mirror of
https://github.com/tianocore/edk2
synced 2026-08-27 00:23:19 -04:00
MdePkg: Add code to detect running as an SEV guest
Similar to Intel's Tdx, we need a mechanism to detect running as an AMD SEV guest that will work in all phases everywhere. This will be immediately used to prevent usage of MTRRs with SEV guests. Signed-off-by: Richard Relph <richard.relph@amd.com>
This commit is contained in:
parent
8058a94f60
commit
b98ccecdec
5 changed files with 91 additions and 0 deletions
|
|
@ -5396,6 +5396,18 @@ TdIsEnabled (
|
|||
VOID
|
||||
);
|
||||
|
||||
/**
|
||||
Probe if running as some kind of SEV guest.
|
||||
|
||||
@return FALSE Not running as a guest under any kind of SEV
|
||||
@return TRUE Running as a guest under any kind of SEV
|
||||
**/
|
||||
BOOLEAN
|
||||
EFIAPI
|
||||
SevGuestIsEnabled (
|
||||
VOID
|
||||
);
|
||||
|
||||
#if defined (MDE_CPU_X64)
|
||||
//
|
||||
// The page size for the PVALIDATE instruction
|
||||
|
|
|
|||
26
MdePkg/Library/BaseLib/AmdSevNull.c
Normal file
26
MdePkg/Library/BaseLib/AmdSevNull.c
Normal file
|
|
@ -0,0 +1,26 @@
|
|||
/** @file
|
||||
|
||||
Null stub of SevLib
|
||||
|
||||
Copyright (c) 2025, Advanced Micro Devices, Inc. All rights reserved.<BR>
|
||||
SPDX-License-Identifier: BSD-2-Clause-Patent
|
||||
|
||||
**/
|
||||
|
||||
#include <Library/BaseLib.h>
|
||||
#include <Uefi/UefiBaseType.h>
|
||||
|
||||
/**
|
||||
Probe if running as some kind of SEV guest.
|
||||
|
||||
@return FALSE Not running as a guest under any kind of SEV
|
||||
@return TRUE Running as a guest under any kind of SEV
|
||||
**/
|
||||
BOOLEAN
|
||||
EFIAPI
|
||||
SevGuestIsEnabled (
|
||||
VOID
|
||||
)
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
|
@ -213,6 +213,7 @@
|
|||
X86PatchInstruction.c
|
||||
X86SpeculationBarrier.c
|
||||
IntelTdxNull.c
|
||||
X64/SevProbe.c
|
||||
|
||||
[Sources.X64]
|
||||
X64/Thunk16.nasm
|
||||
|
|
@ -299,6 +300,7 @@
|
|||
X64/TdCall.nasm
|
||||
X64/TdVmcall.nasm
|
||||
X64/TdProbe.c
|
||||
X64/SevProbe.c
|
||||
|
||||
X64/Non-existing.c
|
||||
Math64.c
|
||||
|
|
@ -340,6 +342,7 @@
|
|||
Unaligned.c
|
||||
Math64.c
|
||||
IntelTdxNull.c
|
||||
AmdSevNull.c
|
||||
|
||||
[Sources.AARCH64]
|
||||
AArch64/InternalSwitchStack.c
|
||||
|
|
@ -368,6 +371,7 @@
|
|||
AArch64/ArmReadCntPctReg.asm | MSFT
|
||||
AArch64/ArmReadIdAA64Isar0Reg.asm | MSFT
|
||||
IntelTdxNull.c
|
||||
AmdSevNull.c
|
||||
|
||||
[Sources.RISCV64]
|
||||
Math64.c
|
||||
|
|
@ -390,6 +394,7 @@
|
|||
RiscV64/RiscVMmu.S | GCC
|
||||
RiscV64/SpeculationBarrier.S | GCC
|
||||
IntelTdxNull.c
|
||||
AmdSevNull.c
|
||||
|
||||
[Sources.LOONGARCH64]
|
||||
Math64.c
|
||||
|
|
@ -411,6 +416,7 @@
|
|||
LoongArch64/Cpucfg.S | GCC
|
||||
LoongArch64/ReadStableCounter.S | GCC
|
||||
IntelTdxNull.c
|
||||
AmdSevNull.c
|
||||
|
||||
[Packages]
|
||||
MdePkg/MdePkg.dec
|
||||
|
|
|
|||
|
|
@ -130,6 +130,7 @@
|
|||
X86SpeculationBarrier.c
|
||||
X86UnitTestHost.c
|
||||
IntelTdxNull.c
|
||||
AmdSevNull.c
|
||||
|
||||
[Sources.X64]
|
||||
X64/LongJump.nasm
|
||||
|
|
@ -170,6 +171,7 @@
|
|||
X64/RdRand.nasm
|
||||
X86UnitTestHost.c
|
||||
IntelTdxNull.c
|
||||
AmdSevNull.c
|
||||
|
||||
[Sources.EBC]
|
||||
Ebc/CpuBreakpoint.c
|
||||
|
|
|
|||
45
MdePkg/Library/BaseLib/X64/SevProbe.c
Normal file
45
MdePkg/Library/BaseLib/X64/SevProbe.c
Normal file
|
|
@ -0,0 +1,45 @@
|
|||
/** @file
|
||||
|
||||
Copyright (c) 2025, Advanced Micro Devices, Inc. All rights reserved.<BR>
|
||||
SPDX-License-Identifier: BSD-2-Clause-Patent
|
||||
|
||||
**/
|
||||
|
||||
#include <Library/BaseLib.h>
|
||||
#include <Register/Amd/Cpuid.h>
|
||||
#include <Register/Amd/SevSnpMsr.h>
|
||||
#include <Register/Intel/Cpuid.h>
|
||||
|
||||
/**
|
||||
Probe if running as some kind of SEV guest.
|
||||
|
||||
@return FALSE Not running as a guest under any kind of SEV
|
||||
@return TRUE Running as a guest under any kind of SEV
|
||||
**/
|
||||
BOOLEAN
|
||||
EFIAPI
|
||||
SevGuestIsEnabled (
|
||||
VOID
|
||||
)
|
||||
{
|
||||
UINT32 MaxExtendedLeaf;
|
||||
MSR_SEV_STATUS_REGISTER SevStatus;
|
||||
CPUID_MEMORY_ENCRYPTION_INFO_EAX MemoryEncryptionInfoEax;
|
||||
|
||||
// Check max extended CPUID leaf
|
||||
AsmCpuid (CPUID_EXTENDED_FUNCTION, &MaxExtendedLeaf, NULL, NULL, NULL);
|
||||
if (MaxExtendedLeaf < CPUID_MEMORY_ENCRYPTION_INFO) {
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
// Check SEV support
|
||||
AsmCpuid (CPUID_MEMORY_ENCRYPTION_INFO, &MemoryEncryptionInfoEax.Uint32, NULL, NULL, NULL);
|
||||
if (MemoryEncryptionInfoEax.Bits.SevBit == 0) {
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
// Read SEV_STATUS MSR
|
||||
SevStatus.Uint64 = AsmReadMsr64 (MSR_SEV_STATUS);
|
||||
|
||||
return (SevStatus.Bits.SevBit | SevStatus.Bits.SevEsBit | SevStatus.Bits.SevSnpBit) ? TRUE : FALSE;
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue