Re: [PATCH v4] x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN"
From: Tom Lendacky
Date: Tue Jul 07 2026 - 12:10:10 EST
On 7/7/26 10:00, Tycho Andersen wrote:
> From: "Tycho Andersen (AMD)" <tycho@xxxxxxxxxx>
>
> This reverts commit 99cf1fb58e68 ("x86/virt/sev: Drop WBINVD before setting
> MSR_AMD64_SYSCFG_SNP_EN").
>
> Section 8.8 of the SNP spec says:
>
> Before invoking SNP_INIT_EX with INIT_RMP set to 1, software must
> ensure that no CPUs contain dirty cache lines for the memory containing
> the RMP.
>
> Cachelines can be moved from cache to cache in a dirty state. The
> wbinvd_on_all_cpus() before SNP_INIT_EX flushes the caches for each cpu,
> but if the IPIs for WBINVD race with this dirty cacheline movement, it is
> possible that they may not get flushed violating the firmware requirement.
>
> Doing wbinvd_on_all_cpus() before setting SNPEn is safer since the RMP
> table is not yet in use.
>
> [ Heroically bisected by Srikanth. ]
> Reported-by: Srikanth Aithal <Srikanth.Aithal@xxxxxxx>
> Tested-by: Srikanth Aithal <Srikanth.Aithal@xxxxxxx>
> Fixes: 99cf1fb58e68 ("x86/virt/sev: Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN")
> Signed-off-by: Tycho Andersen (AMD) <tycho@xxxxxxxxxx>
Reviewed-by: Tom Lendacky <thomas.lendacky@xxxxxxx>
> ---
> arch/x86/virt/svm/sev.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/arch/x86/virt/svm/sev.c b/arch/x86/virt/svm/sev.c
> index 8bcdce98f6dc..cff285d8ad8e 100644
> --- a/arch/x86/virt/svm/sev.c
> +++ b/arch/x86/virt/svm/sev.c
> @@ -536,6 +536,8 @@ int snp_prepare(void)
> goto unlock;
> }
>
> + wbinvd_on_all_cpus();
> +
> /*
> * MtrrFixDramModEn is not shared between threads on a core,
> * therefore it must be set on all CPUs prior to enabling SNP.
>
> base-commit: aa6d9def48ea424a50c21de90ebe609c383cb05d