From nobody Mon Feb 9 18:25:32 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1748589987; cv=none; d=zohomail.com; s=zohoarc; b=lWYF3XH24WX+FJRwwVzNAwR4eYO2QBz2284wkT5xiZnNtStde3fXrXJxqQQuee0KZ6QYNUfwxyWVvC5qKwbkOuVYi6S6CmRRHZ7pB2XkGFxg0gUUMn7DmBtDY8fIEDYzKOfzG8xjvmqjWjVByX2z3M/qvQNEiVn8OwBmbcEzisw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1748589987; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=R7J/PKsdjyO75T/ahNYZnTAukxtHL/1y+JI/M/+zeKQ=; b=O+qwjViDidJPkxFANU5+Eh7fBeYrKNg7Vkjsbc2rOWDfbYvrRYxFEmWfJDF4ztDfvm1gnFO4rfLJjv5V8eD4CAWUd3ijowW074hxvmqNBzV5kdARc8LOrESKcFmv0J9F3ENscE5f8QuLqyfxbgBqNxBB1jRcZIBLIhu9nxddYPc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1748589987110645.1932600064315; Fri, 30 May 2025 00:26:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1uKtvt-0000P3-3p; Fri, 30 May 2025 03:13:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uKtvo-0000AT-K3 for qemu-devel@nongnu.org; Fri, 30 May 2025 03:13:32 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uKtvl-0006qC-Ub for qemu-devel@nongnu.org; Fri, 30 May 2025 03:13:31 -0400 Received: from mail-ej1-f69.google.com (mail-ej1-f69.google.com [209.85.218.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-671-rAidFBXZO0qiw0rL2B_WNg-1; Fri, 30 May 2025 03:13:27 -0400 Received: by mail-ej1-f69.google.com with SMTP id a640c23a62f3a-acbbb0009aeso130569166b.1 for ; Fri, 30 May 2025 00:13:27 -0700 (PDT) Received: from [192.168.122.1] ([151.49.64.79]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-ada5dd04537sm277865566b.92.2025.05.30.00.13.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 30 May 2025 00:13:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1748589209; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=R7J/PKsdjyO75T/ahNYZnTAukxtHL/1y+JI/M/+zeKQ=; b=ggi8xOoznHniQIr1hJoitevqJau6cgTlTfj0llv8X3AVe+23w8hxKDyr8AIfvgHULn7CK2 dqNImylqKBIEnkvMd+62+su8V/1NXSzI0Rh2w4KeliJDhKw3Y26aJ9mwtCSPO/piYveoNl P3FLgt47gR8MrHTuVtwxJ46JuBd34lo= X-MC-Unique: rAidFBXZO0qiw0rL2B_WNg-1 X-Mimecast-MFC-AGG-ID: rAidFBXZO0qiw0rL2B_WNg_1748589206 X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1748589206; x=1749194006; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=R7J/PKsdjyO75T/ahNYZnTAukxtHL/1y+JI/M/+zeKQ=; b=IYbmifEUh6BMaZgOKn41RWo6LPuVJsOSBj2j/3V/Tx0hrqkd2EWjNJGtxUQcyUMR2I vixfWeCtH6HFx8//tiUS1/7snj6oBSV5+iNr0ED2BWypqWlS2dPKCiW6+TBg/HK/TT02 OcCq8jpt/F83Ui0tX5wLC1Pw+erfvbgxXUl/jJpcVOcPLW8c8YfonMNONf/GiYlwh3kF 01s33VXmkm4OXl4ILtoCePTNsufL+nuum0Z2Zi+HMTNTEblTvimuAXRz9hp49V7NvRQ6 xAj5TyV9fLBb8n4SuJK8CAWv5PiktJGK0DSATFNF30p/OeHYl7sESSOLrgKshiPPbJ7R o2QQ== X-Gm-Message-State: AOJu0YwGKDoBygZaqO9vo7M/8Osz7T5TOsY++h6aHYhdB8oze7O21I+h jJwhrIjugjrmhICPD7JBg3ABx+HldmI0M89OTZ8qPVEskL+cughZiBHWbWwu3Si/mhMlrEEg+pF nRj5Z+QIAoFwacMNNNJ9wZfSKJlXS9kI1OXu4Beaaa08nS1MVXqRAGy6fYgY8bKmS0jnUHhm3jM WDoH1U86GC/6d6B9/U+nFdN9Yugw7FemplCdW7b8pJ X-Gm-Gg: ASbGncttJiPqqNrbBHALDTyzlOe1wqsmOO7bTtSL06sXjlIMqfnHsLvydI2UVYiaIoj Lv2cTRoTNmd0/XMq8/mpDNbiBixn9JvH6ApitCA45cdsgMPyWExuy1c8JW9qt55T+mQBuUM55da