From patchwork Tue Sep 19 20:46:04 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Brijesh Singh X-Patchwork-Id: 9960307 X-Patchwork-Delegate: herbert@gondor.apana.org.au Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 6054F6038F for ; Tue, 19 Sep 2017 20:57:11 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 5456228EE9 for ; Tue, 19 Sep 2017 20:57:11 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 4872828EEE; Tue, 19 Sep 2017 20:57:11 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.9 required=2.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,RCVD_IN_DNSWL_HI autolearn=unavailable version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 275EF28EE9 for ; Tue, 19 Sep 2017 20:57:10 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751906AbdISU4t (ORCPT ); Tue, 19 Sep 2017 16:56:49 -0400 Received: from mail-by2nam01on0052.outbound.protection.outlook.com ([104.47.34.52]:32170 "EHLO NAM01-BY2-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1751733AbdISUq6 (ORCPT ); Tue, 19 Sep 2017 16:46:58 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amdcloud.onmicrosoft.com; s=selector1-amd-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=FZgG7CeOqrELbSSph/bzuRR81kBDFTW0vnXsQIUVBWY=; b=Ug0E4kmqtCFAXkbiu8yZ/UPWjvGqnp3wZtGt3IpDA+s6R9/tB44IIUOdygZIL35v9E00yyDBA1rKsXcWKIx8shrTHc6KfCbm1BALfVJRIqkcae6vstSDe3w4IF0Uv5NbSGGX37G+Rd5uX9S+GitRhqxFKVnvbLr9Eo2Afzuqwwc= Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=brijesh.singh@amd.com; Received: from ubuntu-010236106000.amd.com (165.204.78.1) by SN1PR12MB0158.namprd12.prod.outlook.com (10.162.3.145) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.56.11; Tue, 19 Sep 2017 20:46:52 +0000 From: Brijesh Singh To: linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: Brijesh Singh , Paolo Bonzini , =?UTF-8?q?Radim=20Kr=C4=8Dm=C3=A1=C5=99?= , Borislav Petkov , Herbert Xu , Gary Hook , Tom Lendacky , linux-crypto@vger.kernel.org Subject: [Part2 PATCH v4 06/29] ccp: crypto: Define SEV key management command id Date: Tue, 19 Sep 2017 15:46:04 -0500 Message-Id: <20170919204627.3875-7-brijesh.singh@amd.com> X-Mailer: git-send-email 2.9.5 In-Reply-To: <20170919204627.3875-1-brijesh.singh@amd.com> References: <20170919204627.3875-1-brijesh.singh@amd.com> MIME-Version: 1.0 X-Originating-IP: [165.204.78.1] X-ClientProxiedBy: CY4PR04CA0071.namprd04.prod.outlook.com (10.171.243.164) To SN1PR12MB0158.namprd12.prod.outlook.com (10.162.3.145) X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: 6a3ef1f6-0008-44ad-b7b8-08d4ff9f8f30 X-MS-Office365-Filtering-HT: Tenant X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254152)(48565401081)(300000503095)(300135400095)(2017052603199)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:SN1PR12MB0158; X-Microsoft-Exchange-Diagnostics: 1; SN1PR12MB0158; 3:XXBpBm66J4sn/AktvaIDbk+eRCgeOtPaJx/H3sgfy5VwfVbR7tkQ/Jtb+emTcaynJkbfWVcTJN4XAmxhxGQ9+zTaD4waE+HFV7Uli8cpvJQORegdWdPPRj0d439jtljginGe4+aKqb+XfapSdxW1kfeOMWY+nxEdpJzOXjid8JCqWhuLPd+u4o1727HBK+rOb3u/zxo/MFuCAfVT6qjJ1yq1z1/GFxiPkMI2ll5gZ1TGcE9lPCnpMvHvQB47WYsK; 