Received: by 2002:a05:6a10:9afc:0:0:0:0 with SMTP id t28csp1771645pxm; Thu, 24 Feb 2022 09:04:07 -0800 (PST) X-Google-Smtp-Source: ABdhPJwzGdl+CWUPv4VQYu06IqdgdSkmQH5JBwh8HYa+xrRe0HrO0fyNXjOmy6jPFrt2mM9wKSxC X-Received: by 2002:a63:7784:0:b0:374:9cf0:ccc1 with SMTP id s126-20020a637784000000b003749cf0ccc1mr2996626pgc.245.1645722246462; Thu, 24 Feb 2022 09:04:06 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1645722246; cv=pass; d=google.com; s=arc-20160816; b=gUlePYW+LR6PHDrQiOXqibPNhRovzlj+2YFAZhsQ6Z0JtFQqu7B6+OIOo9U0x5kDmu bRU7q2x2ixnbc3nxp8mL2B9E5o56+4wu8WCGyDTJR4kAd6Bnp+a8YyEVcB8w95hfWGfT PIzH3zoZCvzr4t+V/M2+KPUEnwwEak1m25W7vr3s9ssLQEXR/ENLNcOaHc6CFNhMNzmI 1ieYarqaBgWSH/8936fH9qb4dCVBR3EuWSEtWRDKHx5LrNq600D6TakUNaAnpyo+BjyJ 9KuKrMj6Hg6iAm6i8CCqPQDw/SdajBLzFXmpEkctEEOnRq7xA8L1yrcOmA65Y6zvOq4M Mh6A== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=6fi9I656e4S7H65ZCsOcfeus2dxhg7jtErrinnMHud8=; b=hk8AiFmG+Zwzux3arlA7rhVQ4vZ714bu00jCKJs3d6vmkRDfadzmoDgtcmA0mOI9Bs LRjxbjZrWP8Q+IATn+tgAa1k36aMZgHEavyEaYjk95SV0fZXfPzs0H/H10c5oUc0GcKi 8bUX38zUhURgrLL+iJs4bzqERiA2R31y7EwLk0N64Aj6I817CXm3H22q9ogT6BDo8xrs i7HwPVEYftmpEBJ0orDTRYo0lAKv7QyPqhI/ebgQaa2kke8MJvigpqtMS1pHY4EqHQ5n RhJNL9l5+OHRY43qHsuznbPVBX14hWrdKNIKeMyiH8aW35BGQ3/z6DbEE8diLttBCMYL e/CA== ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@amd.com header.s=selector1 header.b=ENrJsPXA; arc=pass (i=1 spf=pass spfdomain=amd.com dmarc=pass fromdomain=amd.com); spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=amd.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id bm10si3339628pgb.28.2022.02.24.09.03.48; Thu, 24 Feb 2022 09:04:06 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@amd.com header.s=selector1 header.b=ENrJsPXA; arc=pass (i=1 spf=pass spfdomain=amd.com dmarc=pass fromdomain=amd.com); spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=amd.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232202AbiBXRC5 (ORCPT + 99 others); Thu, 24 Feb 2022 12:02:57 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:53274 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231809AbiBXRB5 (ORCPT ); Thu, 24 Feb 2022 12:01:57 -0500 Received: from NAM11-DM6-obe.outbound.protection.outlook.com (mail-dm6nam11on2063.outbound.protection.outlook.com [40.107.223.63]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id E89D470903; Thu, 24 Feb 2022 08:59:15 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=JgIhbgiRiK6L6dEEkZIXMOCS27gnlB1DMz3aQ10zrHT88n913pyPPpHOZYwjfkdAXAiprehMVoxp6Nviu1v8rR0A83DS7Doj3m74eVvByMRNTDlk2ypGkG6KSz6KnfJnPACeL36Xv1nSbJHbCX8ouVXmhkSM8C24h3emXkeHQN3uTY3IuWWEfAmas0QYfnJe0E+TpnfeBR9Z8jp43GZ7PoGaLbX/5BoxBJ6+fG2Skiu3t10D2H7ELtdD8EkHb1bCtU2heGpGZ96WROynis+kLobzJYyY5XMkBdotyl8nEIpWg/WXhzEGun44h5noj2EEpRB55MuTONm9gmbvLVd+kg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=6fi9I656e4S7H65ZCsOcfeus2dxhg7jtErrinnMHud8=; b=ZjlznYMAF8DvqVbtbcEgOxxa3Dl4hmTGE3fL3rTMyl/cMSXJjBc3Yb7gLL41WqIvIxH907gWSXwEkFGFHNZ3Pjaks7S/A8ZiiAvVS+RmCV9d7MdRXm4RiRA4wpWZfzVvX3sn5hmgI0BEyTaNXo+kWAipBFTWdLTW2SkTQAnyjpZPtvg9iUbOvH0JvfJXz//Te/T5LscdOXjcut4hzjQbaH1AokkL7tvr6na5ZoVfvHds1duFO6vexKtIR/9SjWgs31hWUYEekd40hy4lRQ8821o1syjpCfHyyB2MYTOp2u5pST9YGHC+Vlr9vMUsuCough5h7e6QuM1gyumMlT53Kw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=kernel.org smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=6fi9I656e4S7H65ZCsOcfeus2dxhg7jtErrinnMHud8=; b=ENrJsPXAo0gDue3myrwcqQ4t7Hsgor2cUqt/Ux+2UUJFNYuh+E1np0zezrD0ajHaG6KYZwPxD8mzatfrqqXNnsnPpw505p/T/d3iys9fk5/pdKU+6gpfLcg/blnq+rhsXc0qAVAss5sZ4QD880gATqt+2O1a0LtRoQm+cWNK91s= Received: from DM5PR13CA0026.namprd13.prod.outlook.com (2603:10b6:3:7b::12) by BN8PR12MB4596.namprd12.prod.outlook.com (2603:10b6:408:71::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5017.21; Thu, 24 Feb 2022 16:59:12 +0000 Received: from DM6NAM11FT034.eop-nam11.prod.protection.outlook.com (2603:10b6:3:7b:cafe::4b) by DM5PR13CA0026.outlook.office365.com (2603:10b6:3:7b::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5038.9 via Frontend Transport; Thu, 24 Feb 2022 16:59:12 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 165.204.84.17) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=amd.com; Received-SPF: Pass (protection.outlook.com: domain of amd.com designates 165.204.84.17 as permitted sender) receiver=protection.outlook.com; client-ip=165.204.84.17; helo=SATLEXMB04.amd.com; Received: from SATLEXMB04.amd.com (165.204.84.17) by DM6NAM11FT034.mail.protection.outlook.com (10.13.173.47) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.20.5017.22 via Frontend Transport; Thu, 24 Feb 2022 16:59:12 +0000 Received: from sbrijesh-desktop.amd.com (10.180.168.240) by SATLEXMB04.amd.com (10.181.40.145) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2375.18; Thu, 24 Feb 2022 10:59:02 -0600 From: Brijesh Singh To: , , , , , , CC: Thomas Gleixner , Ingo Molnar , Joerg Roedel , Tom Lendacky , "H. Peter Anvin" , Ard Biesheuvel , Paolo Bonzini , Sean Christopherson , "Vitaly Kuznetsov" , Jim Mattson , "Andy Lutomirski" , Dave Hansen , Sergio Lopez , Peter Gonda , "Peter Zijlstra" , Srinivas Pandruvada , David Rientjes , Dov Murik , Tobin Feldman-Fitzthum , Borislav Petkov , Michael Roth , Vlastimil Babka , "Kirill A . Shutemov" , Andi Kleen , "Dr . David Alan Gilbert" , , , , , Brijesh Singh Subject: [PATCH v11 40/45] x86/sev: Provide support for SNP guest request NAEs Date: Thu, 24 Feb 2022 10:56:20 -0600 Message-ID: <20220224165625.2175020-41-brijesh.singh@amd.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20220224165625.2175020-1-brijesh.singh@amd.com> References: <20220224165625.2175020-1-brijesh.singh@amd.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-Originating-IP: [10.180.168.240] X-ClientProxiedBy: SATLEXMB04.amd.com (10.181.40.145) To SATLEXMB04.amd.com (10.181.40.145) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: fb9bc073-0d7f-46f5-67cb-08d9f7b6fb49 X-MS-TrafficTypeDiagnostic: BN8PR12MB4596:EE_ X-Microsoft-Antispam-PRVS: X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: LezDQgsO4CtQXkx2yOAfZGzuVMzdkTWxP6Txty9kx5RSNj1uI1YrWNxxsS+JmVFEHksENwpv5Qdtuy+aCYPbORaiU0CgVM5mTdMsyETqfnkwzrc+nQnJgUdr368ANK7s8cUB2/+v6eqPJZRWsIp/bRDMDjGHbDE/F2y1Z24xp9En8q++ZAd3z1eQ+R8eLVDyjMA/77WvEwCr5n6vfUlFVDQsCsRYSXhBmD2PbpwtfTvVXijfFldp9QIojg4mLUroYNSM7MKJzSWaJwWhV/Hl3Iph697EAVQWQU08gDij/5wsXVAnK2jdmpiZfd7hxS6iOPlWnUrY+JaUcZEh9SmW8tlAjoDh0tFvYSPEDtNoAi4PRBSc/6JqHLZ4JAZ+H3jlrFuhYXEsyXiElg0xIUlDdJaWtqa5ZdHrHo3CbGYY6EYRoPafhzQD/RY9jZz9vRVZ0DcR9W8UojcEjadxe7h5USJ8qG0lZunpeR/XWhU8NNwD3kKR9UMze/xOxUinK3fwb2dZWo+9JPDG8zCnKwyhBRmopIfBcjW+a3wtPvebRJVT5MT2z/HqFR5wKMWeDUSKLcczVlXQRf8AhXYxD7zCpuzCuiN7LKlUOq581u12JJWnNor5vl2M1JyBRiJ3uje6+3IpusKQ1H2s04mO59liaLEUG+D//eAYFFpsekcfyZ9g/WKk2CYcTO7xjaQmCNpK6Lmn+knUO1xaDzRgPogrX2VhE/FHRoRg0CXHZYheTR4= X-Forefront-Antispam-Report: CIP:165.204.84.17;CTRY:US;LANG:en;SCL:1;SRV:;IPV:CAL;SFV:NSPM;H:SATLEXMB04.amd.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230001)(4636009)(46966006)(40470700004)(36840700001)(316002)(356005)(86362001)(7696005)(6666004)(508600001)(36756003)(82310400004)(110136005)(54906003)(7406005)(1076003)(426003)(2906002)(16526019)(186003)(26005)(336012)(40460700003)(70206006)(4326008)(7416002)(8936002)(2616005)(36860700001)(5660300002)(81166007)(70586007)(83380400001)(8676002)(47076005)(44832011)(2101003)(36900700001);DIR:OUT;SFP:1101; X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 24 Feb 2022 16:59:12.0386 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: fb9bc073-0d7f-46f5-67cb-08d9f7b6fb49 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[165.204.84.17];Helo=[SATLEXMB04.amd.com] X-MS-Exchange-CrossTenant-AuthSource: DM6NAM11FT034.eop-nam11.prod.protection.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN8PR12MB4596 X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H2,SPF_HELO_PASS,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Version 2 of GHCB specification provides SNP_GUEST_REQUEST and SNP_EXT_GUEST_REQUEST NAE that can be used by the SNP guest to communicate with the PSP. While at it, add a snp_issue_guest_request() helper that will be used by driver or other subsystem to issue the request to PSP. See SEV-SNP firmware and GHCB spec for more details. Signed-off-by: Brijesh Singh --- arch/x86/include/asm/sev-common.h | 3 ++ arch/x86/include/asm/sev.h | 14 ++++++++ arch/x86/include/uapi/asm/svm.h | 4 +++ arch/x86/kernel/sev.c | 55 +++++++++++++++++++++++++++++++ 4 files changed, 76 insertions(+) diff --git a/arch/x86/include/asm/sev-common.h b/arch/x86/include/asm/sev-common.h index 0759af9b1acf..b8357d6ecd47 100644 --- a/arch/x86/include/asm/sev-common.h +++ b/arch/x86/include/asm/sev-common.h @@ -128,6 +128,9 @@ struct snp_psc_desc { struct psc_entry entries[VMGEXIT_PSC_MAX_ENTRY]; } __packed; +/* Guest message request error code */ +#define SNP_GUEST_REQ_INVALID_LEN BIT_ULL(32) + #define GHCB_MSR_TERM_REQ 0x100 #define GHCB_MSR_TERM_REASON_SET_POS 12 #define GHCB_MSR_TERM_REASON_SET_MASK 0xf diff --git a/arch/x86/include/asm/sev.h b/arch/x86/include/asm/sev.h index 219abb4590f2..9830ee1d6ef0 100644 --- a/arch/x86/include/asm/sev.h +++ b/arch/x86/include/asm/sev.h @@ -87,6 +87,14 @@ extern bool handle_vc_boot_ghcb(struct pt_regs *regs); #define RMPADJUST_VMSA_PAGE_BIT BIT(16) +/* SNP Guest message request */ +struct snp_req_data { + unsigned long req_gpa; + unsigned long resp_gpa; + unsigned long data_gpa; + unsigned int data_npages; +}; + #ifdef CONFIG_AMD_MEM_ENCRYPT extern struct static_key_false sev_es_enable_key; extern void __sev_es_ist_enter(struct pt_regs *regs); @@ -154,6 +162,7 @@ void snp_set_memory_private(unsigned long vaddr, unsigned int npages); void snp_set_wakeup_secondary_cpu(void); bool