From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098142; cv=none; d=zohomail.com; s=zohoarc; b=ACYtRExpSsTnYBc6w/4l5YfG/QGyeE7Ex5AX/04u/v5pObC+UzLZGsfut/+EfZxi3vsVZxNd30YBdeK2Vk3j0urHQ/tR7n5O40UYA0OuXMp5u2EeTRjWeVHBRVs21c3z3ryCXINBYpl2SjWn5SIyBgOjmjunb/IDT89cO/hyyGQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098142; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tbuG974DVy7BcZimxvx/tFbgAyqKjL+BcjNFMhSXDvw=; b=nauQHe6SGz2JvKU+qWP6KNwwhEMlTZ1wRUJcYb9C9ur/u6SOc67nj9loXvp9fbQiirYDFdV47v2FtP1KjHcZIxjgS4FMbBMJkTBuBmb9YdS48mEtIctz4UgsvN2Au5KM7ziTSWIC1N1dSTnIz86shhXkNlV8u8RQfysNjGnSxOs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178309814200723.465267950701787; Fri, 3 Jul 2026 10:02:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhFz-0007ZJ-Jw; Fri, 03 Jul 2026 13:00:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhFw-0007YP-EC; Fri, 03 Jul 2026 13:00:50 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhFt-0002xw-Q3; Fri, 03 Jul 2026 13:00:47 -0400 Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GJ4gS3246626; Fri, 3 Jul 2026 17:00:42 GMT Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26qafsss-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:41 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gndg8031499; Fri, 3 Jul 2026 17:00:41 GMT Received: from smtprelay02.dal12v.mail.ibm.com ([172.16.1.4]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2uhysg6g-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:41 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay02.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H0de815467014 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:00:40 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id D558958054; Fri, 3 Jul 2026 17:00:39 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id E5AA45805A; Fri, 3 Jul 2026 17:00:36 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:00:36 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=tbuG974DVy7BcZimx vx/tFbgAyqKjL+BcjNFMhSXDvw=; b=V3dwhowY8kF8EMkVL2otdenJyubroqMD/ kKyaZd94qnfqa4+U1wd8iUoqI16T7OZOZAOD9pTTaLvDeDmpeHA4xYSyP/vJI9Sq YVlSZukIMeG+Zp8uYfhQhxGGpyFxKdfQzllxM0Xcd6Hf/bhHQtG0FNHjdRx11gfp g+snfiAOXqHu8c1zS94LCau4wT4Mc5OiN0pGAoAHr1FBjJUgLu4FCJVXJOvwE80j hlzIvkM99RfX8tg/ClshKNE78Uq0U63j1BIVq3mbHfSecWh28lHelrZVgAU52D1L Sb5KSnErnagStPGaYJ4UJfLerpYLJ/cdaNIqzU8Uxjr4f+8hguXbw== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 01/33] Add boot-certs to s390-ccw-virtio machine type option Date: Fri, 3 Jul 2026 12:59:58 -0400 Message-ID: <20260703170032.1893204-2-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX5PqwMC5LWhTz ijKReHpe5NFyVIEMSBwEc5MzwGJOqa49lQhVTR88x08XYDlmIB+CIGczW72Z3o7iCi+T2IArqgL KtwX93q5s1Mc6q2B3GDM60NLmWzAWWrwGSPQaD9O9erx1R1afCV8sLrQFiXseyQYQKiGLyNLTl/ IjwGr43ifC/BQ/qs3MJ1VCD/pLc+29LExuZxjko7OdzBJgGaKUtu9uCV+1+URZh3WWGh79RhcxZ ZD0N13OphOpAQoTvNlGZ0lSDtggQFdBYPXxdX4Gh745mSfTyBqJ8D919q4d37MSwfavSy2GYyge rrvtlHlP8F1vXy+gjdl3OBWYT4YSNZASA7Z7jeFO3Lic/jNUktdzQGy/P+QrmH9tqWtGnjkDnw/ 5CYMqEMygPW3Iyeczuv7WOoXiCuuQGWRJYWRDM4uVBfuJBU9alTUu824o/VrBh3YWW9JSQnwAyg Z5QhSesWa6gDFdEWaUw== X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX8zoCKZOQBOWx 4v8IjABsOB+Tnhk0BMeYBVMAFZEtrnBWuoJPJbPs/QertGvgkH6Z5M39X0r2VU/4vl+BMGI2Rc7 k2pxnwKNH5yVuttYMZicAaHeF83CPV8= X-Proofpoint-GUID: caGnEWaEwSCSBoIqwIwLL4_xFrL8ZUVN X-Proofpoint-ORIG-GUID: caGnEWaEwSCSBoIqwIwLL4_xFrL8ZUVN X-Authority-Analysis: v=2.4 cv=WZ88rUhX c=1 sm=1 tr=0 ts=6a47eaba cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=wzXgNLvc2PBhCEj-crYA:9 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 adultscore=0 phishscore=0 clxscore=1015 bulkscore=0 impostorscore=0 priorityscore=1501 lowpriorityscore=0 suspectscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098144402158500 Content-Type: text/plain; charset="utf-8" Introduce a new `boot-certs` machine type option for the s390-ccw-virtio machine. This allows users to specify one or more certificate file paths or directories to be used during secure boot. Each entry is specified using the syntax: boot-certs..path=3D/path/to/cert.pem Multiple paths can be specify using array properties: boot-certs.0.path=3D/path/to/cert.pem, boot-certs.1.path=3D/path/to/cert-dir, boot-certs.2.path=3D/path/to/another-dir... Signed-off-by: Zhuoying Cai Acked-by: Markus Armbruster Reviewed-by: Matthew Rosato --- docs/system/s390x/secure-ipl.rst | 20 +++++++++++++++ docs/system/target-s390x.rst | 1 + hw/s390x/s390-virtio-ccw.c | 40 ++++++++++++++++++++++++++++++ include/hw/s390x/s390-virtio-ccw.h | 3 +++ qapi/machine-s390x.json | 23 +++++++++++++++++ qapi/pragma.json | 1 + qemu-options.hx | 6 ++++- 7 files changed, 93 insertions(+), 1 deletion(-) create mode 100644 docs/system/s390x/secure-ipl.rst diff --git a/docs/system/s390x/secure-ipl.rst b/docs/system/s390x/secure-ip= l.rst new file mode 100644 index 0000000000..88df52ce2f --- /dev/null +++ b/docs/system/s390x/secure-ipl.rst @@ -0,0 +1,20 @@ +.. SPDX-License-Identifier: GPL-2.0-or-later + +Secure IPL Command Line Options +------------------------------- + +The s390-ccw-virtio machine type supports secure IPL. These parameters all= ow +users to provide certificates and enable secure IPL directly via the comma= nd +line. + +Providing Certificates +^^^^^^^^^^^^^^^^^^^^^^ + +The certificate store can be populated by supplying a list of X.509 certif= icate +file paths or directories containing certificate files on the command-line: + +Note: certificate files must have a .pem extension. + +.. code-block:: shell + + qemu-system-s390x -machine s390-ccw-virtio,boot-certs.0.path=3D/.../qe= mu/certs,boot-certs.1.path=3D/another/path/cert.pem ... diff --git a/docs/system/target-s390x.rst b/docs/system/target-s390x.rst index 94c981e732..8938a13d10 100644 --- a/docs/system/target-s390x.rst +++ b/docs/system/target-s390x.rst @@ -35,3 +35,4 @@ Architectural features s390x/bootdevices s390x/protvirt s390x/cpu-topology + s390x/secure-ipl diff --git a/hw/s390x/s390-virtio-ccw.c b/hw/s390x/s390-virtio-ccw.c index 25a9fa4955..c68a760f75 100644 --- a/hw/s390x/s390-virtio-ccw.c +++ b/hw/s390x/s390-virtio-ccw.c @@ -44,6 +44,7 @@ #include "target/s390x/kvm/pv.h" #include "migration/blocker.h" #include "qapi/visitor.h" +#include "qapi/qapi-visit-machine-s390x.h" #include "hw/s390x/cpu-topology.h" #include "kvm/kvm_s390x.h" #include "hw/virtio/virtio-md-pci.h" @@ -788,6 +789,36 @@ static void machine_set_loadparm(Object *obj, Visitor = *v, g_free(val); } =20 +static void machine_get_boot_certs(Object *obj, Visitor *v, + const char *name, void *opaque, + Error **errp) +{ + S390CcwMachineState *ms =3D S390_CCW_MACHINE(obj); + BootCertificatesList **certs =3D &ms->boot_certs; + + visit_type_BootCertificatesList(v, name, certs, errp); +} + +static void machine_set_boot_certs(Object *obj, Visitor *v, const char *na= me, + void *opaque, Error **errp) +{ + S390CcwMachineClass *s390mc =3D S390_CCW_MACHINE_GET_CLASS(obj); + S390CcwMachineState *ms =3D S390_CCW_MACHINE(obj); + BootCertificatesList *cert_list =3D NULL; + + if (!s390mc->use_certs) { + error_setg(errp, "boot-certs is not supported by this machine vers= ion"); + return; + } + + visit_type_BootCertificatesList(v, name, &cert_list, errp); + if (!cert_list) { + return; + } + + ms->boot_certs =3D cert_list; +} + /* * S390x-specific global compatibility properties. * @@ -813,6 +844,7 @@ static void ccw_machine_class_init(ObjectClass *oc, con= st void *data) =20 s390mc->max_threads =3D 1; s390mc->use_cpi =3D true; + s390mc->use_certs =3D true; mc->reset =3D s390_machine_reset; mc->block_default_type =3D IF_VIRTIO; mc->no_cdrom =3D 1; @@ -856,6 +888,11 @@ static void ccw_machine_class_init(ObjectClass *oc, co= nst void *data) "Up to 8 chars in set of [A-Za-z0-9. ] (lower case chars conve= rted" " to upper case) to pass to machine loader, boot manager," " and guest kernel"); + + object_class_property_add(oc, "boot-certs", "BootCertificatesList", + machine_get_boot_certs, machine_set_boot_cer= ts, NULL, NULL); + object_class_property_set_description(oc, "boot-certs", + "provide paths to a directory and/or a certificate file for se= cure boot"); } =20 static inline void s390_machine_initfn(Object *obj) @@ -941,6 +978,9 @@ static void ccw_machine_11_0_instance_options(MachineSt= ate *machine) =20 static void ccw_machine_11_0_class_options(MachineClass *mc) { + S390CcwMachineClass *s390mc =3D S390_CCW_MACHINE_CLASS(mc); + + s390mc->use_certs =3D false; /* * Preserve v11.0 and older version behavior: * keep legacy virtio-pci enabled. diff --git a/include/hw/s390x/s390-virtio-ccw.h b/include/hw/s390x/s390-vir= tio-ccw.h index f1f06119d6..d30f1fcc4c 100644 --- a/include/hw/s390x/s390-virtio-ccw.h +++ b/include/hw/s390x/s390-virtio-ccw.h @@ -14,6 +14,7 @@ #include "hw/core/boards.h" #include "qom/object.h" #include "hw/s390x/sclp.h" +#include "qapi/qapi-types-machine-s390x.h" =20 #define TYPE_S390_CCW_MACHINE "s390-ccw-machine" =20 @@ -31,6 +32,7 @@ struct S390CcwMachineState { uint8_t loadparm[8]; uint64_t memory_limit; uint64_t max_pagesize; + BootCertificatesList *boot_certs; =20 SCLPDevice *sclp; }; @@ -55,6 +57,7 @@ struct S390CcwMachineClass { /*< public >*/ int max_threads; bool use_cpi; + bool use_certs; }; =20 #endif diff --git a/qapi/machine-s390x.json b/qapi/machine-s390x.json index ea430e1b88..bbe3646e91 100644 --- a/qapi/machine-s390x.json +++ b/qapi/machine-s390x.json @@ -140,3 +140,26 @@ { 'event': 'SCLP_CPI_INFO_AVAILABLE', 'features': [ 'unstable' ] } + +## +# @BootCertificates: +# +# Boot certificates for secure IPL. +# +# @path: path to an X.509 certificate file or a directory containing +# certificate files. +# +# Since: 11.1 +## +{ 'struct': 'BootCertificates', + 'data': {'path': 'str'} } + +## +# @DummyBootCertificates: +# +# Not used by QMP; hack to let us use BootCertificatesList internally. +# +# Since: 11.1 +## +{ 'struct': 'DummyBootCertificates', + 'data': {'unused-boot-certs': ['BootCertificates'] } } diff --git a/qapi/pragma.json b/qapi/pragma.json index 24aebbe8f5..342cedc42e 100644 --- a/qapi/pragma.json +++ b/qapi/pragma.json @@ -49,6 +49,7 @@ 'DisplayProtocol', 'DriveBackupWrapper', 'DummyBlockCoreForceArrays', + 'DummyBootCertificates', 'DummyForceArrays', 'DummyVirtioForceArrays', 'HotKeyMod', diff --git a/qemu-options.hx b/qemu-options.hx index e44b47de68..83915bd7ef 100644 --- a/qemu-options.hx +++ b/qemu-options.hx @@ -46,7 +46,8 @@ DEF("machine", HAS_ARG, QEMU_OPTION_machine, \ " memory-backend=3D'backend-id' specifies explicitly pr= ovided backend for main RAM (default=3Dnone)\n" " cxl-fmw.0.targets.0=3Dfirsttarget,cxl-fmw.0.targets.1= =3Dsecondtarget,cxl-fmw.0.size=3Dsize[,cxl-fmw.0.interleave-granularity=3Dg= ranularity]\n" " sgx-epc.0.memdev=3Dmemid,sgx-epc.0.node=3Dnumaid\n" - " smp-cache.0.cache=3Dcachename,smp-cache.0.topology=3D= topologylevel\n", + " smp-cache.0.cache=3Dcachename,smp-cache.0.topology=3D= topologylevel\n" + " boot-certs.0.path=3D/path/directory,boot-certs.1.path= =3D/path/file provides paths to a directory and/or a certificate file\n", QEMU_ARCH_ALL) SRST ``-machine [type=3D]name[,prop=3Dvalue[,...]]`` @@ -214,6 +215,9 @@ SRST :: =20 -machine smp-cache.0.cache=3Dl1d,smp-cache.0.topology=3Dcore,s= mp-cache.1.cache=3Dl1i,smp-cache.1.topology=3Dcore + + ``boot-certs.0.path=3D/path/directory,boot-certs.1.path=3D/path/file`` + Provide paths to a directory and/or a certificate file on the host= [s390x only]. ERST =20 DEF("M", HAS_ARG, QEMU_OPTION_M, --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098235; cv=none; d=zohomail.com; s=zohoarc; b=DJ7wZabTOvG3h8IwAwXfg7aKtfM1hXiHLwIyMiAWfHrHOjNNlEVIHMDL2dJp2/t/VrYJjK5wDNe1F0U3WNYhyNB9fkUwMwmrkrxFeKtW4yZK7W/Ars5ozMWaerXWnzTWNW1GLPGxqk27cu9QWxys86AAhIEHmTe6z0YgjDbp4ds= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098235; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=SRItF3Rpj3r/qWUSqrHn8Lr/8FzyN807OwVIui3tyWE=; b=LwUFWqT5KR0OgrF4fr6zBzUL6QXTc7DWmXN6I3wAEUycc1MYKROAILaMavTpvGNgtRKy5CEdkaxSE8OjR095kiyMJfEzf48HvmZIYlHQtWq/CPBJgLE6rw7uc/Z1h1vU6S5UG526vY1xogBSY2UK0gMmVs8qp0QVmaTi4MntffI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098235693908.4626416096688; Fri, 3 Jul 2026 10:03:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhG2-0007b1-HB; Fri, 03 Jul 2026 13:00:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhG0-0007Zk-5S; Fri, 03 Jul 2026 13:00:52 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhFy-0002yT-L0; Fri, 03 Jul 2026 13:00:51 -0400 Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIXUc3382732; Fri, 3 Jul 2026 17:00:45 GMT Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26pegaam-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:45 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gnd00031495; Fri, 3 Jul 2026 17:00:44 GMT Received: from smtprelay06.dal12v.mail.ibm.com ([172.16.1.8]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2uhysg6s-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:44 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay06.