25:CGrBxVNvZ49+8L256hKPJphOhC8BU5UtUgez4SV50tmvUnj3WAsBnyOPe8dZeb4d1+T3FLh1+HocaHgbtk5Lou/iV/shIt2FOt8RIYgtajYxQuZDlc/b8SQTJHTAnUz5BDbBGX0SSKJLy1zrZ1aklZJKy87xHchIDk0kDUzCPZr7llDHPqtJSsxpEV4IFayVABuipsUVRJniyfD1x1UoOXUPTlbzt4RH2kXiDbLfRzWiFsAkxUS4WiWnosiHxAse2Mim6PwtwXebLzqGxk8vW/TQ/LIdGtSJdZRr/TpbiLEQTN13joCTB72soZr+7FS7baaHy2gTVZsNP6cMdVnSlw==; 31:j0VwKV6dQhKgMElGj3cYZeZ/MUZsJ+HQETkS5eE9Dts1PCH01oSdrOa3Pn1ec096upkH34617KmHuUN7dyfV4X5XSA2EauBRQgyJDFJ109YQeqn7nkOsqebar06XL3wSH0IvQpbPxlhYlOtRnNkxcqhtOkSdqXuHEzhW8TYMVNLYwf6dIo0+5dPn4aQV45XmHBHBO0EDbRm4wqhSLYSRT90z6gfs8J+2RLqo1SNcLOo= X-MS-TrafficTypeDiagnostic: SN1PR12MB0158: X-Microsoft-Exchange-Diagnostics: 1; SN1PR12MB0158; 20:pXwTURG41JB41hUrw6l30PVWu0+/xtWZZj4AIDDw2nvN9oF5lAVWofZjhLsiabRBJq4YvoEHSbGBdydIXF+Pk+HjZ3XpCy7k/rce4UlIl/NSKM9wXuXVFZh8Y+LsJUxGec8CTty76FwR4JRjgP+W29yhFE6EBpgOK7HMXwWdAP0hX7a9jf4B66wg2Sa0WBW+IEhMpHSM4+KselkHqB0ZGX5Xhdrg1l8/k9CxeG6Zgvpkm2z5z6Nx9OqUBlHS3Rkb3/9Z8YTvmZh6uvYt0ZX7gjkRr0Vu9Wfi28GKtr3JkOB+qL4EIyCIZ23bPX1eVddObi8ZzeprawyKEIs2drw+5u+yWT7yEJY8SuHjXekemRgHsNY8bJZp329QpPwCh+qGyCXoX4EzlOXE5pyeQdjoVT4FzpCz0deswlZw+MZ5Iqny8q4Vs/NHUwPlJFB/7kU/YSZ+ZTinz8PJrH860awU70eUGUmxKpJrwgeAvLq2VIK4iNwPkqFt8GWx4GoWSCXe; 4:DYajoDK1dD8lydtW7FnD1Hxs6/dwIjjN246+kvA0vuE5jrPozkDlkgwCBoTTp0cZeas5n+1iSiFqsszbBbXU5f1abJbo3mEwEoFSq7p1Aewh2gAYFkIqyHqDbnoknrj/814qM/pyc9TUcveQtKR9ibRjHPh5OxOCkBHiNsPVke1/b1nvIIGd/18d8piwQRJg2Gor0te1X8xk3u7as+HF3vUSoIIpWOC+VNrUR3pMawdADZnsbZgyVEwl+n6nfay0i/a86bXot9S3p3RB8dFRACbhw3UjAnZBBBaB/2OXKZc9vftuMvMtEjxtS8RbiyTKmRLk9UZLStxhhCi/TMXqAQ== X-Exchange-Antispam-Report-Test: UriScan:(9452136761055)(767451399110); X-Microsoft-Antispam-PRVS: X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(5005006)(93006095)(93001095)(100000703101)(100105400095)(3002001)(10201501046)(6055026)(6041248)(20161123560025)(20161123558100)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123555025)(20161123562025)(20161123564025)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:SN1PR12MB0158; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:SN1PR12MB0158; X-Forefront-PRVS: 04359FAD81 X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10009020)(6009001)(346002)(376002)(39860400002)(199003)(189002)(86362001)(50466002)(8936002)(97736004)(6116002)(3846002)(81156014)(8676002)(50226002)(2950100002)(81166006)(316002)(478600001)(16526017)(6666003)(966005)(7736002)(66066001)(305945005)(47776003)(6486002)(6306002)(189998001)(53416004)(25786009)(101416001)(2870700001)(50986999)(76176999)(53936002)(2906002)(68736007)(36756003)(1720100001)(106356001)(1076002)(4326008)(5660300001)(105586002)(33646002)(23676002)(54906003)(2004002); DIR:OUT; SFP:1101; SCL:1; SRVR:SN1PR12MB0158; H:ubuntu-010236106000.amd.com; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en; Received-SPF: None (protection.outlook.com: amd.com does not designate permitted sender hosts) X-Microsoft-Exchange-Diagnostics: =?utf-8?B?MTtTTjFQUjEyTUIwMTU4OzIzOlFFK1FMZStzZmN5amZVOVRsZ1VlZ2YyQXcx?