From: "Kalra, Ashish" <ashish.kalra@amd.com>
To: K Prateek Nayak <kprateek.nayak@amd.com>, Borislav Petkov <bp@alien8.de>
Cc: tglx@kernel.org, mingo@redhat.com, dave.hansen@linux.intel.com,
x86@kernel.org, hpa@zytor.com, seanjc@google.com,
peterz@infradead.org, thomas.lendacky@amd.com,
herbert@gondor.apana.org.au, davem@davemloft.net,
ardb@kernel.org, pbonzini@redhat.com, aik@amd.com,
Michael.Roth@amd.com, Tycho.Andersen@amd.com,
Nathan.Fontenot@amd.com, ackerleytng@google.com,
jackyli@google.com, pgonda@google.com, rientjes@google.com,
jacobhxu@google.com, xin@zytor.com,
pawan.kumar.gupta@linux.intel.com, babu.moger@amd.com,
dyoung@redhat.com, nikunj@amd.com, john.allen@amd.com,
darwi@linutronix.de, linux-kernel@vger.kernel.org,
linux-crypto@vger.kernel.org, kvm@vger.kernel.org,
linux-coco@lists.linux.dev
Subject: Re: [PATCH v10 2/6] x86/sev: Initialize RMPOPT configuration MSRs
Date: Tue, 21 Jul 2026 15:46:21 -0500 [thread overview]
Message-ID: <509ac5f1-d05d-4c95-8e61-f0d4b04bbb92@amd.com> (raw)
In-Reply-To: <2696f0a9-d2a3-41e8-91be-6f00a20d5f27@amd.com>
Hello Prateek,
On 7/21/2026 9:57 AM, K Prateek Nayak wrote:
> Hello Ashish,
>
> On 7/21/2026 7:56 PM, Kalra, Ashish wrote:
>> That's why v7 moved to a runtime check. In v11 (as i mentioned) this will be a small local helper, it will also handles two things
>> the cap-clear can't:
>> - a contiguous (non-segmented) RMP, where RMPOPT isn't usable even with X86_FEATURE_RMPOPT set.
>> - SNP being disabled at runtime (CC_ATTR_HOST_SEV_SNP).
>>
>> static bool rmpopt_capable(void)
>> {
>> return cpu_feature_enabled(X86_FEATURE_RMPOPT) &&
>> cc_platform_has(CC_ATTR_HOST_SEV_SNP) &&
>
> CC_ATTR_HOST_SEV_SNP is set from bsp_determine_snp() ...
>
>> (rmp_cfg & MSR_AMD64_SEG_RMP_ENABLED) &&
>
> ... and that already checks snp_probe_rmptable_info() ...
>
>> rmp_segment_table;
>
> .. and if iommu_snp_enable() fails snp_rmptable_init(), we clear
> CC_ATTR_HOST_SEV_SNP.
>
> So, the way I see it, CC_ATTR_HOST_SEV_SNP being set means we have
> already tried provisioning RMP table.
Agreed, and that makes rmp_segment_table redundant — iommu_snp_enable() clears CC_ATTR_HOST_SEV_SNP when
snp_rmptable_init() fails, so the attr being set already implies rmp_segment_table != NULL. I'll drop it.
The one I'd keep is (rmp_cfg & MSR_AMD64_SEG_RMP_ENABLED). It's a runtime config bit, not the CPUID feature:
setup_rmptable() allocates rmp_segment_table and keeps CC_ATTR_HOST_SEV_SNP set for both segmented and contiguous RMP, so
the MSR bit is the only thing that distinguishes them — and RMPOPT needs a segmented RMP.
Clearing X86_FEATURE_RMPOPT in snp_rmptable_init() won't work on its own as i mentioned in this reply earlier: it runs at
rootfs_initcall, after alternative_instructions(), so cpu_feature_enabled() keeps returning true off the already-patched
static_cpu_has().
So the helper becomes:
static bool rmpopt_capable(void)
{
return cpu_feature_enabled(X86_FEATURE_RMPOPT) &&
cc_platform_has(CC_ATTR_HOST_SEV_SNP) &&
(rmp_cfg & MSR_AMD64_SEG_RMP_ENABLED);
}
Thanks,
Ashish
>
> I'm assuming all platforms that have X86_FEATURE_RMPOPT will all have
> segmented RMP. If not, you can just clear X86_FEATURE_RMPOPT in
> snp_rmptable_init() no?
>
> We can never reach functions that need rmpopt_capable() without
> first checking CC_ATTR_HOST_SEV_SNP.
