Linux Confidential Computing Development
 help / color / mirror / Atom feed
From: K Prateek Nayak <kprateek.nayak@amd.com>
To: "Kalra, Ashish" <ashish.kalra@amd.com>, Borislav Petkov <bp@alien8.de>
Cc: <tglx@kernel.org>, <mingo@redhat.com>,
	<dave.hansen@linux.intel.com>, <x86@kernel.org>, <hpa@zytor.com>,
	<seanjc@google.com>, <peterz@infradead.org>,
	<thomas.lendacky@amd.com>, <herbert@gondor.apana.org.au>,
	<davem@davemloft.net>, <ardb@kernel.org>, <pbonzini@redhat.com>,
	<aik@amd.com>, <Michael.Roth@amd.com>, <Tycho.Andersen@amd.com>,
	<Nathan.Fontenot@amd.com>, <ackerleytng@google.com>,
	<jackyli@google.com>, <pgonda@google.com>, <rientjes@google.com>,
	<jacobhxu@google.com>, <xin@zytor.com>,
	<pawan.kumar.gupta@linux.intel.com>, <babu.moger@amd.com>,
	<dyoung@redhat.com>, <nikunj@amd.com>, <john.allen@amd.com>,
	<darwi@linutronix.de>, <linux-kernel@vger.kernel.org>,
	<linux-crypto@vger.kernel.org>, <kvm@vger.kernel.org>,
	<linux-coco@lists.linux.dev>
Subject: Re: [PATCH v10 2/6] x86/sev: Initialize RMPOPT configuration MSRs
Date: Thu, 23 Jul 2026 12:46:58 +0530	[thread overview]
Message-ID: <535c2a43-47b9-45ac-be9f-d0c53f9f01cc@amd.com> (raw)
In-Reply-To: <6b284f81-3551-471b-bdaa-5c5f8203bdab@amd.com>

Hello Ashish,

On 7/23/2026 12:33 PM, Kalra, Ashish wrote:
> Hello Prateek,
> 
> On 7/23/2026 12:58 AM, K Prateek Nayak wrote:
>> Hello Boris,
>>
>> On 7/23/2026 10:44 AM, Borislav Petkov wrote:
>>> On Thu, Jul 23, 2026 at 10:23:56AM +0530, K Prateek Nayak wrote:
>>>> The offline cores will remain offline since hotplug is disabled. RMPOPT
>>>> is simply a performance optimization for RMP checks and leaving the
>>>> offline cores (that will never exit idle) unoptimized should be
>>>> acceptable.
>>>
>>> What happens if you boot with a subset of cores, the boot flow enables RMPOPT
>>> and then you online the rest?
>>
>> RMPOPT happens at __sev_snp_init_locked() for all online cores. Until
>> then, SnpEn is still 0 and we don't need RMPOPT because RMP checks
>> haven't been enabled yet.
>>
>>>
>>> Have we tried that?
>>
>> That said, Ashish, should snp_rmptable_init() do a
>> snp_rmpopt_all_physmem() (or something equivalent) when it finds SNP_EN
>> set in MSR_AMD64_SYSCFG after a kexec?
>>
> 
> It already happens, just later in the sequence. On kexec __sev_snp_init_locked() still runs: snp_prepare() returns early
> (SnpEn set), SNP_INIT re-initializes the firmware context, and then snp_setup_rmpopt() is called.

But that only happens when the first SNP guest is created right? Until
then RMP checks are enforced but no confidential guest is running and
the CPUs are paying price for those checks.

> On the fresh kexec kernel, rmpopt_wq is NULL, so snp_setup_rmpopt() does the full setup — programs the per-CPU RMPOPT_BASE MSRs and
> queues the initial all-physmem optimization pass. So RMPOPT is re-applied on kexec through the normal path.
> 
> Doing it in snp_rmptable_init() would be too early: the per-CPU RMPOPT_BASE MSRs aren't programmed until
> snp_setup_rmpopt(), so a pass there would have no base configured.

Ack! Which is why I mentioned something equivalent ;-)

-- 
Thanks and Regards,
Prateek


  reply	other threads:[~2026-07-23  7:17 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-30 18:08 [PATCH v10 0/6] Add RMPOPT support Ashish Kalra
2026-06-30 18:09 ` [PATCH v10 1/6] x86/cpufeatures: Add X86_FEATURE_RMPOPT feature flag Ashish Kalra
2026-07-20 21:12   ` Borislav Petkov
2026-06-30 18:10 ` [PATCH v10 2/6] x86/sev: Initialize RMPOPT configuration MSRs Ashish Kalra
2026-07-20 22:17   ` Borislav Petkov
2026-07-20 22:38     ` Kalra, Ashish
2026-07-21  1:48       ` Borislav Petkov
2026-07-21 14:26         ` Kalra, Ashish
2026-07-21 14:57           ` K Prateek Nayak
2026-07-21 20:46             ` Kalra, Ashish
2026-07-22  2:46               ` K Prateek Nayak
2026-07-22 19:17                 ` Kalra, Ashish
2026-07-21 15:32           ` Borislav Petkov
2026-07-23  1:10   ` Borislav Petkov
2026-07-23  4:53     ` K Prateek Nayak
2026-07-23  5:14       ` Borislav Petkov
2026-07-23  5:58         ` K Prateek Nayak
2026-07-23  7:03           ` Kalra, Ashish
2026-07-23  7:16             ` K Prateek Nayak [this message]
2026-07-23  8:00               ` Kalra, Ashish
2026-07-23  6:50         ` Kalra, Ashish
2026-07-23 13:24           ` Kalra, Ashish
2026-07-23 14:29             ` K Prateek Nayak
2026-07-23 18:32           ` Borislav Petkov
2026-06-30 18:11 ` [PATCH v10 3/6] x86/sev: Disable CPU hotplug while SNP is active Ashish Kalra
2026-07-01  9:40   ` Jethro Beekman
2026-07-01 16:39     ` K Prateek Nayak
2026-07-01 21:08       ` Kalra, Ashish
2026-07-01 21:25     ` Kalra, Ashish
2026-07-06 12:02       ` Jethro Beekman
2026-07-23 18:53   ` Borislav Petkov
2026-07-23 19:44     ` Kalra, Ashish
2026-07-23 20:00       ` Borislav Petkov
2026-07-23 20:39         ` Kalra, Ashish
2026-07-23 22:19           ` Kalra, Ashish
2026-06-30 18:11 ` [PATCH v10 4/6] x86/sev: Add support to perform RMP optimizations asynchronously Ashish Kalra
2026-07-21 15:06   ` K Prateek Nayak
2026-07-22 19:43     ` Kalra, Ashish
2026-06-30 18:11 ` [PATCH v10 5/6] x86/sev: Add interface to re-enable RMP optimizations Ashish Kalra
2026-06-30 18:12 ` [PATCH v10 6/6] KVM: SEV: Perform RMP optimizations on SNP guest shutdown Ashish Kalra
2026-07-20 20:17 ` [PATCH v10 0/6] Add RMPOPT support Kalra, Ashish
2026-07-20 20:28   ` Borislav Petkov
2026-07-20 20:39     ` Kalra, Ashish

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=535c2a43-47b9-45ac-be9f-d0c53f9f01cc@amd.com \
    --to=kprateek.nayak@amd.com \
    --cc=Michael.Roth@amd.com \
    --cc=Nathan.Fontenot@amd.com \
    --cc=Tycho.Andersen@amd.com \
    --cc=ackerleytng@google.com \
    --cc=aik@amd.com \
    --cc=ardb@kernel.org \
    --cc=ashish.kalra@amd.com \
    --cc=babu.moger@amd.com \
    --cc=bp@alien8.de \
    --cc=darwi@linutronix.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=davem@davemloft.net \
    --cc=dyoung@redhat.com \
    --cc=herbert@gondor.apana.org.au \
    --cc=hpa@zytor.com \
    --cc=jackyli@google.com \
    --cc=jacobhxu@google.com \
    --cc=john.allen@amd.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=nikunj@amd.com \
    --cc=pawan.kumar.gupta@linux.intel.com \
    --cc=pbonzini@redhat.com \
    --cc=peterz@infradead.org \
    --cc=pgonda@google.com \
    --cc=rientjes@google.com \
    --cc=seanjc@google.com \
    --cc=tglx@kernel.org \
    --cc=thomas.lendacky@amd.com \
    --cc=x86@kernel.org \
    --cc=xin@zytor.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox