Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-17 Thread Yao, Jiewen
ional steps to attest the MH and it > does not change the functionality of any existing attestation mechanisms. > > -Tobin > > > > >> -----Original Message----- > >> From: devel@edk2.groups.io On Behalf Of Yao, > Jiewen > >> Sent: Thursday, March 4, 2021

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-16 Thread Singh, Brijesh
; to...@linux.ibm.com Cc: Dov Murik ; Tobin Feldman-Fitzthum ; James Bottomley ; Hubertus Franke ; Singh, Brijesh ; Kalra, Ashish ; Grimm, Jon ; Lendacky, Thomas Subject: RE: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV Hi We discuss the patch internally. We d

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-16 Thread Tobin Feldman-Fitzthum
Grimm ; Tom Lendacky Subject: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV This is a demonstration of fast migration for encrypted virtual machines using a Migration Handler that lives in OVMF. This demo uses AMD SEV, but the ideas may generalize to other co

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-12 Thread Yao, Jiewen
-Fitzthum > ; James Bottomley ; Hubertus Franke > ; Brijesh Singh ; Ashish Kalra > ; Jon Grimm ; Tom Lendacky > ; Yao, Jiewen > Subject: Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live > Migration for AMD SEV > > Hi Tobin > Thanks for your patch. > Yo

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-05 Thread Tobin Feldman-Fitzthum
On Fri, Mar 05, 2021 at 10:44:23AM +, Ashish Kalra wrote: On Wed, Mar 03, 2021 at 01:25:40PM -0500, Tobin Feldman-Fitzthum wrote: Hi Tobin, On 03/02/21 21:48, Tobin Feldman-Fitzthum wrote: This is a demonstration of fast migration for encrypted virtual machines using a Migration Handler

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-05 Thread Ashish Kalra
On Fri, Mar 05, 2021 at 10:44:23AM +, Ashish Kalra wrote: > On Wed, Mar 03, 2021 at 01:25:40PM -0500, Tobin Feldman-Fitzthum wrote: > > > > > Hi Tobin, > > > > > > On 03/02/21 21:48, Tobin Feldman-Fitzthum wrote: > > > > This is a demonstration of fast migration for encrypted virtual machines

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-05 Thread Ashish Kalra
On Wed, Mar 03, 2021 at 01:25:40PM -0500, Tobin Feldman-Fitzthum wrote: > > > Hi Tobin, > > > > On 03/02/21 21:48, Tobin Feldman-Fitzthum wrote: > > > This is a demonstration of fast migration for encrypted virtual machines > > > using a Migration Handler that lives in OVMF. This demo uses AMD SE

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-05 Thread Paolo Bonzini
On 04/03/21 21:45, Laszlo Ersek wrote: On 03/04/21 10:21, Paolo Bonzini wrote: Hi Tobin, as mentioned in the reply to the QEMU patches posted by Tobin, I think the firmware helper approach is very good, but there are some disadvantages in the idea of auxiliary vCPUs. These are especially true i

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-04 Thread Laszlo Ersek
On 03/04/21 21:45, Laszlo Ersek wrote: > On 03/04/21 10:21, Paolo Bonzini wrote: >> Hi Tobin, >> >> as mentioned in the reply to the QEMU patches posted by Tobin, I >> think the firmware helper approach is very good, but there are some >> disadvantages in the idea of auxiliary vCPUs. These are espe

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-04 Thread Laszlo Ersek
On 03/04/21 10:21, Paolo Bonzini wrote: > Hi Tobin, > > as mentioned in the reply to the QEMU patches posted by Tobin, I > think the firmware helper approach is very good, but there are some > disadvantages in the idea of auxiliary vCPUs. These are especially > true in the VMM, where it's much nic

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-04 Thread Laszlo Ersek
On 03/03/21 19:25, Tobin Feldman-Fitzthum wrote: >> Laszlo wrote: >> I'm quite uncomfortable with an attempt to hide a CPU from the OS via >> ACPI. The OS has other ways to learn (for example, a boot loader could >> use the MP services itself, stash the information, and hand it to the OS >> kernel

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-04 Thread Paolo Bonzini
Hi Tobin, as mentioned in the reply to the QEMU patches posted by Tobin, I think the firmware helper approach is very good, but there are some disadvantages in the idea of auxiliary vCPUs. These are especially true in the VMM, where it's much nicer to have a separate VM that goes through a spec

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-03 Thread Yao, Jiewen
mm ; Tom Lendacky > > Subject: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live > Migration for AMD SEV > > This is a demonstration of fast migration for encrypted virtual machines > using a Migration Handler that lives in OVMF. This demo uses AMD SEV, > but the i

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-03 Thread Tobin Feldman-Fitzthum
Hi Tobin, On 03/02/21 21:48, Tobin Feldman-Fitzthum wrote: This is a demonstration of fast migration for encrypted virtual machines using a Migration Handler that lives in OVMF. This demo uses AMD SEV, but the ideas may generalize to other confidential computing platforms. With AMD SEV, guest

Re: [edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-03 Thread Laszlo Ersek
Hi Tobin, On 03/02/21 21:48, Tobin Feldman-Fitzthum wrote: > This is a demonstration of fast migration for encrypted virtual machines > using a Migration Handler that lives in OVMF. This demo uses AMD SEV, > but the ideas may generalize to other confidential computing platforms. > With AMD SEV, gu

[edk2-devel] [RFC PATCH 00/14] Firmware Support for Fast Live Migration for AMD SEV

2021-03-02 Thread Tobin Feldman-Fitzthum
This is a demonstration of fast migration for encrypted virtual machines using a Migration Handler that lives in OVMF. This demo uses AMD SEV, but the ideas may generalize to other confidential computing platforms. With AMD SEV, guest memory is encrypted and the hypervisor cannot access or move it.