soc/intel/common/block: add VMX support

Enable VMX if supported by CPU and enabled in board devicetree.
Check lock bit unset before enabling VMX.

Change-Id: Ic57eac45e9c65baa4479735c6d70a7eb685f080e
Signed-off-by: Matt DeVillier <matt.devillier@gmail.com>
Reviewed-on: https://review.coreboot.org/25331
Tested-by: build bot (Jenkins) <no-reply@coreboot.org>
Reviewed-by: Aaron Durbin <adurbin@chromium.org>
This commit is contained in:
Matt DeVillier 2018-03-22 13:57:10 -05:00 committed by Patrick Georgi
parent 2410cd9379
commit 9aae51ad11
5 changed files with 107 additions and 0 deletions

View File

@ -19,6 +19,7 @@
#define MSR_CORE_THREAD_COUNT 0x35
#define IA32_FEATURE_CONTROL 0x3a
#define FEATURE_CONTROL_LOCK (1)
#define FEATURE_ENABLE_VMX (1 << 2)
#define CPUID_VMX (1 << 5)
#define CPUID_SMX (1 << 6)
#define SGX_GLOBAL_ENABLE (1 << 18)

View File

@ -0,0 +1,30 @@
/*
* This file is part of the coreboot project.
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; version 2 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*/
#ifndef SOC_INTEL_COMMON_BLOCK_VMX_H
#define SOC_INTEL_COMMON_BLOCK_VMX_H
struct vmx_param {
uint8_t enable;
};
/*
* Configure VMX.
*/
void vmx_configure(void);
/* SOC specific API to get VMX params.
* returns 0, if able to get VMX params; otherwise returns -1 */
int soc_fill_vmx_param(struct vmx_param *vmx_param);
#endif /* SOC_INTEL_COMMON_BLOCK_VMX_H */

View File

@ -0,0 +1,3 @@
config SOC_INTEL_COMMON_BLOCK_VMX
bool "Enable VMX for virtualization"
default n

View File

@ -0,0 +1 @@
ramstage-$(CONFIG_SOC_INTEL_COMMON_BLOCK_VMX) += vmx.c

View File

@ -0,0 +1,72 @@
/*
* This file is part of the coreboot project.
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; version 2 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*/
#include <console/console.h>
#include <cpu/x86/msr.h>
#include <intelblocks/msr.h>
#include <intelblocks/vmx.h>
#include <soc/cpu.h>
#include <string.h>
static bool vmx_param_valid;
static struct vmx_param g_vmx_param;
static const struct vmx_param *get_vmx_param(void)
{
if (vmx_param_valid)
return &g_vmx_param;
memset(&g_vmx_param, 0, sizeof(g_vmx_param));
if (soc_fill_vmx_param(&g_vmx_param) < 0) {
printk(BIOS_ERR, "VMX : Failed to get soc vmx param\n");
return NULL;
}
vmx_param_valid = true;
printk(BIOS_INFO, "VMX : param.enable = %d\n", g_vmx_param.enable);
return &g_vmx_param;
}
static int soc_vmx_enabled(void)
{
const struct vmx_param *vmx_param = get_vmx_param();
return vmx_param ? vmx_param->enable : 0;
}
void vmx_configure(void)
{
msr_t msr;
struct cpuid_result regs;
regs = cpuid(1);
if (!soc_vmx_enabled() || !(regs.ecx & CPUID_VMX)) {
printk(BIOS_ERR, "VMX: pre-conditions not met\n");
return;
}
msr = rdmsr(IA32_FEATURE_CONTROL);
/* Only enable it when it is not locked */
if ((msr.lo & FEATURE_CONTROL_LOCK) == 0) {
/* Enable VMX */
msr.lo |= FEATURE_ENABLE_VMX;
wrmsr(IA32_FEATURE_CONTROL, msr);
}
/* Report current status */
msr = rdmsr(IA32_FEATURE_CONTROL);
printk(BIOS_DEBUG, "VMX status: %s, %s\n",
(msr.lo & FEATURE_ENABLE_VMX) ? "enabled" : "disabled",
(msr.lo & FEATURE_CONTROL_LOCK) ? "locked" : "unlocked");
}