<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/OvmfPkg/Library/BaseMemEncryptSevLib, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2026-09-11T08:27:12+00:00</updated>
<entry>
<title>OvmfPkg/BaseMemEncryptSevLib: Fix read-only pagetable support</title>
<updated>2026-09-11T08:27:12+00:00</updated>
<author>
<name>Tom Lendacky</name>
<email>thomas.lendacky@amd.com</email>
</author>
<published>2026-09-10T14:29:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=664068240f91d2b677d1179afcceb566fa8584a2'/>
<id>urn:sha1:664068240f91d2b677d1179afcceb566fa8584a2</id>
<content type='text'>
SetMemoryEncDec() ensures that any newly created pagetable pages are
marked read-only upon completion of the pagetable changes. This is done
by calling EnablePageTableProtection(). EnablePageTableProtection()
invokes SetPageTablePoolReadOnly() which expects the input PageTableBase
parameter to point to the beginning of the level 4 pagetable as it
calculates the offset/index into the pagetable based on the input address.

However, there is a bug that is seen when the input address is above
512GB. SetMemoryEncDec() uses the PageMapLevel4Entry variable when it
invokes EnablePageTableProtection(), which points to the start of the
level 4 pagetable if the address is below 512GB. Once above that range,
PageMapLevel4Entry points past the start of the pagetable. This causes
SetPageTablePoolReadOnly() to improperly address pagetable entries.

This was recently exposed when 7735ed4f8eb3 ("OvmfPkg/PlatformInitLib:
Set dynamic MMIO window size to 1/4") pushed the MMIO range above 512GB.

Fix the issue by always using the Cr3BaseAddress value when calling
EnablePageTableProtection().

Since PageMapLevel4Entry is never used outside of the loop anymore,
remove the initialization to NULL. Also, the check for Cr3BaseAddress
being NULL does not need to be done inside the loop, so move it to outside
the loop (which will suppress incorrect compiler/analyzer warnings).

Signed-off-by: Tom Lendacky &lt;thomas.lendacky@amd.com&gt;
</content>
</entry>
<entry>
<title>OvmfPkg/BaseMemEncryptSevLib: Fetch Sev data from the work area</title>
<updated>2026-08-27T06:37:01+00:00</updated>
<author>
<name>John Berg</name>
<email>jhnberg@amazon.co.uk</email>
</author>
<published>2026-08-05T13:35:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=196e496a4ec19c083c6e97b87c475c73020807da'/>
<id>urn:sha1:196e496a4ec19c083c6e97b87c475c73020807da</id>
<content type='text'>
The first call to MemEncryptSevGetEncryptionMask() in the Dxe phase will
look for the encryption mask for the page table entry by reading the
PcdPteMemoryEncryptionAddressOrMask (dynamic PCD) token. The value is
then cached for subsequent accesses. But if the first call has
interrupts disabled, as is the case in the MmioExit function in the #VC
handler then the PcdGet64() will re-enable interrupts unexpectedly. A
hypervisor may then inject interrupts into the guest whilst the guest is
not expected to be interrupted. This leads to the ovmf image hanging
when handling too many nested #VC exceptions.

This patch avoids using the PcdPteMemoryEncryptionAddressOrMask token in
the MemEncryptSevGetEncryptionMask() function as it cannot be called
safely from a context where interrupts are disabled. Instead, we fetch
the values from the SEC_SEV_ES_WORK_AREA in the Dxe phase. The work area
is already used in the Pei phase, and is available in the Dxe phase as it
is marked as either EfiBootServicesData or EfiACPIMemoryNVS. However,
the work area will be inaccessible when SetVirtualAddressMap() is called,
so we only read the work area in the Dxe phase through a constructor function.

Signed-off-by: John Berg &lt;jhnberg@amazon.co.uk&gt;
Signed-off-by: Ivan Orlov &lt;iorlov@amazon.co.uk&gt;
</content>
</entry>
<entry>
<title>OvmfPkg/BaseMemEncryptSevLib: Make GetSevEsWorkArea() Pei/Dxe shared</title>
<updated>2026-08-27T06:37:01+00:00</updated>
<author>
<name>John Berg</name>
<email>jhnberg@amazon.co.uk</email>
</author>
<published>2026-08-13T09:01:38+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=6a99d10480bacd0affcfe2c7399d961237e00b79'/>
<id>urn:sha1:6a99d10480bacd0affcfe2c7399d961237e00b79</id>
<content type='text'>
This is a small refactor to the BaseMemEncryptSevLib in the OvmfPkg
which moves the function used in the Pei phase for accessing the
SEC_SEV_ES_WORK_AREA, into the common Pei and Dxe code. The Dxe phase
will consume the work area in a subsequent patch.

