp1701304ybh; Tue, 14 Jul 2020 05:12:50 -0700 (PDT) X-Google-Smtp-Source: ABdhPJz4U1sPHzR8WZUrlKoJKv0+eFIm/X6EmaVmPKfLFRW2Vm/V0ZpCNmDmVuspSN2hZwh1vZsN X-Received: by 2002:a17:907:94c4:: with SMTP id dn4mr4066958ejc.150.1594728770426; Tue, 14 Jul 2020 05:12:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1594728770; cv=none; d=google.com; s=arc-20160816; b=Q/5qR9+vnHlliQtjoK9aJ6pOuD/otzr+Zk382dgDrReVljQ6YPjxeQmHMT9NP8SKKN tk4rvIXO6p8SiX1kBMAACAHfyRZcdyiR0U5KHxLjtLCEjlK0iLixDMGlhvripMPsVLu0 tv8yj76T/coyy9tKC3Ea82j6V2nSkmXh9MlDrg58Y2NGhH0kNidWW1c2/jU/hNsw3+F3 MSBwsQENfuXdXUVIvKMoOwLkzSuTPO8USP/lUBUbggGKfBRLuG7PBcxWd9eq79nsg3uz Tk6gcvEHt3WDyPQugEkA6ZrS60XE2lMbnfS9MQN2v67N6UVHqKLEteZZndrUwWEmedk7 BPog== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=AnK5o42otwAw9+cHSLK/yc/5p1EDi+05ne7psIRWLrs=; b=FJpigTE9dmu84auX3hu7nkk9PV4pJOGwpWKpqmPTCPYXf/X9GnUcighyjTmRfpJXHh YMZLBtJfhTDl01TH+qXDASz0EZxku7qweuDekFjd+FkyemellZQUeR5O6tbHVrmQ/q1E LKtBMmI5WBaHZ9kcz3VQdjZ0/z+nS5vcQ5HwV/fLhucato6FltKTg1zUAlFPnJg2yVrN oyMqTbWT9/XLmSumxFyJRj/XWEJxv0nuIn/66wkbJwg9jKFaWp9qZolLoURnRp0gLh9Y qsmlN+CueRy99in0b+pfl5ZAK5tQDwjJ4X6R4L+wVdGaeHgjEuBOYz09dGedOQ7KlI9x ORNg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=8bytes.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id m25si10570788edr.11.2020.07.14.05.12.26; Tue, 14 Jul 2020 05:12:50 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=8bytes.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1728620AbgGNMLg (ORCPT + 99 others); Tue, 14 Jul 2020 08:11:36 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:60770 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728541AbgGNMLZ (ORCPT ); Tue, 14 Jul 2020 08:11:25 -0400 Received: from theia.8bytes.org (8bytes.org [IPv6:2a01:238:4383:600:38bc:a715:4b6d:a889]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 73139C08C5DF; Tue, 14 Jul 2020 05:11:23 -0700 (PDT) Received: from cap.home.8bytes.org (p5b006776.dip0.t-ipconnect.de [91.0.103.118]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) (No client certificate requested) by theia.8bytes.org (Postfix) with ESMTPSA id B1749FF5; Tue, 14 Jul 2020 14:11:14 +0200 (CEST) From: Joerg Roedel To: x86@kernel.org Cc: Joerg Roedel , Joerg Roedel , Martin Radev , hpa@zytor.com, Andy Lutomirski , Dave Hansen , Peter Zijlstra , Jiri Slaby , Dan Williams , Tom Lendacky , Juergen Gross , Kees Cook , David Rientjes , Cfir Cohen , Erdem Aktas , Masami Hiramatsu , Mike Stunes , Sean Christopherson , linux-kernel@vger.kernel.org, kvm@vger.kernel.org, virtualization@lists.linux-foundation.org Subject: [PATCH v4 75/75] x86/sev-es: Check required CPU features for SEV-ES Date: Tue, 14 Jul 2020 14:09:17 +0200 Message-Id: <20200714120917.11253-76-joro@8bytes.org> X-Mailer: git-send-email 2.27.0 In-Reply-To: <20200714120917.11253-1-joro@8bytes.org> References: <20200714120917.11253-1-joro@8bytes.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Martin Radev Make sure the machine supports RDRAND, otherwise there is no trusted source of of randomness in the system. Signed-off-by: Martin Radev Signed-off-by: Joerg Roedel --- arch/x86/boot/compressed/sev-es.c | 3 +++ arch/x86/kernel/sev-es-shared.c | 15 +++++++++++++++ arch/x86/kernel/sev-es.c | 3 +++ 3 files changed, 21 insertions(+) diff --git a/arch/x86/boot/compressed/sev-es.c b/arch/x86/boot/compressed/sev-es.c index b522c18c0588..eb1a8b5cc753 100644 --- a/arch/x86/boot/compressed/sev-es.c +++ b/arch/x86/boot/compressed/sev-es.c @@ -145,6 +145,9 @@ void sev_es_shutdown_ghcb(void) if (!boot_ghcb) return; + if (!sev_es_check_cpu_features()) + error("SEV-ES CPU Features missing."); + /* * GHCB Page must be flushed from the cache and mapped encrypted again. * Otherwise the running kernel will see strange cache effects when diff --git a/arch/x86/kernel/sev-es-shared.c b/arch/x86/kernel/sev-es-shared.c index 608f76d0d088..56de70cb80d8 100644 --- a/arch/x86/kernel/sev-es-shared.c +++ b/arch/x86/kernel/sev-es-shared.c @@ -9,6 +9,21 @@ * and is included directly into both code-bases. */ +#ifndef __BOOT_COMPRESSED +#define error(v) pr_err(v) +#define has_cpuflag(f) boot_cpu_has(f) +#endif + +static bool __init sev_es_check_cpu_features(void) +{ + if (!has_cpuflag(X86_FEATURE_RDRAND)) { + error("RDRAND instruction not supported - no trusted source of randomness available\n"); + return false; + } + + return true; +} + static void sev_es_terminate(unsigned int reason) { u64 val = GHCB_SEV_TERMINATE; diff --git a/arch/x86/kernel/sev-es.c b/arch/x86/kernel/sev-es.c index 61308f9c8138..481ea00c58b6 100644 --- a/arch/x86/kernel/sev-es.c +++ b/arch/x86/kernel/sev-es.c @@ -682,6 +682,9 @@ void __init sev_es_init_vc_handling(void) if (!sev_es_active()) return; + if (!sev_es_check_cpu_features()) + panic("SEV-ES CPU Features missing"); + /* Initialize per-cpu GHCB pages */ for_each_possible_cpu(cpu) { sev_es_alloc_runtime_data(cpu); -- 2.27.0