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H0hBN31982148 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:00:43 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 86B9558054; Fri, 3 Jul 2026 17:00:43 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 187515805A; Fri, 3 Jul 2026 17:00:40 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:00:39 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=SRItF3 Rpj3r/qWUSqrHn8Lr/8FzyN807OwVIui3tyWE=; b=FTDP0vP0PPrBLmhjmre/mC xbXBoLyCnCMgrU2KfmAZ+Y1p2jRF19v27a45TeU10fLdNcNEzDe7sDV/F1usMzpL ksmHxGGyCTu2jvdcQ4calRUUdDLZ1EMdpaUAfjempK648+qDTv4vTC0VTCve43cr kGENwMSwjF7Cobpn/h3HOUyeuNwr5pxPjPr1cLNs8XdIxgMAslnDBrYPxMgplI6m 0bDwSuL+Qb6oBHP0KbpC6+wrKi3ryQN+SRg2kqJwOSo7YdZHzLxyqdmcnBwbsyq2 FkvDsut5tMNbKrEhOBT2NaR76xBaBA/x5e1NXDjancrH75TXW6TPw9vZE/5xt/NA == From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 02/33] crypto/x509-utils: Refactor with GNUTLS fallback Date: Fri, 3 Jul 2026 12:59:59 -0400 Message-ID: <20260703170032.1893204-3-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: DP40EYMLtQRe6735M_AGeG3tzbB_-UNj X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX+x0/7glYlkr+ H5oGxsoWyVPLNMKarooqSjjxbPG6s53N3/vUDBwT4xpPujrRr3RzjgzkHC6q8dlvFdy7rWkrtU5 TIspBncs5Bh1/zwBi/HbBJWBo+cxZIA= X-Authority-Analysis: v=2.4 cv=edsNubEH c=1 sm=1 tr=0 ts=6a47eabd cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=FUyA0-9y5A7gcD0mOlIA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX6k0pOgh29y0j KtGWoAUuVti2qMrqILkEVKHBIidUsciRtYGCN5kA+X5xfcRJTb1uqq5bQhMDBaY2gGrkLld9Xw6 EZTSCoslzLygWRVY+dOhcXR9qD9KS3Fz/AdBvOthVMCh1IbNH13hTk7aicSTAAym9TPpu7haOfS yUTcgUrkGBlZ1amIRfqDsUOKTyNIYcG3ximxL7nERbrSeecQxTo6a3CC0clQC4BJYUYKzHjRHgZ WC6a4lWMQIanvxBR9sdU+0Q5eOp6Zsy9AX5XNbbJt4l05CC3owxi9XNm4xLSYJYVQRM8dgtuFEU bp1bKufZcdQ/HJprgLOp2n5Qtt/1cGkl4Be+G2GdTn1yxGoDhj2h0V1nwY0mfE3v7HfeAQ+khvj 7m9k8G7kGuk6mvqcqNDY/xnSLISZfv9kxTZK/rzhuqlkPl5ubumxNEFOYxxipZWlAhwAqcHaLuS NSYrwxevpYQXqOzI/2Q== X-Proofpoint-ORIG-GUID: DP40EYMLtQRe6735M_AGeG3tzbB_-UNj X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 adultscore=0 impostorscore=0 bulkscore=0 spamscore=0 suspectscore=0 clxscore=1015 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098237053158500 Always compile x509-utils.c and add a fallback when GNUTLS is unavailable. These functions will be needed in the s390x code regardless of whether GNUTLS is available. Signed-off-by: Zhuoying Cai Acked-by: Daniel P. Berrang=C3=A9 Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Farhan Ali Reviewed-by: Thomas Huth --- crypto/meson.build | 2 +- crypto/x509-utils.c | 16 ++++++++++++++++ 2 files changed, 17 insertions(+), 1 deletion(-) diff --git a/crypto/meson.build b/crypto/meson.build index b51597a879..fda85543de 100644 --- a/crypto/meson.build +++ b/crypto/meson.build @@ -22,12 +22,12 @@ crypto_ss.add(files( 'tlscredsx509.c', 'tlssession.c', 'rsakey.c', + 'x509-utils.c', )) =20 if gnutls.found() crypto_ss.add(files( 'tlscredsbox.c', - 'x509-utils.c', )) endif =20 diff --git a/crypto/x509-utils.c b/crypto/x509-utils.c index 39bb6d4d8c..6176a88653 100644 --- a/crypto/x509-utils.c +++ b/crypto/x509-utils.c @@ -11,6 +11,8 @@ #include "qemu/osdep.h" #include "qapi/error.h" #include "crypto/x509-utils.h" + +#ifdef CONFIG_GNUTLS #include #include #include @@ -78,3 +80,17 @@ int qcrypto_get_x509_cert_fingerprint(uint8_t *cert, siz= e_t size, gnutls_x509_crt_deinit(crt); return ret; } + +#else /* ! CONFIG_GNUTLS */ + +int qcrypto_get_x509_cert_fingerprint(uint8_t *cert, size_t size, + QCryptoHashAlgo hash, + uint8_t *result, + size_t *resultlen, + Error **errp) +{ + error_setg(errp, "GNUTLS is required to get fingerprint"); + return -1; +} + +#endif /* ! CONFIG_GNUTLS */ --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098091; cv=none; d=zohomail.com; s=zohoarc; b=VhhhJuELWZboY7z6nllkXcoaet2+pIxRv26r7Xcxwvk+NEMhli6YV5YvnDaUXfbCf0dVxA8HPod4vkwrPkyTyA1H46oD+M+ZzobpivoAgyUzv3hm4FZ5+w7bpNA2428fcA79fNv540V1A+JHpoLn1igxZS7DCYzOBDh77jwGwiM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098091; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/3eqHNbv4aXfd+u4AnT0IFpGYmbYJdEcHut8ZRCL9ww=; b=C5JLA1vnjFmuRjp38xUaifopEN5eI4CgCqgzO2b9P3jgFGuPgcitNt5vscXs+GHHIGnH1p7hMvvi2yCemMaOxRETv9GovUm7bYn+bt8KKj7Km/gOgLdUOEYru8aKg9MaXsOEe/3fYdy5UUGfhJ6/Lx6Drd4luWuAa2vpkTodf/8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17830980912941015.3842817347911; Fri, 3 Jul 2026 10:01:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhG4-0007bj-37; Fri, 03 Jul 2026 13:00:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhG2-0007bH-S6; Fri, 03 Jul 2026 13:00:54 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhG0-0002z5-Vg; Fri, 03 Jul 2026 13:00:54 -0400 Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIVSF3382673; Fri, 3 Jul 2026 17:00:49 GMT Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26pegaat-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:49 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gnjiu003106; Fri, 3 Jul 2026 17:00:48 GMT Received: from smtprelay02.wdc07v.mail.ibm.com ([172.16.1.69]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2tbhsnbe-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:48 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay02.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H0kfZ30212768 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:00:46 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id C8D0A58054; Fri, 3 Jul 2026 17:00:46 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id D1DED58064; Fri, 3 Jul 2026 17:00:43 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:00:43 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=/3eqHN bv4aXfd+u4AnT0IFpGYmbYJdEcHut8ZRCL9ww=; b=CJMstgMXo3JSezsOJso6us +8/BHt804qxhJf1oGpyJ2y8rdSdlZw1QzOxYUgWVSGju8lKZROcoLxDT2T/VXqhQ EsQwExDHuqCnyO67H0xW5svdOfbD3hiOPMgplzYKiI7KbaSFZmS3DnKLRYRhiV5a y2nDe907MXMLeh6uaKJUXgKNQgyYi0lK58W0FC37oUVqqtWv1zm4Ja4EUj+S5fYN rQpdMU5sf8t8eguhdN+kPZsM/AVS2HJWlBP1QtunYl6fQOciSvcBiy8HT9a3xhj9 XKSH+vsVX+Wp72aX3SAtSUlMYzGqE7xMmniZMMSLH6yo1eOAmgg7znVvrU49Vrww == From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 03/33] crypto/x509-utils: Add helper functions for certificate store Date: Fri, 3 Jul 2026 13:00:00 -0400 Message-ID: <20260703170032.1893204-4-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: Yv2C452eEEAQ0GOhjb3GqRdeh2F6jPlb X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX1FtArYkvvtsC G8bj/s8XrmahY53kIg/5YZfjXTFRwM3EUUCeb+eomb1VL3AJmZhXreg2Qygs7f9x4zPkDyDw1tO CsMHyZLf5VAPLvka2IDDA+exWFna+CM= X-Authority-Analysis: v=2.4 cv=edsNubEH c=1 sm=1 tr=0 ts=6a47eac1 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=GX81FK21qHpjiM7aGUoA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXwEZDXAg4csPu UuhrnIKxNPOIKFSjL9UZLKU6ccW9iboCTUxX1PuT7CvFwGrykQKG6w4AZkIAsHOYGd6GWpz8KMN dDaaMufTZ+ibMgpl7QNCpcEErbJCm2UW8VMjTlJOB4nOfay5vE0pLt6CQx0GlCT/Y7GdOBl4Ab8 NOLnjUAyyb0TY7LJXmmALccf6D7YOsEIO1Bgi9tK0w72wCmGkfAYQnOBAOp520S823mmoLRxQ9U wkUEa4Yx+UuB+SgSWInI2297P/v3YcHPiz5IG/hHRJ4gvAQPO2yy4CPzeCUh7qDdhkolx/RrIZr qoZ7FdO+QrCl+EvLJFmsdHnwW9p4nAaURUL8mDRQuswLiJ5duZLmDBmCv5NcfGCjXnrXuggpzEk SffaOOezukwBCGuauBMHetnM8zrFg5lYVEvEIyWXC7G2fSMY1eIY5q2bzbR4fS8MgNE1vJzLi3+ nWMsTSKwwALOsGi2bmQ== X-Proofpoint-ORIG-GUID: Yv2C452eEEAQ0GOhjb3GqRdeh2F6jPlb X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 adultscore=0 impostorscore=0 bulkscore=0 spamscore=0 suspectscore=0 clxscore=1015 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098093896158500 Introduce new helper functions for x509 certificate, which will be used by the certificate store: qcrypto_x509_convert_cert_der() - converts a certificate from PEM to DER fo= rmat These functions provide support for certificate format conversion. Signed-off-by: Zhuoying Cai Acked-by: Daniel P. Berrang=C3=A9 Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Farhan Ali Reviewed-by: Thomas Huth --- crypto/x509-utils.c | 49 +++++++++++++++++++++++++++++++++++++ include/crypto/x509-utils.h | 21 ++++++++++++++++ 2 files changed, 70 insertions(+) diff --git a/crypto/x509-utils.c b/crypto/x509-utils.c index 6176a88653..68cf008938 100644 --- a/crypto/x509-utils.c +++ b/crypto/x509-utils.c @@ -81,6 +81,46 @@ int qcrypto_get_x509_cert_fingerprint(uint8_t *cert, siz= e_t size, return ret; } =20 +int qcrypto_x509_convert_cert_der(uint8_t *cert, size_t size, + uint8_t **result, size_t *resultlen, + Error **errp) +{ + int ret =3D -1; + int rc; + gnutls_x509_crt_t crt; + gnutls_datum_t datum =3D {.data =3D cert, .size =3D size}; + gnutls_datum_t datum_der =3D {.data =3D NULL, .size =3D 0}; + + rc =3D gnutls_x509_crt_init(&crt); + if (rc < 0) { + error_setg(errp, "Failed to initialize certificate: %s", gnutls_st= rerror(rc)); + return ret; + } + + rc =3D gnutls_x509_crt_import(crt, &datum, GNUTLS_X509_FMT_PEM); + if (rc !=3D 0) { + error_setg(errp, "Failed to import certificate: %s", gnutls_strerr= or(rc)); + goto cleanup; + } + + rc =3D gnutls_x509_crt_export2(crt, GNUTLS_X509_FMT_DER, &datum_der); + if (rc !=3D 0) { + error_setg(errp, "Failed to convert certificate to DER format: %s", + gnutls_strerror(rc)); + goto cleanup; + } + + *resultlen =3D datum_der.size; + *result =3D g_memdup2(datum_der.data, datum_der.size); + + ret =3D 0; + +cleanup: + gnutls_x509_crt_deinit(crt); + g_free(datum_der.data); + return ret; +} + #else /* ! CONFIG_GNUTLS */ =20 int qcrypto_get_x509_cert_fingerprint(uint8_t *cert, size_t size, @@ -93,4 +133,13 @@ int qcrypto_get_x509_cert_fingerprint(uint8_t *cert, si= ze_t size, return -1; } =20 +int qcrypto_x509_convert_cert_der(uint8_t *cert, size_t size, + uint8_t **result, + size_t *resultlen, + Error **errp) +{ + error_setg(errp, "GNUTLS is required to export X.509 certificate"); + return -1; +} + #endif /* ! CONFIG_GNUTLS */ diff --git a/include/crypto/x509-utils.h b/include/crypto/x509-utils.h index 1e99661a71..91ae79fb03 100644 --- a/include/crypto/x509-utils.h +++ b/include/crypto/x509-utils.h @@ -19,4 +19,25 @@ int qcrypto_get_x509_cert_fingerprint(uint8_t *cert, siz= e_t size, size_t *resultlen, Error **errp); =20 +/** + * qcrypto_x509_convert_cert_der + * @cert: pointer to the raw certificate data in PEM format + * @size: size of the certificate + * @result: output location for the allocated buffer for the certificate + * in DER format + * (the function allocates memory which must be freed by the call= er) + * @resultlen: pointer to the size of the buffer (will be updated with the + * actual size of the DER-encoded certificate) + * @errp: error pointer + * + * Convert the given @cert from PEM to DER format. + * + * Returns: 0 on success, + * -1 on error. + */ +int qcrypto_x509_convert_cert_der(uint8_t *cert, size_t size, + uint8_t **result, + size_t *resultlen, + Error **errp); + #endif --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098091; cv=none; d=zohomail.com; s=zohoarc; b=QP/q+5jMgbNI8F7XpXZ3i2psMqpYeotjasXnTWhfJ91YGG+i3o+R5T5bhH2miiTFy38YWOSHKN4f8uDWwQdKJXNTK5bj0nzUjl5f0GDaPsaOwWfvBQJ1UxoFBpkT2lCoWTcbx0GJkU+ooF8haFKa0kcktjkBPfYXzFxhFhVe1eU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098091; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Fmu1qimShXKzAQkP06WB4AJ1WsO9gbtjFMVWt9TVSUk=; b=RdICRTJQ2N3/m43Vh3WxSW7CrvYWCy1ee+oOG7WtO8/f64xFIYpTIfzlVgzCwbHhxVJHOxUVh4WZGpqos+OTDmwcPwZ8pZ+QVXorQdIPCBZ9kazY6izYzijgGTs2VkzhMes7aygRxqE+YlDW1YE1sMEpQqHEVUuwwKJ7DyJhiXc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098091166871.4844933114204; Fri, 3 Jul 2026 10:01:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhGB-0007ce-9G; Fri, 03 Jul 2026 13:01:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhG7-0007cH-6X; Fri, 03 Jul 2026 13:00:59 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhG4-00030H-Pa; Fri, 03 Jul 2026 13:00:58 -0400 Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIq5H3236660; Fri, 3 Jul 2026 17:00:52 GMT Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26rffmdf-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:52 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnaMo019640; Fri, 3 Jul 2026 17:00:51 GMT Received: from smtprelay06.wdc07v.mail.ibm.com ([172.16.1.73]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2ruqsy09-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:51 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay06.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H0oQj066076 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:00:50 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id F12905805D; Fri, 3 Jul 2026 17:00:49 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 226995805A; Fri, 3 Jul 2026 17:00:47 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:00:46 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=Fmu1qimShXKzAQkP0 6WB4AJ1WsO9gbtjFMVWt9TVSUk=; b=iPIJYlo3sAKBfyrxLPx6H+POH3SNtEW78 lnMWMfPvR+PeM/fdY0FyFspy8Ur1to08nHGXC7P3IerKrGusd1quv55o/8lLqJrF +BHZw3hClvtrU9rRWUz+o+pHvN6l/6hP0XzbrEeMjCshiAWqyIvgOuT3Ft3eL7QW 37f5o3jmN1KlPk5qF8qSYk+469fUevTNZL7Ie7s/ghHSRVxQOV/l6z++/vKOsR8D AN2WgVqWqs5WT7+llkBYJQcFTRNzTHTpkFcqVh4KohSkDa7sS8suCxJIXURJX49T 3sGEFGA+PMr3X5n/epDywHpcbZ6yOAm3ua9z//P35rMSrkFWyC+Og== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 04/33] hw/s390x/ipl: Create certificate store Date: Fri, 3 Jul 2026 13:00:01 -0400 Message-ID: <20260703170032.1893204-5-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=a4kAM0SF c=1 sm=1 tr=0 ts=6a47eac4 cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VnNF1IyMAAAA:8 a=U0tahsH2YktMir8Gk2YA:9 X-Proofpoint-ORIG-GUID: aUojIjjdWOm7s8Qy4PN5BhJQnysaji53 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX6zwofUSbm7dV P+eaKNhNW2WzxS1PoGThzYH9Vlr930DDdug3O3xRkvfbUb7C0L6t1oAI+GuWIF48RCBGIuTrPwV sAc9K/95oCcP9jElSxCg+1quQBOx4y2tm7jJXd+PKYRZDEiswEG/D5vjzZFEk7++d3Yzqt+38GC wAu+Z7RbGyJWZC8p/IwUZMd28cfJYQmMAxu4vfurVzPS9EtFOmSA6SglQ4biqg/M9ln2o3xef3i SrP0IYDut6l2STytVtm8JXBdgxxJazgy7kKODXt6K/tgatRV2vq1dxEBWEUsGe6LFPIc+qmqKyB AW0CfXzI29ojQG4uNKsMYRayK2MFvRoZ3jYmqNSbjUd7Cy447ZAirz0lEVeoROhnLvsN52MHXZH HljoWVptuSA8pA56+n2Ip5of8dPcX24tMycDzlP8yH8nJ8rBpEj9dUjuIEvVxqIyFX3zmC+J1uD 5NvCUGC3yIyGJ8T5RQQ== X-Proofpoint-GUID: aUojIjjdWOm7s8Qy4PN5BhJQnysaji53 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX55SluAqVEU+A xvbYZax1DCnhEFfIjC6yctwgaaKnLyX2KMdK5kCI/AAFtOpaysKWRTWOIqv7avelSbOIoJQRMxR UtkRzkwT+wnLjeNRHYZQGBxQUzNQavs= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 bulkscore=0 suspectscore=0 lowpriorityscore=0 impostorscore=0 spamscore=0 priorityscore=1501 adultscore=0 malwarescore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098093955158500 Content-Type: text/plain; charset="utf-8" Create a certificate store for boot certificates used for secure IPL. Load certificates from the `boot-certs` parameter of s390-ccw-virtio machine type option into the cert store. Currently, only X.509 certificates in PEM format are supported, as the QEMU command line accepts certificates in PEM format only. The raw Base64 data is stored, as well as the certificate's size. The binary (DER) size is stored as well, which may later be utilized for secure boot (signature verification). Signed-off-by: Zhuoying Cai Reviewed-by: Farhan Ali Reviewed-by: Matthew Rosato --- docs/specs/index.rst | 1 + docs/specs/s390x-secure-ipl.rst | 20 +++ hw/s390x/cert-store.c | 238 ++++++++++++++++++++++++++++++++ hw/s390x/cert-store.h | 39 ++++++ hw/s390x/ipl.c | 10 ++ hw/s390x/ipl.h | 3 + hw/s390x/meson.build | 1 + include/hw/s390x/ipl/qipl.h | 2 + 8 files changed, 314 insertions(+) create mode 100644 docs/specs/s390x-secure-ipl.rst create mode 100644 hw/s390x/cert-store.c create mode 100644 hw/s390x/cert-store.h diff --git a/docs/specs/index.rst b/docs/specs/index.rst index b7909a108a..76d439782c 100644 --- a/docs/specs/index.rst +++ b/docs/specs/index.rst @@ -40,3 +40,4 @@ guest hardware that is specific to QEMU. riscv-aia aspeed-intc iommu-testdev + s390x-secure-ipl diff --git a/docs/specs/s390x-secure-ipl.rst b/docs/specs/s390x-secure-ipl.= rst new file mode 100644 index 0000000000..d7c0d4eaac --- /dev/null +++ b/docs/specs/s390x-secure-ipl.rst @@ -0,0 +1,20 @@ +.. SPDX-License-Identifier: GPL-2.0-or-later + +s390 Certificate Store and Functions +------------------------------------ + +s390 Certificate Store +^^^^^^^^^^^^^^^^^^^^^^ + +A certificate store is implemented for s390-ccw guests to retain within +memory all certificates provided by the user via the command-line, which +are expected to be stored somewhere on the host's file system. The store +will keep track of the number of certificates, their respective size, +and a summation of the sizes. + +Each certificate is stroed in an S390IPLCertificate struct, which has a +name (converted to EBCDIC), size fields of PEM and DER data, and the raw +PEM Base64 data. + +Note: A maximum of 64 certificates are allowed to be stored in the certifi= cate +store. diff --git a/hw/s390x/cert-store.c b/hw/s390x/cert-store.c new file mode 100644 index 0000000000..aa2c1259eb --- /dev/null +++ b/hw/s390x/cert-store.c @@ -0,0 +1,238 @@ +/* + * S390 certificate store implementation + * + * Copyright 2025 IBM Corp. + * Author(s): Zhuoying Cai + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#include "qemu/osdep.h" +#include "cert-store.h" +#include "qapi/error.h" +#include "qemu/error-report.h" +#include "qemu/option.h" +#include "qemu/config-file.h" +#include "hw/s390x/ebcdic.h" +#include "hw/s390x/s390-virtio-ccw.h" +#include "qemu/cutils.h" +#include "crypto/x509-utils.h" +#include "qapi/qapi-types-machine-s390x.h" + +static BootCertificatesList *s390_get_boot_certs(void) +{ + return S390_CCW_MACHINE(qdev_get_machine())->boot_certs; +} + +static S390IPLCertificate *init_cert(char *path, Error **errp) +{ + int rc; + size_t size; + size_t der_len; + char name[CERT_NAME_MAX_LEN]; + g_autofree char *buf =3D NULL; + g_autofree gchar *filename =3D NULL; + S390IPLCertificate *cert =3D NULL; + g_autofree uint8_t *cert_der =3D NULL; + Error *local_err =3D NULL; + + filename =3D g_path_get_basename(path); + + if (!g_file_get_contents(path, &buf, &size, NULL)) { + error_setg(errp, "Failed to load certificate: %s", path); + return NULL; + } + + rc =3D qcrypto_x509_convert_cert_der((uint8_t *)buf, size, + &cert_der, &der_len, &local_err); + if (rc !=3D 0) { + error_propagate_prepend(errp, local_err, + "Failed to initialize certificate: %s: ", = path); + return NULL; + } + + cert =3D g_new0(S390IPLCertificate, 1); + cert->size =3D size; + /* + * Store DER length only - reused for size calculation. + * cert_der is discarded because DER certificate data will be used once + * and can be regenerated from cert->raw. + */ + cert->der_size =3D der_len; + /* store raw pointer - ownership transfers to cert */ + cert->raw =3D (uint8_t *)g_steal_pointer(&buf); + + /* + * Left justified certificate name with padding on the right with blan= ks. + * Convert certificate name to EBCDIC. + */ + strpadcpy(name, CERT_NAME_MAX_LEN, filename, ' '); + ebcdic_put(cert->name, name, CERT_NAME_MAX_LEN); + + return cert; +} + +static int update_cert_store(S390IPLCertificateStore *cert_store, + S390IPLCertificate *cert) +{ + size_t data_buf_size; + size_t keyid_buf_size; + size_t hash_buf_size; + size_t cert_buf_size; + + /* length field is word aligned for later DIAG use */ + keyid_buf_size =3D ROUND_UP(CERT_KEY_ID_LEN, 4); + hash_buf_size =3D ROUND_UP(CERT_HASH_LEN, 4); + cert_buf_size =3D ROUND_UP(cert->der_size, 4); + data_buf_size =3D keyid_buf_size + hash_buf_size + cert_buf_size; + + if (cert_store->largest_cert_size < data_buf_size) { + cert_store->largest_cert_size =3D data_buf_size; + } + + if (cert_store->count >=3D MAX_CERTIFICATES) { + error_report("Cert store is full"); + return -1; + } + + cert_store->certs[cert_store->count] =3D *cert; + cert_store->total_bytes +=3D data_buf_size; + cert_store->count++; + + return 0; +} + +static GPtrArray *get_cert_paths(Error **errp) +{ + struct stat st; + BootCertificatesList *path_list =3D NULL; + BootCertificatesList *list =3D NULL; + gchar *cert_path; + GDir *dir =3D NULL; + const gchar *filename; + bool is_empty; + g_autoptr(GError) err =3D NULL; + g_autoptr(GPtrArray) cert_path_builder =3D g_ptr_array_new_full(0, g_f= ree); + + path_list =3D s390_get_boot_certs(); + + for (list =3D path_list; list; list =3D list->next) { + cert_path =3D list->value->path; + + if (g_strcmp0(cert_path, "") =3D=3D 0) { + error_setg(errp, "Empty path in certificate path list is not a= llowed"); + goto fail; + } + + if (stat(cert_path, &st) !=3D 0) { + error_setg(errp, "Failed to stat path '%s': %s", + cert_path, g_strerror(errno)); + goto fail; + } + + if (S_ISREG(st.st_mode)) { + if (!g_str_has_suffix(cert_path, ".pem")) { + error_setg(errp, "Certificate file '%s' must have a .pem e= xtension", + cert_path); + goto fail; + } + + g_ptr_array_add(cert_path_builder, g_strdup(cert_path)); + } else if (S_ISDIR(st.st_mode)) { + dir =3D g_dir_open(cert_path, 0, &err); + if (dir =3D=3D NULL) { + error_setg(errp, "Failed to open directory '%s': %s", + cert_path, err->message); + + goto fail; + } + + is_empty =3D true; + while ((filename =3D g_dir_read_name(dir))) { + is_empty =3D false; + + if (g_str_has_suffix(filename, ".pem")) { + g_ptr_array_add(cert_path_builder, + g_build_filename(cert_path, filename, = NULL)); + } else { + warn_report("skipping '%s': not a .pem file", filename= ); + } + } + + if (is_empty) { + warn_report("'%s' directory is empty", cert_path); + } + + g_dir_close(dir); + } else { + error_setg(errp, "Path '%s' is neither a file nor a directory"= , cert_path); + goto fail; + } + } + + qapi_free_BootCertificatesList(path_list); + return g_steal_pointer(&cert_path_builder); + +fail: + qapi_free_BootCertificatesList(path_list); + return NULL; +} + +static void s390_ipl_destroy_cert_store(S390IPLCertificateStore *cert_stor= e) +{ + for (int i =3D 0; i < cert_store->count; i++) { + g_free(cert_store->certs[i].raw); + } + memset(cert_store, 0, sizeof(*cert_store)); +} + +void s390_ipl_create_cert_store(S390IPLCertificateStore *cert_store) +{ + GPtrArray *cert_path_builder; + Error *err =3D NULL; + + /* If cert store is already populated, then no work to do */ + if (cert_store->count) { + return; + } + + cert_path_builder =3D get_cert_paths(&err); + if (cert_path_builder =3D=3D NULL) { + error_report_err(err); + exit(1); + } + + if (cert_path_builder->len =3D=3D 0) { + g_ptr_array_free(cert_path_builder, TRUE); + return; + } + + if (cert_path_builder->len > MAX_CERTIFICATES) { + error_report("Cert store exceeds maximum of %d certificates", MAX_= CERTIFICATES); + g_ptr_array_free(cert_path_builder, TRUE); + exit(1); + } + + cert_store->largest_cert_size =3D 0; + cert_store->total_bytes =3D 0; + + for (int i =3D 0; i < cert_path_builder->len; i++) { + g_autofree S390IPLCertificate *cert =3D + init_cert((char *) cert_path_builder->pdata[i], + &err); + if (!cert) { + error_report_err(err); + g_ptr_array_free(cert_path_builder, TRUE); + s390_ipl_destroy_cert_store(cert_store); + exit(1); + } + + if (update_cert_store(cert_store, cert)) { + g_ptr_array_free(cert_path_builder, TRUE); + s390_ipl_destroy_cert_store(cert_store); + exit(1); + } + } + + g_ptr_array_free(cert_path_builder, TRUE); +} diff --git a/hw/s390x/cert-store.h b/hw/s390x/cert-store.h new file mode 100644 index 0000000000..7fc9503cb9 --- /dev/null +++ b/hw/s390x/cert-store.h @@ -0,0 +1,39 @@ +/* + * S390 certificate store + * + * Copyright 2025 IBM Corp. + * Author(s): Zhuoying Cai + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#ifndef HW_S390_CERT_STORE_H +#define HW_S390_CERT_STORE_H + +#include "hw/s390x/ipl/qipl.h" +#include "crypto/x509-utils.h" + +#define CERT_NAME_MAX_LEN 64 + +#define CERT_KEY_ID_LEN QCRYPTO_HASH_DIGEST_LEN_SHA256 +#define CERT_HASH_LEN QCRYPTO_HASH_DIGEST_LEN_SHA256 + +struct S390IPLCertificate { + uint8_t name[CERT_NAME_MAX_LEN]; + size_t size; + size_t der_size; + uint8_t *raw; +}; +typedef struct S390IPLCertificate S390IPLCertificate; + +struct S390IPLCertificateStore { + uint16_t count; + size_t largest_cert_size; + size_t total_bytes; + S390IPLCertificate certs[MAX_CERTIFICATES]; +}; +typedef struct S390IPLCertificateStore S390IPLCertificateStore; + +void s390_ipl_create_cert_store(S390IPLCertificateStore *cert_store); + +#endif diff --git a/hw/s390x/ipl.c b/hw/s390x/ipl.c index 4cca21c621..09c24203c7 100644 --- a/hw/s390x/ipl.c +++ b/hw/s390x/ipl.c @@ -38,6 +38,7 @@ #include "qemu/option.h" #include "qemu/ctype.h" #include "standard-headers/linux/virtio_ids.h" +#include "cert-store.h" =20 #define KERN_IMAGE_START 0x010000UL #define LINUX_MAGIC_ADDR 0x010008UL @@ -453,6 +454,13 @@ void s390_ipl_convert_loadparm(char *ascii_lp, uint8_t= *ebcdic_lp) } } =20 +S390IPLCertificateStore *s390_ipl_get_certificate_store(void) +{ + S390IPLState *ipl =3D get_ipl_device(); + + return &ipl->cert_store; +} + static bool s390_build_iplb(DeviceState *dev_st, IplParameterBlock *iplb) { CcwDevice *ccw_dev =3D NULL; @@ -767,6 +775,8 @@ void s390_ipl_prepare_cpu(S390CPU *cpu) cpu->env.psw.addr =3D ipl->start_addr; cpu->env.psw.mask =3D IPL_PSW_MASK; =20 + s390_ipl_create_cert_store(&ipl->cert_store); + if (!ipl->kernel || ipl->iplb_valid) { cpu->env.psw.addr =3D ipl->bios_start_addr; if (!ipl->iplb_valid) { diff --git a/hw/s390x/ipl.h b/hw/s390x/ipl.h index fac30763df..f5a49a4431 100644 --- a/hw/s390x/ipl.h +++ b/hw/s390x/ipl.h @@ -13,6 +13,7 @@ #ifndef HW_S390_IPL_H #define HW_S390_IPL_H =20 +#include "cert-store.h" #include "target/s390x/cpu.h" #include "exec/target_page.h" #include "system/address-spaces.h" @@ -35,6 +36,7 @@ int s390_ipl_pv_unpack(struct S390PVResponse *pv_resp); void s390_ipl_prepare_cpu(S390CPU *cpu); IplParameterBlock *s390_ipl_get_iplb(void); IplParameterBlock *s390_ipl_get_iplb_pv(void); +S390IPLCertificateStore *s390_ipl_get_certificate_store(void); =20 enum s390_reset { /* default is a reset not triggered by a CPU e.g. issued by QMP */ @@ -63,6 +65,7 @@ struct S390IPLState { IplParameterBlock iplb; IplParameterBlock iplb_pv; QemuIplParameters qipl; + S390IPLCertificateStore cert_store; uint64_t start_addr; uint64_t compat_start_addr; uint64_t bios_start_addr; diff --git a/hw/s390x/meson.build b/hw/s390x/meson.build index 57cc2a6be3..6b39ad012f 100644 --- a/hw/s390x/meson.build +++ b/hw/s390x/meson.build @@ -17,6 +17,7 @@ s390x_ss.add(files( 'sclpcpu.c', 'sclpquiesce.c', 'tod.c', + 'cert-store.c', )) s390x_ss.add(when: 'CONFIG_KVM', if_true: files( 'tod-kvm.c', diff --git a/include/hw/s390x/ipl/qipl.h b/include/hw/s390x/ipl/qipl.h index 8d3c83a80b..ed1a91182a 100644 --- a/include/hw/s390x/ipl/qipl.h +++ b/include/hw/s390x/ipl/qipl.h @@ -31,6 +31,8 @@ typedef enum S390IplType S390IplType; =20 #define QEMU_DEFAULT_IPL S390_IPL_TYPE_CCW =20 +#define MAX_CERTIFICATES 64 + /* * The QEMU IPL Parameters will be stored at absolute address * 204 (0xcc) which means it is 32-bit word aligned but not --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098115; cv=none; d=zohomail.com; s=zohoarc; b=cQIZzOB+5r8H8iqV5E4DPs0oORD9p5V0P6A2nzmVpSarG2plNGaztvHAkOnFkrVt1I4U9WgGV/XWfvdCFIZAGpMk+7+wVqdODByP3kv0LpkYdoECbMqC7I4VlqmsKSeAVTadA1U/rgFRKtUPGE6rwho64VMjfe3b11aLrsjZZns= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098115; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=MDQ+yUUIZECwheS015R6J/LbJHk8pwKujTNxZzwylTI=; b=BIeCb4MGL7TbC/fXll2MioGzYoWQ9z8uzf9lnYSX0qshEZuoqWOSG1FGTW8FEcRUY1G7wcQ0j5j4EkU7piWC0grZJ20Hz5uVoKyqwF3upMx2BTrRL2AZqzBSagTBWZzdugAHvKrVDd3/2RGbKxuRfiWlvgXISV0q8kZjVZ/CWOg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098115091902.6286643965525; Fri, 3 Jul 2026 10:01:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhGE-0007e8-G9; Fri, 03 Jul 2026 13:01:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGB-0007co-4T; Fri, 03 Jul 2026 13:01:03 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhG8-00030c-FB; Fri, 03 Jul 2026 13:01:02 -0400 Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIXop3382717; Fri, 3 Jul 2026 17:00:56 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26pegab7-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:55 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GncBa025844; Fri, 3 Jul 2026 17:00:54 GMT Received: from smtprelay03.dal12v.mail.ibm.com ([172.16.1.5]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2sukhqpf-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:54 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay03.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H0r9m29360794 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:00:53 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 22D5258054; Fri, 3 Jul 2026 17:00:53 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3F9025805A; Fri, 3 Jul 2026 17:00:50 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:00:50 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=MDQ+yUUIZECwheS01 5R6J/LbJHk8pwKujTNxZzwylTI=; b=d/6S7LrpYiZTWRSMXM1yOn9W/mO+z/ya4 9xRNaBb+FK9eJXJXIQzNkLu5iaLCURvbvRHSTOr2O5piDMjuVr9CTqlnIyXPX5dM EP0w82UbAvg44QQatZ+JTMdBlpq7Iv/tjjWkiIHEATuQAljt0IqfI+tCJVqE81YR 6OmnBBYDX2/F3lGmPDRXXrEcv5xPrkdTI60X6mHh44WhNTl3le1RSmO9TGPR0up2 pECVALXAXEkMOyAdp4m/2l1tIWyi2KYiktqvUYWXWHFP1KVk0citVISlHga3aGkW 760HFinKbKIqu5JETbmMCNkAbR5thP/H95T8vzeq8bCzJC4U6NNJQ== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 05/33] s390x/diag: Introduce DIAG 320 for Certificate Store Facility Date: Fri, 3 Jul 2026 13:00:02 -0400 Message-ID: <20260703170032.1893204-6-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: 5eBHObH133WwBIcD9M8M7STwqgzU5zuk X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXwZFYZRTJL2lR Sx6cSedOk6Crq80SGVnfBBDPukbVnEFwhtqNwLF76lSRXQ9TyyQ6BDwoNLzisX7fGCBGqW86eF6 93fjgU2YZSOYkYUi4gv5yldILLibGvg= X-Authority-Analysis: v=2.4 cv=edsNubEH c=1 sm=1 tr=0 ts=6a47eac7 cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=mM8oulnVqnlOJU-pfAMA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXzbxq29QsJ7ii 5wTf5qfz83f+bI4lS+XfoWFAmTfEwLOcrHd9pfF4dogjJeL/F75B+Rjj0qRlQUs5B85rZvCX9LX wjEIZLbRPRskitHmp5f8lGdvvNxvfeD9nYIfgKaBIrELzSr7/WI0BA9UuT0DGiWJQj53Ug9ZIWg FcXGlqjcCuTAruK8QVNNgEOhHxms+UJOq3EX+c+nNLVJrB/8BQFJUcmMI6Mx+wDIiLIkgCzcztZ naiZsc4FmUWoWzfSx1y3qND/wekXe8/6/0vmI0buzVpkLCA41Qi1YsoiF/wyh47elBxEuiw2zKQ s0UlMDgNmCocfF17E2P9r4L2hzEAAVH/4PvNQehaiMyh0UKnzMzeD3DMUayNclQOfoxAvUhotgl zEMHhYcd0/B0sP2pcrifSbkRTmcwx2+1X5CQ6zQ95xglpThqKSt1g+lWNftDtVQuNC38XZflOTA dkmcWQAZepKJDR0BmwQ== X-Proofpoint-ORIG-GUID: 5eBHObH133WwBIcD9M8M7STwqgzU5zuk X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 adultscore=0 impostorscore=0 bulkscore=0 spamscore=0 suspectscore=0 clxscore=1015 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098116035158500 Content-Type: text/plain; charset="utf-8" DIAGNOSE 320 is introduced to support Certificate Store (CS) Facility, which includes operations such as query certificate storage information and provide certificates in the certificate store. Currently, only subcode 0 is supported with this patch, which is used to query the Installed Subcodes Mask (ISM). This subcode is only supported when the CS facility is enabled. Availability of CS facility is determined by byte 134 bit 5 of the SCLP Read Info block. Byte 134's facilities cannot be represented without the availability of the extended-length-SCCB, so add it as a check for consistency. Note: secure IPL is not available for Secure Execution (SE) guests, as their images are already integrity protected, and an additional protection of the kernel by secure IPL is not necessary. This feature is available starting with the gen16 CPU model. Signed-off-by: Zhuoying Cai Reviewed-by: Collin Walling Reviewed-by: Farhan Ali Reviewed-by: Thomas Huth --- docs/specs/s390x-secure-ipl.rst | 12 +++++++++ include/hw/s390x/ipl/diag320.h | 20 ++++++++++++++ target/s390x/cpu_features.c | 1 + target/s390x/cpu_features_def.h.inc | 1 + target/s390x/cpu_models.c | 2 ++ target/s390x/diag.c | 42 +++++++++++++++++++++++++++++ target/s390x/gen-features.c | 3 +++ target/s390x/kvm/kvm.c | 16 +++++++++++ target/s390x/s390x-internal.h | 2 ++ target/s390x/tcg/misc_helper.c | 7 +++++ 10 files changed, 106 insertions(+) create mode 100644 include/hw/s390x/ipl/diag320.h diff --git a/docs/specs/s390x-secure-ipl.rst b/docs/specs/s390x-secure-ipl.= rst index d7c0d4eaac..331d793008 100644 --- a/docs/specs/s390x-secure-ipl.rst +++ b/docs/specs/s390x-secure-ipl.rst @@ -18,3 +18,15 @@ PEM Base64 data. =20 Note: A maximum of 64 certificates are allowed to be stored in the certifi= cate store. + +DIAGNOSE function code 'X'320' - Certificate Store Facility +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +DIAGNOSE 'X'320' is used to provide support for guest code to directly +query the s390 certificate store. Guest code may be the s390-ccw BIOS or +the guest kernel. + +Subcode 0 - query installed subcodes + Returns a 256-bit installed subcodes mask (ISM) stored in the installed + subcodes block (ISB). This mask indicates which subcodes are currently + installed and available for use. diff --git a/include/hw/s390x/ipl/diag320.h b/include/hw/s390x/ipl/diag320.h new file mode 100644 index 0000000000..aa04b699c6 --- /dev/null +++ b/include/hw/s390x/ipl/diag320.h @@ -0,0 +1,20 @@ +/* + * S/390 DIAGNOSE 320 definitions and structures + * + * Copyright 2025 IBM Corp. + * Author(s): Zhuoying Cai + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#ifndef S390X_DIAG320_H +#define S390X_DIAG320_H + +#define DIAG_320_SUBC_QUERY_ISM 0 + +#define DIAG_320_RC_OK 0x0001 +#define DIAG_320_RC_NOT_SUPPORTED 0x0102 + +#define DIAG_320_ISM_QUERY_SUBCODES 0x80000000 + +#endif diff --git a/target/s390x/cpu_features.c b/target/s390x/cpu_features.c index 4b5be6798e..436471f4b4 100644 --- a/target/s390x/cpu_features.c +++ b/target/s390x/cpu_features.c @@ -147,6 +147,7 @@ void s390_fill_feat_block(const S390FeatBitmap features= , S390FeatType type, break; case S390_FEAT_TYPE_SCLP_FAC134: clear_be_bit(s390_feat_def(S390_FEAT_DIAG_318)->bit, data); + clear_be_bit(s390_feat_def(S390_FEAT_CERT_STORE)->bit, data); break; default: return; diff --git a/target/s390x/cpu_features_def.h.inc b/target/s390x/cpu_feature= s_def.h.inc index c017bffcdc..2976ecd0ee 100644 --- a/target/s390x/cpu_features_def.h.inc +++ b/target/s390x/cpu_features_def.h.inc @@ -138,6 +138,7 @@ DEF_FEAT(SIE_IBS, "ibs", SCLP_CONF_CHAR_EXT, 10, "SIE: = Interlock-and-broadcast-s =20 /* Features exposed via SCLP SCCB Facilities byte 134 (bit numbers relativ= e to byte-134) */ DEF_FEAT(DIAG_318, "diag318", SCLP_FAC134, 0, "Control program name and ve= rsion codes") +DEF_FEAT(CERT_STORE, "cstore", SCLP_FAC134, 5, "Certificate Store function= s") =20 /* Features exposed via SCLP CPU info. */ DEF_FEAT(SIE_F2, "sief2", SCLP_CPU, 4, "SIE: interception format 2 (Virtua= l SIE)") diff --git a/target/s390x/cpu_models.c b/target/s390x/cpu_models.c index 0b88868289..962f135f42 100644 --- a/target/s390x/cpu_models.c +++ b/target/s390x/cpu_models.c @@ -248,6 +248,7 @@ bool s390_has_feat(S390Feat feat) if (s390_is_pv()) { switch (feat) { case S390_FEAT_DIAG_318: + case S390_FEAT_CERT_STORE: case S390_FEAT_HPMA2: case S390_FEAT_SIE_F2: case S390_FEAT_SIE_SKEY: @@ -505,6 +506,7 @@ static void check_consistency(const S390CPUModel *model) { S390_FEAT_PTFF_STOUE, S390_FEAT_MULTIPLE_EPOCH }, { S390_FEAT_AP_QUEUE_INTERRUPT_CONTROL, S390_FEAT_AP }, { S390_FEAT_DIAG_318, S390_FEAT_EXTENDED_LENGTH_SCCB }, + { S390_FEAT_CERT_STORE, S390_FEAT_EXTENDED_LENGTH_SCCB }, { S390_FEAT_NNPA, S390_FEAT_VECTOR }, { S390_FEAT_RDP, S390_FEAT_LOCAL_TLB_CLEARING }, { S390_FEAT_UV_FEAT_AP, S390_FEAT_AP }, diff --git a/target/s390x/diag.c b/target/s390x/diag.c index 80f0958478..9131e8b1c9 100644 --- a/target/s390x/diag.c +++ b/target/s390x/diag.c @@ -18,6 +18,7 @@ #include "hw/watchdog/wdt_diag288.h" #include "system/cpus.h" #include "hw/s390x/ipl.h" +#include "hw/s390x/ipl/diag320.h" #include "hw/s390x/s390-virtio-ccw.h" #include "system/kvm.h" #include "kvm/kvm_s390x.h" @@ -199,3 +200,44 @@ out: return false; } } + +void handle_diag_320(CPUS390XState *env, uint64_t r1, uint64_t r3, uintptr= _t ra) +{ + S390CPU *cpu =3D env_archcpu(env); + uint64_t subcode =3D env->regs[r3]; + uint64_t addr =3D env->regs[r1]; + + if (env->psw.mask & PSW_MASK_PSTATE) { + s390_program_interrupt(env, PGM_PRIVILEGED, ra); + return; + } + + if (!s390_has_feat(S390_FEAT_CERT_STORE) || + (subcode & ~0x000ffULL) || + (r1 & 1)) { + s390_program_interrupt(env, PGM_SPECIFICATION, ra); + return; + } + + + switch (subcode) { + case DIAG_320_SUBC_QUERY_ISM: + /* + * The Installed Subcode Block (ISB) can be up 8 words in size, + * but the current set of subcodes can fit within a single word + * for now. + */ + uint32_t ism_word0 =3D cpu_to_be32(DIAG_320_ISM_QUERY_SUBCODES); + + if (s390_cpu_virt_mem_write(cpu, addr, r1, &ism_word0, sizeof(ism_= word0))) { + s390_cpu_virt_mem_handle_exc(cpu, ra); + return; + } + + env->regs[r1 + 1] =3D DIAG_320_RC_OK; + break; + default: + env->regs[r1 + 1] =3D DIAG_320_RC_NOT_SUPPORTED; + break; + } +} diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index 8218e6470e..6c20c3a862 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -720,6 +720,7 @@ static uint16_t full_GEN16_GA1[] =3D { S390_FEAT_PAIE, S390_FEAT_UV_FEAT_AP, S390_FEAT_UV_FEAT_AP_INTR, + S390_FEAT_CERT_STORE, }; =20 static uint16_t full_GEN17_GA1[] =3D { @@ -919,6 +920,8 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KIMD_SHA_512, S390_FEAT_KLMD_SHA_512, S390_FEAT_PRNO_TRNG, + S390_FEAT_EXTENDED_LENGTH_SCCB, + S390_FEAT_CERT_STORE, }; =20 /****** END FEATURE DEFS ******/ diff --git a/target/s390x/kvm/kvm.c b/target/s390x/kvm/kvm.c index fdef8f9e8a..138b5b9c67 100644 --- a/target/s390x/kvm/kvm.c +++ b/target/s390x/kvm/kvm.c @@ -99,6 +99,7 @@ #define DIAG_TIMEREVENT 0x288 #define DIAG_IPL 0x308 #define DIAG_SET_CONTROL_PROGRAM_CODES 0x318 +#define DIAG_CERT_STORE 0x320 #define DIAG_KVM_HYPERCALL 0x500 #define DIAG_KVM_BREAKPOINT 0x501 =20 @@ -1531,6 +1532,16 @@ static void handle_diag_318(S390CPU *cpu, struct kvm= _run *run) } } =20 +static void kvm_handle_diag_320(S390CPU *cpu, struct kvm_run *run) +{ + uint64_t r1, r3; + + r1 =3D (run->s390_sieic.ipa & 0x00f0) >> 4; + r3 =3D run->s390_sieic.ipa & 0x000f; + + handle_diag_320(&cpu->env, r1, r3, RA_IGNORED); +} + #define DIAG_KVM_CODE_MASK 0x000000000000ffff =20 static int handle_diag(S390CPU *cpu, struct kvm_run *run, uint32_t ipb) @@ -1561,6 +1572,9 @@ static int handle_diag(S390CPU *cpu, struct kvm_run *= run, uint32_t ipb) case DIAG_KVM_BREAKPOINT: r =3D handle_sw_breakpoint(cpu, run); break; + case DIAG_CERT_STORE: + kvm_handle_diag_320(cpu, run); + break; default: trace_kvm_insn_diag(func_code); kvm_s390_program_interrupt(cpu, PGM_SPECIFICATION); @@ -2471,6 +2485,8 @@ bool kvm_s390_get_host_cpu_model(S390CPUModel *model,= Error **errp) set_bit(S390_FEAT_DIAG_318, model->features); } =20 + set_bit(S390_FEAT_CERT_STORE, model->features); + /* Test for Ultravisor features that influence secure guest behavior */ query_uv_feat_guest(model->features); =20 diff --git a/target/s390x/s390x-internal.h b/target/s390x/s390x-internal.h index 35d1e34ef4..1945bdf40c 100644 --- a/target/s390x/s390x-internal.h +++ b/target/s390x/s390x-internal.h @@ -388,6 +388,8 @@ int handle_diag_288(CPUS390XState *env, uint64_t r1, ui= nt64_t r3); /* Return whether a CPU reset is pending */ bool handle_diag_308(CPUS390XState *env, uint64_t r1, uint64_t r3, uintptr_t ra); +void handle_diag_320(CPUS390XState *env, uint64_t r1, uint64_t r3, + uintptr_t ra); =20 =20 /* translate.c */ diff --git a/target/s390x/tcg/misc_helper.c b/target/s390x/tcg/misc_helper.c index 09a45e58a5..403388145e 100644 --- a/target/s390x/tcg/misc_helper.c +++ b/target/s390x/tcg/misc_helper.c @@ -147,6 +147,13 @@ void HELPER(diag)(CPUS390XState *env, uint32_t r1, uin= t32_t r3, uint32_t num) /* time bomb (watchdog) */ r =3D handle_diag_288(env, r1, r3); break; + case 0x320: + /* cert store */ + bql_lock(); + handle_diag_320(env, r1, r3, GETPC()); + bql_unlock(); + r =3D 0; + break; default: r =3D -1; break; --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098142; cv=none; d=zohomail.com; s=zohoarc; b=dunrdxCh5mk+2IDXngOgXsQyHCSZuS3aUPn+iQkq/IbLBfFamo1iiyhKC16mR5cGTrmefiZIfEaKPjGvv8CMXjI2MXhsu+L3jn6FMqY+N3xg/HPCc3GGhn64CN73rsqBYwS4IIUQLz92ng2q9DNUhF/aQmnlyQXdtYCCNzjg2sk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098142; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=k8tvPzrQo6/t7WcdVeAWkNdKQiKyShsjewFS2iwPC9A=; b=jiOR3HAvmmNSse7D8hPn3Pv09K1MAsICTYyhef3Pf3ekTiXgc09KVhwc9UuawZfb4I2OY+Z0ZCDaGtIz7nrZTdKBu70NG3YvxlgF+pDDJqtP4RnlwV/LMrjG0XHGxRx5QLz3Sx5LulJ/HeIAMrfpv3mC08lKJd4R1yCrCm8UXS8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098142079280.16993887642263; Fri, 3 Jul 2026 10:02:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhGE-0007e9-Il; Fri, 03 Jul 2026 13:01:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGB-0007cp-7N; Fri, 03 Jul 2026 13:01:03 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhG9-00030x-Hm; Fri, 03 Jul 2026 13:01:02 -0400 Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIxdI3246493; Fri, 3 Jul 2026 17:00:58 GMT Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26qafstn-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:58 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gnids001524; Fri, 3 Jul 2026 17:00:57 GMT Received: from smtprelay06.dal12v.mail.ibm.com ([172.16.1.8]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2s7whtau-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:00:57 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay06.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H0uZB17564258 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:00:56 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 1B00D5805C; Fri, 3 Jul 2026 17:00:56 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 5CA545805A; Fri, 3 Jul 2026 17:00:53 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:00:53 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=k8tvPzrQo6/t7WcdV eAWkNdKQiKyShsjewFS2iwPC9A=; b=aNu7qPAhGRcg0oovUmdrGHubvRCSgouUM Yl4RjIc99MLdlwNOYYuSCFa+/D6eXsnuWEP8ATCz1n8eyhIdvKrKsnhvqkAERcL5 xYt3ES8EmuO4JMaI9xKJE0a8UBOI4GLzGw78dnA3Jd3oVwtpOWb+shBx8J3Qeh79 RA3mpgtfECx4aJv5RzbQcmC3VZfjTTwdC3mxNRat/BIWdnkDWt8d13yBZA739tDV UFh6RRM8AnrF3YNzjjUI4Am5CXVEq5JLFszHR7fGYsE3i5CNwXjDq96lhcVpXZ4Z 6GVAamk0G9A/B8f01JyeDzGduiBu55vLUFed50dfqhTPwVQPrSYMQ== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 06/33] s390x/diag: Refactor address validation check from diag308_parm_check Date: Fri, 3 Jul 2026 13:00:03 -0400 Message-ID: <20260703170032.1893204-7-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXzY5Lc5qu373r yL1Nf22eYE0Csa2v9i0uYEtleJc3GRJe0jpPjruQPoyEdr//Jnwieq6qR9de3MQWdswfaX83+M3 fXe6rPpnnHDvF/WsIEB19SxYYcZPy4zm467orT83v/F9oxKoE1qSsv00hGSfPsirk6N5zEs+SOp z4Cb2nHVDAAXRxd5AkbidzIUoneza0j9mJgYl+08XuG2oL9voUplS/geR5s2IQJoGB8LiM7mPTb /+/W6Le7RTVjN2gZ3NRMy7AWdfRwgJ3b3Yi+yY1cckZkbzirj5xGzSJaCNYMXA00S8YSewXSQ4Z 82gTL2m4DfvNm9bQATXXMX8zZ+xUqkF5prEjw9ylm7/utFplspQGNsfYG86qgAnriNfYUzHD6SG ydJnVOOrtWJHAp3LPM06tM20B73BNiPE6L/Njnu8GsJNYZStFAOurc+ghVmMRYGaqjVC+pUlgdK 7rymvzg8U4p9G1LbgeA== X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX3rqRFqrFdJTR P9t58yFgGJsrvyypZMjXo94/TRTmeVrRuxwN79om3VWmOTekOSTvb07rFSV+WkXdIiokUFzTOAT e5nW+sHMONT9MzrjeQuTMLZGGDKtYAo= X-Proofpoint-GUID: OlWXuEba3WkWaBAiWE8pfvozqlps93Pj X-Proofpoint-ORIG-GUID: OlWXuEba3WkWaBAiWE8pfvozqlps93Pj X-Authority-Analysis: v=2.4 cv=WZ88rUhX c=1 sm=1 tr=0 ts=6a47eaca cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=130TwiEZxdn8fhqcL5YA:9 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 adultscore=0 phishscore=0 clxscore=1015 bulkscore=0 impostorscore=0 priorityscore=1501 lowpriorityscore=0 suspectscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098144314158500 Content-Type: text/plain; charset="utf-8" Create a function to validate the address parameter of DIAGNOSE. Refactor the function for reuse in the next patch, which allows address validation in read or write operation of DIAGNOSE. Signed-off-by: Zhuoying Cai Reviewed-by: Farhan Ali Reviewed-by: Collin Walling Reviewed-by: Hendrik Brueckner Reviewed-by: Thomas Huth --- target/s390x/diag.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/target/s390x/diag.c b/target/s390x/diag.c index 9131e8b1c9..9f98e4b677 100644 --- a/target/s390x/diag.c +++ b/target/s390x/diag.c @@ -26,6 +26,12 @@ #include "qemu/error-report.h" =20 =20 +static inline bool diag_parm_addr_valid(uint64_t addr, size_t size, bool w= rite) +{ + return address_space_access_valid(&address_space_memory, addr, + size, write, MEMTXATTRS_UNSPECIFIED); +} + int handle_diag_288(CPUS390XState *env, uint64_t r1, uint64_t r3) { uint64_t func =3D env->regs[r1]; @@ -65,9 +71,7 @@ static int diag308_parm_check(CPUS390XState *env, uint64_= t r1, uint64_t addr, s390_program_interrupt(env, PGM_SPECIFICATION, ra); return -1; } - if (!address_space_access_valid(&address_space_memory, addr, - sizeof(IplParameterBlock), write, - MEMTXATTRS_UNSPECIFIED)) { + if (!diag_parm_addr_valid(addr, sizeof(IplParameterBlock), write)) { s390_program_interrupt(env, PGM_ADDRESSING, ra); return -1; } --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098108; cv=none; d=zohomail.com; s=zohoarc; b=HVbzhdDtfp9QHAWyanfY7yTCspEQtjlHwOHHPAmzwQya3a9e0B8+jNoL+iTBNcKZmld9Ihr2ETnEfj96KYXfP+0G1GvDkLUI+j0mCyzFSncGQHyYjWIquzT4w/HFsRxrQwJ8DPGCC6ffV4gKyL40QzOTV7EAu09v8xV6aXH60P4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098108; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=c4iH93wBW1NvzUVt5L7Do94rqjQ67AL441bLHt0Hh7E=; b=XmwVxNTANVTywOVGXi54XaRywAXHz80uqrwUHQN/1U8brYh/jcJmjvXkWKC36awTtTb9JspAXF9NWd88AuWWAyEtn9y3Jok6pENxhVfRGjaKGusIl4YNsUv6HQsh2YTGhm7kMqUOQ5cl8VAjQXRr6M6xipjyqfpPHUKa4W/C0Mw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098108478293.2604351730488; Fri, 3 Jul 2026 10:01:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhGK-0007g6-VP; Fri, 03 Jul 2026 13:01:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGE-0007eZ-SE; Fri, 03 Jul 2026 13:01:08 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGC-00032X-EE; Fri, 03 Jul 2026 13:01:06 -0400 Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GJCij3218123; Fri, 3 Jul 2026 17:01:01 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26mk7rps-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:01 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gncgt025854; Fri, 3 Jul 2026 17:01:00 GMT Received: from smtprelay02.wdc07v.mail.ibm.com ([172.16.1.69]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2sukhqpu-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:00 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay02.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H0x0Q4194874 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:00:59 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 560E45805A; Fri, 3 Jul 2026 17:00:59 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 531EB58054; Fri, 3 Jul 2026 17:00:56 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:00:56 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=c4iH93wBW1NvzUVt5 L7Do94rqjQ67AL441bLHt0Hh7E=; b=AZh29pc8ASyBcBP+F9pz/LGsS8nyLgjmB 48edY7IH/+JFao7R7l/LW5tEiiO5szBg1WgLE3S7RHOlGqCT//Q/SU0OZvKW1YM2 ykaIO3DJOyeNhaU9IfeTjPdtzyWY87bksC8jR50ennOwfH2zzPMX/hUhWvPgVRym jgOjEhRMOQq43OHLCWyV3/BiR61XUHgCtHvzLxXI9kJyRM3zNCI1UFQvoynpQwy9 bBhGUwTxZDFM/4IWi/bulkZNIq2uDmiFR+qNB3qTaHVfYtPl0lvpEdxSMZgMxbJB ggr9BBSOYgNBpSG8VRRQIHIFi+Ed8medpTA7bermqbb/h22btxtlg== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 07/33] s390x/diag: Implement DIAG 320 subcode 1 Date: Fri, 3 Jul 2026 13:00:04 -0400 Message-ID: <20260703170032.1893204-8-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXxzz3kIVMbnSQ Hh8CR0oTkGbxIepkdtOODKFO1a70R+xU8yCFLhiFrMqNATdDk8jjcuAVaFRq09pcLMbMaKMnfSC bbU0Ll8lIm21hR0ZWSuy4qUUqCxfP8ICmn4Hdc7I8RNnzRfLRjUODwrtTc6z9pqkg+wPEP3E1cC ECexLmAgM0KA4dgS2BJ2s+o7Ib2cAfwBmocMdr+VyhTMJM1jNSMyMbErvbyDJOB/+pjVxvdg5yE x+z/fR3vylejo7d5nXpC/JWIEFTYDlUflXtNZoleXlOild+zVBkC21VSXOqbfWPWseudaxfUsvr F0YDUhR0g3xTwB9CG6ds+P/IFg9bkFfQnyA6riwpdcQsBZfjPF1NhNBN/RYdnB9+Prx9NmICGZv XIWwWhYF1C4lbyGk1XjU1INu8TAxZESQlxyPkGkxd3pVKzR9vaQ5iGm5ndqa3cFXg+k46c+2UNH DanLsRNxvhqM9+Cb4vQ== X-Proofpoint-GUID: Mzx1xfoUyfGYmPFQMf-aIX0UDVe64snl X-Authority-Analysis: v=2.4 cv=Z8bc2nRA c=1 sm=1 tr=0 ts=6a47eacd cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=MguaJt8dR91BFOVN_IAA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX3koCEfF2zJ1V HD3CdqwHQyMjShVu1NKcnzPnckc3pV1p0X4Z5nchLase13fzgdeGF4zMkPF2bVEcprUTVDadkZI lTG/WTOyMmPGdok46NqsheMulRY7wKE= X-Proofpoint-ORIG-GUID: Mzx1xfoUyfGYmPFQMf-aIX0UDVe64snl X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 adultscore=0 spamscore=0 priorityscore=1501 impostorscore=0 malwarescore=0 phishscore=0 bulkscore=0 lowpriorityscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098110032158500 Content-Type: text/plain; charset="utf-8" DIAG 320 subcode 1 provides information needed to determine the amount of storage to store one or more certificates from the certificate store. Upon successful completion, this subcode returns information of the current cert store, such as the number of certificates stored and allowed in the ce= rt store, amount of space may need to be allocate to store a certificate, etc for verification-certificate blocks (VCBs). The subcode value is denoted by setting the left-most bit of an 8-byte field. The verification-certificate-storage-size block (VCSSB) contains the output data when the operation completes successfully. A VCSSB length of 4 indicates that no certificate are available in the cert store. Signed-off-by: Zhuoying Cai Reviewed-by: Farhan Ali Reviewed-by: Collin Walling Reviewed-by: Eric Farman --- docs/specs/s390x-secure-ipl.rst | 12 +++++++ hw/s390x/cert-store.h | 3 +- include/hw/s390x/ipl/diag320.h | 57 ++++++++++++++++++++++++++++++ target/s390x/diag.c | 61 ++++++++++++++++++++++++++++++++- 4 files changed, 130 insertions(+), 3 deletions(-) diff --git a/docs/specs/s390x-secure-ipl.rst b/docs/specs/s390x-secure-ipl.= rst index 331d793008..d5d4c3a24d 100644 --- a/docs/specs/s390x-secure-ipl.rst +++ b/docs/specs/s390x-secure-ipl.rst @@ -30,3 +30,15 @@ Subcode 0 - query installed subcodes Returns a 256-bit installed subcodes mask (ISM) stored in the installed subcodes block (ISB). This mask indicates which subcodes are currently installed and available for use. + +Subcode 1 - query verification certificate storage information + Provides the information required to determine the amount of memory ne= eded + to store one or more verification-certificates (VCs) from the certific= ate + store (CS). + + Upon successful completion, this subcode returns various storage size = values + for verification-certificate blocks (VCBs). + + The output is returned in the verification-certificate-storage-size bl= ock + (VCSSB). A VCSSB length of 4 indicates that no certificates are availa= ble + in the CS. diff --git a/hw/s390x/cert-store.h b/hw/s390x/cert-store.h index 7fc9503cb9..6f5ee63177 100644 --- a/hw/s390x/cert-store.h +++ b/hw/s390x/cert-store.h @@ -11,10 +11,9 @@ #define HW_S390_CERT_STORE_H =20 #include "hw/s390x/ipl/qipl.h" +#include "hw/s390x/ipl/diag320.h" #include "crypto/x509-utils.h" =20 -#define CERT_NAME_MAX_LEN 64 - #define CERT_KEY_ID_LEN QCRYPTO_HASH_DIGEST_LEN_SHA256 #define CERT_HASH_LEN QCRYPTO_HASH_DIGEST_LEN_SHA256 =20 diff --git a/include/hw/s390x/ipl/diag320.h b/include/hw/s390x/ipl/diag320.h index aa04b699c6..d37d8eaa86 100644 --- a/include/hw/s390x/ipl/diag320.h +++ b/include/hw/s390x/ipl/diag320.h @@ -11,10 +11,67 @@ #define S390X_DIAG320_H =20 #define DIAG_320_SUBC_QUERY_ISM 0 +#define DIAG_320_SUBC_QUERY_VCSI 1 =20 #define DIAG_320_RC_OK 0x0001 #define DIAG_320_RC_NOT_SUPPORTED 0x0102 +#define DIAG_320_RC_INVAL_VCSSB_LEN 0x0202 =20 #define DIAG_320_ISM_QUERY_SUBCODES 0x80000000 +#define DIAG_320_ISM_QUERY_VCSI 0x40000000 + +#define VCSSB_NO_VC 4 +#define VCSSB_LEN_VALID 128 + +#define CERT_NAME_MAX_LEN 64 + +struct VCStorageSizeBlock { + uint32_t length; + uint8_t reserved0[3]; + uint8_t version; + uint32_t reserved1[6]; + uint16_t total_vc_ct; + uint16_t max_vc_ct; + uint32_t reserved3[11]; + uint32_t max_single_vcb_len; + uint32_t total_vcb_len; + uint32_t reserved4[10]; +}; +typedef struct VCStorageSizeBlock VCStorageSizeBlock; + +struct VCEntryHeader { + uint32_t len; + uint8_t flags; + uint8_t key_type; + uint16_t cert_idx; + uint8_t name[CERT_NAME_MAX_LEN]; + uint8_t format; + uint8_t reserved0; + uint16_t keyid_len; + uint8_t reserved1; + uint8_t hash_type; + uint16_t hash_len; + uint32_t reserved2; + uint32_t cert_len; + uint32_t reserved3[2]; + uint16_t hash_offset; + uint16_t cert_offset; + uint32_t reserved4[7]; +}; +typedef struct VCEntryHeader VCEntryHeader; + +struct VCBlockHeader { + uint32_t in_len; + uint32_t reserved0; + uint16_t first_vc_index; + uint16_t last_vc_index; + uint32_t reserved1[5]; + uint32_t out_len; + uint8_t reserved2[4]; + uint16_t stored_ct; + uint16_t remain_ct; + uint32_t reserved3[5]; +}; +typedef struct VCBlockHeader VCBlockHeader; =20 #endif diff --git a/target/s390x/diag.c b/target/s390x/diag.c index 9f98e4b677..228956ab13 100644 --- a/target/s390x/diag.c +++ b/target/s390x/diag.c @@ -205,11 +205,52 @@ out: } } =20 +static int handle_diag320_query_vcsi(S390CPU *cpu, uint64_t addr, uint64_t= r1, + uintptr_t ra, S390IPLCertificateStore= *cs) +{ + g_autofree VCStorageSizeBlock *vcssb =3D NULL; + + vcssb =3D g_new0(VCStorageSizeBlock, 1); + if (s390_cpu_virt_mem_read(cpu, addr, r1, vcssb, sizeof(*vcssb))) { + s390_cpu_virt_mem_handle_exc(cpu, ra); + return -1; + } + + if (be32_to_cpu(vcssb->length) !=3D VCSSB_LEN_VALID) { + return DIAG_320_RC_INVAL_VCSSB_LEN; + } + + if (!cs->count) { + vcssb->length =3D cpu_to_be32(VCSSB_NO_VC); + } else { + vcssb->version =3D 0; + vcssb->total_vc_ct =3D cpu_to_be16(cs->count); + vcssb->max_vc_ct =3D cpu_to_be16(MAX_CERTIFICATES); + vcssb->max_single_vcb_len =3D cpu_to_be32(sizeof(VCBlockHeader) + + sizeof(VCEntryHeader) + + cs->largest_cert_size); + vcssb->total_vcb_len =3D cpu_to_be32(sizeof(VCBlockHeader) + + cs->count * sizeof(VCEntryHeade= r) + + cs->total_bytes); + } + + if (s390_cpu_virt_mem_write(cpu, addr, r1, vcssb, be32_to_cpu(vcssb->l= ength))) { + s390_cpu_virt_mem_handle_exc(cpu, ra); + return -1; + } + return DIAG_320_RC_OK; +} + +QEMU_BUILD_BUG_MSG(sizeof(VCStorageSizeBlock) !=3D VCSSB_LEN_VALID, + "size of VCStorageSizeBlock is wrong"); + void handle_diag_320(CPUS390XState *env, uint64_t r1, uint64_t r3, uintptr= _t ra) { S390CPU *cpu =3D env_archcpu(env); + S390IPLCertificateStore *cs =3D s390_ipl_get_certificate_store(); uint64_t subcode =3D env->regs[r3]; uint64_t addr =3D env->regs[r1]; + int rc; =20 if (env->psw.mask & PSW_MASK_PSTATE) { s390_program_interrupt(env, PGM_PRIVILEGED, ra); @@ -231,7 +272,8 @@ void handle_diag_320(CPUS390XState *env, uint64_t r1, u= int64_t r3, uintptr_t ra) * but the current set of subcodes can fit within a single word * for now. */ - uint32_t ism_word0 =3D cpu_to_be32(DIAG_320_ISM_QUERY_SUBCODES); + uint32_t ism_word0 =3D cpu_to_be32(DIAG_320_ISM_QUERY_SUBCODES | + DIAG_320_ISM_QUERY_VCSI); =20 if (s390_cpu_virt_mem_write(cpu, addr, r1, &ism_word0, sizeof(ism_= word0))) { s390_cpu_virt_mem_handle_exc(cpu, ra); @@ -240,6 +282,23 @@ void handle_diag_320(CPUS390XState *env, uint64_t r1, = uint64_t r3, uintptr_t ra) =20 env->regs[r1 + 1] =3D DIAG_320_RC_OK; break; + case DIAG_320_SUBC_QUERY_VCSI: + if (addr & 0x7) { + s390_program_interrupt(env, PGM_SPECIFICATION, ra); + return; + } + + if (!diag_parm_addr_valid(addr, sizeof(VCStorageSizeBlock), true))= { + s390_program_interrupt(env, PGM_ADDRESSING, ra); + return; + } + + rc =3D handle_diag320_query_vcsi(cpu, addr, r1, ra, cs); + if (rc =3D=3D -1) { + return; + } + env->regs[r1 + 1] =3D rc; + break; default: env->regs[r1 + 1] =3D DIAG_320_RC_NOT_SUPPORTED; break; --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098302; cv=none; d=zohomail.com; s=zohoarc; b=QDYgVi3LTxkWHacQ660SmBvshLbB4ALQONZjFEN5OUhsbhh7zh+uX/OXT5p1ShLet1neVGpQmMX47ulDcCAj5PiqnFBL1Rb1qHMOOijmWK8m9dc2tSGHzrg7g1KvUcE9aECouj9NPLJOOLZu5BpqlBJSaMJSxPPUxxD+IK4ABMo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098302; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wQ+il+s9Xg/o08k/00pPOPcbrUnAgwjkgTF3VysbxK4=; b=bKpUiy5mkYz7JW/kcwe44tqZ8qDxIVH4/ZTZNnNcxbFdaTWO9jfKTGLQEuz32ibjU8JrPYWHMcxqgB9QIo4ngLmY8Phd1XkfyIHxSh+kUCGW2oH3b/e8/5LVSosZLo7RRWZF+H5lgmDZP0Uau0QiDp3Ybe5/dfJgBslMfhlPcHs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098302274278.7521113299716; Fri, 3 Jul 2026 10:05:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhGM-0007gb-Dy; Fri, 03 Jul 2026 13:01:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGJ-0007fY-Sd; Fri, 03 Jul 2026 13:01:12 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGH-00033Y-OT; Fri, 03 Jul 2026 13:01:11 -0400 Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIUSv3382590; Fri, 3 Jul 2026 17:01:05 GMT Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26pegabr-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:04 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnZmj031463; Fri, 3 Jul 2026 17:01:04 GMT Received: from smtprelay05.wdc07v.mail.ibm.com ([172.16.1.72]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2uhysg88-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:04 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay05.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H121X15926014 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:02 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 682565805C; Fri, 3 Jul 2026 17:01:02 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8DB1B5805A; Fri, 3 Jul 2026 17:00:59 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:00:59 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=wQ+il+ s9Xg/o08k/00pPOPcbrUnAgwjkgTF3VysbxK4=; b=bc4POnv4j7WS9270pINQBC WvGslJWCNl73M0H5c7mb/8R7YnoH+B7/HBSVdr9O2QqjLslNP8eC6ILY8OpgLg54 lje7INQMYozBRQZm8PRbeQvaiwA9u0Fl+42aJf+Hq8S+ppRL3vbfkRMlZR2n/3Bp m1ES3+2hfC+LHi0MBe27Z1gUqWwCMXW7qZEOmUglT+mGRFrYTslK8naFg0weuikf 3jtPMf/mRw3iNaDmzfvKr+lcG9I6zyTPZT8Jg02Lp+zA8hKCR/xoaK8fE9WrKYcS P8wkwMq54TTSmOvZRn7AQyg9qA6gkuJH/2EaDlv5lo7ycMSQmkseKTEdB8WcEMVA == From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 08/33] crypto/x509-utils: Add helper functions for DIAG 320 subcode 2 Date: Fri, 3 Jul 2026 13:00:05 -0400 Message-ID: <20260703170032.1893204-9-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: xc4Cmj2PcyVngYtakOnCw6wQYAKcetx5 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX5ZE78lGTulFB jJcHWgRe0KksD2ygQdzRietMwzA6vM4iQ742/KJoRf34xzGZZcX3ibsiqehb9/6KXirXAWXqEAJ 5nVZIrwVE//IAbxccm0MMs+iRgyBwOA= X-Authority-Analysis: v=2.4 cv=edsNubEH c=1 sm=1 tr=0 ts=6a47ead1 cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=cx8EP_J7U0ANkHmDKVUA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX06G1sbceC4eQ JzQDc+Rl0kw2mphV/IVooUSdCZSJpv391YoesC19z4L/7aH0Sq7xl1F8wkRxhCZ7aUnXWO/E26n tWtGV1DWmZFALSjiHEA4LvLdQ3rtF08UnuV+4lEBJbgvvIh0ieo6GpQKKFirY5VUVwiDgE4xv+2 DQ4y4J8qD4+iQ5vKwwUekhTEYbeGMOCj7PLl8I6IJZAnr4HvV0yKwWCTmdx14IYSAJeGMmQyUHx s5YbeyfK4hF0ketje1FSSidbU/z+pwyC7X8dXEzmrKnI4Sxat/FnqeGsQ7WcP5blg5xovIB2ebY mTlWSsZ25QB7fv6C3By6W0zyRUFnZw+K2hte4SletwQqfFsIUlg8eFMZz2eLO7mFRyR4rbTYIy7 MTNvCXbPqYp8Otml82/4uM6UPkxW8wHFl/9M36F9QpklAI5P2oCXqbBU8aLFgSsJms3x8GhQ7gz /2nDvQYrgv/cqXMtxwA== X-Proofpoint-ORIG-GUID: xc4Cmj2PcyVngYtakOnCw6wQYAKcetx5 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 adultscore=0 impostorscore=0 bulkscore=0 spamscore=0 suspectscore=0 clxscore=1015 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098303743158500 Introduce new helper functions to extract certificate metadata: qcrypto_x509_check_cert_times() - validates the certificate's validity peri= od against the current time qcrypto_x509_get_cert_key_id() - extracts the key ID from the certificate qcrypto_x509_check_ecc_curve_p521() - determines the ECC public key algorit= hm uses P-521 curve These functions provide support for metadata extraction and validity checki= ng for X.509 certificates. Signed-off-by: Zhuoying Cai Acked-by: Daniel P. Berrang=C3=A9 Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Farhan Ali --- crypto/x509-utils.c | 236 ++++++++++++++++++++++++++++++++++++ include/crypto/x509-utils.h | 51 ++++++++ 2 files changed, 287 insertions(+) diff --git a/crypto/x509-utils.c b/crypto/x509-utils.c index 68cf008938..d0e0384e9c 100644 --- a/crypto/x509-utils.c +++ b/crypto/x509-utils.c @@ -27,6 +27,16 @@ static const int qcrypto_to_gnutls_hash_alg_map[QCRYPTO_= HASH_ALGO__MAX] =3D { [QCRYPTO_HASH_ALGO_RIPEMD160] =3D GNUTLS_DIG_RMD160, }; =20 +static const int qcrypto_to_gnutls_keyid_flags_map[] =3D { + [QCRYPTO_HASH_ALGO_MD5] =3D -1, + [QCRYPTO_HASH_ALGO_SHA1] =3D GNUTLS_KEYID_USE_SHA1, + [QCRYPTO_HASH_ALGO_SHA224] =3D -1, + [QCRYPTO_HASH_ALGO_SHA256] =3D GNUTLS_KEYID_USE_SHA256, + [QCRYPTO_HASH_ALGO_SHA384] =3D -1, + [QCRYPTO_HASH_ALGO_SHA512] =3D GNUTLS_KEYID_USE_SHA512, + [QCRYPTO_HASH_ALGO_RIPEMD160] =3D -1, +}; + int qcrypto_get_x509_cert_fingerprint(uint8_t *cert, size_t size, QCryptoHashAlgo alg, uint8_t *result, @@ -121,6 +131,210 @@ cleanup: return ret; } =20 +int qcrypto_x509_check_cert_times(uint8_t *cert, size_t size, Error **errp) +{ + int rc; + int ret =3D -1; + gnutls_x509_crt_t crt; + gnutls_datum_t datum =3D {.data =3D cert, .size =3D size}; + time_t now =3D time(NULL); + time_t exp_time; + time_t act_time; + + if (now =3D=3D ((time_t)-1)) { + error_setg_errno(errp, errno, "Cannot get current time"); + return ret; + } + + rc =3D gnutls_x509_crt_init(&crt); + if (rc < 0) { + error_setg(errp, "Failed to initialize certificate: %s", gnutls_st= rerror(rc)); + return ret; + } + + rc =3D gnutls_x509_crt_import(crt, &datum, GNUTLS_X509_FMT_PEM); + if (rc !=3D 0) { + error_setg(errp, "Failed to import certificate: %s", gnutls_strerr= or(rc)); + goto cleanup; + } + + exp_time =3D gnutls_x509_crt_get_expiration_time(crt); + if (exp_time =3D=3D ((time_t)-1)) { + error_setg(errp, "Failed to get certificate expiration time"); + goto cleanup; + } + if (exp_time < now) { + error_setg(errp, "The certificate has expired"); + goto cleanup; + } + + act_time =3D gnutls_x509_crt_get_activation_time(crt); + if (act_time =3D=3D ((time_t)-1)) { + error_setg(errp, "Failed to get certificate activation time"); + goto cleanup; + } + if (act_time > now) { + error_setg(errp, "The certificate is not yet active"); + goto cleanup; + } + + ret =3D 0; + +cleanup: + gnutls_x509_crt_deinit(crt); + return ret; +} + +static int qcrypto_x509_get_pk_algorithm(uint8_t *cert, size_t size, Error= **errp) +{ + int rc; + int ret =3D -1; + unsigned int bits; + gnutls_x509_crt_t crt; + gnutls_datum_t datum =3D {.data =3D cert, .size =3D size}; + + rc =3D gnutls_x509_crt_init(&crt); + if (rc < 0) { + error_setg(errp, "Failed to initialize certificate: %s", gnutls_st= rerror(rc)); + return ret; + } + + rc =3D gnutls_x509_crt_import(crt, &datum, GNUTLS_X509_FMT_PEM); + if (rc !=3D 0) { + error_setg(errp, "Failed to import certificate: %s", gnutls_strerr= or(rc)); + goto cleanup; + } + + rc =3D gnutls_x509_crt_get_pk_algorithm(crt, &bits); + if (rc < 0) { + error_setg(errp, "Unknown public key algorithm %d", rc); + goto cleanup; + } + + ret =3D rc; + +cleanup: + gnutls_x509_crt_deinit(crt); + return ret; +} + +int qcrypto_x509_get_cert_key_id(uint8_t *cert, size_t size, + QCryptoHashAlgo hash_alg, + uint8_t **result, + size_t *resultlen, + Error **errp) +{ + int rc; + int ret =3D -1; + gnutls_x509_crt_t crt; + gnutls_datum_t datum =3D {.data =3D cert, .size =3D size}; + + if (hash_alg >=3D G_N_ELEMENTS(qcrypto_to_gnutls_hash_alg_map)) { + error_setg(errp, "Unknown hash algorithm %d", hash_alg); + return ret; + } + + if (hash_alg >=3D G_N_ELEMENTS(qcrypto_to_gnutls_keyid_flags_map) || + qcrypto_to_gnutls_keyid_flags_map[hash_alg] =3D=3D -1) { + error_setg(errp, "Unsupported key id flag %d", hash_alg); + return ret; + } + + rc =3D gnutls_x509_crt_init(&crt); + if (rc < 0) { + error_setg(errp, "Failed to initialize certificate: %s", gnutls_st= rerror(rc)); + return ret; + } + + rc =3D gnutls_x509_crt_import(crt, &datum, GNUTLS_X509_FMT_PEM); + if (rc !=3D 0) { + error_setg(errp, "Failed to import certificate: %s", gnutls_strerr= or(rc)); + goto cleanup; + } + + *resultlen =3D gnutls_hash_get_len(qcrypto_to_gnutls_hash_alg_map[hash= _alg]); + if (*resultlen =3D=3D 0) { + error_setg(errp, "Failed to get hash algorithm length: %s", gnutls= _strerror(rc)); + goto cleanup; + } + + *result =3D g_malloc0(*resultlen); + if (gnutls_x509_crt_get_key_id(crt, + qcrypto_to_gnutls_keyid_flags_map[hash_= alg], + *result, resultlen) !=3D 0) { + error_setg(errp, "Failed to get key ID from certificate"); + g_clear_pointer(result, g_free); + goto cleanup; + } + + ret =3D 0; + +cleanup: + gnutls_x509_crt_deinit(crt); + return ret; +} + +static int qcrypto_x509_get_ecc_curve(uint8_t *cert, size_t size, Error **= errp) +{ + int rc; + int ret =3D -1; + gnutls_x509_crt_t crt; + gnutls_datum_t datum =3D {.data =3D cert, .size =3D size}; + gnutls_ecc_curve_t curve_id; + gnutls_datum_t x =3D {.data =3D NULL, .size =3D 0}; + gnutls_datum_t y =3D {.data =3D NULL, .size =3D 0}; + + rc =3D gnutls_x509_crt_init(&crt); + if (rc < 0) { + error_setg(errp, "Failed to initialize certificate: %s", gnutls_st= rerror(rc)); + return ret; + } + + rc =3D gnutls_x509_crt_import(crt, &datum, GNUTLS_X509_FMT_PEM); + if (rc !=3D 0) { + error_setg(errp, "Failed to import certificate: %s", gnutls_strerr= or(rc)); + goto cleanup; + } + + rc =3D gnutls_x509_crt_get_pk_ecc_raw(crt, &curve_id, &x, &y); + if (rc !=3D 0) { + error_setg(errp, "Failed to get ECC public key curve: %s", gnutls_= strerror(rc)); + goto cleanup; + } + + ret =3D curve_id; + +cleanup: + gnutls_x509_crt_deinit(crt); + g_free(x.data); + g_free(y.data); + return ret; +} + +int qcrypto_x509_check_ecc_curve_p521(uint8_t *cert, size_t size, Error **= errp) +{ + int algo; + int curve_id; + + algo =3D qcrypto_x509_get_pk_algorithm(cert, size, errp); + if (algo !=3D GNUTLS_PK_ECDSA) { + return 0; + } + + curve_id =3D qcrypto_x509_get_ecc_curve(cert, size, errp); + if (curve_id =3D=3D -1) { + error_setg(errp, "Failed to get ECC curve"); + return -1; + } + + if (curve_id =3D=3D GNUTLS_ECC_CURVE_INVALID) { + error_setg(errp, "Invalid ECC curve"); + return -1; + } + + return curve_id =3D=3D GNUTLS_ECC_CURVE_SECP521R1; +} + #else /* ! CONFIG_GNUTLS */ =20 int qcrypto_get_x509_cert_fingerprint(uint8_t *cert, size_t size, @@ -142,4 +356,26 @@ int qcrypto_x509_convert_cert_der(uint8_t *cert, size_= t size, return -1; } =20 +int qcrypto_x509_check_cert_times(uint8_t *cert, size_t size, Error **errp) +{ + error_setg(errp, "GNUTLS is required to get certificate times"); + return -1; +} + +int qcrypto_x509_get_cert_key_id(uint8_t *cert, size_t size, + QCryptoHashAlgo hash_alg, + uint8_t **result, + size_t *resultlen, + Error **errp) +{ + error_setg(errp, "GNUTLS is required to get key ID"); + return -1; +} + +int qcrypto_x509_check_ecc_curve_p521(uint8_t *cert, size_t size, Error **= errp) +{ + error_setg(errp, "GNUTLS is required to determine ecc curve"); + return -1; +} + #endif /* ! CONFIG_GNUTLS */ diff --git a/include/crypto/x509-utils.h b/include/crypto/x509-utils.h index 91ae79fb03..fcace73c49 100644 --- a/include/crypto/x509-utils.h +++ b/include/crypto/x509-utils.h @@ -40,4 +40,55 @@ int qcrypto_x509_convert_cert_der(uint8_t *cert, size_t = size, size_t *resultlen, Error **errp); =20 +/** + * qcrypto_x509_check_cert_times + * @cert: pointer to the raw certificate data + * @size: size of the certificate + * @errp: error pointer + * + * Check whether the activation and expiration times of @cert + * are valid at the current time. + * + * Returns: 0 if the certificate times are valid, + * -1 on error. + */ +int qcrypto_x509_check_cert_times(uint8_t *cert, size_t size, Error **errp= ); + +/** + * qcrypto_x509_get_cert_key_id + * @cert: pointer to the raw certificate data + * @size: size of the certificate + * @hash_alg: the hash algorithm flag + * @result: output location for the allocated buffer for key ID + * (the function allocates memory which must be freed by the call= er) + * @resultlen: pointer to the size of the buffer + * (will be updated with the actual size of key id) + * @errp: error pointer + * + * Retrieve the key ID from the @cert based on the specified @hash_alg. + * + * Returns: 0 if key ID was successfully stored in @result, + * -1 on error. + */ +int qcrypto_x509_get_cert_key_id(uint8_t *cert, size_t size, + QCryptoHashAlgo hash_alg, + uint8_t **result, + size_t *resultlen, + Error **errp); + +/** + * qcrypto_x509_check_ecc_curve_p521 + * @cert: pointer to the raw certificate data + * @size: size of the certificate + * @errp: error pointer + * + * Determine whether the ECC public key in the given certificate uses the = P-521 + * curve. + * + * Returns: 0 if ECC public key does not use P521 curve. + * 1 if ECC public key uses P521 curve. + * -1 on error. + */ +int qcrypto_x509_check_ecc_curve_p521(uint8_t *cert, size_t size, Error **= errp); + #endif --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098239; cv=none; d=zohomail.com; s=zohoarc; b=Baw56GB3C2FWMXTpGok2pYrXLL7g00pWjouV796HgcAVI9bt9CZa5iimzsUTcmwcWT72FyC+8WzYaIck9NsYrl5yS6jBc8VwbJyZawhioTPPCt/E1oQl61Dd0EYEahcMqYA1zPooZyZ4i0tcY/H3D38gzov65RTInmLTP2diSaI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098239; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=vZ6XjVwKJ57vr6VLpDkiPjHiiY2cc54kZG6p99I4YVs=; b=ER+/F1ErQp4k61J/qb+HbT7ath2JPHg8xGs/gAcqsRGSaznmSA58xAqTGXj8EGr63cBsLAcdhOzlolViGsHXatt0Uhml+oxj955BPnH3yv6r+wQlWJK8hV9IyIWtrjceNba+3HwbtNEHRkw79cvQibbXbsquVuVzsPMJM6JBVAg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098239059880.1864428148637; Fri, 3 Jul 2026 10:03:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhGT-0007hj-AU; Fri, 03 Jul 2026 13:01:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGO-0007gu-TO; Fri, 03 Jul 2026 13:01:18 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGL-00033u-1i; Fri, 03 Jul 2026 13:01:16 -0400 Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIbgd3302552; Fri, 3 Jul 2026 17:01:09 GMT Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26n688w9-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:08 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gngvq003089; Fri, 3 Jul 2026 17:01:07 GMT Received: from smtprelay02.dal12v.mail.ibm.com ([172.16.1.4]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2tbhsnd0-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:07 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay02.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H15KT13173458 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:06 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id D39345805F; Fri, 3 Jul 2026 17:01:05 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id AAD2758054; Fri, 3 Jul 2026 17:01:02 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:02 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=vZ6XjVwKJ57vr6VLp DkiPjHiiY2cc54kZG6p99I4YVs=; b=Ui2JbTdiHJx+t9/Mq/U3hETA4iUHDJr5y oKIGiuSq2Y+k4piX4otJSGhxTfoUF7gHp8DcVshF6ofMFeuwvAxplwwC/2nV5qs7 2XgWuwg1tb5jMwNSQtIpN0z/c2iDff1wJzu7aF1kc+cPJ5FE1jU/Gikzmscs8KfW /k1WIQu0Gq+TO91KMr1iTo2h0Tm31itXn1DQ/D6lpHKMfkE+tJ82x2hd/icF3En6 OvemGijHwm5l/7sQgL5ZeTZGLnPJRySCXRf1SjG9BZHVpLXOoMPgBdt5hJBy1u+6 Ut9gHWx/wltFaVXR4zpJS1eJxFu0Agn7rtJ4bT8kamnwWeNoNOo6g== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 09/33] s390x/diag: Implement DIAG 320 subcode 2 Date: Fri, 3 Jul 2026 13:00:06 -0400 Message-ID: <20260703170032.1893204-10-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX6BSj3NtdRVNH Db5Ac5wmpvIs6nfLfpVG6u2+oUPfG/PV4i+lJwUJuEMd7B+j8Z49JTiAvrGioCgUKrrX0lYrJ+J GA7NW5EE3f0YFl79RfYtI3rZdSQe7VOBkVmGZE5TX0vLFwFxnj37TmxtdjqGl5ZL9egcqfWSqjo BBOHFAC9O9xZ87QpQJ/XRabSzno1Wicflt+2+MaWdZCzvTjwVbPy9pdSr69We8ceaMnGlTMUOHl CvZt0k/1027VruVNrJYeenw/PGQszJlB7BgDXy96pLn0BMv1CdG8yHGsxI9QAoYXcDKDvrh1nSK Qx3LPHz/QE+rfPhvm4UYClG15isQ0dwkkhp6X9OzSeSijr9CKKjONpO0h7qoRIV3wOMUClP4e9s hLZU3/od63JCBV68hpCSwR+ktNIzZPFw+viVyqW2HsUKoGHmu4MKQaM6YasQu/ky3+rGBl/msgG BTllKE2DXPTbsmjXypQ== X-Authority-Analysis: v=2.4 cv=V45NF+ni c=1 sm=1 tr=0 ts=6a47ead4 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=yb4F8fGd1MjoyQfLk7gA:9 X-Proofpoint-ORIG-GUID: TUOhPHvgazEHCpfl0f5UCVcrXLagvc0A X-Proofpoint-GUID: TUOhPHvgazEHCpfl0f5UCVcrXLagvc0A X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX0QTpd7UhznQG uO7RGmxR0VAskWc1uXbriMMN8l0LJdEMblpquwDfZDnuMnlOAc44ab/w4nAbfVh7AliF0q1QmSQ YFi/WBfCW/alaLeVBVZyp7Cm4dOlEvs= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 spamscore=0 suspectscore=0 lowpriorityscore=0 priorityscore=1501 adultscore=0 clxscore=1015 impostorscore=0 malwarescore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098241185158500 Content-Type: text/plain; charset="utf-8" DIAG 320 subcode 2 provides verification-certificates (VCs) that are in the certificate store. Only X509 certificates in DER format and SHA-256 hash type are recognized. The subcode value is denoted by setting the second-left-most bit of an 8-byte field. The Verification Certificate Block (VCB) contains the output data when the operation completes successfully. It includes a common header followed by zero or more Verification Certificate Entries (VCEs), depending on the VCB input length and the VC range (from the first VC index to the last VC index) in the certificate store. Each VCE contains information about a certificate retrieved from the S390IPLCertificateStore, such as the certificate name, key type, key ID length, hash length, and the raw certificate data. The key ID and hash are extracted from the raw certificate by the crypto AP= I. Note: SHA2-256 VC hash type is required for retrieving the hash (fingerprint) of the certificate. Signed-off-by: Zhuoying Cai Reviewed-by: Eric Farman --- docs/specs/s390x-secure-ipl.rst | 24 +++ include/hw/s390x/ipl/diag320.h | 38 ++++ target/s390x/diag.c | 316 +++++++++++++++++++++++++++++++- 3 files changed, 377 insertions(+), 1 deletion(-) diff --git a/docs/specs/s390x-secure-ipl.rst b/docs/specs/s390x-secure-ipl.