From mboxrd@z Thu Jan 1 00:00:00 1970 From: Tom Lendacky Subject: Re: [RFC Part1 PATCH v3 12/17] x86/mm: DMA support for SEV memory encryption Date: Thu, 17 Aug 2017 14:35:25 -0500 Message-ID: <4002e0e2-34e8-c8ea-80e8-f5deae8b21e7@amd.com> References: <20170724190757.11278-1-brijesh.singh@amd.com> <20170724190757.11278-13-brijesh.singh@amd.com> <20170807034820.GA7521@nazgul.tnic> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit Cc: linux-kernel@vger.kernel.org, x86@kernel.org, linux-efi@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, kvm@vger.kernel.org, Thomas Gleixner , Ingo Molnar , "H . Peter Anvin" , Andy Lutomirski , Tony Luck , Piotr Luc , Fenghua Yu , Lu Baolu , Reza Arbab , David Howells , Matt Fleming , "Kirill A . Shutemov" , Laura Abbott , Ard Biesheuvel , Andrew Morton , Eric Biederman , Benjamin Herr To: Borislav Petkov , Brijesh Singh Return-path: Received: from mail-co1nam03on0084.outbound.protection.outlook.com ([104.47.40.84]:53151 "EHLO NAM03-CO1-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1753482AbdHQTfk (ORCPT ); Thu, 17 Aug 2017 15:35:40 -0400 In-Reply-To: <20170807034820.GA7521@nazgul.tnic> Content-Language: en-US Sender: kvm-owner@vger.kernel.org List-ID: On 8/6/2017 10:48 PM, Borislav Petkov wrote: > On Mon, Jul 24, 2017 at 02:07:52PM -0500, Brijesh Singh wrote: >> From: Tom Lendacky >> >> DMA access to memory mapped as encrypted while SEV is active can not be >> encrypted during device write or decrypted during device read. > > Yeah, definitely rewrite that sentence. Heh, yup. > >> In order >> for DMA to properly work when SEV is active, the SWIOTLB bounce buffers >> must be used. >> >> Signed-off-by: Tom Lendacky >> Signed-off-by: Brijesh Singh >> --- >> arch/x86/mm/mem_encrypt.c | 86 +++++++++++++++++++++++++++++++++++++++++++++++ >> lib/swiotlb.c | 5 +-- >> 2 files changed, 89 insertions(+), 2 deletions > > ... > >> @@ -202,6 +280,14 @@ void __init mem_encrypt_init(void) >> /* Call into SWIOTLB to update the SWIOTLB DMA buffers */ >> swiotlb_update_mem_attributes(); >> >> + /* >> + * With SEV, DMA operations cannot use encryption. New DMA ops >> + * are required in order to mark the DMA areas as decrypted or >> + * to use bounce buffers. >> + */ >> + if (sev_active()) >> + dma_ops = &sme_dma_ops; > > Well, we do differentiate between SME and SEV and the check is > sev_active but the ops are called sme_dma_ops. Call them sev_dma_ops > instead for less confusion. Yup, will do. Thanks, Tom >