>
next prev parent reply other threads:[~2026-07-21 20:46 UTC|newest]
Thread overview: 43+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-30 18:08 [PATCH v10 0/6] Add RMPOPT support Ashish Kalra
2026-06-30 18:09 ` [PATCH v10 1/6] x86/cpufeatures: Add X86_FEATURE_RMPOPT feature flag Ashish Kalra
2026-07-20 21:12 ` Borislav Petkov
2026-06-30 18:10 ` [PATCH v10 2/6] x86/sev: Initialize RMPOPT configuration MSRs Ashish Kalra
2026-07-20 22:17 ` Borislav Petkov
2026-07-20 22:38 ` Kalra, Ashish
2026-07-21 1:48 ` Borislav Petkov
2026-07-21 14:26 ` Kalra, Ashish
2026-07-21 14:57 ` K Prateek Nayak
2026-07-21 20:46 ` Kalra, Ashish [this message]
2026-07-22 2:46 ` K Prateek Nayak
2026-07-22 19:17 ` Kalra, Ashish
2026-07-21 15:32 ` Borislav Petkov
2026-07-23 1:10 ` Borislav Petkov
2026-07-23 4:53 ` K Prateek Nayak
2026-07-23 5:14 ` Borislav Petkov
2026-07-23 5:58 ` K Prateek Nayak
2026-07-23 7:03 ` Kalra, Ashish
2026-07-23 7:16 ` K Prateek Nayak
2026-07-23 8:00 ` Kalra, Ashish
2026-07-23 6:50 ` Kalra, Ashish
2026-07-23 13:24 ` Kalra, Ashish
2026-07-23 14:29 ` K Prateek Nayak
2026-07-23 18:32 ` Borislav Petkov
2026-06-30 18:11 ` [PATCH v10 3/6] x86/sev: Disable CPU hotplug while SNP is active Ashish Kalra
2026-07-01 9:40 ` Jethro Beekman
2026-07-01 16:39 ` K Prateek Nayak
2026-07-01 21:08 ` Kalra, Ashish
2026-07-01 21:25 ` Kalra, Ashish
2026-07-06 12:02 ` Jethro Beekman
2026-07-23 18:53 ` Borislav Petkov
2026-07-23 19:44 ` Kalra, Ashish
2026-07-23 20:00 ` Borislav Petkov
2026-07-23 20:39 ` Kalra, Ashish
2026-07-23 22:19 ` Kalra, Ashish
2026-06-30 18:11 ` [PATCH v10 4/6] x86/sev: Add support to perform RMP optimizations asynchronously Ashish Kalra
2026-07-21 15:06 ` K Prateek Nayak
2026-07-22 19:43 ` Kalra, Ashish
2026-06-30 18:11 ` [PATCH v10 5/6] x86/sev: Add interface to re-enable RMP optimizations Ashish Kalra
2026-06-30 18:12 ` [PATCH v10 6/6] KVM: SEV: Perform RMP optimizations on SNP guest shutdown Ashish Kalra
2026-07-20 20:17 ` [PATCH v10 0/6] Add RMPOPT support Kalra, Ashish
2026-07-20 20:28 ` Borislav Petkov
2026-07-20 20:39 ` Kalra, Ashish
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=509ac5f1-d05d-4c95-8e61-f0d4b04bbb92@amd.com \
--to=ashish.kalra@amd.com \
--cc=Michael.Roth@amd.com \
--cc=Nathan.Fontenot@amd.com \
--cc=Tycho.Andersen@amd.com \
--cc=ackerleytng@google.com \
--cc=aik@amd.com \
--cc=ardb@kernel.org \
--cc=babu.moger@amd.com \
--cc=bp@alien8.de \
--cc=darwi@linutronix.de \
--cc=dave.hansen@linux.intel.com \
--cc=davem@davemloft.net \
--cc=dyoung@redhat.com \
--cc=herbert@gondor.apana.org.au \
--cc=hpa@zytor.com \
--cc=jackyli@google.com \
--cc=jacobhxu@google.com \
--cc=john.allen@amd.com \
--cc=kprateek.nayak@amd.com \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=nikunj@amd.com \
--cc=pawan.kumar.gupta@linux.intel.com \
--cc=pbonzini@redhat.com \
--cc=peterz@infradead.org \
--cc=pgonda@google.com \
--cc=rientjes@google.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=thomas.lendacky@amd.com \
--cc=x86@kernel.org \
--cc=xin@zytor.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox