Re: [RFC Part1 PATCH v3 13/17] x86/io: Unroll string I/O when SEV is active
From: Brijesh Singh <hidden>
Date: 2017-09-15 14:49:09
Also in:
kvm, linux-efi, lkml
From: Brijesh Singh <hidden>
Date: 2017-09-15 14:49:09
Also in:
kvm, linux-efi, lkml
On 09/15/2017 09:40 AM, Borislav Petkov wrote:
I need to figure out the include hell first.
I am working with slightly newer patch sets -- in that patch Tom has moved the sev_active() definition in arch/x86/mm/mem_encrypt.c and I have no issue using your recommended (since I no longer need the include path changes). But in my quick run I did found a runtime issue, it seems enabling the static key in sme_enable is too early. Guest reboots as soon as it tries to enable the key. I see the similar issue with non SEV guest with my simple patch below. Guest will reboot as soon as it tries to enable the key.
--- a/arch/x86/kernel/head64.c
+++ b/arch/x86/kernel/head64.c@@ -40,6 +40,8 @@ pmdval_t early_pmd_flags = __PAGE_KERNEL_LARGE & ~(_PAGE_GLOBAL | _PAGE_NX); #define __head __section(.head.text) +DEFINE_STATIC_KEY_FALSE(__testme); + static void __head *fixup_pointer(void *ptr, unsigned long physaddr) { return ptr - (void *)_text + (void *)physaddr;
@@ -71,6 +73,8 @@ unsigned long __head __startup_64(unsigned long physaddr, if (load_delta & ~PMD_PAGE_MASK) for (;;); + static_branch_enable(&__testme); + /* Activate Secure Memory Encryption (SME) if supported and enabled */ sme_enable(bp);