From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from NAM02-BL2-obe.outbound.protection.outlook.com (mail-bl2nam02on0078.outbound.protection.outlook.com [104.47.38.78]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 3xSpGs4tm9zDqs4 for ; Thu, 10 Aug 2017 23:03:32 +1000 (AEST) Subject: Re: [RFC Part1 PATCH v3 05/17] x86, realmode: Don't decrypt trampoline area under SEV To: Borislav Petkov , Brijesh Singh Cc: linux-kernel@vger.kernel.org, x86@kernel.org, linux-efi@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, kvm@vger.kernel.org, Thomas Gleixner , Ingo Molnar , "H . Peter Anvin" , Andy Lutomirski , Tony Luck , Piotr Luc , Fenghua Yu , Lu Baolu , Reza Arbab , David Howells , Matt Fleming , "Kirill A . Shutemov" , Laura Abbott , Ard Biesheuvel , Andrew Morton , Eric Biederman , Benjamin Herrenschmidt , Paul Mackerras , Konrad Rzeszutek Wilk , Jonathan Corbet , Dave Airlie , Kees Cook , Paolo Bonzini , =?UTF-8?B?UmFkaW0gS3LEjW3DocWZ?= , Arnd Bergmann , Tejun Heo , Christoph Lameter References: <20170724190757.11278-1-brijesh.singh@amd.com> <20170724190757.11278-6-brijesh.singh@amd.com> <20170726160304.GE30471@nazgul.tnic> From: Tom Lendacky Message-ID: Date: Thu, 10 Aug 2017 08:03:12 -0500 MIME-Version: 1.0 In-Reply-To: <20170726160304.GE30471@nazgul.tnic> Content-Type: text/plain; charset=utf-8; format=flowed List-Id: Linux on PowerPC Developers Mail List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , On 7/26/2017 11:03 AM, Borislav Petkov wrote: > Subject: x86/realmode: ... Done. > > On Mon, Jul 24, 2017 at 02:07:45PM -0500, Brijesh Singh wrote: >> From: Tom Lendacky >> >> When SEV is active the trampoline area will need to be in encrypted >> memory so only mark the area decrypted if SME is active. >> >> Signed-off-by: Tom Lendacky >> Signed-off-by: Brijesh Singh >> --- >> arch/x86/realmode/init.c | 6 ++++-- >> 1 file changed, 4 insertions(+), 2 deletions(-) >> >> diff --git a/arch/x86/realmode/init.c b/arch/x86/realmode/init.c >> index 1f71980..c7eeca7 100644 >> --- a/arch/x86/realmode/init.c >> +++ b/arch/x86/realmode/init.c >> @@ -63,9 +63,11 @@ static void __init setup_real_mode(void) >> /* >> * If SME is active, the trampoline area will need to be in >> * decrypted memory in order to bring up other processors >> - * successfully. >> + * successfully. For SEV the trampoline area needs to be in >> + * encrypted memory, so only do this for SME. > > Or simply say: > > "It is not needed for SEV." Will do. Thanks, Tom >