<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/OvmfPkg/Library/BaseMemEncryptSevLib/DxeMemEncryptSevLibInternal.c, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2026-08-27T06:37:01+00:00</updated>
<entry>
<title>OvmfPkg/BaseMemEncryptSevLib: Fetch Sev data from the work area</title>
<updated>2026-08-27T06:37:01+00:00</updated>
<author>
<name>John Berg</name>
<email>jhnberg@amazon.co.uk</email>
</author>
<published>2026-08-05T13:35:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=196e496a4ec19c083c6e97b87c475c73020807da'/>
<id>urn:sha1:196e496a4ec19c083c6e97b87c475c73020807da</id>
<content type='text'>
The first call to MemEncryptSevGetEncryptionMask() in the Dxe phase will
look for the encryption mask for the page table entry by reading the
PcdPteMemoryEncryptionAddressOrMask (dynamic PCD) token. The value is
then cached for subsequent accesses. But if the first call has
interrupts disabled, as is the case in the MmioExit function in the #VC
handler then the PcdGet64() will re-enable interrupts unexpectedly. A
hypervisor may then inject interrupts into the guest whilst the guest is
not expected to be interrupted. This leads to the ovmf image hanging
when handling too many nested #VC exceptions.

This patch avoids using the PcdPteMemoryEncryptionAddressOrMask token in
the MemEncryptSevGetEncryptionMask() function as it cannot be called
safely from a context where interrupts are disabled. Instead, we fetch
the values from the SEC_SEV_ES_WORK_AREA in the Dxe phase. The work area
is already used in the Pei phase, and is available in the Dxe phase as it
is marked as either EfiBootServicesData or EfiACPIMemoryNVS. However,
the work area will be inaccessible when SetVirtualAddressMap() is called,
so we only read the work area in the Dxe phase through a constructor function.

Signed-off-by: John Berg &lt;jhnberg@amazon.co.uk&gt;
Signed-off-by: Ivan Orlov &lt;iorlov@amazon.co.uk&gt;
</content>
</entry>
<entry>
<title>OvmfPkg/BaseMemEncryptSevLib: Make GetSevEsWorkArea() Pei/Dxe shared</title>
<updated>2026-08-27T06:37:01+00:00</updated>
<author>
<name>John Berg</name>
<email>jhnberg@amazon.co.uk</email>
</author>
<published>2026-08-13T09:01:38+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=6a99d10480bacd0affcfe2c7399d961237e00b79'/>
<id>urn:sha1:6a99d10480bacd0affcfe2c7399d961237e00b79</id>
<content type='text'>
This is a small refactor to the BaseMemEncryptSevLib in the OvmfPkg
which moves the function used in the Pei phase for accessing the
SEC_SEV_ES_WORK_AREA, into the common Pei and Dxe code. The Dxe phase
will consume the work area in a subsequent patch.

Signed-off-by: John Berg &lt;jhnberg@amazon.co.uk&gt;
</content>
</entry>
<entry>
<title>OvmfPkg/MemEncryptSevLib: Check if SEV-SNP coherency mitigitation is needed</title>
<updated>2025-09-09T17:43:31+00:00</updated>
<author>
<name>Tom Lendacky</name>
<email>thomas.lendacky@amd.com</email>
</author>
<published>2025-07-22T20:06:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=20f24c0f67b3364cd590e1eea470f74be40e7710'/>
<id>urn:sha1:20f24c0f67b3364cd590e1eea470f74be40e7710</id>
<content type='text'>
CPUID bit Fn8000001F_EBX[31] defines the COHERNECY_SFW_NO CPUID bit that,
when set, indicates that the software mitigation for this vulnerability is
not needed.

Add support to check for this CPUID bit and avoid the mitigation if set.

Signed-off-by: Tom Lendacky &lt;thomas.lendacky@amd.com&gt;
</content>
</entry>
<entry>
<title>OvmfPkg: Add AMD SEV-ES DebugVirtualization feature support</title>
<updated>2024-07-04T20:39:26+00:00</updated>
<author>
<name>Alexey Kardashevskiy</name>
<email>aik@amd.com</email>
</author>
<published>2022-11-30T08:41:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=9f06feb5d2fa43e184690034e70e6d427cf6913d'/>
<id>urn:sha1:9f06feb5d2fa43e184690034e70e6d427cf6913d</id>
<content type='text'>
The SEV-ES DebugVirtualization feature enables type B swapping of
debug registers on #VMEXIT and makes #DB and DR7 intercepts
unnecessary and unwanted.

When DebugVirtualization is enabled, this stops booting if
interaction from the HV.

Add new API to PEI, SEC, DXE.

This does not change the existing behaviour yet.

Cc: Ard Biesheuvel &lt;ardb+tianocore@kernel.org&gt;
Cc: Erdem Aktas &lt;erdemaktas@google.com&gt;
Cc: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Michael Roth &lt;michael.roth@amd.com&gt;
Cc: Min Xu &lt;min.m.xu@intel.com&gt;
Reviewed-by: Tom Lendacky &lt;thomas.lendacky@amd.com&gt;
Signed-off-by: Alexey Kardashevskiy &lt;aik@amd.com&gt;
---
Changes:
v5:
* "rb" from Tom

v4:
* s/DebugSwap/DebugVirtualization/
</content>
</entry>
<entry>
<title>OvmfPkg/BaseMemEncryptLib: use the SEV_STATUS MSR value from workarea</title>
<updated>2022-02-28T02:46:08+00:00</updated>
<author>
<name>Brijesh Singh</name>
<email>brijesh.singh@amd.com</email>
</author>
<published>2022-02-21T14:59:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=f1d1c337e7c0575da7fd248b2dd9cffc755940df'/>
<id>urn:sha1:f1d1c337e7c0575da7fd248b2dd9cffc755940df</id>
<content type='text'>
BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=3582

Improve the MemEncryptSev{Es,Snp}IsEnabled() to use the SEV_STATUS MSR
value saved in the workarea. Since workarea is valid until the PEI phase,
so, for the Dxe phase use the PcdConfidentialComputingGuestAttr to
determine which SEV technology is enabled.

Cc: Min Xu &lt;min.m.xu@intel.com&gt;
Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Tom Lendacky &lt;thomas.lendacky@amd.com&gt;
Cc: Jordan Justen &lt;jordan.l.justen@intel.com&gt;
Cc: Ard Biesheuvel &lt;ardb+tianocore@kernel.org&gt;
Cc: Erdem Aktas &lt;erdemaktas@google.com&gt;
Cc: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
Acked-by: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
Signed-off-by: Brijesh Singh &lt;brijesh.singh@amd.com&gt;
Acked-by: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
</content>
</entry>
<entry>
<title>OvmfPkg/MemEncryptSevLib: add MemEncryptSevSnpEnabled()</title>
<updated>2021-12-09T06:28:10+00:00</updated>
<author>
<name>Brijesh Singh</name>
<email>brijesh.singh@amd.com</email>
</author>
<published>2021-12-09T03:27:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=d9822304ce0075b1075edf93cc6e2514685b5212'/>
<id>urn:sha1:d9822304ce0075b1075edf93cc6e2514685b5212</id>
<content type='text'>
BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=3275

Create a function that can be used to determine if VM is running as an
SEV-SNP guest.

Cc: Michael Roth &lt;michael.roth@amd.com&gt;
Cc: James Bottomley &lt;jejb@linux.ibm.com&gt;
Cc: Min Xu &lt;min.m.xu@intel.com&gt;
Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Tom Lendacky &lt;thomas.lendacky@amd.com&gt;
Cc: Jordan Justen &lt;jordan.l.justen@intel.com&gt;
Cc: Ard Biesheuvel &lt;ardb+tianocore@kernel.org&gt;
Cc: Erdem Aktas &lt;erdemaktas@google.com&gt;
Cc: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
Acked-by: Jiewen Yao &lt;Jiewen.yao@intel.com&gt;
Acked-by: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
Signed-off-by: Brijesh Singh &lt;brijesh.singh@amd.com&gt;
</content>
</entry>
<entry>
<title>OvmfPkg: Apply uncrustify changes</title>
<updated>2021-12-07T17:24:28+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2021-12-05T22:54:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=ac0a286f4d747a4c6c603a7b225917293cbe1e9f'/>
<id>urn:sha1:ac0a286f4d747a4c6c603a7b225917293cbe1e9f</id>
<content type='text'>
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3737

Apply uncrustify changes to .c/.h files in the OvmfPkg package

Cc: Andrew Fish &lt;afish@apple.com&gt;
Cc: Leif Lindholm &lt;leif@nuviainc.com&gt;
Cc: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
Signed-off-by: Michael Kubacki &lt;michael.kubacki@microsoft.com&gt;
Reviewed-by: Andrew Fish &lt;afish@apple.com&gt;
</content>
</entry>
<entry>
<title>OvmfPkg/MemEncryptSevLib: Add an interface to retrieve the encryption mask</title>
<updated>2021-01-07T19:34:39+00:00</updated>
<author>
<name>Tom Lendacky</name>
<email>thomas.lendacky@amd.com</email>
</author>
<published>2021-01-07T18:48:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=b97dc4b92ba1cc9f351854aed1c35c636d2d3992'/>
<id>urn:sha1:b97dc4b92ba1cc9f351854aed1c35c636d2d3992</id>
<content type='text'>
BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=3108

To ensure that we always use a validated encryption mask for an SEV-ES
guest, create a new interface in the MemEncryptSevLib library to return
the encryption mask. This can be used in place of the multiple locations
where CPUID is used to retrieve the value (which would require validation
again) and allows the validated mask to be returned.

The PEI phase will use the value from the SEV-ES work area. Since the
SEV-ES work area isn't valid in the DXE phase, the DXE phase will use the
PcdPteMemoryEncryptionAddressOrMask PCD which is set during PEI.

Cc: Jordan Justen &lt;jordan.l.justen@intel.com&gt;
Cc: Laszlo Ersek &lt;lersek@redhat.com&gt;
Cc: Ard Biesheuvel &lt;ard.biesheuvel@arm.com&gt;
Cc: Rebecca Cran &lt;rebecca@bsdio.com&gt;
Cc: Peter Grehan &lt;grehan@freebsd.org&gt;
Cc: Anthony Perard &lt;anthony.perard@citrix.com&gt;
Cc: Julien Grall &lt;julien@xen.org&gt;
Cc: Brijesh Singh &lt;brijesh.singh@amd.com&gt;
Acked-by: Laszlo Ersek &lt;lersek@redhat.com&gt;
Signed-off-by: Tom Lendacky &lt;thomas.lendacky@amd.com&gt;
Message-Id: &lt;e12044dc01b21e6fc2e9535760ddf3a38a142a71.1610045305.git.thomas.lendacky@amd.com&gt;
</content>
</entry>
</feed>