snp_init(struct boot_params *bp); void snp_abort(void); +int snp_issue_guest_request(u64 exit_code, struct snp_req_data *input, unsigned long *fw_err); #else static inline void sev_es_ist_enter(struct pt_regs *regs) { } static inline void sev_es_ist_exit(void) { } @@ -173,6 +182,11 @@ static inline void snp_set_memory_private(unsigned long vaddr, unsigned int npag static inline void snp_set_wakeup_secondary_cpu(void) { } static inline bool snp_init(struct boot_params *bp) { return false; } static inline void snp_abort(void) { } +static inline int snp_issue_guest_request(u64 exit_code, struct snp_req_data *input, + unsigned long *fw_err) +{ + return -ENOTTY; +} #endif #endif diff --git a/arch/x86/include/uapi/asm/svm.h b/arch/x86/include/uapi/asm/svm.h index 8b4c57baec52..5b8bc2b65a5e 100644 --- a/arch/x86/include/uapi/asm/svm.h +++ b/arch/x86/include/uapi/asm/svm.h @@ -109,6 +109,8 @@ #define SVM_VMGEXIT_SET_AP_JUMP_TABLE 0 #define SVM_VMGEXIT_GET_AP_JUMP_TABLE 1 #define SVM_VMGEXIT_PSC 0x80000010 +#define SVM_VMGEXIT_GUEST_REQUEST 0x80000011 +#define SVM_VMGEXIT_EXT_GUEST_REQUEST 0x80000012 #define SVM_VMGEXIT_AP_CREATION 0x80000013 #define SVM_VMGEXIT_AP_CREATE_ON_INIT 0 #define SVM_VMGEXIT_AP_CREATE 1 @@ -225,6 +227,8 @@ { SVM_VMGEXIT_AP_HLT_LOOP, "vmgexit_ap_hlt_loop" }, \ { SVM_VMGEXIT_AP_JUMP_TABLE, "vmgexit_ap_jump_table" }, \ { SVM_VMGEXIT_PSC, "vmgexit_page_state_change" }, \ + { SVM_VMGEXIT_GUEST_REQUEST, "vmgexit_guest_request" }, \ + { SVM_VMGEXIT_EXT_GUEST_REQUEST, "vmgexit_ext_guest_request" }, \ { SVM_VMGEXIT_AP_CREATION, "vmgexit_ap_creation" }, \ { SVM_VMGEXIT_HV_FEATURES, "vmgexit_hypervisor_feature" }, \ { SVM_EXIT_ERR, "invalid_guest_state" } diff --git a/arch/x86/kernel/sev.c b/arch/x86/kernel/sev.c index 7bef422b428f..cafced2237f3 100644 --- a/arch/x86/kernel/sev.c +++ b/arch/x86/kernel/sev.c @@ -2093,3 +2093,58 @@ static int __init report_cpuid_table(void) } arch_initcall(report_cpuid_table); + +int snp_issue_guest_request(u64 exit_code, struct snp_req_data *input, unsigned long *fw_err) +{ + struct ghcb_state state; + struct es_em_ctxt ctxt; + unsigned long flags; + struct ghcb *ghcb; + int ret; + + if (!cc_platform_has(CC_ATTR_GUEST_SEV_SNP)) + return -ENODEV; + + /* + * __sev_get_ghcb() needs to run with IRQs disabled because it is using + * a per-CPU GHCB. + */ + local_irq_save(flags); + + ghcb = __sev_get_ghcb(&state); + if (!ghcb) { + ret = -EIO; + goto e_restore_irq; + } + + vc_ghcb_invalidate(ghcb); + + if (exit_code == SVM_VMGEXIT_EXT_GUEST_REQUEST) { + ghcb_set_rax(ghcb, input->data_gpa); + ghcb_set_rbx(ghcb, input->data_npages); + } + + ret = sev_es_ghcb_hv_call(ghcb, true, &ctxt, exit_code, input->req_gpa, input->resp_gpa); + if (ret) + goto e_put; + + if (ghcb->save.sw_exit_info_2) { + /* Number of expected pages are returned in RBX */ + if (exit_code == SVM_VMGEXIT_EXT_GUEST_REQUEST && + ghcb->save.sw_exit_info_2 == SNP_GUEST_REQ_INVALID_LEN) + input->data_npages = ghcb_get_rbx(ghcb); + + if (fw_err) + *fw_err = ghcb->save.sw_exit_info_2; + + ret = -EIO; + } + +e_put: + __sev_put_ghcb(&state); +e_restore_irq: + local_irq_restore(flags); + + return ret; +} +EXPORT_SYMBOL_GPL(snp_issue_guest_request); -- 2.25.1