Received: by 2002:a05:7412:bbc7:b0:fc:a2b0:25d7 with SMTP id kh7csp1342020rdb; Sat, 3 Feb 2024 02:28:52 -0800 (PST) X-Google-Smtp-Source: AGHT+IGNKUn7ncIiRKzMkkT9y824msqlJuoPa12xIM7jwJUmuueI85nLqSzbXrbdElhRkbtb+faE X-Received: by 2002:a05:6a20:8188:b0:19e:4abb:bb4d with SMTP id q8-20020a056a20818800b0019e4abbbb4dmr4401412pzb.14.1706956132301; Sat, 03 Feb 2024 02:28:52 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1706956132; cv=pass; d=google.com; s=arc-20160816; b=qABnktCcfvJ1aWM7FvgPoSQkfI7wL0TJCnlUqAvd95jlCxLcHluCmQivbwaGKbd/0K jl2a7rcsfiLAYDWbrVQp8JKgElvjddJLl0/UxrexQSrunnzhBEvkVciAYcrBOam+c1A+ otEQJToZlr4tMdsos8hzNw2mC7mVGSsjVcsqDe/DzI1Ab8nztO0uBTWHBXr8HYz5kWQC Ynoh796WEGxFwOkiz9irRw0jyFRRnaoKPNp7f12PRUTDZiDPFHckpWbnMQLBJqsGrXgl oXCHZSzxvUC2KIEKLe4fqdcfOb9bv6OBBYMjs33Ajnsx6HIV9dT3SW60n9wVHtG5+afO ThMQ== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:list-unsubscribe:list-subscribe:list-id:precedence :dkim-signature; bh=B4bk7dzGbSHGKNZDKeGcdqRqL3ZpWncF3+ZDt0jsh40=; fh=uRLp+4xmD/+uMlT3VT7bnmEMhOX1bRp4emJEWCavWKs=; b=r0ru3Ji6xefwAHAzkKQhZrZ/MKjFIoereMypy/fZ0+3e3O68Amkd1Ex0/64MC3oKjW BsjyqktD1xn2B56RfV1J7866ztiwOL0Gw62vnHlA6PXVL5v56gqaiocndtMdjFjcToWC ogPNxkzAJTfnPVcyi48oSteXOyHPycmPrlTvVooAXfftvRROo5dJ/nzNx/oVUm/TAmCW 2fcKaT4SJ8LqjuLFElfNVfF8AyPR4N+oVPea43uiyfKnt57dTea1Mb6Z5+E3XKW/UOKt hIJ98Qmu5064CDdXOnNJl+s4Xxo9y29+CAEpfMY1riOjE8ih+yTcUKAQxjmSKyRT/SdH aW/Q==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=Q27ZZ3+M; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-51026-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) smtp.mailfrom="linux-kernel+bounces-51026-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org X-Forwarded-Encrypted: i=1; AJvYcCXzZRvjm92Hc95AMk/7IMpEAhvXvWmJG/zYYiRvBBVDuBWw5FzfbYMAFSTPHWXVfzUIBw6ePe07xwQdlZudnw22aXKP/zrzkB0oUfeSmQ== Return-Path: Received: from sv.mirrors.kernel.org (sv.mirrors.kernel.org. [139.178.88.99]) by mx.google.com with ESMTPS id mm3-20020a17090b358300b002963122496fsi1360524pjb.72.2024.02.03.02.28.52 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 03 Feb 2024 02:28:52 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-51026-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) client-ip=139.178.88.99; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=Q27ZZ3+M; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-51026-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) smtp.mailfrom="linux-kernel+bounces-51026-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by sv.mirrors.kernel.org (Postfix) with ESMTPS id DA2A4288E56 for ; Sat, 3 Feb 2024 10:27:52 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 9E3FF5D8E4; Sat, 3 Feb 2024 10:27:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Q27ZZ3+M" Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C467D5D754 for ; Sat, 3 Feb 2024 10:27:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1706956052; cv=none; b=MOtzzVdGFqunTCtQKgIzwMH2cxFbBr/UXc0rIl7eN+Rk7WZrbz21RoxnPlm6/W9x48CGQon37dR2X9fLk7jvmuAIZ2EwctDUu/r/WdPQAqeELKbnrro7+l89dl8HwdC0XEibGlxMcW1r5DwVxmPOHU47egGuMQqxM58UWxmj+CU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1706956052; c=relaxed/simple; bh=cP0msj1t8wyJ2dcgj7bifErL/pCrSLrZq5t++VseJdg=; h=MIME-Version:References:In-Reply-To:From:Date:Message-ID:Subject: To:Cc:Content-Type; b=TPqmZbEcwudG420P8PcAwl5xuWwupQaYihjNX9ZaSE9kLzUtQM1FiznPZa5mrRJof79XgtpI/FyGYAx3vF0hCrVnOIghqdMh6xYpik/y2Z0fF7oYhRjvIIu0izbr5X3bLgE9bzAsES0Hgxu7+A2hWqh0g7h31ZT25QnJ67I+NZI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Q27ZZ3+M; arc=none smtp.client-ip=10.30.226.201 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4B28EC433F1 for ; Sat, 3 Feb 2024 10:27:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1706956052; bh=cP0msj1t8wyJ2dcgj7bifErL/pCrSLrZq5t++VseJdg=; h=References:In-Reply-To:From:Date:Subject:To:Cc:From; b=Q27ZZ3+MqG3q5LcScV1zUuNSPUoXLpeL88B4qOiKwTRer/4jqsvzIFfoIpYfGKAWW +2BQ196gyxJiMvG7OdH3gjBPHuwkVFmsz0vI05v+6A2AQ6pb9KAOkzRJ60uFGmzKi8 IuMbEDXHoUMU8jdZqedcTuOy4cKwlLd6WpRZfcChpeOGpfaTRA6PUJE2QexIzYf9kf LlxlQiVXC8c9is+FD7oMy7ji5WAh8W2iIcsFPckZBLRhoppF+Py+j83G+wq1Gai0QN r3jFwDkEgifF+tJcYnKEpIFh5ylTAjPrDV1pWEcUvZdlC3JwTtRarML/4la0/cmv7E eS5diNfv6sCSQ== Received: by mail-lf1-f54.google.com with SMTP id 2adb3069b0e04-51032058f17so3444505e87.3 for ; Sat, 03 Feb 2024 02:27:32 -0800 (PST) X-Gm-Message-State: AOJu0YyucrbMJkc3nhUws9oJjkk6cUDipoadRnLRrvmCZLT6jjbC/Se1 X0y2otni0CZ0WCTL0eKl8xJfkryMplFAsh6nn7qMCPYIquM1PeppuaG0iI6lCAc9q4014mSBIzq xtZFoiFHfwYsI+X0bgaUYAul7tz8= X-Received: by 2002:ac2:4e8e:0:b0:511:3208:d4e7 with SMTP id o14-20020ac24e8e000000b005113208d4e7mr4341732lfr.69.1706956050543; Sat, 03 Feb 2024 02:27:30 -0800 (PST) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 References: <20240121182040.GBZa1geI5NxWSslvt0@fat_crate.local> <20240130220845.1978329-1-kevinloughlin@google.com> <20240131140037.GDZbpShX2b0elXlqDA@fat_crate.local> <20240131182944.GJZbqRmBN_KDgK_nmB@fat_crate.local> <20240203101927.GEZb4TL2H3XTqCSo5d@fat_crate.local> In-Reply-To: <20240203101927.GEZb4TL2H3XTqCSo5d@fat_crate.local> From: Ard Biesheuvel Date: Sat, 3 Feb 2024 11:27:19 +0100 X-Gmail-Original-Message-ID: Message-ID: Subject: Re: [PATCH v3 0/2] x86: enforce and cleanup RIP-relative accesses in early boot code To: Borislav Petkov Cc: Kevin Loughlin , Jacob Xu , Thomas Gleixner , Ingo Molnar , Dave Hansen , x86@kernel.org, Nick Desaulniers , Justin Stitt , Tom Lendacky , Pankaj Gupta , Hou Wenlong , Dionna Glaze , Brijesh Singh , Michael Roth , "Kirill A. Shutemov" , linux-kernel@vger.kernel.org, llvm@lists.linux.dev, linux-coco@lists.linux.dev, Ashish Kalra , Andi Kleen , Adam Dunlap , Peter Gonda , Sidharth Telang Content-Type: text/plain; charset="UTF-8" On Sat, 3 Feb 2024 at 11:20, Borislav Petkov wrote: > > On Fri, Feb 02, 2024 at 04:22:02PM -0800, Kevin Loughlin wrote: > > True. I just think it would be better to have an upstream fix for > > clang builds of SEV-SNP guests; I believe the first such SEV-SNP code > > was merged in 5.19 if I'm not mistaken. > > SNP host support is not upstream yet. So we'd be supporting something > which is out-of-tree. Lemme see how ugly it'll get... > The minimal fix doesn't look that bad IMHO. Note that this version is based on your patch that removes CONFIG_AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT, and we'd need to see whether or not to backport that as well. arch/x86/include/asm/asm.h | 13 +++++++++++++ arch/x86/include/asm/mem_encrypt.h | 13 ++++++++----- arch/x86/kernel/sev-shared.c | 12 ++++++------ arch/x86/kernel/sev.c | 9 +++++++-- arch/x86/mm/mem_encrypt_identity.c | 27 ++++++++++++--------------- 5 files changed, 46 insertions(+), 28 deletions(-) https://git.kernel.org/pub/scm/linux/kernel/git/ardb/linux.git/commit/?h=x86-pie-for-sev-v4a&id=65d0e5f4ed6ca807cdf28a1c5c0389af2c9f9bda