[PATCH 0/7] target/i386: VM type infrastructure and KVM_SEV_INIT2 support

Paolo Bonzini posted 7 patches 1 month, 1 week ago
Failed in applying to current master (apply log)
include/sysemu/kvm.h             | 12 ++-----
include/sysemu/kvm_int.h         |  1 +
linux-headers/asm-x86/kvm.h      |  8 +++++
linux-headers/linux/kvm.h        |  2 ++
target/i386/confidential-guest.h | 59 ++++++++++++++++++++++++++++++++
target/i386/kvm/kvm_i386.h       |  2 ++
accel/kvm/kvm-accel-ops.c        |  2 +-
accel/kvm/kvm-all.c              | 19 ++++++----
hw/i386/x86.c                    |  6 ++++
system/runstate.c                | 15 +++++++-
target/arm/kvm.c                 |  5 ---
target/i386/confidential-guest.c | 33 ++++++++++++++++++
target/i386/kvm/kvm.c            | 49 +++++++++++++++++++++++---
target/i386/sev.c                | 48 ++++++++++++++++++++++----
target/loongarch/kvm/kvm.c       |  5 ---
target/mips/kvm.c                |  5 ---
target/ppc/kvm.c                 |  5 ---
target/riscv/kvm/kvm-cpu.c       |  5 ---
target/s390x/kvm/kvm.c           |  5 ---
target/i386/meson.build          |  2 +-
20 files changed, 226 insertions(+), 62 deletions(-)
create mode 100644 target/i386/confidential-guest.h
create mode 100644 target/i386/confidential-guest.c
[PATCH 0/7] target/i386: VM type infrastructure and KVM_SEV_INIT2 support
Posted by Paolo Bonzini 1 month, 1 week ago
This series adds another vendor-neutral part of the SEV-SNP/TDX support
patches, namely support for KVM_CAP_VM_TYPES.  In Linux 6.10 this will
also be available for SEV and SEV-ES, so introduce it now already.

Also, Linux 6.10 will _not_ allow KVM_GET/SET_* ioctls for VMs with
encrypted state and a VM type other than KVM_X86_DEFAULT_VM, so prepare
for that.

The patches are not yet available in kvm.git, hence the hackish
linux-headers update in patch 1.  Apart from that, however, the API
should be final.

Tested by booting a SEV-ES guest.

Paolo

Based-on: <20240229060038.606591-1-xiaoyao.li@intel.com>

Paolo Bonzini (6):
  linux-headers hack
  runstate: skip initial CPU reset if reset is not actually possible
  KVM: track whether guest state is encrypted
  KVM: remove kvm_arch_cpu_check_are_resettable
  target/i386: introduce x86-confidential-guest
  target/i386: SEV: use KVM_SEV_INIT2 if possible

Xiaoyao Li (1):
  target/i386: Implement mc->kvm_type() to get VM type

 include/sysemu/kvm.h             | 12 ++-----
 include/sysemu/kvm_int.h         |  1 +
 linux-headers/asm-x86/kvm.h      |  8 +++++
 linux-headers/linux/kvm.h        |  2 ++
 target/i386/confidential-guest.h | 59 ++++++++++++++++++++++++++++++++
 target/i386/kvm/kvm_i386.h       |  2 ++
 accel/kvm/kvm-accel-ops.c        |  2 +-
 accel/kvm/kvm-all.c              | 19 ++++++----
 hw/i386/x86.c                    |  6 ++++
 system/runstate.c                | 15 +++++++-
 target/arm/kvm.c                 |  5 ---
 target/i386/confidential-guest.c | 33 ++++++++++++++++++
 target/i386/kvm/kvm.c            | 49 +++++++++++++++++++++++---
 target/i386/sev.c                | 48 ++++++++++++++++++++++----
 target/loongarch/kvm/kvm.c       |  5 ---
 target/mips/kvm.c                |  5 ---
 target/ppc/kvm.c                 |  5 ---
 target/riscv/kvm/kvm-cpu.c       |  5 ---
 target/s390x/kvm/kvm.c           |  5 ---
 target/i386/meson.build          |  2 +-
 20 files changed, 226 insertions(+), 62 deletions(-)
 create mode 100644 target/i386/confidential-guest.h
 create mode 100644 target/i386/confidential-guest.c

-- 
2.44.0