mirror of
https://github.com/acidanthera/audk.git
synced 2025-07-25 22:54:51 +02:00
OvmfPkg/ResetVector: Save the encryption mask at boot time
BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=3108 The early assembler code performs validation for some of the SEV-related information, specifically the encryption bit position. To avoid having to re-validate the encryption bit position as the system proceeds through its boot phases, save the validated encryption bit position in the SEV-ES work area for use by later phases. Cc: Jordan Justen <jordan.l.justen@intel.com> Cc: Laszlo Ersek <lersek@redhat.com> Cc: Ard Biesheuvel <ard.biesheuvel@arm.com> Cc: Brijesh Singh <brijesh.singh@amd.com> Reviewed-by: Laszlo Ersek <lersek@redhat.com> Signed-off-by: Tom Lendacky <thomas.lendacky@amd.com> Message-Id: <2609724859cf21f0c6d45bc323e94465dca4e621.1610045305.git.thomas.lendacky@amd.com>
This commit is contained in:
parent
bd0c1c8e22
commit
3b32be7e71
@ -29,6 +29,8 @@ typedef struct _SEC_SEV_ES_WORK_AREA {
|
|||||||
UINT8 Reserved1[7];
|
UINT8 Reserved1[7];
|
||||||
|
|
||||||
UINT64 RandomData;
|
UINT64 RandomData;
|
||||||
|
|
||||||
|
UINT64 EncryptionMask;
|
||||||
} SEC_SEV_ES_WORK_AREA;
|
} SEC_SEV_ES_WORK_AREA;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
@ -145,7 +145,7 @@ GetSevEncBit:
|
|||||||
|
|
||||||
; The encryption bit position is always above 31
|
; The encryption bit position is always above 31
|
||||||
sub ebx, 32
|
sub ebx, 32
|
||||||
jns SevExit
|
jns SevSaveMask
|
||||||
|
|
||||||
; Encryption bit was reported as 31 or below, enter a HLT loop
|
; Encryption bit was reported as 31 or below, enter a HLT loop
|
||||||
SevEncBitLowHlt:
|
SevEncBitLowHlt:
|
||||||
@ -153,6 +153,14 @@ SevEncBitLowHlt:
|
|||||||
hlt
|
hlt
|
||||||
jmp SevEncBitLowHlt
|
jmp SevEncBitLowHlt
|
||||||
|
|
||||||
|
SevSaveMask:
|
||||||
|
xor edx, edx
|
||||||
|
bts edx, ebx
|
||||||
|
|
||||||
|
mov dword[SEV_ES_WORK_AREA_ENC_MASK], 0
|
||||||
|
mov dword[SEV_ES_WORK_AREA_ENC_MASK + 4], edx
|
||||||
|
jmp SevExit
|
||||||
|
|
||||||
NoSev:
|
NoSev:
|
||||||
;
|
;
|
||||||
; Perform an SEV-ES sanity check by seeing if a #VC exception occurred.
|
; Perform an SEV-ES sanity check by seeing if a #VC exception occurred.
|
||||||
|
@ -74,6 +74,7 @@
|
|||||||
%define GHCB_SIZE (FixedPcdGet32 (PcdOvmfSecGhcbSize))
|
%define GHCB_SIZE (FixedPcdGet32 (PcdOvmfSecGhcbSize))
|
||||||
%define SEV_ES_WORK_AREA (FixedPcdGet32 (PcdSevEsWorkAreaBase))
|
%define SEV_ES_WORK_AREA (FixedPcdGet32 (PcdSevEsWorkAreaBase))
|
||||||
%define SEV_ES_WORK_AREA_RDRAND (FixedPcdGet32 (PcdSevEsWorkAreaBase) + 8)
|
%define SEV_ES_WORK_AREA_RDRAND (FixedPcdGet32 (PcdSevEsWorkAreaBase) + 8)
|
||||||
|
%define SEV_ES_WORK_AREA_ENC_MASK (FixedPcdGet32 (PcdSevEsWorkAreaBase) + 16)
|
||||||
%define SEV_ES_VC_TOP_OF_STACK (FixedPcdGet32 (PcdOvmfSecPeiTempRamBase) + FixedPcdGet32 (PcdOvmfSecPeiTempRamSize))
|
%define SEV_ES_VC_TOP_OF_STACK (FixedPcdGet32 (PcdOvmfSecPeiTempRamBase) + FixedPcdGet32 (PcdOvmfSecPeiTempRamSize))
|
||||||
%include "Ia32/Flat32ToFlat64.asm"
|
%include "Ia32/Flat32ToFlat64.asm"
|
||||||
%include "Ia32/PageTables64.asm"
|
%include "Ia32/PageTables64.asm"
|
||||||
|
Loading…
x
Reference in New Issue
Block a user