mirror of https://github.com/acidanthera/audk.git
OvmfPkg/SecMain: validate the memory used for decompressing Fv
BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=3275 The VMM launch sequence should have pre-validated all the data pages used in the Reset vector. The range does not cover the data pages used during the SEC phase (mainly PEI and DXE firmware volume decompression memory). When SEV-SNP is active, the memory must be pre-validated before the access. Add support to pre-validate the memory range from SnpSecPreValidatedStart to SnpSecPreValidatedEnd. This should be sufficent to enter into the PEI phase. Cc: Michael Roth <michael.roth@amd.com> Cc: James Bottomley <jejb@linux.ibm.com> Cc: Min Xu <min.m.xu@intel.com> Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Tom Lendacky <thomas.lendacky@amd.com> Cc: Jordan Justen <jordan.l.justen@intel.com> Cc: Ard Biesheuvel <ardb+tianocore@kernel.org> Cc: Erdem Aktas <erdemaktas@google.com> Cc: Gerd Hoffmann <kraxel@redhat.com> Acked-by: Jiewen Yao <Jiewen.yao@intel.com> Acked-by: Gerd Hoffmann <kraxel@redhat.com> Signed-off-by: Brijesh Singh <brijesh.singh@amd.com>
This commit is contained in:
parent
d39f8d88ec
commit
202fb22be6
|
@ -63,3 +63,8 @@ DEFINE DECOMP_SCRATCH_BASE_MASK = 0xFFF00000
|
||||||
DEFINE DECOMP_SCRATCH_BASE = (($(DECOMP_SCRATCH_BASE_UNALIGNED) + $(DECOMP_SCRATCH_BASE_ALIGNMENT)) & $(DECOMP_SCRATCH_BASE_MASK))
|
DEFINE DECOMP_SCRATCH_BASE = (($(DECOMP_SCRATCH_BASE_UNALIGNED) + $(DECOMP_SCRATCH_BASE_ALIGNMENT)) & $(DECOMP_SCRATCH_BASE_MASK))
|
||||||
|
|
||||||
SET gUefiOvmfPkgTokenSpaceGuid.PcdOvmfDecompressionScratchEnd = $(DECOMP_SCRATCH_BASE) + $(DECOMP_SCRATCH_SIZE)
|
SET gUefiOvmfPkgTokenSpaceGuid.PcdOvmfDecompressionScratchEnd = $(DECOMP_SCRATCH_BASE) + $(DECOMP_SCRATCH_SIZE)
|
||||||
|
|
||||||
|
#
|
||||||
|
# The range of pages that should be pre-validated during the SEC phase when SEV-SNP is active in the guest VM.
|
||||||
|
SET gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecValidatedStart = $(MEMFD_BASE_ADDRESS) + gUefiOvmfPkgTokenSpaceGuid.PcdOvmfPeiMemFvBase
|
||||||
|
SET gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecValidatedEnd = $(DECOMP_SCRATCH_BASE) + $(DECOMP_SCRATCH_SIZE)
|
||||||
|
|
|
@ -60,3 +60,5 @@
|
||||||
gUefiCpuPkgTokenSpaceGuid.PcdSevEsWorkAreaBase
|
gUefiCpuPkgTokenSpaceGuid.PcdSevEsWorkAreaBase
|
||||||
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfPeiMemFvBase
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfPeiMemFvBase
|
||||||
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecPageTablesBase
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecPageTablesBase
|
||||||
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecValidatedEnd
|
||||||
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecValidatedStart
|
||||||
|
|
|
@ -29,6 +29,11 @@ STATIC SNP_PRE_VALIDATED_RANGE mPreValidatedRange[] = {
|
||||||
FixedPcdGet32 (PcdOvmfSecPageTablesBase),
|
FixedPcdGet32 (PcdOvmfSecPageTablesBase),
|
||||||
FixedPcdGet32 (PcdOvmfPeiMemFvBase),
|
FixedPcdGet32 (PcdOvmfPeiMemFvBase),
|
||||||
},
|
},
|
||||||
|
// The below range is pre-validated by the Sec/SecMain.c
|
||||||
|
{
|
||||||
|
FixedPcdGet32 (PcdOvmfSecValidatedStart),
|
||||||
|
FixedPcdGet32 (PcdOvmfSecValidatedEnd)
