Chipsets & PCIe

AMD Secure Processor / CCP PCI function

A checked AMD secure-processor function whose crypto and virtualization features depend on separate configuration.

On this page
  1. Overview & identity
  2. Driver & binding
  3. Firmware
  4. Read-only diagnostics
  5. Limitations & related issues
  6. References

Overview & identity

The reviewed sp-pci.c table contains AMD 1022:1456 and 1022:1486 with different device-data entries. These are curated secure-processor driver matches, not exact CPU model labels or proof of an enabled confidential-computing feature. Keep this PCI function distinct from graphics devices using AMD vendor 1002.

Curated identifiers
pci 1022:1456 pci 1022:1486

A numeric match establishes a candidate family within the reviewed evidence. Marketing names, board variants, subsystem conditions and successful operation remain separate questions.

Driver & binding

The CCP build combines PCI secure-processor transport with selected crypto/PSP components. Kernel configuration separates the secure-processor device driver, crypto acceleration and related feature code. A ccp binding alone does not establish that a particular algorithm uses hardware or that SEV is available to a virtual machine.

  • ccp — kernel driver/module candidate

Detected, bound, operational: learn the difference

Firmware

Device/revision dependent

Secure-processor services involve platform firmware and separately configured feature code. The PCI table and build files are not a complete feature-firmware manifest; no exact universal external filename is established here. Use a specific PSP/SEV initialization report before relating a firmware issue to this host function.

Inspect firmware packaging on your distribution

Read-only diagnostics

Run one displayed command at a time. Replace uppercase placeholders with the affected device, interface or module from your own output. Commands are never executed here. Read-only output can still contain private identifiers.

Read this function and its bound driver

lspci -nnk -s BDF

Replace BDF with the address of the AMD secure processor function. The summary normally needs no sudo. Numeric ID and the “driver in use” observation are stronger evidence than a descriptive name or candidate-module list.

Confirm the PCI driver owner

readlink /sys/bus/pci/devices/BDF/driver

Use a full domain:bus:slot.function BDF. This normally needs no sudo and only reads a symlink. The last component is the bound driver; no link records an unbound/absent function, not a missing software package.

Read current-boot controller messages

journalctl -k -b --no-pager

Read ccp/PSP initialization and the exact feature named in a failure; a disabled optional service is not the same as failure to bind the PCI transport. Journal access may require local group membership; failure to read it is not controller failure.

Read registered kernel crypto implementations

cat /proc/crypto

This normally requires no sudo and only reads the registered crypto API list. An entry can report an implementation driver, but the list does not prove that a specific application used it or that SEV guest support works. It is separate evidence from the PCI owner.

Limitations & related issues

These table rows do not determine TPM implementation, platform firmware version or every virtualization capability. No confidential-guest launch, crypto benchmark or firmware-flashing operation is tested or performed by this profile.

These guides are linked for relevant observations, not as known defects of every device in this family.

Choose a hardware diagnostic workflow · Inspect a log excerpt in Fix Lab

References

Source review records a checked implementation or document, not a reproduced hardware test. Version-specific tables do not establish a minimum kernel or guaranteed operation.