= =?utf-8?B?c09CQlBxTkVHRlBna1A4Z1JaR2g0TWh4YnpiWUFQWVBuWGczblB2M3oxdDhS?= =?utf-8?B?UlZENjd4TDd6elVSYWhBKy9ZeDA0WFpXRE1haEttUXJ5STVXZHVVU21rR055?= =?utf-8?B?ZkhUSlhqRHJZOWdqSzF1SkdCL2FFU3NHeHMxSXg1S2w5Rm1CRUJtUklUSW0v?= =?utf-8?B?eC9rRFpLMGxNQi81MnVZSlpKOFdnTFp1M3NYMDRLbDVzNXZjY3JQb2pYaTJW?= =?utf-8?B?bHN3UmFtWUZpYm9IYlVwK3BoMWZqTFRnSjlwRmZHSUpzOXZnQlZ4bEdESWFu?= =?utf-8?B?U25OdmV3UjV2T25kK0RXY08zTmJ5V3NUUm51S2tONW1KbTNxZ1FYQnhqN0pV?= =?utf-8?B?Sno2bVdHdkFHLzNXeXRVTit3THo0REJveGtLRG5EdmdETWdDdUk5MW1uWHEz?= =?utf-8?B?Mm9vWUdhWHRTQ1hibFRhR0x3VDhBdm5Xc0Z2VnE5eWtwV1BwTSs1QjVCUmtY?= =?utf-8?B?aTYyRlI1K1d4NzBXWWlRZkpDYjhkVktMSlBndUQ1RGJMQ0hhTEtzcXArd3d4?= =?utf-8?B?VUhHcGxpencveW9KMjlDckFXcGRieHI4MU9YY3RMTFZNS3NRKzFiM3p3VmJi?= =?utf-8?B?QWhoZk1NelVyV0F0d1ZSTFIreWl4a000OEM4VmtLNmdRa0NieFhFQ3E2NER0?= =?utf-8?B?QzRVd25uQ1BqZkhWalBzenZONkw4OTh3Vk5KT0lGNHU0ZnlTa2swemh3YnBI?= =?utf-8?B?VW9zcmRJZG5GY3dRUEVjT0E5TkdaNzZxRWdLNTY2cVVUaFBpajU3TEJ4TTg3?= =?utf-8?B?Qk9IYWFSOXRNYnVKRnRHdFRST0VQbDQxQk5TZ1BNeEgvU3pPR1BwUGU3N1dq?= =?utf-8?B?Q3VIMzNGT3dnenVzVDU1OEg3RXdqTTlRUDlVU3p1TnR3NjdWVk8yZ0p5Z2ts?= =?utf-8?B?RnRBaTcvNU4zZjhpQmZtd0FTZ3lsaU9KdnplMHgxeTd1U1JHMGJlVmw0VUNp?= =?utf-8?B?NUFVQWhpRWloWHMrQ0c2bFhRakU4WHJReXNocjlubUdINVcrdVByS3NVUXNt?= =?utf-8?B?ZUZIRFl2eFdQQ21zRUF1WG9SVGxtcWlDR0czbDgyTjl3dTUvdVpJZHVxditE?= =?utf-8?B?cVV3VTJRQTRtYkcyQ0VIL2ExS3NlNnlVUEQ1blZ1ZkVTVkdJZmhueDQrdmp4?= =?utf-8?B?RFdKcE01SzNwaG02R3NodVQ3L3hDYUZ5bldaZ1ppeVVGaS9uaTA5em94L2I2?= =?utf-8?B?UVUrNW1jd1lvd3VEYjVJNkp1cEk5TnBhaVh2MUs3WCsvRjRVU0lBaUk4aDdv?= =?utf-8?B?eGY2TEYzSXhuNGJ4VjByZHcwNm5vOFVGK2N1SmtCWmVBNm5UbjhsQi9Ralhl?= =?utf-8?B?dlE2QmZLMS85SElIbm5GbEZUMmZwVlNCcWdxbVpDbnhqYWFtUjdMWEZHM0N5?= =?utf-8?B?YVk3VUZKMUd3NFlETzZaS3NoRWt1bVp6eDlFOTdLQVA4cHp5VlJJNmxINWZ6?= =?utf-8?Q?VLg7e6aK/jK/+a8dakoEXPGVlLxZqiY+qG/aVRiHV9Jbck?= X-Microsoft-Exchange-Diagnostics: 1; SN1PR12MB0158; 6:6Uo6ep7FcS7GLyQVc6v0qf89dX7QMupS8LWbJFKMhhD3eQO8S0Ta3vB34tmyhsoXNU9eL2WnL6hW87P/VIfSjvMJLMWL8romTBhzVlCrorj9HYT2wNPLlcTpbvo3nYvWndlUUYgyv1rwvDBo6zYymlcwI4qp3YCLIcH8jCT8ErJ1P6rIYpNexCUz92m9oXi0opxAxQ72DF0mPSLtWenUwH7Olfgp50wvYm4MhzLjb1WItlub6KhOY7mUl2eBbsHYm6yfPQkTMzlmT/4T4ecoyc5rMQJW8v53VvCk72HHrKkInSuJ/xwl4xvMRY3CKKv49X7+VLb4XZbnfk6Ru6XU9A==; 5:fuoz3y9AiKsdlcO/HLpZWMmzNuTfuA8dc8U/J0U3Y5YcfepFRWuYn3NA8FlJaGa5Uc02B1F5U7Ew+ce5Qdc8/TiskAogjtdDKCeMGJg+hiIas1CvKSDZip1pO4AJ/rSv1rGjhfE/we0lC2PTRMzQCg==; 24:x25acOiiU0ZKYT0MfFYAjEW0ZOeSHUhobhJegW8tHfdoBVdTAW8moKyEUk16rtP+/hawOSmDEVAseBhcYX3qS286NhP7m7T3TAX9B//uuf0=; 7:uahUmXEBaxqThd5tiNcxweYgq/MjWi/t6SxDWUuLiu2spjGCKWaEaCEwJvJEgrpbj4H1ZM7bCzqOBo8jIbhUI4vltB1RdlrZpep6LFR23JdqJqwQMO9Le+GEsajjeMWWuJDt9+Sqwc2slZ2vtK/wq68lbsXx1tVb5dnGAp3qCnCDRVZlx0pPqTv4TqeNwX78yd5P9ch35uBBXxnwjyiWBFkLeqwLa6mg1U7Dh05RkpM= SpamDiagnosticOutput: 1:99 SpamDiagnosticMetadata: NSPM X-Microsoft-Exchange-Diagnostics: 1; SN1PR12MB0158; 20:U37g+7SJx+zY5TB/d7BgIyf5id4LWuW/8a9GVZJjioeuMXFLyM6am79zH/44R+TPGsZAJBPvqmhtC3AosLe3nMJpff8tkxJaJd8YTJA4n3/wVPYjq/gSoNLk2s5WUMLIFQ8pagIiJxXFr0t5V3NlhtM+WuA+XElEl7h71FunEa0aG5Yorj4d+XzyJEvgIHx/E8YZBB1mVdl/sRFiBIaaZsdS0/gJCc0AlxhV6PPQCwZ2um89biWbYxYq40/UECeR X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 19 Sep 2017 20:46:52.5645 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN1PR12MB0158 Sender: linux-crypto-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-crypto@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP Define Secure Encrypted Virtualization (SEV) key management command id and structure. The command definition is available in SEV KM [1] spec 0.14 and Documentation/virtual/kvm/amd-memory-encryption.txt [1] http://support.amd.com/TechDocs/55766_SEV-KM API_Specification.pdf Cc: Paolo Bonzini Cc: "Radim Krčmář" Cc: Borislav Petkov Cc: Herbert Xu Cc: Gary Hook Cc: Tom Lendacky Cc: linux-crypto@vger.kernel.org Cc: kvm@vger.kernel.org Cc: linux-kernel@vger.kernel.org Signed-off-by: Brijesh Singh --- include/linux/psp-sev.h | 512 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 512 insertions(+) create mode 100644 include/linux/psp-sev.h diff --git a/include/linux/psp-sev.h b/include/linux/psp-sev.h new file mode 100644 index 000000000000..d40709b65b18 --- /dev/null +++ b/include/linux/psp-sev.h @@ -0,0 +1,512 @@ +/* + * AMD Secure Encrypted Virtualization (SEV) driver interface + * + * Copyright (C) 2016-2017 Advanced Micro Devices, Inc. + * + * Author: Brijesh Singh + * + * This program is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License version 2 as + * published by the Free Software Foundation. + */ + +#ifndef __PSP_SEV_H__ +#define __PSP_SEV_H__ + +#ifdef CONFIG_X86 +#include + +#define __psp_pa(x) __sme_pa(x) +#else +#define __psp_pa(x) __pa(x) +#endif + +#define SEV_FW_BLOB_MAX_SIZE 0x4000 /* 16KB */ + +/** + * SEV platform state + */ +enum sev_state { + SEV_STATE_UNINIT = 0x0, + SEV_STATE_INIT = 0x1, + SEV_STATE_WORKING = 0x2, + + SEV_STATE_MAX +}; + +/** + * SEV platform and guest management commands + */ +enum sev_cmd { + /* platform commands */ + SEV_CMD_INIT = 0x001, + SEV_CMD_SHUTDOWN = 0x002, + SEV_CMD_FACTORY_RESET = 0x003, + SEV_CMD_PLATFORM_STATUS = 0x004, + SEV_CMD_PEK_GEN = 0x005, + SEV_CMD_PEK_CSR = 0x006, + SEV_CMD_PEK_CERT_IMPORT = 0x007, + SEV_CMD_PDH_CERT_EXPORT = 0x008, + SEV_CMD_PDH_GEN = 0x009, + SEV_CMD_DF_FLUSH = 0x00A, + + /* Guest commands */ + SEV_CMD_DECOMMISSION = 0x020, + SEV_CMD_ACTIVATE = 0x021, + SEV_CMD_DEACTIVATE = 0x022, + SEV_CMD_GUEST_STATUS = 0x023, + + /* Guest launch commands */ + SEV_CMD_LAUNCH_START = 0x030, + SEV_CMD_LAUNCH_UPDATE_DATA = 0x031, + SEV_CMD_LAUNCH_UPDATE_VMSA = 0x032, + SEV_CMD_LAUNCH_MEASURE = 0x033, + SEV_CMD_LAUNCH_UPDATE_SECRET = 0x034, + SEV_CMD_LAUNCH_FINISH = 0x035, + + /* Guest migration commands (outgoing) */ + SEV_CMD_SEND_START = 0x040, + SEV_CMD_SEND_UPDATE_DATA = 0x041, + SEV_CMD_SEND_UPDATE_VMSA = 0x042, + SEV_CMD_SEND_FINISH = 0x043, + + /* Guest migration commands (incoming) */ + SEV_CMD_RECEIVE_START = 0x050, + SEV_CMD_RECEIVE_UPDATE_DATA = 0x051, + SEV_CMD_RECEIVE_UPDATE_VMSA = 0x052, + SEV_CMD_RECEIVE_FINISH = 0x053, + + /* Guest debug commands */ + SEV_CMD_DBG_DECRYPT = 0x060, + SEV_CMD_DBG_ENCRYPT = 