Overview & identity
The reviewed sp-pci.c table contains AMD 1022:1456 and 1022:1486 with different device-data entries. These are curated secure-processor driver matches, not exact CPU model labels or proof of an enabled confidential-computing feature. Keep this PCI function distinct from graphics devices using AMD vendor 1002.
- Curated identifiers
pci 1022:1456pci 1022:1486
A numeric match establishes a candidate family within the reviewed evidence. Marketing names, board variants, subsystem conditions and successful operation remain separate questions.
Driver & binding
The CCP build combines PCI secure-processor transport with selected crypto/PSP components. Kernel configuration separates the secure-processor device driver, crypto acceleration and related feature code. A ccp binding alone does not establish that a particular algorithm uses hardware or that SEV is available to a virtual machine.
ccp— kernel driver/module candidate
Firmware
Device/revision dependent
Secure-processor services involve platform firmware and separately configured feature code. The PCI table and build files are not a complete feature-firmware manifest; no exact universal external filename is established here. Use a specific PSP/SEV initialization report before relating a firmware issue to this host function.
Read-only diagnostics
Run one displayed command at a time. Replace uppercase placeholders with the affected device, interface or module from your own output. Commands are never executed here. Read-only output can still contain private identifiers.
Read this function and its bound driver
lspci -nnk -s BDFReplace BDF with the address of the AMD secure processor function. The summary normally needs no sudo. Numeric ID and the “driver in use” observation are stronger evidence than a descriptive name or candidate-module list.
Confirm the PCI driver owner
readlink /sys/bus/pci/devices/BDF/driverUse a full domain:bus:slot.function BDF. This normally needs no sudo and only reads a symlink. The last component is the bound driver; no link records an unbound/absent function, not a missing software package.
Read current-boot controller messages
journalctl -k -b --no-pagerRead ccp/PSP initialization and the exact feature named in a failure; a disabled optional service is not the same as failure to bind the PCI transport. Journal access may require local group membership; failure to read it is not controller failure.
Read registered kernel crypto implementations
cat /proc/cryptoThis normally requires no sudo and only reads the registered crypto API list. An entry can report an implementation driver, but the list does not prove that a specific application used it or that SEV guest support works. It is separate evidence from the PCI owner.
Limitations & related issues
These table rows do not determine TPM implementation, platform firmware version or every virtualization capability. No confidential-guest launch, crypto benchmark or firmware-flashing operation is tested or performed by this profile.
These guides are linked for relevant observations, not as known defects of every device in this family.
Choose a hardware diagnostic workflow · Inspect a log excerpt in Fix Lab
References
Source review records a checked implementation or document, not a reproduced hardware test. Version-specific tables do not establish a minimum kernel or guaranteed operation.
- Linux AMD Secure Processor PCI table
Reviewed upstream source
lines 555–558 - Linux CCP component build
Reviewed upstream source
lines 2–17 - Linux Secure Processor feature configuration
Reviewed upstream source
CRYPTO_DEV_CCP_DD and related entries