[RFC Part2 PATCH 00/30] Add AMD Secure Nested Paging (SEV-SNP) Hypervisor Support
From: Brijesh Singh
Date: Wed Mar 24 2021 - 13:05:52 EST
This part of the Secure Encrypted Paging (SEV-SNP) series focuses on the
changes required in a host OS for SEV-SNP support. The series builds upon
SEV-SNP Part-1 https://marc.info/?l=kvm&m=161660430125343&w=2 .
This series provides the basic building blocks to support booting the SEV-SNP
VMs, it does not cover all the security enhancement introduced by the SEV-SNP
such as interrupt protection.
The CCP driver is enhanced to provide new APIs that use the SEV-SNP
specific commands defined in the SEV-SNP firmware specification. The KVM
driver uses those APIs to create and managed the SEV-SNP guests.
The GHCB specification version 2 introduces new set of NAE's that is
used by the SEV-SNP guest to communicate with the hypervisor. The series
provides support to handle the following new NAE events:
- Register GHCB GPA
- Page State Change Request
The RMP check is enforced as soon as SEV-SNP is enabled. Not every memory
access requires an RMP check. In particular, the read accesses from the
hypervisor do not require RMP checks because the data confidentiality is
already protected via memory encryption. When hardware encounters an RMP
checks failure, it raises a page-fault exception. If RMP check failure
is due to the page-size mismatch, then split the large page to resolve
the fault. See patch 4 and 7 for further details.
The series does not provide support for the following SEV-SNP specific
NAE's yet:
* Query Attestation
* AP bring up
* Interrupt security
The series is based on kvm/master commit:
87aa9ec939ec KVM: x86/mmu: Fix TDP MMU zap collapsible SPTEs
The complete source is available at
https://github.com/AMDESE/linux/tree/sev-snp-part-2-rfc1
Cc: Thomas Gleixner <tglx@xxxxxxxxxxxxx>
Cc: Ingo Molnar <mingo@xxxxxxxxxx>
Cc: Borislav Petkov <bp@xxxxxxxxx>
Cc: Joerg Roedel <jroedel@xxxxxxx>
Cc: "H. Peter Anvin" <hpa@xxxxxxxxx>
Cc: Tony Luck <tony.luck@xxxxxxxxx>
Cc: Dave Hansen <dave.hansen@xxxxxxxxx>
Cc: "Peter Zijlstra (Intel)" <peterz@xxxxxxxxxxxxx>
Cc: Paolo Bonzini <pbonzini@xxxxxxxxxx>
Cc: Tom Lendacky <thomas.lendacky@xxxxxxx>
Cc: David Rientjes <rientjes@xxxxxxxxxx>
Cc: Sean Christopherson <seanjc@xxxxxxxxxx>
Cc: x86@xxxxxxxxxx
Cc: kvm@xxxxxxxxxxxxxxx
Additional resources
---------------------
SEV-SNP whitepaper
https://www.amd.com/system/files/TechDocs/SEV-SNP-strengthening-vm-isolation-with-integrity-protection-and-more.pdf
APM 2: https://www.amd.com/system/files/TechDocs/24593.pdf
(section 15.36)
GHCB spec v2:
The draft specification is posted on AMD-SEV-SNP mailing list:
https://lists.suse.com/mailman/private/amd-sev-snp/
Copy of draft spec is also available at
https://github.com/AMDESE/AMDSEV/blob/sev-snp-devel/docs/56421-Guest_Hypervisor_Communication_Block_Standardization.pdf
GHCB spec v1:
SEV-SNP firmware specification:
https://developer.amd.com/sev/
Brijesh Singh (30):
x86: Add the host SEV-SNP initialization support
x86/sev-snp: add RMP entry lookup helpers
x86: add helper functions for RMPUPDATE and PSMASH instruction
x86/mm: split the physmap when adding the page in RMP table
x86: define RMP violation #PF error code
x86/fault: dump the RMP entry on #PF
mm: add support to split the large THP based on RMP violation
crypto:ccp: define the SEV-SNP commands
crypto: ccp: Add support to initialize the AMD-SP for SEV-SNP
crypto: ccp: shutdown SNP firmware on kexec
crypto:ccp: provide APIs to issue SEV-SNP commands
crypto ccp: handle the legacy SEV command when SNP is enabled
KVM: SVM: add initial SEV-SNP support
KVM: SVM: make AVIC backing, VMSA and VMCB memory allocation SNP safe
KVM: SVM: define new SEV_FEATURES field in the VMCB Save State Area
KVM: SVM: add KVM_SNP_INIT command
KVM: SVM: add KVM_SEV_SNP_LAUNCH_START command
KVM: SVM: add KVM_SEV_SNP_LAUNCH_UPDATE command
KVM: SVM: Reclaim the guest pages when SEV-SNP VM terminates
KVM: SVM: add KVM_SEV_SNP_LAUNCH_FINISH command
KVM: X86: Add kvm_x86_ops to get the max page level for the TDP
x86/mmu: Introduce kvm_mmu_map_tdp_page() for use by SEV
KVM: X86: Introduce kvm_mmu_get_tdp_walk() for SEV-SNP use
KVM: X86: define new RMP check related #NPF error bits
KVM: X86: update page-fault trace to log the 64-bit error code
KVM: SVM: add support to handle GHCB GPA register VMGEXIT
KVM: SVM: add support to handle MSR based Page State Change VMGEXIT
KVM: SVM: add support to handle Page State Change VMGEXIT
KVM: X86: export the kvm_zap_gfn_range() for the SNP use
KVM: X86: Add support to handle the RMP nested page fault
arch/x86/include/asm/kvm_host.h | 14 +
arch/x86/include/asm/msr-index.h | 6 +
arch/x86/include/asm/sev-snp.h | 68 +++
arch/x86/include/asm/svm.h | 12 +-
arch/x86/include/asm/trap_pf.h | 2 +
arch/x86/kvm/lapic.c | 5 +-
arch/x86/kvm/mmu.h | 5 +-
arch/x86/kvm/mmu/mmu.c | 76 ++-
arch/x86/kvm/svm/sev.c | 925 ++++++++++++++++++++++++++++++-
arch/x86/kvm/svm/svm.c | 28 +-
arch/x86/kvm/svm/svm.h | 49 ++
arch/x86/kvm/trace.h | 6 +-
arch/x86/kvm/vmx/vmx.c | 8 +
arch/x86/mm/fault.c | 157 ++++++
arch/x86/mm/mem_encrypt.c | 163 ++++++
drivers/crypto/ccp/sev-dev.c | 312 ++++++++++-
drivers/crypto/ccp/sev-dev.h | 3 +
drivers/crypto/ccp/sp-pci.c | 12 +
include/linux/mm.h | 6 +-
include/linux/psp-sev.h | 311 +++++++++++
include/uapi/linux/kvm.h | 42 ++
include/uapi/linux/psp-sev.h | 27 +
mm/memory.c | 11 +
23 files changed, 2224 insertions(+), 24 deletions(-)
--
2.17.1