Skip to content

debian 13 SEV version 3.0-0 #227

@DGonzalezVillal

Description

@DGonzalezVillal

====== SEV CERTIFICATE ======

SEV VERSION: 3.0-0

=== TEST ENVIRONMENT DETAILS ===

Host Environment Details:
Host Operating System: Debian GNU/Linux 13 (trixie)
OVMF Version: 2025.02-8
QEMU Version: 1:10.0.6+ds-0+deb13u2
Host Kernel Version: 6.12.57+deb13-amd64

Guest Environment Details:
Display of guest environment detail fails with the exit code 1

=== SUMMARY ===

[ ❌ ] SEV VERSION 3.0-0 SNP HOST TESTS
❌ calculate-measurement.service : Calculate guest measurement...
calculate-measurement.service fails !!! Please check below for more details:
ERROR: AMDSEV compatible OVMF is not present, can't calculate measurement
✅ snphost-ok.service : Run snphost ok to make sure host is correctly set-up for SNP functionalities....
❌ verify-guest.service : Verify the SEV-SNP guest booted correctly...
verify-guest.service fails !!! Please check below for more details:
ERROR: Timed out waiting for SNP Guest to signal successful boot.

[ ? ] SEV VERSION 3.0-0 SNP GUEST TESTS

=== SEV VERSION 3.0-0 LOG ===
Dec 19 18:00:19 systemd[1]: Starting calculate-measurement.service - Calculate guest measurement...
Dec 19 18:00:19 guest_measurement.sh[1906]: ERROR: AMDSEV compatible OVMF is not present, can't calculate measurement
Dec 19 18:00:19 systemd[1]: calculate-measurement.service: Main process exited, code=exited, status=1/FAILURE
Dec 19 18:00:19 systemd[1]: calculate-measurement.service: Failed with result 'exit-code'.
Dec 19 18:00:19 systemd[1]: Failed to start calculate-measurement.service - Calculate guest measurement.
Dec 19 18:00:19 systemd[1]: Starting verify-guest.service - Verify the SEV-SNP guest booted correctly...
Dec 19 18:00:19 systemd[1]: Starting snphost-ok.service - Run snphost ok to make sure host is correctly set-up for SNP functionalities....
Dec 19 18:00:19 snphost[2043]: [ PASS ] - AMD CPU
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Microcode support
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Secure Memory Encryption (SME)
Dec 19 18:00:19 snphost[2043]: [ PASS ] - SME: Enabled in MSR
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Secure Encrypted Virtualization (SEV)
Dec 19 18:00:19 snphost[2043]: [ PASS ] - SEV firmware version: 1.55
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Encrypted State (SEV-ES)
Dec 19 18:00:19 snphost[2043]: [ PASS ] - SEV-ES initialized
Dec 19 18:00:19 snphost[2043]: [ PASS ] - SEV initialized: Initialized, no guests running
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Secure Nested Paging (SEV-SNP)
Dec 19 18:00:19 snphost[2043]: [ PASS ] - VM Permission Levels
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Number of VMPLs: 4
Dec 19 18:00:19 snphost[2043]: [ PASS ] - SNP: Enabled in MSR
Dec 19 18:00:19 snphost[2043]: [ PASS ] - SNP initialized
Dec 19 18:00:19 snphost[2043]: [ PASS ] - RMP table addresses: 0x7ffe500000 - 0x807edfffff
Dec 19 18:00:19 snphost[2043]: [ PASS ] - RMP table initialized
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Alias check: Completed since last system update, no aliasing addresses
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Physical address bit reduction: 5
Dec 19 18:00:19 snphost[2043]: [ PASS ] - C-bit location: 51
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Number of encrypted guests supported simultaneously: 509
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Minimum ASID value for SEV-enabled, SEV-ES disabled guest: 100
Dec 19 18:00:19 snphost[2043]: [ PASS ] - /dev/sev readable
Dec 19 18:00:19 snphost[2043]: [ PASS ] - /dev/sev writable
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Page flush MSR: ENABLED
Dec 19 18:00:19 snphost[2043]: [ PASS ] - KVM supported: API version: 12
Dec 19 18:00:19 snphost[2043]: [ PASS ] - SEV enabled in KVM
Dec 19 18:00:19 snphost[2043]: [ PASS ] - SEV-ES enabled in KVM
Dec 19 18:00:19 snphost[2043]: [ PASS ] - SEV-SNP enabled in KVM
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Memlock resource limit: Soft: 8388608 | Hard: 8388608
Dec 19 18:00:19 snphost[2043]: [ PASS ] - Comparing TCB values: TCB versions match
Dec 19 18:00:19 snphost[2043]: Platform TCB version: TCB Version:
Dec 19 18:00:19 snphost[2043]: Microcode: 219
Dec 19 18:00:19 snphost[2043]: SNP: 25
Dec 19 18:00:19 snphost[2043]: TEE: 0
Dec 19 18:00:19 snphost[2043]: Boot Loader: 4
Dec 19 18:00:19 snphost[2043]: FMC: None
Dec 19 18:00:19 snphost[2043]: Reported TCB version: TCB Version:
Dec 19 18:00:19 snphost[2043]: Microcode: 219
Dec 19 18:00:19 snphost[2043]: SNP: 25
Dec 19 18:00:19 snphost[2043]: TEE: 0
Dec 19 18:00:19 snphost[2043]: Boot Loader: 4
Dec 19 18:00:19 snphost[2043]: FMC: None
Dec 19 18:00:19 systemd[1]: snphost-ok.service: Deactivated successfully.
Dec 19 18:00:19 systemd[1]: Finished snphost-ok.service - Run snphost ok to make sure host is correctly set-up for SNP functionalities..
Dec 19 18:01:19 verify-guest.sh[1974]: ERROR: Timed out waiting for SNP Guest to signal successful boot.
Dec 19 18:01:19 systemd[1]: verify-guest.service: Main process exited, code=exited, status=2/INVALIDARGUMENT
Dec 19 18:01:19 systemd[1]: verify-guest.service: Failed with result 'exit-code'.
Dec 19 18:01:19 systemd[1]: Failed to start verify-guest.service - Verify the SEV-SNP guest booted correctly.
Dec 19 18:01:19 systemd[1]: Dependency failed for display-guest-logs.service - Show the guest logs for the appropriate services in the host.
Dec 19 18:01:19 systemd[1]: display-guest-logs.service: Job display-guest-logs.service/start failed with result 'dependency'.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions