]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
x86/sev: Enable NMI support for Secure AVIC
authorKishon Vijay Abraham I <kvijayab@amd.com>
Thu, 28 Aug 2025 11:13:15 +0000 (16:43 +0530)
committerBorislav Petkov (AMD) <bp@alien8.de>
Mon, 1 Sep 2025 11:00:43 +0000 (13:00 +0200)
Now that support to send NMI IPI and support to inject NMI from the hypervisor
has been added, set V_NMI_ENABLE in the VINTR_CTRL field of the VMSA to enable
NMI for Secure AVIC guests.

  [ bp: Zap useless brackets. ]

Signed-off-by: Kishon Vijay Abraham I <kvijayab@amd.com>
Signed-off-by: Neeraj Upadhyay <Neeraj.Upadhyay@amd.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Tianyu Lan <tiala@microsoft.com>
Link: https://lore.kernel.org/20250828111315.208959-1-Neeraj.Upadhyay@amd.com
arch/x86/coco/sev/core.c

index 37b1d41e68d0d7c5f90f26fd0bb34336feed798e..e4740611228dc7a869289c9ec3299ed288a1b81b 100644 (file)
@@ -975,7 +975,7 @@ static int wakeup_cpu_via_vmgexit(u32 apic_id, unsigned long start_ip, unsigned
        vmsa->x87_fcw           = AP_INIT_X87_FCW_DEFAULT;
 
        if (cc_platform_has(CC_ATTR_SNP_SECURE_AVIC))
-               vmsa->vintr_ctrl        |= V_GIF_MASK;
+               vmsa->vintr_ctrl |= V_GIF_MASK | V_NMI_ENABLE_MASK;
 
        /* SVME must be set. */
        vmsa->efer              = EFER_SVME;