Branch: refs/heads/master
Home: https://github.com/tianocore/edk2
Commit: 2c0d84e8a3764d81c3e0013777d812be5c56006f
https://github.com/tianocore/edk2/commit/2c0d84e8a3764d81c3e0013777d812be5c56006f
Author: John Berg <[email protected]>
Date: 2026-08-27 (Thu, 27 Aug 2026)
Changed paths:
M OvmfPkg/Include/WorkArea.h
M OvmfPkg/ResetVector/ResetVector.nasmb
Log Message:
-----------
OvmfPkg: Reserve the AP Jump buffer in the SEV_ES_WORK_AREA
The PcdSevEsWorkAreaBase is used for the work area for SEV-ES during Sec
and Pei. During the Dxe phase, the same address is used for the
SEV_ES_AP_JMP_FAR to start the AP CPUs. Since the SEV_ES_WORK_AREA is
being reused it scribbles over the data from Sec/Pei. This patch adds a
16 byte buffer to the start of the work area so that the values stored
in the work area do not get overwritten. We also adjust the offsets for
the work area in ResetVector.nasmb to correctly populate the work area.
Signed-off-by: John Berg <[email protected]>
Commit: 6a99d10480bacd0affcfe2c7399d961237e00b79
https://github.com/tianocore/edk2/commit/6a99d10480bacd0affcfe2c7399d961237e00b79
Author: John Berg <[email protected]>
Date: 2026-08-27 (Thu, 27 Aug 2026)
Changed paths:
M OvmfPkg/Library/BaseMemEncryptSevLib/DxeMemEncryptSevLib.inf
M OvmfPkg/Library/BaseMemEncryptSevLib/DxeMemEncryptSevLibInternal.c
M OvmfPkg/Library/BaseMemEncryptSevLib/PeiDxeMemEncryptSevLibInternal.c
A OvmfPkg/Library/BaseMemEncryptSevLib/PeiDxeMemEncryptSevLibInternal.h
M OvmfPkg/Library/BaseMemEncryptSevLib/PeiMemEncryptSevLib.inf
M OvmfPkg/Library/BaseMemEncryptSevLib/PeiMemEncryptSevLibInternal.c
Log Message:
-----------
OvmfPkg/BaseMemEncryptSevLib: Make GetSevEsWorkArea() Pei/Dxe shared
This is a small refactor to the BaseMemEncryptSevLib in the OvmfPkg
which moves the function used in the Pei phase for accessing the
SEC_SEV_ES_WORK_AREA, into the common Pei and Dxe code. The Dxe phase
will consume the work area in a subsequent patch.
Signed-off-by: John Berg <[email protected]>
Commit: 196e496a4ec19c083c6e97b87c475c73020807da
https://github.com/tianocore/edk2/commit/196e496a4ec19c083c6e97b87c475c73020807da
Author: John Berg <[email protected]>
Date: 2026-08-27 (Thu, 27 Aug 2026)
Changed paths:
M OvmfPkg/Library/BaseMemEncryptSevLib/DxeMemEncryptSevLib.inf
M OvmfPkg/Library/BaseMemEncryptSevLib/DxeMemEncryptSevLibInternal.c
Log Message:
-----------
OvmfPkg/BaseMemEncryptSevLib: Fetch Sev data from the work area
The first call to MemEncryptSevGetEncryptionMask() in the Dxe phase will
look for the encryption mask for the page table entry by reading the
PcdPteMemoryEncryptionAddressOrMask (dynamic PCD) token. The value is
then cached for subsequent accesses. But if the first call has
interrupts disabled, as is the case in the MmioExit function in the #VC
handler then the PcdGet64() will re-enable interrupts unexpectedly. A
hypervisor may then inject interrupts into the guest whilst the guest is
not expected to be interrupted. This leads to the ovmf image hanging
when handling too many nested #VC exceptions.
This patch avoids using the PcdPteMemoryEncryptionAddressOrMask token in
the MemEncryptSevGetEncryptionMask() function as it cannot be called
safely from a context where interrupts are disabled. Instead, we fetch
the values from the SEC_SEV_ES_WORK_AREA in the Dxe phase. The work area
is already used in the Pei phase, and is available in the Dxe phase as it
is marked as either EfiBootServicesData or EfiACPIMemoryNVS. However,
the work area will be inaccessible when SetVirtualAddressMap() is called,
so we only read the work area in the Dxe phase through a constructor function.
Signed-off-by: John Berg <[email protected]>
Signed-off-by: Ivan Orlov <[email protected]>
Compare: https://github.com/tianocore/edk2/compare/0d486397bacf...196e496a4ec1
To unsubscribe from these emails, change your notification settings at
https://github.com/tianocore/edk2/settings/notifications
_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits