From nobody Tue Feb 10 05:46:19 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1612239541; cv=none; d=zohomail.com; s=zohoarc; b=Mrfz52Ld6UKv7/PqdrvInlZGvJ05z/tjyCbH84icCLz7PMz/Lb6P/c7pMzoYIWm66VlGJYQeja3CPTTH8gBlFO9IvHqe890Gdsiu5imz6lRAkzC3cKQ1vvkn3L+M/44KAyQib6etOMJ64xk5mjmXIylOmrpURL6pA7srW5y7D9M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1612239541; h=Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:To; bh=H8/9VN3srpLh2lpBPKJmHFBpU2kH+AUknysM1pM59QM=; b=J0tT4S+M6t/9Q4SQtkmBr06fEWvipg0IUZ6Q4UHR5XH2U+InlvPbTPQjeRT4hSfzoj9vEfeC460conkJBAbOgU8LuMGieXbyEZAN/vUzv/pNyAAvI/uBo9Z5fQs82BLAFLfnAqqZ0lw0Izcqrm3z+P8INSsjz72L1pa52vb0wjo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1612239541574636.7133987482349; Mon, 1 Feb 2021 20:19:01 -0800 (PST) Received: from localhost ([::1]:56492 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1l6n9Y-0003h3-F5 for importer@patchew.org; Mon, 01 Feb 2021 23:19:00 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:45982) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1l6n4T-00064R-1L; Mon, 01 Feb 2021 23:13:45 -0500 Received: from bilbo.ozlabs.org ([2401:3900:2:1::2]:33299 helo=ozlabs.org) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1l6n4P-0004ys-K0; Mon, 01 Feb 2021 23:13:44 -0500 Received: by ozlabs.org (Postfix, from userid 1007) id 4DVBHz1qqjz9tkv; Tue, 2 Feb 2021 15:13:19 +1100 (AEDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=gibson.dropbear.id.au; s=201602; t=1612239199; bh=sgqCxTU3ldDr2MDL7pZNPx7v/t7kq8/KrSPm5nvDlJE=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=X4L0x6hTVEYQusVRvDY1CcV4UGEiEcPCuk9+WDLdo9sE7z5an7PriJbbRMDxD/Bkr mu4pFJJ7QQ9Tpbb346NHIz09+JQosqqaiyEtjhXMHVOU2UwYAEGLZ2cb7wuOlKW/rr ezh64AAFsarEEY9WswP2jPNrEJqReUUYpHXfoUg8= From: David Gibson To: dgilbert@redhat.com, pair@us.ibm.com, qemu-devel@nongnu.org, brijesh.singh@amd.com, pasic@linux.ibm.com Subject: [PATCH v8 07/13] confidential guest support: Introduce cgs "ready" flag Date: Tue, 2 Feb 2021 15:13:09 +1100 Message-Id: <20210202041315.196530-8-david@gibson.dropbear.id.au> X-Mailer: git-send-email 2.29.2 In-Reply-To: <20210202041315.196530-1-david@gibson.dropbear.id.au> References: <20210202041315.196530-1-david@gibson.dropbear.id.au> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=2401:3900:2:1::2; envelope-from=dgibson@ozlabs.org; helo=ozlabs.org X-Spam_score_int: -17 X-Spam_score: -1.8 X-Spam_bar: - X-Spam_report: (-1.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: thuth@redhat.com, Cornelia Huck , berrange@redhat.com, mst@redhat.com, kvm@vger.kernel.org, David Hildenbrand , jun.nakajima@intel.com, mtosatti@redhat.com, richard.henderson@linaro.org, mdroth@linux.vnet.ibm.com, Eduardo Habkost , Greg Kurz , pragyansri.pathi@intel.com, qemu-s390x@nongnu.org, frankja@linux.ibm.com, qemu-ppc@nongnu.org, andi.kleen@intel.com, pbonzini@redhat.com, borntraeger@de.ibm.com, David Gibson Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: fail (Header signature does not verify) Content-Type: text/plain; charset="utf-8" The platform specific details of mechanisms for implementing confidential guest support may require setup at various points during initialization. Thus, it's not really feasible to have a single cgs initialization hook, but instead each mechanism needs its own initialization calls in arch or machine specific code. However, to make it harder to have a bug where a mechanism isn't properly initialized under some circumstances, we want to have a common place, late in boot, where we verify that cgs has been initialized if it was requested. This patch introduces a ready flag to the ConfidentialGuestSupport base type to accomplish this, which we verify in qemu_machine_creation_done(). Signed-off-by: David Gibson Reviewed-by: Dr. David Alan Gilbert Reviewed-by: Greg Kurz --- include/exec/confidential-guest-support.h | 24 +++++++++++++++++++++++ softmmu/vl.c | 10 ++++++++++ target/i386/sev.c | 2 ++ 3 files changed, 36 insertions(+) diff --git a/include/exec/confidential-guest-support.h b/include/exec/confi= dential-guest-support.h index 3db6380e63..5dcf602047 100644 --- a/include/exec/confidential-guest-support.h +++ b/include/exec/confidential-guest-support.h @@ -27,6 +27,30 @@ OBJECT_DECLARE_SIMPLE_TYPE(ConfidentialGuestSupport, CON= FIDENTIAL_GUEST_SUPPORT) =20 struct ConfidentialGuestSupport { Object parent; + + /* + * ready: flag set by CGS initialization code once it's ready to + * start executing instructions in a potentially-secure + * guest + * + * The definition here is a bit fuzzy, because this is essentially + * part of a self-sanity-check, rather than a strict mechanism. + * + * It's not fasible to have a single point in the common machine + * init path to configure confidential guest support, because + * different mechanisms have different interdependencies requiring + * initialization in different places, often in arch or machine + * type specific code. It's also usually not possible to check + * for invalid configurations until that initialization code. + * That means it would be very easy to have a bug allowing CGS + * init to be bypassed entirely in certain configurations. + * + * Silently ignoring a requested security feature would be bad, so + * to avoid that we check late in init that this 'ready' flag is + * set if CGS was requested. If the CGS init hasn't happened, and + * so 'ready' is not set, we'll abort. + */ + bool ready; }; =20 typedef struct ConfidentialGuestSupportClass { diff --git a/softmmu/vl.c b/softmmu/vl.c index 1b464e3474..1869ed54a9 100644 --- a/softmmu/vl.c +++ b/softmmu/vl.c @@ -101,6 +101,7 @@ #include "qemu/plugin.h" #include "qemu/queue.h" #include "sysemu/arch_init.h" +#include "exec/confidential-guest-support.h" =20 #include "ui/qemu-spice.h" #include "qapi/string-input-visitor.h" @@ -2497,6 +2498,8 @@ static void qemu_create_cli_devices(void) =20 static void qemu_machine_creation_done(void) { + MachineState *machine =3D MACHINE(qdev_get_machine()); + /* Did we create any drives that we failed to create a device for? */ drive_check_orphaned(); =20 @@ -2516,6 +2519,13 @@ static void qemu_machine_creation_done(void) =20 qdev_machine_creation_done(); =20 + if (machine->cgs) { + /* + * Verify that Confidential Guest Support has actually been initia= lized + */ + assert(machine->cgs->ready); + } + if (foreach_device_config(DEV_GDB, gdbserver_start) < 0) { exit(1); } diff --git a/target/i386/sev.c b/target/i386/sev.c index 590cb31fa8..f9e9b5d8ae 100644 --- a/target/i386/sev.c +++ b/target/i386/sev.c @@ -737,6 +737,8 @@ int sev_kvm_init(ConfidentialGuestSupport *cgs, Error *= *errp) qemu_add_machine_init_done_notifier(&sev_machine_done_notify); qemu_add_vm_change_state_handler(sev_vm_state_change, sev); =20 + cgs->ready =3D true; + return 0; err: sev_guest =3D NULL; --=20 2.29.2