• Brijesh Singh's avatar
    x86/sev: Register SEV-SNP guest request platform device · 3a45b375
    Brijesh Singh authored
    Version 2 of the GHCB specification provides a Non Automatic Exit (NAE)
    event type that can be used by the SEV-SNP guest to communicate with the
    PSP without risk from a malicious hypervisor who wishes to read, alter,
    drop or replay the messages sent.
    
    SNP_LAUNCH_UPDATE can insert two special pages into the guest’s memory:
    the secrets page and the CPUID page. The PSP firmware populates the
    contents of the secrets page. The secrets page contains encryption keys
    used by the guest to interact with the firmware. Because the secrets
    page is encrypted with the guest’s memory encryption key, the hypervisor
    cannot read the keys. See SEV-SNP firmware spec for further details on
    the secrets page format.
    
    Create a platform device that the SEV-SNP guest driver can bind to get
    the platform resources such as encryption key and message id to use to
    communicate with the PSP. The SEV-SNP guest driver provides a userspace
    interface to get the attestation report, key derivation, extended
    attestation report etc.
    Signed-off-by: default avatarBrijesh Singh <brijesh.singh@amd.com>
    Signed-off-by: default avatarBorislav Petkov <bp@suse.de>
    Link: https://lore.kernel.org/r/20220307213356.2797205-43-brijesh.singh@amd.com
    3a45b375
sev.h 5.81 KB