[AMD Official Use Only - General]

Hello Nikunj,

That is true, but there is no SEV live migration happening before GHCB pages 
are re-setup and the hypercalls are invoked again for GHCB pages from
the guest kernel after it checks the live migration runtime environment flag 
setup by OVMF.

Thanks,
Ashish

-----Original Message-----
From: Dadhania, Nikunj <[email protected]> 
Sent: Tuesday, May 31, 2022 10:14 AM
To: [email protected]; Kalra, Ashish <[email protected]>
Cc: [email protected]; [email protected]; [email protected]; 
Lendacky, Thomas <[email protected]>; [email protected]; 
[email protected]; [email protected]; [email protected]; 
[email protected]; [email protected]
Subject: Re: [edk2-devel] [PATCH v7 5/6] OvmfPkg/PlatformPei: Mark SEC GHCB 
page as unencrypted via hypercall

Hi Ashish,

On 8/19/2021 7:36 PM, Ashish Kalra via groups.io wrote:
> From: Ashish Kalra <[email protected]>
> 
> Mark the SEC GHCB page (that is mapped as unencrypted in ResetVector 
> code) in the hypervisor's guest page encryption state tracking.
> 
> Cc: Jordan Justen <[email protected]>
> Cc: Ard Biesheuvel <[email protected]>
> Signed-off-by: Ashish Kalra <[email protected]>
> ---
>  OvmfPkg/PlatformPei/AmdSev.c | 11 +++++++++++
>  1 file changed, 11 insertions(+)
> 
> diff --git a/OvmfPkg/PlatformPei/AmdSev.c 
> b/OvmfPkg/PlatformPei/AmdSev.c index a8bf610022..1d38056ec0 100644
> --- a/OvmfPkg/PlatformPei/AmdSev.c
> +++ b/OvmfPkg/PlatformPei/AmdSev.c
> @@ -52,6 +52,17 @@ AmdSevEsInitialize (
>    PcdStatus = PcdSetBoolS (PcdSevEsIsEnabled, TRUE);
>    ASSERT_RETURN_ERROR (PcdStatus);
>  
> +  //
> +  // The SEC Ghcb setup during reset-vector needs to be marked as  // 
> + decrypted in the hypervisor's guest page encryption state  // 
> + tracking.
> +  //
> +  SetMemoryEncDecHypercall3 (
> +    FixedPcdGet32 (PcdOvmfSecGhcbBase),
> +    EFI_SIZE_TO_PAGES(FixedPcdGet32 (PcdOvmfSecGhcbSize)),
> +    FALSE
> +    );

PcdOvmfSecGhcbSize is set to 2 pages (8192 bytes). AFAIU, only first page needs 
to be change to shared, second page should be kept private.

>    //
>    // Allocate GHCB and per-CPU variable pages.
>    //   Since the pages must survive across the UEFI to OS transition
> 

Regards
Nikunj


-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#90113): https://edk2.groups.io/g/devel/message/90113
Mute This Topic: https://groups.io/mt/84997535/21656
Group Owner: [email protected]
Unsubscribe: https://edk2.groups.io/g/devel/unsub [[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to