Re: [edk2-devel] [RESEND] [PATCH v2 2/2] OvmfPkg/ResetVector: Exclude SEV launch secrets page from pre-validation

2023-02-27 Thread Lendacky, Thomas via groups.io
On 2/23/23 09:04, Dov Murik wrote: On 23/02/2023 16:58, Dov Murik wrote: On 21/02/2023 11:38, Gerd Hoffmann wrote: On Mon, Feb 20, 2023 at 08:44:23AM -0600, Tom Lendacky wrote: On 2/20/23 02:49, Dov Murik wrote: In order to allow the VMM (such as QEMU) to add a page with hashes of

Re: [edk2-devel] [RESEND] [PATCH v2 2/2] OvmfPkg/ResetVector: Exclude SEV launch secrets page from pre-validation

2023-02-23 Thread Dov Murik
On 23/02/2023 16:58, Dov Murik wrote: > > > On 21/02/2023 11:38, Gerd Hoffmann wrote: >> On Mon, Feb 20, 2023 at 08:44:23AM -0600, Tom Lendacky wrote: >>> On 2/20/23 02:49, Dov Murik wrote: In order to allow the VMM (such as QEMU) to add a page with hashes of kernel/initrd/cmdline

Re: [edk2-devel] [RESEND] [PATCH v2 2/2] OvmfPkg/ResetVector: Exclude SEV launch secrets page from pre-validation

2023-02-23 Thread Dov Murik
On 21/02/2023 11:38, Gerd Hoffmann wrote: > On Mon, Feb 20, 2023 at 08:44:23AM -0600, Tom Lendacky wrote: >> On 2/20/23 02:49, Dov Murik wrote: >>> In order to allow the VMM (such as QEMU) to add a page with hashes of >>> kernel/initrd/cmdline for measured direct boot on SNP, this page must >>>

Re: [edk2-devel] [RESEND] [PATCH v2 2/2] OvmfPkg/ResetVector: Exclude SEV launch secrets page from pre-validation

2023-02-21 Thread Gerd Hoffmann
On Mon, Feb 20, 2023 at 08:44:23AM -0600, Tom Lendacky wrote: > On 2/20/23 02:49, Dov Murik wrote: > > In order to allow the VMM (such as QEMU) to add a page with hashes of > > kernel/initrd/cmdline for measured direct boot on SNP, this page must > > not be part of the SNP metadata list reported

Re: [edk2-devel] [RESEND] [PATCH v2 2/2] OvmfPkg/ResetVector: Exclude SEV launch secrets page from pre-validation

2023-02-20 Thread Lendacky, Thomas via groups.io
On 2/20/23 02:49, Dov Murik wrote: In order to allow the VMM (such as QEMU) to add a page with hashes of kernel/initrd/cmdline for measured direct boot on SNP, this page must not be part of the SNP metadata list reported to the VMM. Check if that page is defined; if it is, skip it in the

[edk2-devel] [RESEND] [PATCH v2 2/2] OvmfPkg/ResetVector: Exclude SEV launch secrets page from pre-validation

2023-02-20 Thread Dov Murik
In order to allow the VMM (such as QEMU) to add a page with hashes of kernel/initrd/cmdline for measured direct boot on SNP, this page must not be part of the SNP metadata list reported to the VMM. Check if that page is defined; if it is, skip it in the metadata list. In such case, VMM should