= rst index d5d4c3a24d..a17bb0ab55 100644 --- a/docs/specs/s390x-secure-ipl.rst +++ b/docs/specs/s390x-secure-ipl.rst @@ -42,3 +42,27 @@ Subcode 1 - query verification certificate storage infor= mation The output is returned in the verification-certificate-storage-size bl= ock (VCSSB). A VCSSB length of 4 indicates that no certificates are availa= ble in the CS. + +Subcode 2 - store verification certificates + Provides VCs that are in the certificate store. + + The output is provided in a VCB, which includes a common header follow= ed by + zero or more verification-certificate entries (VCEs). + + The instruction expects the cert store to maintain an origin of 1 for = the + index (i.e. a retrieval of the first certificate in the store should be + denoted by setting first-VC to 1). + + The first-VC and last-VC fields of the VCB specify the index range of + VCs to be stored in the VCB. Certs are stored sequentially, starting + with first-VC index. As each cert is stored, a "stored count" is + incremented. If there is not enough space to store all certs requested + by the index range, a "remaining count" will be recorded and no more + certificates will be stored. + + Each VCE contains a header followed by information extracted from a + certificate within the certificate store. The information includes: + key-id, hash, and certificate data. This information is stored + contiguously in a VCE (with zero-padding). Following the header, the + key-id is immediately stored. The hash and certificate data follow and + may be accessed via the respective offset fields stored in the VCE. diff --git a/include/hw/s390x/ipl/diag320.h b/include/hw/s390x/ipl/diag320.h index d37d8eaa86..7fda2d44fd 100644 --- a/include/hw/s390x/ipl/diag320.h +++ b/include/hw/s390x/ipl/diag320.h @@ -12,19 +12,45 @@ =20 #define DIAG_320_SUBC_QUERY_ISM 0 #define DIAG_320_SUBC_QUERY_VCSI 1 +#define DIAG_320_SUBC_STORE_VC 2 =20 #define DIAG_320_RC_OK 0x0001 #define DIAG_320_RC_NOT_SUPPORTED 0x0102 #define DIAG_320_RC_INVAL_VCSSB_LEN 0x0202 +#define DIAG_320_RC_INVAL_VCB_LEN 0x0204 +#define DIAG_320_RC_BAD_RANGE 0x0302 =20 #define DIAG_320_ISM_QUERY_SUBCODES 0x80000000 #define DIAG_320_ISM_QUERY_VCSI 0x40000000 +#define DIAG_320_ISM_STORE_VC 0x20000000 =20 #define VCSSB_NO_VC 4 #define VCSSB_LEN_VALID 128 =20 #define CERT_NAME_MAX_LEN 64 =20 +/* + * If the VCE flags indicate an invalid certificate, + * the VCE length is set to 72, containing only the + * first five fields of VCEntry. + */ +#define VCE_INVALID_LEN 72 + +#define DIAG_320_VCE_FLAGS_VALID 0x80 + +typedef enum Diag320VceKeyType { + DIAG_320_VCE_KEYTYPE_SELF_DESCRIBING =3D 0, + DIAG_320_VCE_KEYTYPE_ECDSA_P521 =3D 1, +} Diag320VceKeyType; + +typedef enum Diag320VceFormat { + DIAG_320_VCE_FORMAT_X509_DER =3D 1, +} Diag320VceFormat; + +typedef enum Diag320VceHashType { + DIAG_320_VCE_HASHTYPE_SHA2_256 =3D 1, +} Diag320VceHashType; + struct VCStorageSizeBlock { uint32_t length; uint8_t reserved0[3]; @@ -60,6 +86,12 @@ struct VCEntryHeader { }; typedef struct VCEntryHeader VCEntryHeader; =20 +struct VCEntry { + VCEntryHeader vce_hdr; + uint8_t cert_buf[]; +}; +typedef struct VCEntry VCEntry; + struct VCBlockHeader { uint32_t in_len; uint32_t reserved0; @@ -74,4 +106,10 @@ struct VCBlockHeader { }; typedef struct VCBlockHeader VCBlockHeader; =20 +struct VCBlock { + VCBlockHeader vcb_hdr; + uint8_t vce_buf[]; +}; +typedef struct VCBlock VCBlock; + #endif diff --git a/target/s390x/diag.c b/target/s390x/diag.c index 228956ab13..c072daca3a 100644 --- a/target/s390x/diag.c +++ b/target/s390x/diag.c @@ -17,13 +17,16 @@ #include "s390x-internal.h" #include "hw/watchdog/wdt_diag288.h" #include "system/cpus.h" +#include "hw/s390x/cert-store.h" #include "hw/s390x/ipl.h" #include "hw/s390x/ipl/diag320.h" #include "hw/s390x/s390-virtio-ccw.h" #include "system/kvm.h" #include "kvm/kvm_s390x.h" #include "target/s390x/kvm/pv.h" +#include "qapi/error.h" #include "qemu/error-report.h" +#include "crypto/x509-utils.h" =20 =20 static inline bool diag_parm_addr_valid(uint64_t addr, size_t size, bool w= rite) @@ -241,8 +244,306 @@ static int handle_diag320_query_vcsi(S390CPU *cpu, ui= nt64_t addr, uint64_t r1, return DIAG_320_RC_OK; } =20 +static bool is_cert_valid(const S390IPLCertificate *cert) +{ + int rc; + Error *err =3D NULL; + + rc =3D qcrypto_x509_check_cert_times(cert->raw, cert->size, &err); + if (rc !=3D 0) { + error_report_err(err); + return false; + } + + return true; +} + +static int handle_key_id(VCEntry *vce, const S390IPLCertificate *cert) +{ + int rc; + g_autofree unsigned char *key_id_data =3D NULL; + size_t key_id_len; + Error *err =3D NULL; + + rc =3D qcrypto_x509_get_cert_key_id(cert->raw, cert->size, + QCRYPTO_HASH_ALGO_SHA256, + &key_id_data, &key_id_len, &err); + if (rc < 0) { + error_report_err(err); + return 0; + } + + if (sizeof(VCEntryHeader) + key_id_len > be32_to_cpu(vce->vce_hdr.len)= ) { + error_report("Unable to write key ID: exceeds buffer bounds"); + return 0; + } + + vce->vce_hdr.keyid_len =3D cpu_to_be16(key_id_len); + + memcpy(vce->cert_buf, key_id_data, key_id_len); + + return ROUND_UP(key_id_len, 4); +} + +static int handle_hash(VCEntry *vce, const S390IPLCertificate *cert, + uint16_t keyid_field_len) +{ + int rc; + uint16_t hash_offset; + g_autofree void *hash_data =3D NULL; + size_t hash_len; + Error *err =3D NULL; + + hash_len =3D CERT_HASH_LEN; + hash_data =3D g_malloc0(hash_len); + rc =3D qcrypto_get_x509_cert_fingerprint(cert->raw, cert->size, + QCRYPTO_HASH_ALGO_SHA256, + hash_data, &hash_len, &err); + if (rc < 0) { + error_report_err(err); + return 0; + } + + hash_offset =3D sizeof(VCEntryHeader) + keyid_field_len; + if (hash_offset + hash_len > be32_to_cpu(vce->vce_hdr.len)) { + error_report("Unable to write hash: exceeds buffer bounds"); + return 0; + } + + vce->vce_hdr.hash_len =3D cpu_to_be16(hash_len); + vce->vce_hdr.hash_type =3D DIAG_320_VCE_HASHTYPE_SHA2_256; + vce->vce_hdr.hash_offset =3D cpu_to_be16(hash_offset); + + memcpy((uint8_t *)vce + hash_offset, hash_data, hash_len); + + return ROUND_UP(hash_len, 4); +} + +static int handle_cert(VCEntry *vce, const S390IPLCertificate *cert, + uint16_t hash_field_len) +{ + int rc; + uint16_t cert_offset; + g_autofree uint8_t *cert_der =3D NULL; + size_t der_size; + Error *err =3D NULL; + + rc =3D qcrypto_x509_convert_cert_der(cert->raw, cert->size, + &cert_der, &der_size, &err); + if (rc < 0) { + error_report_err(err); + return 0; + } + + cert_offset =3D be16_to_cpu(vce->vce_hdr.hash_offset) + hash_field_len; + if (cert_offset + der_size > be32_to_cpu(vce->vce_hdr.len)) { + error_report("Unable to write certificate: exceeds buffer bounds"); + return 0; + } + + vce->vce_hdr.format =3D DIAG_320_VCE_FORMAT_X509_DER; + vce->vce_hdr.cert_len =3D cpu_to_be32(der_size); + vce->vce_hdr.cert_offset =3D cpu_to_be16(cert_offset); + + memcpy((uint8_t *)vce + cert_offset, cert_der, der_size); + + return ROUND_UP(der_size, 4); +} + +static int get_key_type(const S390IPLCertificate *cert) +{ + int rc; + Error *err =3D NULL; + + rc =3D qcrypto_x509_check_ecc_curve_p521(cert->raw, cert->size, &err); + if (rc =3D=3D -1) { + error_report_err(err); + return -1; + } + + return (rc =3D=3D 1) ? DIAG_320_VCE_KEYTYPE_ECDSA_P521 : + DIAG_320_VCE_KEYTYPE_SELF_DESCRIBING; +} + +static int build_vce_header(VCEntry *vce, const S390IPLCertificate *cert, = int idx) +{ + int key_type; + + vce->vce_hdr.len =3D cpu_to_be32(sizeof(VCEntryHeader)); + vce->vce_hdr.cert_idx =3D cpu_to_be16(idx + 1); + memcpy(vce->vce_hdr.name, cert->name, CERT_NAME_MAX_LEN); + + if (!is_cert_valid(cert)) { + return -1; + } + + key_type =3D get_key_type(cert); + if (key_type =3D=3D -1) { + return -1; + } + vce->vce_hdr.key_type =3D key_type; + + return 0; +} + +static int build_vce_data(VCEntry *vce, const S390IPLCertificate *cert, + uint32_t vce_max_len) +{ + uint16_t keyid_field_len; + uint16_t hash_field_len; + uint32_t cert_field_len; + uint32_t vce_len; + + vce->vce_hdr.len =3D cpu_to_be32(vce_max_len); + + keyid_field_len =3D handle_key_id(vce, cert); + if (!keyid_field_len) { + return -1; + } + + hash_field_len =3D handle_hash(vce, cert, keyid_field_len); + if (!hash_field_len) { + return -1; + } + + cert_field_len =3D handle_cert(vce, cert, hash_field_len); + if (!cert_field_len) { + return -1; + } + + vce_len =3D sizeof(VCEntryHeader) + keyid_field_len + hash_field_len += cert_field_len; + if (vce_len > vce_max_len) { + return -1; + } + + vce->vce_hdr.flags |=3D DIAG_320_VCE_FLAGS_VALID; + + /* Update vce length to reflect the actual size used by vce */ + vce->vce_hdr.len =3D cpu_to_be32(vce_len); + + return 0; +} + +static int handle_diag320_store_vc(S390CPU *cpu, uint64_t addr, uint64_t r= 1, uintptr_t ra, + S390IPLCertificateStore *cs) +{ + g_autofree VCBlockHeader *vcb_hdr =3D NULL; + size_t remaining_space; + uint16_t first_vc_index; + uint16_t last_vc_index; + int cs_start_index; + int cs_end_index; + uint32_t vce_max_len; + uint32_t vce_len; + uint32_t in_len; + + vcb_hdr =3D g_new0(VCBlockHeader, 1); + if (s390_cpu_virt_mem_read(cpu, addr, r1, vcb_hdr, sizeof(*vcb_hdr))) { + s390_cpu_virt_mem_handle_exc(cpu, ra); + return -1; + } + + in_len =3D be32_to_cpu(vcb_hdr->in_len); + first_vc_index =3D be16_to_cpu(vcb_hdr->first_vc_index); + last_vc_index =3D be16_to_cpu(vcb_hdr->last_vc_index); + + if (in_len % TARGET_PAGE_SIZE !=3D 0) { + return DIAG_320_RC_INVAL_VCB_LEN; + } + + if (first_vc_index > last_vc_index) { + return DIAG_320_RC_BAD_RANGE; + } + + vcb_hdr->out_len =3D sizeof(VCBlockHeader); + + /* + * DIAG 320 subcode 2 expects to query a certificate store that + * maintains an index origin of 1. However, the S390IPLCertificateStore + * maintains an index origin of 0. Thus, the indices must be adjusted + * for correct access into the cert store. A couple of special cases + * must also be accounted for. + */ + + /* Both indices are 0; return header with no certs */ + if (first_vc_index =3D=3D 0 && last_vc_index =3D=3D 0) { + goto out; + } + + /* Normalize indices */ + cs_start_index =3D (first_vc_index =3D=3D 0) ? 0 : first_vc_index - 1; + cs_end_index =3D last_vc_index - 1; + + /* Requested range is outside the cert store; return header with no ce= rts */ + if (cs_start_index >=3D cs->count || cs_end_index >=3D cs->count) { + goto out; + } + + remaining_space =3D in_len - sizeof(VCBlockHeader); + + for (int i =3D cs_start_index; i <=3D cs_end_index; i++) { + const S390IPLCertificate *cert =3D &cs->certs[i]; + /* + * Each field of the VCE is word-aligned. + * Allocate enough space for the largest possible size for this VC= E. + * As the certificate fields (key-id, hash, data) are parsed, the + * VCE's length field will be updated accordingly. + */ + vce_max_len =3D sizeof(VCEntryHeader) + ROUND_UP(CERT_KEY_ID_LEN, = 4) + + ROUND_UP(CERT_HASH_LEN, 4) + ROUND_UP(cert->der_size= , 4); + g_autofree VCEntry *vce =3D g_malloc0(vce_max_len); + + /* + * Bit 0 of the VCE flags indicates whether the certificate is val= id. + * The caller of DIAG320 subcode 2 is responsible for verifying th= at + * the VCE contains a valid certificate. + */ + if (build_vce_header(vce, cert, i) || build_vce_data(vce, cert, vc= e_max_len)) { + /* + * Error occurs - VCE does not contain a valid certificate. + * Bit 0 of the VCE flags is 0 and the VCE length is set. + */ + vce->vce_hdr.len =3D cpu_to_be32(VCE_INVALID_LEN); + } + vce_len =3D be32_to_cpu(vce->vce_hdr.len); + + /* + * If there is no more space to store the cert, + * set the remaining verification cert count and + * break early. + */ + if (remaining_space < vce_len) { + vcb_hdr->remain_ct =3D cpu_to_be16(last_vc_index - i); + break; + } + + /* Write VCE */ + if (s390_cpu_virt_mem_write(cpu, addr + vcb_hdr->out_len, r1, vce,= vce_len)) { + s390_cpu_virt_mem_handle_exc(cpu, ra); + return -1; + } + + vcb_hdr->out_len +=3D vce_len; + remaining_space -=3D vce_len; + vcb_hdr->stored_ct++; + } + vcb_hdr->stored_ct =3D cpu_to_be16(vcb_hdr->stored_ct); + +out: + vcb_hdr->out_len =3D cpu_to_be32(vcb_hdr->out_len); + + if (s390_cpu_virt_mem_write(cpu, addr, r1, vcb_hdr, sizeof(VCBlockHead= er))) { + s390_cpu_virt_mem_handle_exc(cpu, ra); + return -1; + } + + return DIAG_320_RC_OK; +} + QEMU_BUILD_BUG_MSG(sizeof(VCStorageSizeBlock) !=3D VCSSB_LEN_VALID, "size of VCStorageSizeBlock is wrong"); +QEMU_BUILD_BUG_MSG(sizeof(VCBlock) !=3D 64, "size of VCBlock is wrong"); +QEMU_BUILD_BUG_MSG(sizeof(VCEntry) !=3D 128, "size of VCEntry is wrong"); =20 void handle_diag_320(CPUS390XState *env, uint64_t r1, uint64_t r3, uintptr= _t ra) { @@ -273,7 +574,8 @@ void handle_diag_320(CPUS390XState *env, uint64_t r1, u= int64_t r3, uintptr_t ra) * for now. */ uint32_t ism_word0 =3D cpu_to_be32(DIAG_320_ISM_QUERY_SUBCODES | - DIAG_320_ISM_QUERY_VCSI); + DIAG_320_ISM_QUERY_VCSI | + DIAG_320_ISM_STORE_VC); =20 if (s390_cpu_virt_mem_write(cpu, addr, r1, &ism_word0, sizeof(ism_= word0))) { s390_cpu_virt_mem_handle_exc(cpu, ra); @@ -299,6 +601,18 @@ void handle_diag_320(CPUS390XState *env, uint64_t r1, = uint64_t r3, uintptr_t ra) } env->regs[r1 + 1] =3D rc; break; + case DIAG_320_SUBC_STORE_VC: + if (addr & ~TARGET_PAGE_MASK) { + s390_program_interrupt(env, PGM_SPECIFICATION, ra); + return; + } + + rc =3D handle_diag320_store_vc(cpu, addr, r1, ra, cs); + if (rc =3D=3D -1) { + return; + } + env->regs[r1 + 1] =3D rc; + break; default: env->regs[r1 + 1] =3D DIAG_320_RC_NOT_SUPPORTED; break; --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098341; cv=none; d=zohomail.com; s=zohoarc; b=VvnHHbwaxdmJ4njcG87yXupU+dpy5w6b3AM3yndH+Gdw+EeRKGPG7oP55d3nde1UoDLFnAOJJKPwcCNp/9KDSahz1plpD+iHGOgvW8ygLuWfsUzQxuSY4iFB0tExvwoXyvT4lRhVe33Ns5q2noaN4W6ymzwFFq3RLLIOLvuI/38= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098341; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=QGXDDUXKK2xre5/SnnNg35LEW56O+VfWaEd/bKTCS6Y=; b=Dc3JUGmESJRDmdgIQDEjSzRItfIpqby9PDRQIJB/cz2zZpwooV3U+hIRz5DZQTv9KyE/oAFpV5E7CBQoiqiJWlI1WAX/XAPmPqlMixNHs3SHwfdprZya6ki0aEfW/Okzmf7C0cWkINHOVa50l0L2yfgveap/JzM5vxy/Rhxsb64= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178309834119450.117771494836234; Fri, 3 Jul 2026 10:05:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhGs-0007xx-5U; Fri, 03 Jul 2026 13:01:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGO-0007gv-WD; Fri, 03 Jul 2026 13:01:18 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGM-000345-PH; Fri, 03 Jul 2026 13:01:16 -0400 Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GJlNr3247555; Fri, 3 Jul 2026 17:01:11 GMT Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26qafsu8-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:11 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gnjj6003106; Fri, 3 Jul 2026 17:01:10 GMT Received: from smtprelay06.dal12v.mail.ibm.com ([172.16.1.8]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2tbhsndb-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:10 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay06.