Re: [PATCH v3 00/11] SEV-ES guest support fixes and cleanup

Laszlo Ersek

On 10/29/20 15:17, Tom Lendacky wrote:
From: Tom Lendacky <thomas.lendacky@...>

This patch series provides some fixes, updates and cleanup to the SEV-ES
guest support:

- Update the calculation of the qword offset of fields within the GHCB
by removing the hardcoding of the offsets and using the OFFSET_OF ()
and sizeof () functions to calculate the values. Remove unused values
and add values that will be used in later patches.

- Set the SwExitCode, SwExitInfo1, SwExitInfo2 and SwScratch valid bits
in the GHCB ValidBitmap area when these fields are for a VMGEXIT. This
is done by adding two new interfaces to the VmgExitLib library to set
and test the bits of the GHCB ValidBitmap. This reduces code duplication
and keeps access to the ValidBitmap field within the VmgExitLib library.

- Update the Qemu flash drive services support to add SEV-ES support for
erasing blocks.

- Disable interrupts when using the GHCB.

- Use the processor number for setting the AP stack pointer instead of the
APIC ID by calling GetProcessorNumber().



These patches are based on commit:
6ad819c1abe3 ("FmpDevicePkg/FmpDeviceLib: Add Last Attempt Status to Check/Set API")

Cc: Ard Biesheuvel <ard.biesheuvel@...>
Cc: Eric Dong <eric.dong@...>
Cc: Laszlo Ersek <lersek@...>
Cc: Liming Gao <gaoliming@...>
Cc: Jordan Justen <jordan.l.justen@...>
Cc: Michael D Kinney <michael.d.kinney@...>
Cc: Rahul Kumar <rahul1.kumar@...>
Cc: Zhiguang Liu <zhiguang.liu@...>
Cc: Ray Ni <>
Cc: Tom Lendacky <thomas.lendacky@...>
Cc: Brijesh Singh <brijesh.singh@...>

Changes since v2:
- Don't rename the GHCB_REGISTER enum type.
I've got this queued for review. I'll need some time for getting to it,
as I've just returned after some absence, and everything seems to have
collapsed on my head (as usual).


Changes since v1:
- For the GHCB savearea changes, create a new reserved area name instead
of "renumbering" the reserved areas.
- Rework the ValidBitmap set/test support to be part of the VmgExitLib
library. Create two new interfaces for setting and testing bits in the
GHCB ValidBitmap field and adjust all existing code and the new code in
this series to use these interfaces for the ValidBitmap updates/checks.
- Don't disable interrupts for just the Qemu flash services support, but
rather, cover all users of the GHCB by disabling interrupts in VmgInit()
and restoring them in VmgDone(). This requires changes to those

Tom Lendacky (11):
MdePkg: Clean up GHCB field offsets and save area
UefiCpuPkg/VmgExitLib: Add interfaces to set/read GHCB ValidBitmap
OvmfPkg/VmgExitLib: Implement new VmgExitLib interfaces
OvmfPkg/VmgExitLib: Set the SW exit fields when performing VMGEXIT
OvmfPkg/VmgExitLib: Set the SwScratch valid bit for IOIO events
OvmfPkg/VmgExitLib: Set the SwScratch valid bit for MMIO events
UefiCpuPkg/MpInitLib: Set the SW exit fields when performing VMGEXIT
OvmfPkg/QemuFlashFvbServicesRuntimeDxe: Set the SwScratch valid bit
OvmfPkg/QemuFlashFvbServicesRuntimeDxe: Fix erase blocks for SEV-ES
UefiCpuPkg, OvmfPkg: Disable interrupts when using the GHCB
UefiCpuPkg/MpInitLib: For SEV-ES guest, set stack based on processor

MdePkg/Include/Register/Amd/Ghcb.h | 40 +++---
UefiCpuPkg/Include/Library/VmgExitLib.h | 51 +++++++-
OvmfPkg/Library/VmgExitLib/VmgExitLib.c | 84 ++++++++++++-
OvmfPkg/Library/VmgExitLib/VmgExitVcHandler.c | 129 ++++++--------------
OvmfPkg/QemuFlashFvbServicesRuntimeDxe/QemuFlash.c | 4 +-
OvmfPkg/QemuFlashFvbServicesRuntimeDxe/QemuFlashDxe.c | 6 +-
UefiCpuPkg/Library/MpInitLib/DxeMpLib.c | 5 +-
UefiCpuPkg/Library/MpInitLib/MpLib.c | 14 ++-
UefiCpuPkg/Library/VmgExitLibNull/VmgExitLibNull.c | 60 +++++++--
UefiCpuPkg/Library/MpInitLib/X64/MpFuncs.nasm | 6 +
10 files changed, 258 insertions(+), 141 deletions(-)

Join to automatically receive all group messages.