G3r3Sqoll3AwLAO4/EWJHNKzqqOFLp7URR06kFVxg0zkdDejajyYYEpBGYhmmNkkec6tUc6FTPl y7yWKIWOsFzv6yzAHNUY77g43bUfy2De+Q5vl3h0MVZte7zdsfdZZC6qqNEu06su9xAHXRlaQG6 mquy2mB5V+2Fiz0gGkU+1Cji X-Received: by 2002:a17:907:2d10:b0:adb:7f8:9ecf with SMTP id a640c23a62f3a-adb32301978mr201230366b.45.1748589205453; Fri, 30 May 2025 00:13:25 -0700 (PDT) X-Google-Smtp-Source: AGHT+IFbeDxfmsjJ49OrrqGMQCVowujdXZ7NQpIqjgaIYZJqMak5sjF+jQEYgnCy1xZ7+s+RNwOvkA== X-Received: by 2002:a17:907:2d10:b0:adb:7f8:9ecf with SMTP id a640c23a62f3a-adb32301978mr201227466b.45.1748589204976; Fri, 30 May 2025 00:13:24 -0700 (PDT) From: Paolo Bonzini To: qemu-devel@nongnu.org Cc: Xiaoyao Li , Gerd Hoffmann , Markus Armbruster , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Zhao Liu Subject: [PULL 14/77] i386: Introduce tdx-guest object Date: Fri, 30 May 2025 09:11:44 +0200 Message-ID: <20250530071250.2050910-15-pbonzini@redhat.com> X-Mailer: git-send-email 2.49.0 In-Reply-To: <20250530071250.2050910-1-pbonzini@redhat.com> References: <20250530071250.2050910-1-pbonzini@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=pbonzini@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -49 X-Spam_score: -5.0 X-Spam_bar: ----- X-Spam_report: (-5.0 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-2.902, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1748589988773116600 From: Xiaoyao Li Introduce tdx-guest object which inherits X86_CONFIDENTIAL_GUEST, and will be used to create TDX VMs (TDs) by qemu -machine ...,confidential-guest-support=3Dtdx0 \ -object tdx-guest,id=3Dtdx0 It has one QAPI member 'attributes' defined, which allows user to set TD's attributes directly. Signed-off-by: Xiaoyao Li Acked-by: Gerd Hoffmann Acked-by: Markus Armbruster Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Zhao Liu Link: https://lore.kernel.org/r/20250508150002.689633-3-xiaoyao.li@intel.com Signed-off-by: Paolo Bonzini --- configs/devices/i386-softmmu/default.mak | 1 + qapi/qom.json | 15 +++++++++ target/i386/kvm/tdx.h | 21 ++++++++++++ target/i386/kvm/tdx.c | 43 ++++++++++++++++++++++++ hw/i386/Kconfig | 5 +++ target/i386/kvm/meson.build | 2 ++ 6 files changed, 87 insertions(+) create mode 100644 target/i386/kvm/tdx.h create mode 100644 target/i386/kvm/tdx.c diff --git a/configs/devices/i386-softmmu/default.mak b/configs/devices/i38= 6-softmmu/default.mak index 4faf2f0315e..bc0479a7e0a 100644 --- a/configs/devices/i386-softmmu/default.mak +++ b/configs/devices/i386-softmmu/default.mak @@ -18,6 +18,7 @@ #CONFIG_QXL=3Dn #CONFIG_SEV=3Dn #CONFIG_SGA=3Dn +#CONFIG_TDX=3Dn #CONFIG_TEST_DEVICES=3Dn #CONFIG_TPM_CRB=3Dn #CONFIG_TPM_TIS_ISA=3Dn diff --git a/qapi/qom.json b/qapi/qom.json index 04c118e4d61..3d7e11efc38 100644 --- a/qapi/qom.json +++ b/qapi/qom.json @@ -1047,6 +1047,19 @@ '*host-data': 'str', '*vcek-disabled': 'bool' } } =20 +## +# @TdxGuestProperties: +# +# Properties for tdx-guest objects. +# +# @attributes: The 'attributes' of a TD guest that is passed to +# KVM_TDX_INIT_VM +# +# Since: 10.1 +## +{ 'struct': 'TdxGuestProperties', + 'data': { '*attributes': 