Signed-off-by: John Berg &lt;jhnberg@amazon.co.uk&gt;
</content>
</entry>
<entry>
<title>OvmfPkg/BaseMemEncryptSevLib: IGVM data HOB ranges are prevalidated</title>
<updated>2026-04-08T20:38:21+00:00</updated>
<author>
<name>Gerd Hoffmann</name>
<email>kraxel@redhat.com</email>
</author>
<published>2026-04-01T12:01:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=3ed3b7a4aeaf12040f33a138af6767403cde0126'/>
<id>urn:sha1:3ed3b7a4aeaf12040f33a138af6767403cde0126</id>
<content type='text'>
Exclude these ranges in addition to the ranges from the static
mPreValidatedRange array, by checking the IGVM data HOBs in
DetectPreValidatedOverLap().

Signed-off-by: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
</content>
</entry>
<entry>
<title>OvmfPkg/BaseMemEncryptSevLib: DEBUG_VERBOSE -&gt; DEBUG_PAGING</title>
<updated>2026-03-23T09:55:50+00:00</updated>
<author>
<name>Gerd Hoffmann</name>
<email>kraxel@redhat.com</email>
</author>
<published>2025-10-02T09:53:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=3d6453f515cdbe829c2a17f0ba95ae352811bc6e'/>
<id>urn:sha1:3d6453f515cdbe829c2a17f0ba95ae352811bc6e</id>
<content type='text'>
Use new DEBUG_PAGING log bit in OvmfPkg/BaseMemEncryptSevLib.

Signed-off-by: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
</content>
</entry>
<entry>
<title>OvmfPkg: Replace include guards with #pragma once</title>
<updated>2026-02-23T21:01:28+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2026-02-03T19:10:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=a536e5d6991ebb18cdc0a29e224ce5bd50ca9bc0'/>
<id>urn:sha1:a536e5d6991ebb18cdc0a29e224ce5bd50ca9bc0</id>
<content type='text'>
Replace traditional `#ifndef`/`#define`/`#endif` include guards with
`#pragma` once.

`#pragma once` is a widely supported preprocessor directive that
prevents header files from being included multiple times. It is
supported by all toolchains used to build edk2: GCC, Clang/LLVM, and
MSVC.

Note: Headers taken directly from external projects, such as those
in OvmfPkg/Include/IndustryStandard/Xen/ were not modified since they
may be periodically re-synced and do not follow other edk2 coding
stadards.

Compared to macro-based include guards, `#pragma once`:

- Eliminates the risk of macro name collisions or copy/paste errors
  where two headers inadvertently use the same guard macro.
- Eliminate inconsistency in the way include guard macros are named
  (e.g., some files use `__FILE_H__`, others use `FILE_H_`, etc.).
- Reduces boilerplate (three lines replaced by one).
- Avoids polluting the macro namespace with guard symbols.
- Can improve build times as the preprocessor can skip re-opening the
  file entirely, rather than re-reading it to find the matching
  `#endif` ("multiple-include optimization").
  - Note that some compilers may already optimize traditional include
    guards, by recognzining the idiomatic pattern.

This change is made acknowledging that overall portability of the
code will technically be reduced, as `#pragma once` is not part of the
C/C++ standards.

However, this is considered acceptable given:

1. edk2 already defines a subset of supported compilers in
   BaseTools/Conf/tools_def.template, all of which have supported
   `#pragma once` for over two decades.
2. There have been concerns raised to the project about inconsistent
   include guard naming and potential macro collisions.

