[PATCH v4 0/3] efi: Don't initalize SEV-SNP from the EFI stub

From: Ard Biesheuvel

Date: Tue Sep 09 2025 - 04:06:58 EST


From: Ard Biesheuvel <ardb@xxxxxxxxxx>

The EFI stub no longer invokes the legacy decompressor, and so there is
no longer any reason to perform all SEV-SNP initialization twice: it is
sufficient to rely on the SEV-SNP work done by the core kernel.

Changes since v3: [2]
- Drop patches that have been merged in the meantime
- Rebase onto tip/x86/sev

Note that the issue pointed out by Tom in reply to the v3 cover letter
has been fixed in the meantime as well [3]

Changes since v2: [1]
- rebase onto tip/x86/boot
- add patch to remove unused static inline fallback implementation of
sev_enable()

Changes since v1: [0]
- address shortcomings pointed out by Tom, related to missing checks and
to discovery of the CC blob table from the EFI stub

[0] https://lore.kernel.org/all/20250414130417.1486395-2-ardb+git@xxxxxxxxxx/T/#u
[1] https://lore.kernel.org/all/20250416165743.4080995-6-ardb+git@xxxxxxxxxx/T/#u
[2] https://lore.kernel.org/all/20250422100728.208479-7-ardb+git@xxxxxxxxxx/T/#u
[3] https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=8ed12ab1319b2d8e4a529504777aacacf71371e4

Cc: Tom Lendacky <thomas.lendacky@xxxxxxx>
Cc: Borislav Petkov <bp@xxxxxxxxx>

Ard Biesheuvel (3):
x86/boot: Drop unused sev_enable() fallback
x86/efistub: Obtain SEV CC blob address from the stub
x86/efistub: Don't bother enabling SEV in the EFI stub

arch/x86/boot/compressed/misc.h | 11 --------
arch/x86/include/asm/sev.h | 2 --
drivers/firmware/efi/libstub/x86-stub.c | 27 ++++++++++++--------
3 files changed, 16 insertions(+), 24 deletions(-)


base-commit: 0ca77f8d33e8136b8926775380506f78a8d04811
--
2.51.0.384.g4c02a37b29-goog