[PATCH v4 0/5] TDX host: kexec() support

From: Kai Huang
Date: Thu Apr 18 2024 - 07:48:28 EST


Currently kexec() support and TDX host are muturally exclusive in the
Kconfig. This series adds the TDX host kexec support so that they can
work together and can be enabled at the same time in the Kconfig.

v3 -> v4:
- Updated changelog and comments of patch 1/2 per comments from
Kirill and Tom (see specific patch for details).

v3: https://lore.kernel.org/linux-kernel/cover.1712493366.git.kai.huang@xxxxxxxxx/

v2 -> v3:
- Change to only do WBINVD for bare-metal, as Kirill/Tom pointed out
WBINVD in TDX guests and SEV-ES/SEV-SNP guests triggers #VE.

v2: https://lore.kernel.org/linux-kernel/cover.1710811610.git.kai.huang@xxxxxxxxx/

v1 -> v2:
- Do unconditional WBINVD during kexec() -- Boris
- Change to cover crash kexec() -- Rick
- Add a new patch (last one) to add a mechanism to reset all TDX private
pages due to having to cover crash kexec().
- Other code improvements -- Dave
- Rebase to latest tip/master.

v1: https://lore.kernel.org/linux-kernel/cover.1706698706.git.kai.huang@xxxxxxxxx/

Hi Dave, Kirill, Sean, Paolo,

The last patch provides a new mechanism to handle all other TDX private
pages when they become possible to exist, e.g., when KVM is ready to run
TDX guests. It covers both normal kexec and crash kexec. Strictly
speaking, it is not mandatory to be in this series though. I appreciate
if you can help to review.

Hi Tom, Ashish,

This series touches AMD SME code too, and I don't have AMD machine to
test. I appreciate if you can help to review and/or test.


Kai Huang (5):
x86/kexec: do unconditional WBINVD for bare-metal in stop_this_cpu()
x86/kexec: do unconditional WBINVD for bare-metal in relocate_kernel()
x86/kexec: Reset TDX private memory on platforms with TDX erratum
x86/virt/tdx: Remove the !KEXEC_CORE dependency
x86/virt/tdx: Add TDX memory reset notifier to reset other private
pages

arch/x86/Kconfig | 1 -
arch/x86/include/asm/kexec.h | 2 +-
arch/x86/include/asm/tdx.h | 16 +++++
arch/x86/kernel/machine_kexec_64.c | 29 ++++++--
arch/x86/kernel/process.c | 19 +++--
arch/x86/kernel/relocate_kernel_64.S | 19 +++--
arch/x86/virt/vmx/tdx/tdx.c | 100 +++++++++++++++++++++++++++
7 files changed, 165 insertions(+), 21 deletions(-)


base-commit: 1e0fd81e4f32a8a383c05d27a672d742b45c1088
--
2.43.2