Approximate compiler support dates:

- MSVC: Supported since Visual C++ 4.2 (1996)
- GCC: Supported since 3.4 (2004)
  (http://gnu.ist.utl.pt/software/gcc/gcc-3.4/changes.html)
- Clang (LLVM based): Since initial release in 2007

Signed-off-by: Michael Kubacki &lt;michael.kubacki@microsoft.com&gt;
</content>
</entry>
<entry>
<title>OvmfPkg: Remove OVMF IA32</title>
<updated>2025-09-09T18:49:32+00:00</updated>
<author>
<name>Oliver Smith-Denny</name>
<email>osde@microsoft.com</email>
</author>
<published>2025-08-25T18:24:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=1fb88ffe284782cc79e306306b8d19829b6248b7'/>
<id>urn:sha1:1fb88ffe284782cc79e306306b8d19829b6248b7</id>
<content type='text'>
This commit removes OVMF IA32 from edk2 per RFC
https://edk2.groups.io/g/devel/topic/rfc_remove_ovmf_ia32_and/114152215.

OVMF IA32 is a 32 bit only platform that no longer represents the vast
majority of physical platforms. The RFC details more reasoning in
much more depth.

OVMF IA32 will be kept in a branch off the edk2-stable202508 tag for
any long term consumers; it will receive build break updates only
(e.g. if an upstream submodule changes location).

Signed-off-by: Oliver Smith-Denny &lt;osde@microsoft.com&gt;
</content>
</entry>
<entry>
<title>OvmfPkg/MemEncryptSevLib: Check if SEV-SNP coherency mitigitation is needed</title>
<updated>2025-09-09T17:43:31+00:00</updated>
<author>
<name>Tom Lendacky</name>
<email>thomas.lendacky@amd.com</email>
</author>
<published>2025-07-22T20:06:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=20f24c0f67b3364cd590e1eea470f74be40e7710'/>
<id>urn:sha1:20f24c0f67b3364cd590e1eea470f74be40e7710</id>
<content type='text'>
CPUID bit Fn8000001F_EBX[31] defines the COHERNECY_SFW_NO CPUID bit that,
when set, indicates that the software mitigation for this vulnerability is
not needed.

Add support to check for this CPUID bit and avoid the mitigation if set.

Signed-off-by: Tom Lendacky &lt;thomas.lendacky@amd.com&gt;
</content>
</entry>
<entry>
<title>OvmfPkg/MemEncryptSevLib: Evict cache lines during SNP memory validation</title>
<updated>2025-09-09T17:43:31+00:00</updated>
<author>
<name>Tom Lendacky</name>
<email>thomas.lendacky@amd.com</email>
</author>
<published>2025-08-12T19:43:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=3b0d834db286a236fd22c41923fc271fc44ead5f'/>
<id>urn:sha1:3b0d834db286a236fd22c41923fc271fc44ead5f</id>
<content type='text'>
An SNP cache coherency vulnerability may require a mitigation to evict
cache lines after memory has been validated. Perform this mitigation
after having validated memory.

CVE-2024-36331

Signed-off-by: Michael Roth &lt;michael.roth@amd.com&gt;
Co-developed-by: Tom Lendacky &lt;thomas.lendacky@amd.com&gt;
Signed-off-by: Tom Lendacky &lt;thomas.lendacky@amd.com&gt;</content>
</entry>
<entry>
<title>OvmfPkg: Enable AMD SEV-ES DebugVirtualization</title>
<updated>2024-07-04T20:39:26+00:00</updated>
<author>
<name>Alexey Kardashevskiy</name>
<email>aik@amd.com</email>
</author>
<published>2024-05-28T04:48:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=28099661893327296e18b8f98a1e7c3e757c7d49'/>
<id>urn:sha1:28099661893327296e18b8f98a1e7c3e757c7d49</id>
<content type='text'>
Write the feature bit into PcdConfidentialComputingGuestAttr
and enable DebugVirtualization in PEI, SEC, DXE.

Cc: Ard Biesheuvel &lt;ardb+tianocore@kernel.org&gt;
Cc: Erdem Aktas &lt;erdemaktas@google.com&gt;
Cc: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Michael Roth &lt;michael.roth@amd.com&gt;
Cc: Min Xu &lt;min.m.xu@intel.com&gt;
Reviewed-by: Tom Lendacky &lt;thomas.lendacky@amd.com&gt;
Signed-off-by: Alexey Kardashevskiy &lt;aik@amd.com&gt;
---
Changes:
v5:
* "rb" from Tom

v4:
* s/DebugSwap/DebugVirtualization/g
</content>
</entry>
</feed>
