]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
x86/boot: Skip video memory access in the decompressor for SEV-ES/SNP
authorAshish Kalra <ashish.kalra@amd.com>
Thu, 1 Aug 2024 19:14:17 +0000 (19:14 +0000)
committerBorislav Petkov (AMD) <bp@alien8.de>
Mon, 28 Oct 2024 15:54:16 +0000 (16:54 +0100)
Accessing guest video memory/RAM in the decompressor causes guest
termination as the boot stage2 #VC handler for SEV-ES/SNP systems does
not support MMIO handling.

This issue is observed during a SEV-ES/SNP guest kexec as kexec -c adds
screen_info to the boot parameters passed to the second kernel, which
causes console output to be dumped to both video and serial.

As the decompressor output gets cleared really fast, it is preferable to
get the console output only on serial, hence, skip accessing the video
RAM during decompressor stage to prevent guest termination.

Serial console output during decompressor stage works as boot stage2 #VC
handler already supports handling port I/O.

  [ bp: Massage. ]

Suggested-by: Borislav Petkov (AMD) <bp@alien8.de>
Suggested-by: Thomas Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Ashish Kalra <ashish.kalra@amd.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
Link: https://lore.kernel.org/r/8a55ea86524c686e575d273311acbe57ce8cee23.1722520012.git.ashish.kalra@amd.com
arch/x86/boot/compressed/misc.c

index 04a35b2c26e9be271b1bbe58fbbf8d38a13b1796..0d37420cad0259554f8160dea0c502cb7e2fc6cd 100644 (file)
@@ -385,6 +385,19 @@ static void parse_mem_encrypt(struct setup_header *hdr)
                hdr->xloadflags |= XLF_MEM_ENCRYPTION;
 }
 
+static void early_sev_detect(void)
+{
+       /*
+        * Accessing video memory causes guest termination because
+        * the boot stage2 #VC handler of SEV-ES/SNP guests does not
+        * support MMIO handling and kexec -c adds screen_info to the
+        * boot parameters passed to the kexec kernel, which causes
+        * console output to be dumped to both video and serial.
+        */
+       if (sev_status & MSR_AMD64_SEV_ES_ENABLED)
+               lines = cols = 0;
+}
+
 /*
  * The compressed kernel image (ZO), has been moved so that its position
  * is against the end of the buffer used to hold the uncompressed kernel
@@ -440,6 +453,8 @@ asmlinkage __visible void *extract_kernel(void *rmode, unsigned char *output)
         */
        early_tdx_detect();
 
+       early_sev_detect();
+
        console_init();
 
        /*