CPUID only announces what the silicon is capable of. SEV, SEV-ES and SNP can all still be disabled by firmware/platform config. If KVM signals support, Qemu is able launch VMs with that feature. Signed-off-by: Christian Ludwig --- .../query-machine-capabilities.c | 42 ++++++++++++++++--- 1 file changed, 37 insertions(+), 5 deletions(-) diff --git a/src/query-machine-capabilities/query-machine-capabilities.c b/src/query-machine-capabilities/query-machine-capabilities.c index 0a9ab805..b7e06286 100644 --- a/src/query-machine-capabilities/query-machine-capabilities.c +++ b/src/query-machine-capabilities/query-machine-capabilities.c @@ -120,9 +120,44 @@ int read_msr(uint32_t msr_index, uint64_t *value) { return 0; } + void query_cpu_capabilities_sev(cpu_caps_amd_sev_t *res) { #ifdef __x86_64__ uint32_t eax, ebx, ecx, edx; + struct { + const char *path; + bool *result; + } s[] = { + { "/sys/module/kvm_amd/parameters/sev", &res->sev_support }, + { "/sys/module/kvm_amd/parameters/sev_es", &res->sev_es_support }, + { "/sys/module/kvm_amd/parameters/sev_snp", &res->sev_snp_support }, + }; + + for (size_t i = 0; i < sizeof(s) / sizeof(s[0]); i++) { + char c; + FILE *fp = fopen(s[i].path, "r"); + if (fp == NULL) + continue; + if (fscanf(fp, " %c", &c) != 1) { + fclose(fp); + continue; + } + fclose(fp); + + switch (c) { + case '1': + case 'y': + case 'Y': + *s[i].result = true; + break; + default: + *s[i].result = false; + break; + } + } + + if (!res->sev_support && !res->sev_es_support && !res->sev_snp_support) + return; // query Encrypted Memory Capabilities, see: // https://en.wikipedia.org/wiki/CPUID#EAX=8000001Fh:_Encrypted_Memory_Capabilities @@ -132,12 +167,9 @@ void query_cpu_capabilities_sev(cpu_caps_amd_sev_t *res) { : "0"(query_function) ); - res->sev_support = (eax & (1<<1)) != 0; - res->sev_es_support = (eax & (1<<3)) != 0; - res->sev_snp_support = (eax & (1<<4)) != 0; - res->cbitpos = ebx & 0x3f; res->reduced_phys_bits = (ebx >> 6) & 0x3f; + #else memset(res, 0, sizeof(*res)); #endif @@ -206,7 +238,7 @@ int main() { #ifdef __x86_64__ if (strncmp(vendor, "AuthenticAMD", 12) == 0) { - cpu_caps_amd_sev_t caps_sev; + cpu_caps_amd_sev_t caps_sev = { 0 }; query_cpu_capabilities_sev(&caps_sev); ret = fprintf(file, -- 2.34.1