summaryrefslogtreecommitdiff
path: root/OvmfPkg/Library/BaseMemEncryptSevLib/DxeMemEncryptSevLibInternal.c
blob: cde504f33bc37826c0e19bbee59fa5e4f12946ac (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
/** @file

  Secure Encrypted Virtualization (SEV) library helper function

  Copyright (c) 2017 - 2020, AMD Incorporated. All rights reserved.<BR>

  SPDX-License-Identifier: BSD-2-Clause-Patent

**/

#include <Library/BaseLib.h>
#include <Library/DebugLib.h>
#include <Library/MemEncryptSevLib.h>
#include <Library/PcdLib.h>
#include <Register/Amd/Cpuid.h>
#include <Register/Amd/Msr.h>
#include <Register/Cpuid.h>
#include <Uefi/UefiBaseType.h>
#include "PeiDxeMemEncryptSevLibInternal.h"

STATIC UINT64   mSevEncryptionMask      = 0;
STATIC BOOLEAN  mSevIsEnabled           = FALSE;
STATIC BOOLEAN  mSevEsIsEnabled         = FALSE;
STATIC BOOLEAN  mSevSnpIsEnabled        = FALSE;
STATIC BOOLEAN  mSevDebugVirtualization = FALSE;
STATIC BOOLEAN  mSevSnpCoherencySfwNo   = FALSE;

RETURN_STATUS
EFIAPI
DxeMemEncryptSevLibConstructor (
  VOID
  )
{
  SEC_SEV_ES_WORK_AREA     *SevEsWorkArea;
  MSR_SEV_STATUS_REGISTER  Msr;

  //
  // The work area should at least be EfiBootServicesData since the work area
  // is also used for AP bring up to setup the AP jump table.
  //
  SevEsWorkArea = GetSevEsWorkArea ();
  if (SevEsWorkArea == NULL) {
    return RETURN_SUCCESS;
  }

  //
  // The work area will not be mapped at the expected physical address once
  // SetVirtualAddressMap() is called. So fetch the values from the work area
  // and store them in variables so the MemEncryptSev*() functions do not need
  // to access the work area.
  //
  Msr.Uint32              = (UINT32)(UINTN)SevEsWorkArea->SevStatusMsrValue;
  mSevEncryptionMask      = SevEsWorkArea->EncryptionMask;
  mSevIsEnabled           = Msr.Bits.SevBit ? TRUE : FALSE;
  mSevEsIsEnabled         = Msr.Bits.SevEsBit ? TRUE : FALSE;
  mSevSnpIsEnabled        = Msr.Bits.SevSnpBit ? TRUE : FALSE;
  mSevDebugVirtualization = Msr.Bits.DebugVirtualization ? TRUE : FALSE;
  mSevSnpCoherencySfwNo   = (SevEsWorkArea->Flags & SEV_ES_WORK_AREA_FLAG_CSFW_NO) != 0;

  return RETURN_SUCCESS;
}

/**
  Returns a boolean to indicate whether SEV-SNP is enabled.

  @retval TRUE           SEV-SNP is enabled
  @retval FALSE          SEV-SNP is not enabled
**/
BOOLEAN
EFIAPI
MemEncryptSevSnpIsEnabled (
  VOID
  )
{
  return mSevSnpIsEnabled;
}

/**
  Returns a boolean to indicate whether SEV-ES is enabled.

  @retval TRUE           SEV-ES is enabled
  @retval FALSE          SEV-ES is not enabled
**/
BOOLEAN
EFIAPI
MemEncryptSevEsIsEnabled (
  VOID
  )
{
  return mSevEsIsEnabled;
}

/**
  Returns a boolean to indicate whether SEV is enabled.

  @retval TRUE           SEV is enabled
  @retval FALSE          SEV is not enabled
**/
BOOLEAN
EFIAPI
MemEncryptSevIsEnabled (
  VOID
  )
{
  return mSevIsEnabled;
}

/**
  Returns the SEV encryption mask.

  @return  The SEV pagtable encryption mask
**/
UINT64
EFIAPI
MemEncryptSevGetEncryptionMask (
  VOID
  )
{
  return mSevEncryptionMask;
}

/**
  Returns a boolean to indicate whether DebugVirtualization is enabled.

  @retval TRUE           DebugVirtualization is enabled
  @retval FALSE          DebugVirtualization is not enabled
**/
BOOLEAN
EFIAPI
MemEncryptSevEsDebugVirtualizationIsEnabled (
  VOID
  )
{
  return mSevDebugVirtualization;
}

/**
  Returns a boolean to indicate whether the SEV-SNP cache line eviction
  mitigation is needed.

  @retval TRUE           Cache line eviction mitigation required
  @retval FALSE          Cache line eviction migigation not required

**/
BOOLEAN
EFIAPI
MemEncryptSevSnpDoCoherencyMitigation (
  VOID
  )
{
  return MemEncryptSevSnpIsEnabled () && !mSevSnpCoherencySfwNo;
}