From nobody Fri Mar 14 18:35:34 2025 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1606427514; cv=none; d=zohomail.com; s=zohoarc; b=PZvqTAQiX75p+hJK/666QggY2+SywQCfFPBfmFcJ9mh6O9aYvu7WAELce4ZyskmFyuxG/HteBKbtXvj63BFTsbrAtWybeYddY9dAOjhDxTLfbNSCLm7nV1S3r8rLusp7X+H4bNRJnIZcvfWwI1koZR8X2NBnOcXidHwux5yqZvE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1606427514; h=Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:To; bh=Sf+DuqwDCUCV+d8d2OBlRlg2vsmiKOSNpN5e7g3jBgk=; b=It7GFFgjqzD2TSCcPQR+0C9gOwr5o0U6dJWOruBagfpz85FuC7OST3pXZbtGhsP5VlMBYy2CY9HykFXQuVXdBYA07VIB9HLV4SkuFEaOuHxG7rsWIuDQ5tXOfDCK+5de/g5BYyLWcm3BqwodwTQ5jpKuk3CAAIdVJ4l44X72WMs= ARC-Authentication-Results: i=1; mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1606427514427334.42991840837556; Thu, 26 Nov 2020 13:51:54 -0800 (PST) Received: from localhost ([::1]:60382 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1kiPBB-0003Nq-Av for importer@patchew.org; Thu, 26 Nov 2020 16:51:53 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:36294) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kiP9l-0001jw-Mf; Thu, 26 Nov 2020 16:50:25 -0500 Received: from mail.csgraf.de ([188.138.100.120]:60516 helo=zulu616.server4you.de) by eggs.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1kiP9i-0005jn-N8; Thu, 26 Nov 2020 16:50:25 -0500 Received: from localhost.localdomain (dynamic-077-009-187-158.77.9.pool.telefonica.de [77.9.187.158]) by csgraf.de (Postfix) with ESMTPSA id 920D63900501; Thu, 26 Nov 2020 22:50:18 +0100 (CET) From: Alexander Graf To: qemu-devel@nongnu.org Subject: [PATCH 1/8] hvf: Add hypervisor entitlement to output binaries Date: Thu, 26 Nov 2020 22:50:10 +0100 Message-Id: <20201126215017.41156-2-agraf@csgraf.de> X-Mailer: git-send-email 2.24.3 (Apple Git-128) In-Reply-To: <20201126215017.41156-1-agraf@csgraf.de> References: <20201126215017.41156-1-agraf@csgraf.de> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=188.138.100.120; envelope-from=agraf@csgraf.de; helo=zulu616.server4you.de X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Peter Maydell , Eduardo Habkost , Richard Henderson , Cameron Esfahani , Roman Bolshakov , qemu-arm@nongnu.org, Paolo Bonzini Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" Content-Type: text/plain; charset="utf-8" In macOS 11, QEMU only gets access to Hypervisor.framework if it has the respective entitlement. Add an entitlement template and automatically self sign and apply the entitlement in the build. Signed-off-by: Alexander Graf --- accel/hvf/entitlements.plist | 8 ++++++++ meson.build | 30 ++++++++++++++++++++++++++---- scripts/entitlement.sh | 11 +++++++++++ 3 files changed, 45 insertions(+), 4 deletions(-) create mode 100644 accel/hvf/entitlements.plist create mode 100755 scripts/entitlement.sh diff --git a/accel/hvf/entitlements.plist b/accel/hvf/entitlements.plist new file mode 100644 index 0000000000..154f3308ef --- /dev/null +++ b/accel/hvf/entitlements.plist @@ -0,0 +1,8 @@ + + + + + com.apple.security.hypervisor + + + diff --git a/meson.build b/meson.build index 5062407c70..2a7ff5560c 100644 --- a/meson.build +++ b/meson.build @@ -1844,9 +1844,14 @@ foreach target : target_dirs }] endif foreach exe: execs - emulators +=3D {exe['name']: - executable(exe['name'], exe['sources'], - install: true, + exe_name =3D exe['name'] + exe_sign =3D 'CONFIG_HVF' in config_target + if exe_sign + exe_name +=3D '-unsigned' + endif + + emulator =3D executable(exe_name, exe['sources'], + install: not exe_sign, c_args: c_args, dependencies: arch_deps + deps + exe['dependencies'], objects: lib.extract_all_objects(recursive: true), @@ -1854,7 +1859,24 @@ foreach target : target_dirs link_depends: [block_syms, qemu_syms] + exe.get('link_depen= ds', []), link_args: link_args, gui_app: exe['gui']) - } + + if exe_sign + exe_full =3D meson.current_build_dir() / exe['name'] + emulators +=3D {exe['name'] : custom_target(exe['name'], + install: true, + install_dir: get_option('bindir'), + depends: emulator, + output: exe['name'], + command: [ + meson.current_source_dir() / 'scripts/entitlement.sh', + meson.current_build_dir() / exe['name'] + '-unsigned', + meson.current_build_dir() / exe['name'], + meson.current_source_dir() / 'accel/hvf/entitlements.= plist' + ]) + } + else + emulators +=3D {exe['name']: emulator} + endif =20 if 'CONFIG_TRACE_SYSTEMTAP' in config_host foreach stp: [ diff --git a/scripts/entitlement.sh b/scripts/entitlement.sh new file mode 100755 index 0000000000..7ed9590bf9 --- /dev/null +++ b/scripts/entitlement.sh @@ -0,0 +1,11 @@ +#!/bin/sh -e +# +# Helper script for the build process to apply entitlements + +SRC=3D"$1" +DST=3D"$2" +ENTITLEMENT=3D"$3" + +rm -f "$2" +cp -a "$SRC" "$DST" +codesign --entitlements "$ENTITLEMENT" --force -s - "$DST" --=20 2.24.3 (Apple Git-128)