From 08e8067a58177f65a5fa191a28aea5d52e37c541 Mon Sep 17 00:00:00 2001 From: Pratikkumar Prajapati Date: Mon, 19 Dec 2022 11:21:56 -0800 Subject: soc/intel/common: Add API to check Key Locker support Add is_keylocker_supported() API in common cpulib. This function checks if the CPU supports Key Locker feature. Returns true if Key Locker feature is supported otherwise false. Change-Id: Ide9e59a4f11a63df48838eab02c2c584cced12e1 Signed-off-by: Pratikkumar Prajapati Reviewed-on: https://review.coreboot.org/c/coreboot/+/71117 Reviewed-by: Sridhar Siricilla Tested-by: build bot (Jenkins) --- src/soc/intel/common/block/cpu/cpulib.c | 10 ++++++++++ src/soc/intel/common/block/include/intelblocks/cpulib.h | 5 +++++ src/soc/intel/common/block/include/intelblocks/msr.h | 7 +++++-- 3 files changed, 20 insertions(+), 2 deletions(-) (limited to 'src/soc/intel/common') diff --git a/src/soc/intel/common/block/cpu/cpulib.c b/src/soc/intel/common/block/cpu/cpulib.c index 0e783447cf..534feb1155 100644 --- a/src/soc/intel/common/block/cpu/cpulib.c +++ b/src/soc/intel/common/block/cpu/cpulib.c @@ -533,3 +533,13 @@ bool is_sgx_supported(void) msr = rdmsr(MTRR_CAP_MSR); /* Bit 12 is PRMRR enablement */ return ((cpuid_regs.ebx & SGX_SUPPORTED) && (msr.lo & MTRR_CAP_PRMRR)); } + +bool is_keylocker_supported(void) +{ + struct cpuid_result cpuid_regs; + msr_t msr; + + cpuid_regs = cpuid_ext(0x7, 0x0); /* ECX[23] is feature capability */ + msr = rdmsr(MTRR_CAP_MSR); /* Bit 12 is PRMRR enablement */ + return ((cpuid_regs.ecx & KEYLOCKER_SUPPORTED) && (msr.lo & MTRR_CAP_PRMRR)); +} diff --git a/src/soc/intel/common/block/include/intelblocks/cpulib.h b/src/soc/intel/common/block/include/intelblocks/cpulib.h index 6c3aa56443..c72e1eaed9 100644 --- a/src/soc/intel/common/block/include/intelblocks/cpulib.h +++ b/src/soc/intel/common/block/include/intelblocks/cpulib.h @@ -217,4 +217,9 @@ void set_tme_core_activate(void); */ bool is_sgx_supported(void); +/* + * This function checks if the CPU supports Key Locker feature. + * Returns true if Key Locker feature is supported otherwise false. + */ +bool is_keylocker_supported(void); #endif /* SOC_INTEL_COMMON_BLOCK_CPULIB_H */ diff --git a/src/soc/intel/common/block/include/intelblocks/msr.h b/src/soc/intel/common/block/include/intelblocks/msr.h index 47b9e4a9b9..d4d8732418 100644 --- a/src/soc/intel/common/block/include/intelblocks/msr.h +++ b/src/soc/intel/common/block/include/intelblocks/msr.h @@ -107,7 +107,10 @@ #define PRMRR_SUPPORTED (1<<12) #define SMRR_LOCK_SUPPORTED (1<<14) -#define SGX_SUPPORTED (1<<2) -#define TME_SUPPORTED (1<<13) +#define SGX_SUPPORTED (1<<2) +#define TME_SUPPORTED (1<<13) + +#define KEYLOCKER_SUPPORTED (1<<23) +#define KEYLOCKER_AESKL (1) #endif /* SOC_INTEL_COMMON_MSR_H */ -- cgit v1.2.3