BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=3108
If a hypervisor incorrectly reports through CPUID that SEV-ES is not
active, ensure that a #VC exception was not taken. If it is found that
a #VC was taken, then the code enters a HLT loop.
Cc: Jordan Justen <jordan.l.justen@intel.com>
Cc: Laszlo Ersek <lersek@redhat.com>
Cc: Ard Biesheuvel <ard.biesheuvel@arm.com>
Cc: Brijesh Singh <brijesh.singh@amd.com>
Reviewed-by: Laszlo Ersek <lersek@redhat.com>
Signed-off-by: Tom Lendacky <thomas.lendacky@amd.com>
Message-Id: <
afa2030b95b852313b13982df82d472187e59b92.
1610045305.git.thomas.lendacky@amd.com>
jmp SevEncBitLowHlt\r
\r
NoSev:\r
+ ;\r
+ ; Perform an SEV-ES sanity check by seeing if a #VC exception occurred.\r
+ ;\r
+ cmp byte[SEV_ES_WORK_AREA], 0\r
+ jz NoSevPass\r
+\r
+ ;\r
+ ; A #VC was received, yet CPUID indicates no SEV-ES support, something\r
+ ; isn't right.\r
+ ;\r
+NoSevEsVcHlt:\r
+ cli\r
+ hlt\r
+ jmp NoSevEsVcHlt\r
+\r
+NoSevPass:\r
xor eax, eax\r
\r
SevExit:\r