0x061, + + SEV_CMD_MAX, +}; + +/** + * status code returned by the commands + */ +enum psp_ret_code { + SEV_RET_SUCCESS = 0, + SEV_RET_INVALID_PLATFORM_STATE, + SEV_RET_INVALID_GUEST_STATE, + SEV_RET_INAVLID_CONFIG, + SEV_RET_INVALID_len, + SEV_RET_ALREADY_OWNED, + SEV_RET_INVALID_CERTIFICATE, + SEV_RET_POLICY_FAILURE, + SEV_RET_INACTIVE, + SEV_RET_INVALID_ADDRESS, + SEV_RET_BAD_SIGNATURE, + SEV_RET_BAD_MEASUREMENT, + SEV_RET_ASID_OWNED, + SEV_RET_INVALID_ASID, + SEV_RET_WBINVD_REQUIRED, + SEV_RET_DFFLUSH_REQUIRED, + SEV_RET_INVALID_GUEST, + SEV_RET_INVALID_COMMAND, + SEV_RET_ACTIVE, + SEV_RET_HWSEV_RET_PLATFORM, + SEV_RET_HWSEV_RET_UNSAFE, + SEV_RET_UNSUPPORTED, + SEV_RET_MAX, +}; + +/** + * struct sev_data_init - INIT command parameters + * + * @flags: processing flags + * @tmr_address: system physical address used for SEV-ES + * @tmr_len: len of tmr_address + */ +struct __attribute__((__packed__)) sev_data_init { + u32 flags; /* In */ + u32 reserved; /* In */ + u64 tmr_address; /* In */ + u32 tmr_len; /* In */ +}; + +/** + * struct sev_data_status - PLATFORM_STATUS command parameters + * + * @major: major API version + * @minor: minor API version + * @state: platform state + * @owner: self-owned or externally owned + * @config: platform config flags + * @build: firmware build id for API version + * @guest_count: number of active guests + */ +struct __attribute__((__packed__)) sev_data_status { + u8 api_major; /* Out */ + u8 api_minor; /* Out */ + u8 state; /* Out */ + u8 owner : 1; /* Out */ + u8 reserved1 : 7; + u32 config : 1; /* Out */ + u32 reserved2 : 23; + u32 build : 8; /* Out */ + u32 guest_count; /* Out */ +}; + +/** + * struct sev_data_pek_csr - PEK_CSR command parameters + * + * @address: PEK certificate chain + * @len: len of certificate + */ +struct __attribute__((__packed__)) sev_data_pek_csr { + u64 address; /* In */ + u32 len; /* In/Out */ +}; + +/** + * struct sev_data_cert_import - PEK_CERT_IMPORT command parameters + * + * @pek_address: PEK certificate chain + * @pek_len: len of PEK certificate + * @oca_address: OCA certificate chain + * @oca_len: len of OCA certificate + */ +struct __attribute__((__packed__)) sev_data_pek_cert_import { + u64 pek_cert_address; /* In */ + u32 pek_cert_len; /* In */ + u32 reserved; /* In */ + u64 oca_cert_address; /* In */ + u32 oca_cert_len; /* In */ +}; + +/** + * struct sev_data_pdh_cert_export - PDH_CERT_EXPORT command parameters + * + * @pdh_address: PDH certificate address + * @pdh_len: len of PDH certificate + * @cert_chain_address: PDH certificate chain + * @cert_chain_len: len of PDH certificate chain + */ +struct __attribute__((__packed__)) sev_data_pdh_cert_export { + u64 pdh_cert_address; /* In */ + u32 pdh_cert_len; /* In/Out */ + u32 reserved; /* In */ + u64 cert_chain_address; /* In */ + u32 cert_chain_len; /* In/Out */ +}; + +/** + * struct sev_data_decommission - DECOMMISSION command parameters + * + * @handle: handle of the VM to decommission + */ +struct __attribute__((__packed__)) sev_data_decommission { + u32 handle; /* In */ +}; + +/** + * struct sev_data_activate - ACTIVATE command parameters + * + * @handle: handle of the VM to activate + * @asid: asid assigned to the VM + */ +struct __attribute__((__packed__)) sev_data_activate { + u32 handle; /* In */ + u32 asid; /* In */ +}; + +/** + * struct sev_data_deactivate - DEACTIVATE command parameters + * + * @handle: handle of the VM to deactivate + */ +struct __attribute__((__packed__)) sev_data_deactivate { + u32 handle; /* In */ +}; + +/** + * struct sev_data_guest_status - SEV GUEST_STATUS command parameters + * + * @handle: handle of the VM to retrieve status + * @policy: policy information for the VM + * @asid: current ASID of the VM + * @state: current state of the VM + */ +struct __attribute__((__packed__)) sev_data_guest_status { + u32 handle; /* In */ + u32 policy; /* Out */ + u32 asid; /* Out */ + u8 state; /* Out */ +}; + +/** + * struct sev_data_launch_start - LAUNCH_START command parameters + * + * @handle: handle assigned to the VM + * @policy: guest launch policy + * @dh_cert_address: physical address of DH certificate blob + * @dh_cert_len: len of DH certificate blob + * @session_address: physical address of session parameters + * @session_len: len of session parameters + */ +struct __attribute__((__packed__)) sev_data_launch_start { + u32 handle; /* In/Out */ + u32 policy; /* In */ + u64 dh_cert_address; /* In */ + u32 dh_cert_len; /* In */ + u32 reserved; /* In */ + u64 session_address; /* In */ + u32 session_len; /* In */ +}; + +/** + * struct sev_data_launch_update_data - LAUNCH_UPDATE_DATA command parameter + * + * @handle: handle of the VM to update + * @len: len of memory to be encrypted + * @address: physical address of memory region to encrypt + */ +struct __attribute__((__packed__)) sev_data_launch_update_data { + u32 handle; /* In */ + u32 reserved; + u64 address; /* In */ + u32 len; /* In */ +}; + +/** + * struct sev_data_launch_update_vmsa - LAUNCH_UPDATE_VMSA command + * + * @handle: handle of the VM + * @address: physical address of memory region to encrypt + * @len: len of memory region to encrypt + */ +struct __attribute__((__packed__)) sev_data_launch_update_vmsa { + u32 handle; /* In */ + u32 reserved; + u64 address; /* In */ + u32 len; /* In */ +}; + +/** + * struct sev_data_launch_measure - LAUNCH_MEASURE command parameters + * + * @handle: handle of the VM to process + * @address: physical address containing the measurement blob + * @len: len of measurement blob + */ +struct __attribute__((__packed__)) sev_data_launch_measure { + u32 handle; /* In */ + u32 reserved; + u64 address; /* In */ + u32 len; /* In/Out */ +}; + +/** + * struct sev_data_launch_secret - LAUNCH_SECRET command parameters + * + * @handle: handle of the VM to process + * @hdr_address: physical address containing the packet header + * @hdr_len: len of packet header + * @guest_address: system physical address of guest memory region + * @guest_len: len of guest_paddr + * @trans_address: physical address of transport memory buffer + * @trans_len: len of