|
||||||
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
STATIC
|
STATIC
|
||||||
|
|
|
@ -364,6 +364,10 @@
|
||||||
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfCpuidBase|0|UINT32|0x60
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfCpuidBase|0|UINT32|0x60
|
||||||
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfCpuidSize|0|UINT32|0x61
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfCpuidSize|0|UINT32|0x61
|
||||||
|
|
||||||
|
## The range of memory that is validated by the SEC phase.
|
||||||
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecValidatedStart|0|UINT32|0x62
|
||||||
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecValidatedEnd|0|UINT32|0x63
|
||||||
|
|
||||||
[PcdsDynamic, PcdsDynamicEx]
|
[PcdsDynamic, PcdsDynamicEx]
|
||||||
gUefiOvmfPkgTokenSpaceGuid.PcdEmuVariableEvent|0|UINT64|2
|
gUefiOvmfPkgTokenSpaceGuid.PcdEmuVariableEvent|0|UINT64|2
|
||||||
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfFlashVariablesEnable|FALSE|BOOLEAN|0x10
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfFlashVariablesEnable|FALSE|BOOLEAN|0x10
|
||||||
|
|
|
@ -55,7 +55,6 @@ SevEsProtocolFailure (
|
||||||
@retval FALSE SEV-SNP is not enabled
|
@retval FALSE SEV-SNP is not enabled
|
||||||
|
|
||||||
**/
|
**/
|
||||||
STATIC
|
|
||||||
BOOLEAN
|
BOOLEAN
|
||||||
SevSnpIsEnabled (
|
SevSnpIsEnabled (
|
||||||
VOID
|
VOID
|
||||||
|
@ -281,3 +280,24 @@ SevEsIsEnabled (
|
||||||
|
|
||||||
return (SevEsWorkArea->SevEsEnabled != 0);
|
return (SevEsWorkArea->SevEsEnabled != 0);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
Validate System RAM used for decompressing the PEI and DXE firmware volumes
|
||||||
|
when SEV-SNP is active. The PCDs SecValidatedStart and SecValidatedEnd are
|
||||||
|
set in OvmfPkg/FvmainCompactScratchEnd.fdf.inc.
|
||||||
|
|
||||||
|
**/
|
||||||
|
VOID
|
||||||
|
SecValidateSystemRam (
|
||||||
|
VOID
|
||||||
|
)
|
||||||
|
{
|
||||||
|
PHYSICAL_ADDRESS Start, End;
|
||||||
|
|
||||||
|
if (IsSevGuest () && SevSnpIsEnabled ()) {
|
||||||
|
Start = (EFI_PHYSICAL_ADDRESS)(UINTN)PcdGet32 (PcdOvmfSecValidatedStart);
|
||||||
|
End = (EFI_PHYSICAL_ADDRESS)(UINTN)PcdGet32 (PcdOvmfSecValidatedEnd);
|
||||||
|
|
||||||
|
MemEncryptSevSnpPreValidateSystemRam (Start, EFI_SIZE_TO_PAGES ((UINTN)(End - Start)));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
|
@ -68,4 +68,27 @@ SevEsIsEnabled (
|
||||||
VOID
|
VOID
|
||||||
);
|
);
|
||||||
|
|
||||||
|
/**
|
||||||
|
Validate System RAM used for decompressing the PEI and DXE firmware volumes
|
||||||
|
when SEV-SNP is active. The PCDs SecValidatedStart and SecValidatedEnd are
|
||||||
|
set in OvmfPkg/FvmainCompactScratchEnd.fdf.inc.
|
||||||
|
|
||||||
|
**/
|
||||||
|
VOID
|
||||||
|
SecValidateSystemRam (
|
||||||
|
VOID
|
||||||
|
);
|
||||||
|
|
||||||
|
/**
|
||||||
|
Determine if SEV-SNP is active.
|
||||||
|
|
||||||
|
@retval TRUE SEV-SNP is enabled
|
||||||
|
@retval FALSE SEV-SNP is not enabled
|
||||||
|
|
||||||
|
**/
|
||||||
|
BOOLEAN
|
||||||
|
SevSnpIsEnabled (
|
||||||
|
VOID
|
||||||
|
);
|
||||||
|
|
||||||
#endif
|
#endif
|
||||||
|
|
|
@ -860,6 +860,11 @@ SecCoreStartupWithStack (
|
||||||
SecCoreData.BootFirmwareVolumeBase = BootFv;
|
SecCoreData.BootFirmwareVolumeBase = BootFv;
|
||||||
SecCoreData.BootFirmwareVolumeSize = (UINTN)BootFv->FvLength;
|
SecCoreData.BootFirmwareVolumeSize = (UINTN)BootFv->FvLength;
|
||||||
|
|
||||||
|
//
|
||||||
|
// Validate the System RAM used in the SEC Phase
|
||||||
|
//
|
||||||
|
SecValidateSystemRam ();
|
||||||
|
|
||||||
//
|
//
|
||||||
// Make sure the 8259 is masked before initializing the Debug Agent and the debug timer is enabled
|
// Make sure the 8259 is masked before initializing the Debug Agent and the debug timer is enabled
|
||||||
//
|
//
|
||||||
|
|
|
@ -52,6 +52,7 @@
|
||||||
PeCoffExtraActionLib
|
PeCoffExtraActionLib
|
||||||
ExtractGuidedSectionLib
|
ExtractGuidedSectionLib
|
||||||
LocalApicLib
|
LocalApicLib
|
||||||
|
MemEncryptSevLib
|
||||||
CpuExceptionHandlerLib
|
CpuExceptionHandlerLib
|
||||||
|
|
||||||
[Ppis]
|
[Ppis]
|
||||||
|
@ -74,6 +75,8 @@
|
||||||
gEfiMdeModulePkgTokenSpaceGuid.PcdInitValueInTempStack
|
gEfiMdeModulePkgTokenSpaceGuid.PcdInitValueInTempStack
|
||||||
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfConfidentialComputingWorkAreaHeader
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfConfidentialComputingWorkAreaHeader
|
||||||
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfWorkAreaBase
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfWorkAreaBase
|
||||||
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecValidatedStart
|
||||||
|
gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecValidatedEnd
|
||||||
|
|
||||||
[FeaturePcd]
|
[FeaturePcd]
|
||||||
gUefiOvmfPkgTokenSpaceGuid.PcdSmmSmramRequire
|
gUefiOvmfPkgTokenSpaceGuid.PcdSmmSmramRequire
|
||||||
|
|
Loading…
Reference in New Issue