'uint64' } } + ## # @ThreadContextProperties: # @@ -1132,6 +1145,7 @@ 'sev-snp-guest', 'thread-context', 's390-pv-guest', + 'tdx-guest', 'throttle-group', 'tls-creds-anon', 'tls-creds-psk', @@ -1204,6 +1218,7 @@ 'if': 'CONFIG_SECRET_KEYRING' }, 'sev-guest': 'SevGuestProperties', 'sev-snp-guest': 'SevSnpGuestProperties', + 'tdx-guest': 'TdxGuestProperties', 'thread-context': 'ThreadContextProperties', 'throttle-group': 'ThrottleGroupProperties', 'tls-creds-anon': 'TlsCredsAnonProperties', diff --git a/target/i386/kvm/tdx.h b/target/i386/kvm/tdx.h new file mode 100644 index 00000000000..f3b72533616 --- /dev/null +++ b/target/i386/kvm/tdx.h @@ -0,0 +1,21 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ + +#ifndef QEMU_I386_TDX_H +#define QEMU_I386_TDX_H + +#include "confidential-guest.h" + +#define TYPE_TDX_GUEST "tdx-guest" +#define TDX_GUEST(obj) OBJECT_CHECK(TdxGuest, (obj), TYPE_TDX_GUEST) + +typedef struct TdxGuestClass { + X86ConfidentialGuestClass parent_class; +} TdxGuestClass; + +typedef struct TdxGuest { + X86ConfidentialGuest parent_obj; + + uint64_t attributes; /* TD attributes */ +} TdxGuest; + +#endif /* QEMU_I386_TDX_H */ diff --git a/target/i386/kvm/tdx.c b/target/i386/kvm/tdx.c new file mode 100644 index 00000000000..ab70566c7df --- /dev/null +++ b/target/i386/kvm/tdx.c @@ -0,0 +1,43 @@ +/* + * QEMU TDX support + * + * Copyright (c) 2025 Intel Corporation + * + * Author: + * Xiaoyao Li + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#include "qemu/osdep.h" +#include "qom/object_interfaces.h" + +#include "tdx.h" + +/* tdx guest */ +OBJECT_DEFINE_TYPE_WITH_INTERFACES(TdxGuest, + tdx_guest, + TDX_GUEST, + X86_CONFIDENTIAL_GUEST, + { TYPE_USER_CREATABLE }, + { NULL }) + +static void tdx_guest_init(Object *obj) +{ + ConfidentialGuestSupport *cgs =3D CONFIDENTIAL_GUEST_SUPPORT(obj); + TdxGuest *tdx =3D TDX_GUEST(obj); + + cgs->require_guest_memfd =3D true; + tdx->attributes =3D 0; + + object_property_add_uint64_ptr(obj, "attributes", &tdx->attributes, + OBJ_PROP_FLAG_READWRITE); +} + +static void tdx_guest_finalize(Object *obj) +{ +} + +static void tdx_guest_class_init(ObjectClass *oc, const void *data) +{ +} diff --git a/hw/i386/Kconfig b/hw/i386/Kconfig index d34ce07b215..cce9521ba93 100644 --- a/hw/i386/Kconfig +++ b/hw/i386/Kconfig @@ -10,6 +10,10 @@ config SGX bool depends on KVM =20 +config TDX + bool + depends on KVM + config PC bool imply APPLESMC @@ -26,6 +30,7 @@ config PC imply QXL imply SEV imply SGX + imply TDX imply TEST_DEVICES imply TPM_CRB imply TPM_TIS_ISA diff --git a/target/i386/kvm/meson.build b/target/i386/kvm/meson.build index 3996cafaf29..466bccb9cb1 100644 --- a/target/i386/kvm/meson.build +++ b/target/i386/kvm/meson.build @@ -8,6 +8,8 @@ i386_kvm_ss.add(files( =20 i386_kvm_ss.add(when: 'CONFIG_XEN_EMU', if_true: files('xen-emu.c')) =20 +i386_kvm_ss.add(when: 'CONFIG_TDX', if_true: files('tdx.c')) + i386_system_ss.add(when: 'CONFIG_HYPERV', if_true: files('hyperv.c'), if_f= alse: files('hyperv-stub.c')) =20 i386_system_ss.add_all(when: 'CONFIG_KVM', if_true: i386_kvm_ss) --=20 2.49.0