transport memory buffer + */ +struct __attribute__((__packed__)) sev_data_launch_secret { + u32 handle; /* In */ + u32 reserved1; + u64 hdr_address; /* In */ + u32 hdr_len; /* In */ + u32 reserved2; + u64 guest_address; /* In */ + u32 guest_len; /* In */ + u32 reserved3; + u64 trans_address; /* In */ + u32 trans_len; /* In */ +}; + +/** + * struct sev_data_launch_finish - LAUNCH_FINISH command parameters + * + * @handle: handle of the VM to process + */ +struct __attribute__((__packed__)) sev_data_launch_finish { + u32 handle; /* In */ +}; + +/** + * struct sev_data_send_start - SEND_START command parameters + * + * @handle: handle of the VM to process + * @policy: policy information for the VM + * @pdh_cert_address: physical address containing PDH certificate + * @pdh_cert_len: len of PDH certificate + * @plat_certs_address: physical address containing platform certificate + * @plat_certs_len: len of platform certificate + * @amd_certs_address: physical address containing AMD certificate + * @amd_certs_len: len of AMD certificate + * @session_address: physical address containing Session data + * @session_len: len of session data + */ +struct __attribute__((__packed__)) sev_data_send_start { + u32 handle; /* In */ + u32 policy; /* Out */ + u64 pdh_cert_address; /* In */ + u32 pdh_cert_len; /* In */ + u32 reserved1; + u64 plat_cert_address; /* In */ + u32 plat_cert_len; /* In */ + u32 reserved2; + u64 amd_cert_address; /* In */ + u32 amd_cert_len; /* In */ + u32 reserved3; + u64 session_address; /* In */ + u32 session_len; /* In/Out */ +}; + +/** + * struct sev_data_send_update - SEND_UPDATE_DATA command + * + * @handle: handle of the VM to process + * @hdr_address: physical address containing packet header + * @hdr_len: len of packet header + * @guest_address: physical address of guest memory region to send + * @guest_len: len of guest memory region to send + * @trans_address: physical address of host memory region + * @trans_len: len of host memory region + */ +struct __attribute__((__packed__)) sev_data_send_update_data { + u32 handle; /* In */ + u32 reserved1; + u64 hdr_address; /* In */ + u32 hdr_len; /* In/Out */ + u32 reserved2; + u64 guest_address; /* In */ + u32 guest_len; /* In */ + u32 reserved3; + u64 trans_address; /* In */ + u32 trans_len; /* In */ +}; + +/** + * struct sev_data_send_update - SEND_UPDATE_VMSA command + * + * @handle: handle of the VM to process + * @hdr_address: physical address containing packet header + * @hdr_len: len of packet header + * @guest_address: physical address of guest memory region to send + * @guest_len: len of guest memory region to send + * @trans_address: physical address of host memory region + * @trans_len: len of host memory region + */ +struct __attribute__((__packed__)) sev_data_send_update_vmsa { + u32 handle; /* In */ + u64 hdr_address; /* In */ + u32 hdr_len; /* In/Out */ + u32 reserved2; + u64 guest_address; /* In */ + u32 guest_len; /* In */ + u32 reserved3; + u64 trans_address; /* In */ + u32 trans_len; /* In */ +}; + +/** + * struct sev_data_send_finish - SEND_FINISH command parameters + * + * @handle: handle of the VM to process + */ +struct __attribute__((__packed__)) sev_data_send_finish { + u32 handle; /* In */ +}; + +/** + * struct sev_data_receive_start - RECEIVE_START command parameters + * + * @handle: handle of the VM to perform receive operation + * @pdh_cert_address: system physical address containing PDH certificate blob + * @pdh_cert_len: len of PDH certificate blob + * @session_address: system physical address containing session blob + * @session_len: len of session blob + */ +struct __attribute__((__packed__)) sev_data_receive_start { + u32 handle; /* In/Out */ + u32 policy; /* In */ + u64 pdh_cert_address; /* In */ + u32 pdh_cert_len; /* In */ + u32 reserved1; + u64 session_address; /* In */ + u32 session_len; /* In */ +}; + +/** + * struct sev_data_receive_update_data - RECEIVE_UPDATE_DATA command parameters + * + * @handle: handle of the VM to update + * @hdr_address: physical address containing packet header blob + * @hdr_len: len of packet header + * @guest_address: system physical address of guest memory region + * @guest_len: len of guest memory region + * @trans_address: system physical address of transport buffer + * @trans_len: len of transport buffer + */ +struct __attribute__((__packed__)) sev_data_receive_update_data { + u32 handle; /* In */ + u32 reserved1; + u64 hdr_address; /* In */ + u32 hdr_len; /* In */ + u32 reserved2; + u64 guest_address; /* In */ + u32 guest_len; /* In */ + u32 reserved3; + u64 trans_address; /* In */ + u32 trans_len; /* In */ +}; + +/** + * struct sev_data_receive_update_vmsa - RECEIVE_UPDATE_VMSA command parameters + * + * @handle: handle of the VM to update + * @hdr_address: physical address containing packet header blob + * @hdr_len: len of packet header + * @guest_address: system physical address of guest memory region + * @guest_len: len of guest memory region + * @trans_address: system physical address of transport buffer + * @trans_len: len of transport buffer + */ +struct __attribute__((__packed__)) sev_data_receive_update_vmsa { + u32 handle; /* In */ + u32 reserved1; + u64 hdr_address; /* In */ + u32 hdr_len; /* In */ + u32 reserved2; + u64 guest_address; /* In */ + u32 guest_len; /* In */ + u32 reserved3; + u64 trans_address; /* In */ + u32 trans_len; /* In */ +}; + +/** + * struct sev_data_receive_finish - RECEIVE_FINISH command parameters + * + * @handle: handle of the VM to finish + */ +struct __attribute__((__packed__)) sev_data_receive_finish { + u32 handle; /* In */ +}; + +/** + * struct sev_data_dbg - DBG_ENCRYPT/DBG_DECRYPT command parameters + * + * @handle: handle of the VM to perform debug operation + * @src_addr: source address of data to operate on + * @dst_addr: destination address of data to operate on + * @len: len of data to operate on + */ +struct __attribute__((__packed__)) sev_data_dbg { + u32 handle; /* In */ + u32 reserved; + u64 src_addr; /* In */ + u64 dst_addr; /* In */ + u32 len; /* In */ +}; + +#endif /* __PSP_SEV_H__ */