[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[PULL 5/7] docs/interop/firmware.json: Add SEV-ES support
From: |
Eduardo Habkost |
Subject: |
[PULL 5/7] docs/interop/firmware.json: Add SEV-ES support |
Date: |
Fri, 18 Jun 2021 15:52:35 -0400 |
From: Tom Lendacky <thomas.lendacky@amd.com>
Create an enum definition, '@amd-sev-es', for SEV-ES and add documention
for the new enum. Add an example that shows some of the requirements for
SEV-ES, including not having SMM support and the requirement for an
X64-only build.
Signed-off-by: Tom Lendacky <thomas.lendacky@amd.com>
Reviewed-by: Laszlo Ersek <lersek@redhat.com>
Reviewed-by: Connor Kuehl <ckuehl@redhat.com>
Message-Id:
<b941a7ee105dfeb67607cf2d24dafcb82658b212.1619208498.git.thomas.lendacky@amd.com>
Signed-off-by: Eduardo Habkost <ehabkost@redhat.com>
---
docs/interop/firmware.json | 47 +++++++++++++++++++++++++++++++++++++-
1 file changed, 46 insertions(+), 1 deletion(-)
diff --git a/docs/interop/firmware.json b/docs/interop/firmware.json
index 9d94ccafa9e..8d8b0be030e 100644
--- a/docs/interop/firmware.json
+++ b/docs/interop/firmware.json
@@ -115,6 +115,12 @@
# this feature are documented in
# "docs/amd-memory-encryption.txt".
#
+# @amd-sev-es: The firmware supports running under AMD Secure Encrypted
+# Virtualization - Encrypted State, as specified in the AMD64
+# Architecture Programmer's Manual. QEMU command line options
+# related to this feature are documented in
+# "docs/amd-memory-encryption.txt".
+#
# @enrolled-keys: The variable store (NVRAM) template associated with
# the firmware binary has the UEFI Secure Boot
# operational mode turned on, with certificates
@@ -179,7 +185,7 @@
# Since: 3.0
##
{ 'enum' : 'FirmwareFeature',
- 'data' : [ 'acpi-s3', 'acpi-s4', 'amd-sev', 'enrolled-keys',
+ 'data' : [ 'acpi-s3', 'acpi-s4', 'amd-sev', 'amd-sev-es', 'enrolled-keys',
'requires-smm', 'secure-boot', 'verbose-dynamic',
'verbose-static' ] }
@@ -504,6 +510,45 @@
# }
#
# {
+# "description": "OVMF with SEV-ES support",
+# "interface-types": [
+# "uefi"
+# ],
+# "mapping": {
+# "device": "flash",
+# "executable": {
+# "filename": "/usr/share/OVMF/OVMF_CODE.fd",
+# "format": "raw"
+# },
+# "nvram-template": {
+# "filename": "/usr/share/OVMF/OVMF_VARS.fd",
+# "format": "raw"
+# }
+# },
+# "targets": [
+# {
+# "architecture": "x86_64",
+# "machines": [
+# "pc-q35-*"
+# ]
+# }
+# ],
+# "features": [
+# "acpi-s3",
+# "amd-sev",
+# "amd-sev-es",
+# "verbose-dynamic"
+# ],
+# "tags": [
+# "-a X64",
+# "-p OvmfPkg/OvmfPkgX64.dsc",
+# "-t GCC48",
+# "-b DEBUG",
+# "-D FD_SIZE_4MB"
+# ]
+# }
+#
+# {
# "description": "UEFI firmware for ARM64 virtual machines",
# "interface-types": [
# "uefi"
--
2.31.1
- [PULL 0/7] x86 queue, 2021-06-18, Eduardo Habkost, 2021/06/18
- [PULL 3/7] doc: Fix some mistakes in the SEV documentation, Eduardo Habkost, 2021/06/18
- [PULL 1/7] Update Linux headers to 5.13-rc4, Eduardo Habkost, 2021/06/18
- [PULL 2/7] i386: Add ratelimit for bus locks acquired in guest, Eduardo Habkost, 2021/06/18
- [PULL 5/7] docs/interop/firmware.json: Add SEV-ES support,
Eduardo Habkost <=
- [PULL 4/7] docs: Add SEV-ES documentation to amd-memory-encryption.txt, Eduardo Habkost, 2021/06/18
- [PULL 6/7] docs: add a table showing x86-64 ABI compatibility levels, Eduardo Habkost, 2021/06/18
- [PULL 7/7] scripts: helper to generate x86_64 CPU ABI compat info, Eduardo Habkost, 2021/06/18
- Re: [PULL 0/7] x86 queue, 2021-06-18, Peter Maydell, 2021/06/21