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H19LE33096396 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:09 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 1078A5805C; Fri, 3 Jul 2026 17:01:09 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 18A4758064; Fri, 3 Jul 2026 17:01:06 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:05 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=QGXDDUXKK2xre5/Sn nNg35LEW56O+VfWaEd/bKTCS6Y=; b=ZQuXwsAkQ+cQ8g5QUcK+AMj8VWbTDrV4Y o8D6aUes9KXuGby3LANS07XIKrmCjxU9vhuAp7C1gFlfzi9E4RZSeExX4WDda5Ti lidoBUwPrINxcJBrq36+v5UFM7vD7whD/TKJEnKjVAcHGf1K+Ll/B8Gr4CykNsPo Nrcf8OQH9hLpo952rM44cwJXotaGPdDnjZtuH9el72YRGWFWVHM2WRsa/Px6q2gx o20nMVbYktkRsP0KmUkDsXQni4nenxZmHOSxUrvUpT3OveZ4tBBzv1e3Xy3tYwJ5 ddZuB5hDwHA/jz4Coyg7HD07VsA7xWr6YT9h+tLcxID5cL3Qkozdg== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 10/33] hw/s390x: Define finite size for single entry VCEntry Date: Fri, 3 Jul 2026 13:00:07 -0400 Message-ID: <20260703170032.1893204-11-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXyQBm/KDXKvlL PwXA2ziRoQT0h4NINZDQQIimTBWNZVV/1vKq0lfJ6MfZ5AyCPOSt8iUFfOTziuupF9EefDTleEn q8Ea9YBIW1RCky5yR6R6zM87hxl3V6/FI6KnUanFXE/u8Y46ZAQQutJ9UCWLpfFWcK5Eumf/sOW dU+uofBAqwfd8tmS2iHTCcl64s44+G+axhoXnsQeOs2Wt8HBZm254SQddrHi977A7rSaP1NS4c6 Q7wk2jQrVAQj/ZwXF5CA19o16NSSnjXi+25QmP4t7zPhfiv5HVLq72XJYXZbHM+GQ6lDLQX4vGF i2762ceSlLUy+M9G4snK1XhhD5u9xP1nuxN9QGiZWes0RaZo8q+S+lO9ONa/BSkzclMWhYd8rG3 Ukrm7hptIoKILNTzJVEP60HE0X2QPjh7Ucdh7e8Bi29PtjHRRTI/n9NpgacVD5bkiGb3kO/2KBs JIEodscdBdml29xReqg== X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXyPhMG1XB4V3u 3cgx5D7oDVpfnLUcVHdz6dRPh3EWMzAqjHB0TQYL4l80huCU4F8eEkACAHXj2nYYxQ7EzMZ9QmU +leYYHOEqQ7TLcNuYmEoSIhL8YFbMhM= X-Proofpoint-GUID: _4FovV8T5Q0RC-zBKI-E2PV0fJxwOlXr X-Proofpoint-ORIG-GUID: _4FovV8T5Q0RC-zBKI-E2PV0fJxwOlXr X-Authority-Analysis: v=2.4 cv=WZ88rUhX c=1 sm=1 tr=0 ts=6a47ead7 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=HeWPiYe96b1ufxwsDYQA:9 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 adultscore=0 phishscore=0 clxscore=1015 bulkscore=0 impostorscore=0 priorityscore=1501 lowpriorityscore=0 suspectscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098344037158500 Content-Type: text/plain; charset="utf-8" Define MAX_VCENTRY_SIZE(8KB) and CERT_BUF_MAX_LEN to establish a finite size for a single entry VCEntry. Add validation in update_cert_store() to ensure certificate data does not exceed this limit. This finite size definition is needed for proper memory allocation and will be used in a later commit to handle VCEntry structures with known size constraints. Signed-off-by: Zhuoying Cai Reviewed-by: Matthew Rosato Reviewed-by: Eric Farman --- hw/s390x/cert-store.c | 6 ++++++ include/hw/s390x/ipl/diag320.h | 3 +++ 2 files changed, 9 insertions(+) diff --git a/hw/s390x/cert-store.c b/hw/s390x/cert-store.c index aa2c1259eb..e5f79c4ed7 100644 --- a/hw/s390x/cert-store.c +++ b/hw/s390x/cert-store.c @@ -86,6 +86,12 @@ static int update_cert_store(S390IPLCertificateStore *ce= rt_store, cert_buf_size =3D ROUND_UP(cert->der_size, 4); data_buf_size =3D keyid_buf_size + hash_buf_size + cert_buf_size; =20 + if (data_buf_size > CERT_BUF_MAX_LEN) { + error_report("Certificate data size %zu exceeds maximum buffer siz= e %ld", + data_buf_size, CERT_BUF_MAX_LEN); + return -1; + } + if (cert_store->largest_cert_size < data_buf_size) { cert_store->largest_cert_size =3D data_buf_size; } diff --git a/include/hw/s390x/ipl/diag320.h b/include/hw/s390x/ipl/diag320.h index 7fda2d44fd..f3c23a3176 100644 --- a/include/hw/s390x/ipl/diag320.h +++ b/include/hw/s390x/ipl/diag320.h @@ -92,6 +92,9 @@ struct VCEntry { }; typedef struct VCEntry VCEntry; =20 +#define MAX_VCENTRY_SIZE (8 * 1024) +#define CERT_BUF_MAX_LEN (MAX_VCENTRY_SIZE - sizeof(VCEntryHeader)) + struct VCBlockHeader { uint32_t in_len; uint32_t reserved0; --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098165; cv=none; d=zohomail.com; s=zohoarc; b=kvllNzf/Dt5/AIVp8PDA7GDDZnQX8HRkhFhYGYsPAst/iMYJvUy+2NGylY6XyyKHxfUua70s9XDQjklSRATnLjATqHCNc9QbD92O7PBkRyK3qRIRGc4k9ANbGNwLvbKdnkkWMo1amp18oZ++eS37HnHjt6hk+fLXhhQaxmVVK8U= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098165; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=mxOAgalPCAZK6LEo4mt470EIxh2EZpWwIL7flqDNWTg=; b=J+wuABN26LLuZjtYErdGwwtqS+AxjbEZcMd+LusEdVTlYlwH75ImtOFtm3IzdQLsUzV0GWxp9kVFlB15hLidMgWsjqi5IqetOqD2tYq7jWZvqJ2rjwRcDiTL67IpZaBKSCyVRmloGiragMqupZ2HXDOsMcb+ImPoYWGPqnJ/Jy8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098165100158.10986217952734; Fri, 3 Jul 2026 10:02:45 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhH9-0008JI-2o; Fri, 03 Jul 2026 13:02:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGT-0007ho-BI; Fri, 03 Jul 2026 13:01:33 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGR-00034j-Ed; Fri, 03 Jul 2026 13:01:21 -0400 Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIhkw3497514; Fri, 3 Jul 2026 17:01:15 GMT Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26qgg6uq-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:14 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gnavg020075; Fri, 3 Jul 2026 17:01:13 GMT Received: from smtprelay02.wdc07v.mail.ibm.com ([172.16.1.69]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2u2gsk4v-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:13 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay02.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1CFp29557382 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:12 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 2D78F58062; Fri, 3 Jul 2026 17:01:12 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 496B45805D; Fri, 3 Jul 2026 17:01:09 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:09 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=mxOAgalPCAZK6LEo4 mt470EIxh2EZpWwIL7flqDNWTg=; b=S54dYFdyyoZU9Re2irgUIt0id7iYE+oMJ zAgqZVJ8Nv6NLJotHaxzy/ath8bQCqUA+5x7Q07uX2bV13uGePQPV+oq/TRIdtlI 9WyI8dV9kv9twBHkKrSfiZ7A/XmGAMkIUaDVFqNh3tJROBTFz0tdb9BsybmrOtp8 Agk51gGGYWdKL9uMf3fqu9+kDpkG5r1gp9yf0aI9IBw26Qw+n/jgFC2ZJsqZ0JxW 3sWIPreHe2jKK0+gTkZzOxbRRk4WC9BGfV2KJhoSGbct1JB+H5pEPliZkxkKz3fJ NAJGkSNj/Hj6OXQ9KYeRILEslFQlinq28ENMEhtC6GAk9gpbku44Q== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 11/33] s390x/diag: Introduce DIAG 508 for secure IPL operations Date: Fri, 3 Jul 2026 13:00:08 -0400 Message-ID: <20260703170032.1893204-12-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=RYqgzVtv c=1 sm=1 tr=0 ts=6a47eada cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=hXQcL9AfcS-IPDpH2m0A:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX9VSuIJlweF6A pFCE3eBixfZdlUtOABk5DlxczxLhV8AhAIE1iOi1z40ThXlXF2moBkC4TjWBx78Fass5E0ADQl2 3Vo0LK/54XQaZ6BdFDtHmbsN0G4oO1s= X-Proofpoint-GUID: qQAoPtmLmn0efYhBWq_xoNRW47BPLjWk X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX5DxgPlCtFIm2 b+alhAT4G29Vj6T03A0+jS6zJJVJ+9at3jA+PS8k16gjYm9oQjC7JbCbHIatMdih1LEZvX2S5FF RdTRLWEfLPtDz4/Es3/8X1sTdhVICcCTtu4QVIGKDzm99Jtrh+mNrLvPMVP9XzviR2Gi0vubaTi sa9b+nqAlhjPwj+HIgb63pxg7hKHTvWSBlngLAiXHCTp939SprKA9t4UyOpUqpf+6evYuH5L7Qk Izn9Yw8wCrhQEovvLG8Mqg8cpf/z19V6KNhz5KZ/cARuXvIp60F0Wo8z7WPcR7SKk5FR01HQKrN jpXVxfLqsGDcrEXu3Hs30NAD2Pst4oQ+p1URkzZUUQ/62aUoneANHF98gb6RqncCfRZlvQ4O0PB EysLasukjUc7tcNLcQ4cO3rMqblA3eawlUiv/TlptmS5ycWW7LsxjIawElxDdKceEPhVaEhcABG JmATpOTVoN9lZGrTjJQ== X-Proofpoint-ORIG-GUID: qQAoPtmLmn0efYhBWq_xoNRW47BPLjWk X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 impostorscore=0 malwarescore=0 spamscore=0 lowpriorityscore=0 adultscore=0 priorityscore=1501 suspectscore=0 bulkscore=0 clxscore=1015 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098166549158500 Content-Type: text/plain; charset="utf-8" From: Collin Walling In order to support secure IPL (aka secure boot) for the s390-ccw BIOS, a new s390 DIAGNOSE instruction is introduced to leverage QEMU for handling operations such as signature verification and certificate retrieval. Currently, only subcode 0 is supported with this patch, which is used to query a bitmap of which subcodes are supported. Signed-off-by: Collin Walling Reviewed-by: Farhan Ali Reviewed-by: Thomas Huth --- docs/specs/s390x-secure-ipl.rst | 18 ++++++++++++++++++ include/hw/s390x/ipl/diag508.h | 15 +++++++++++++++ target/s390x/diag.c | 27 +++++++++++++++++++++++++++ target/s390x/kvm/kvm.c | 14 ++++++++++++++ target/s390x/s390x-internal.h | 2 ++ target/s390x/tcg/misc_helper.c | 7 +++++++ 6 files changed, 83 insertions(+) create mode 100644 include/hw/s390x/ipl/diag508.h diff --git a/docs/specs/s390x-secure-ipl.rst b/docs/specs/s390x-secure-ipl.= rst index a17bb0ab55..2198805b47 100644 --- a/docs/specs/s390x-secure-ipl.rst +++ b/docs/specs/s390x-secure-ipl.rst @@ -66,3 +66,21 @@ Subcode 2 - store verification certificates contiguously in a VCE (with zero-padding). Following the header, the key-id is immediately stored. The hash and certificate data follow and may be accessed via the respective offset fields stored in the VCE. + + +Secure IPL Data Structures, Facilities, and Functions +----------------------------------------------------- + +DIAGNOSE function code 'X'508' - IPL extensions +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +DIAGNOSE 'X'508' is reserved for guest use in order to facilitate communic= ation +of additional IPL operations that cannot be handled by guest code, such as +signature verification for secure IPL. + +If the function code specifies 0x508, IPL extension functions are performe= d. +These functions are meant to provide extended functionality for s390 guest= boot +that requires assistance from QEMU. + +Subcode 0 - query installed subcodes + Returns a 64-bit mask indicating which subcodes are supported. diff --git a/include/hw/s390x/ipl/diag508.h b/include/hw/s390x/ipl/diag508.h new file mode 100644 index 0000000000..6281ad8299 --- /dev/null +++ b/include/hw/s390x/ipl/diag508.h @@ -0,0 +1,15 @@ +/* + * S/390 DIAGNOSE 508 definitions and structures + * + * Copyright 2025 IBM Corp. + * Author(s): Collin Walling + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#ifndef S390X_DIAG508_H +#define S390X_DIAG508_H + +#define DIAG_508_SUBC_QUERY_SUBC 0x0000 + +#endif diff --git a/target/s390x/diag.c b/target/s390x/diag.c index c072daca3a..88f419b09c 100644 --- a/target/s390x/diag.c +++ b/target/s390x/diag.c @@ -20,6 +20,7 @@ #include "hw/s390x/cert-store.h" #include "hw/s390x/ipl.h" #include "hw/s390x/ipl/diag320.h" +#include "hw/s390x/ipl/diag508.h" #include "hw/s390x/s390-virtio-ccw.h" #include "system/kvm.h" #include "kvm/kvm_s390x.h" @@ -618,3 +619,29 @@ void handle_diag_320(CPUS390XState *env, uint64_t r1, = uint64_t r3, uintptr_t ra) break; } } + +void handle_diag_508(CPUS390XState *env, uint64_t r1, uint64_t r3, uintptr= _t ra) +{ + uint64_t subcode =3D env->regs[r3]; + int rc; + + if (env->psw.mask & PSW_MASK_PSTATE) { + s390_program_interrupt(env, PGM_PRIVILEGED, ra); + return; + } + + if ((subcode & ~0x0ffffULL) || (r1 & 1)) { + s390_program_interrupt(env, PGM_SPECIFICATION, ra); + return; + } + + switch (subcode) { + case DIAG_508_SUBC_QUERY_SUBC: + rc =3D 0; + break; + default: + s390_program_interrupt(env, PGM_SPECIFICATION, ra); + return; + } + env->regs[r1 + 1] =3D rc; +} diff --git a/target/s390x/kvm/kvm.c b/target/s390x/kvm/kvm.c index 138b5b9c67..56795837f5 100644 --- a/target/s390x/kvm/kvm.c +++ b/target/s390x/kvm/kvm.c @@ -102,6 +102,7 @@ #define DIAG_CERT_STORE 0x320 #define DIAG_KVM_HYPERCALL 0x500 #define DIAG_KVM_BREAKPOINT 0x501 +#define DIAG_SECURE_IPL 0x508 =20 #define ICPT_INSTRUCTION 0x04 #define ICPT_PROGRAM 0x08 @@ -1542,6 +1543,16 @@ static void kvm_handle_diag_320(S390CPU *cpu, struct= kvm_run *run) handle_diag_320(&cpu->env, r1, r3, RA_IGNORED); } =20 +static void kvm_handle_diag_508(S390CPU *cpu, struct kvm_run *run) +{ + uint64_t r1, r3; + + r1 =3D (run->s390_sieic.ipa & 0x00f0) >> 4; + r3 =3D run->s390_sieic.ipa & 0x000f; + + handle_diag_508(&cpu->env, r1, r3, RA_IGNORED); +} + #define DIAG_KVM_CODE_MASK 0x000000000000ffff =20 static int handle_diag(S390CPU *cpu, struct kvm_run *run, uint32_t ipb) @@ -1575,6 +1586,9 @@ static int handle_diag(S390CPU *cpu, struct kvm_run *= run, uint32_t ipb) case DIAG_CERT_STORE: kvm_handle_diag_320(cpu, run); break; + case DIAG_SECURE_IPL: + kvm_handle_diag_508(cpu, run); + break; default: trace_kvm_insn_diag(func_code); kvm_s390_program_interrupt(cpu, PGM_SPECIFICATION); diff --git a/target/s390x/s390x-internal.h b/target/s390x/s390x-internal.h index 1945bdf40c..81da207a5f 100644 --- a/target/s390x/s390x-internal.h +++ b/target/s390x/s390x-internal.h @@ -390,6 +390,8 @@ bool handle_diag_308(CPUS390XState *env, uint64_t r1, u= int64_t r3, uintptr_t ra); void handle_diag_320(CPUS390XState *env, uint64_t r1, uint64_t r3, uintptr_t ra); +void handle_diag_508(CPUS390XState *env, uint64_t r1, uint64_t r3, + uintptr_t ra); =20 =20 /* translate.c */ diff --git a/target/s390x/tcg/misc_helper.c b/target/s390x/tcg/misc_helper.c index 403388145e..f1c8563af0 100644 --- a/target/s390x/tcg/misc_helper.c +++ b/target/s390x/tcg/misc_helper.c @@ -154,6 +154,13 @@ void HELPER(diag)(CPUS390XState *env, uint32_t r1, uin= t32_t r3, uint32_t num) bql_unlock(); r =3D 0; break; + case 0x508: + /* secure ipl operations */ + bql_lock(); + handle_diag_508(env, r1, r3, GETPC()); + bql_unlock(); + r =3D 0; + break; default: r =3D -1; break; --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098196; cv=none; d=zohomail.com; s=zohoarc; b=ZsPwXBrWjMfA265ZWjXzCZL3cXnNAPt9Zf5bU1MpKsFt2dX73CG12bqvEnFRDPMNL412anExbZuoBk9ijDVWLq75KQoNslqBcExD+pbLeJ4gbVQiDAek9M0azqwcsMKTqUkezBbu0/C+tttGpwuLdnkiQ1Ly+nLcbe8GN9WkCOs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098196; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=mXU26Fu2/R8eROgDuf/6BQoFcSLeWh1d8e0Fq3O8M8A=; b=OpbEl6ug4JDh55wdIuVBTbhspcljmflMUL0e1+qPpQPDQHuzQCTDHDdOb7GwDZG0/nKZ0GQuxZQguFNU5CRpLr+LQ1MzTdlaUW7dsyi9DIHL00tf2dqsCaFea0WchLNdXyyU9ODa/4SHcaOe7auLLA2IBDSe0F0+CLdaK1fpRq0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098196345721.6630899306804; Fri, 3 Jul 2026 10:03:16 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHG-0000CQ-1K; Fri, 03 Jul 2026 13:02:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGV-0007i5-Ds; Fri, 03 Jul 2026 13:01:38 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGT-00035K-HO; Fri, 03 Jul 2026 13:01:23 -0400 Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIX843302336; Fri, 3 Jul 2026 17:01:18 GMT Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26n688ws-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:18 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnhUc019692; Fri, 3 Jul 2026 17:01:17 GMT Received: from smtprelay05.wdc07v.mail.ibm.com ([172.16.1.72]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2ruqsy2v-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:17 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay05.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1F6O34341582 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:15 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8F35358054; Fri, 3 Jul 2026 17:01:15 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 62FD65805D; Fri, 3 Jul 2026 17:01:12 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:12 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=mXU26F u2/R8eROgDuf/6BQoFcSLeWh1d8e0Fq3O8M8A=; b=F3szkFL/gJJ7CiR0GtsJYm A9NKpmuAczHbAcRfN9EAuUiQdcbk7f3tatRVbEQhP8T2sNHAsmzfL+TN1DknHKGK XYWgMxnGSxg/OB6rC2QU5Z7qo4qC5WK0sTReSjx8a3uB26MC4FPyQuNCwjVcsDFY fF28fy8D+F81QX5rBSFsGr3v5v4HNddi0e/xRAhDZWoPS/Gha54yMglwDJR0sBna 4uWbtdz7CINHtrt2eqQlj1ya4HsEBNUX3l1BSOTmdTcz9X959RcFeyKu/KWaWp1w wCSEZRV7YfPZvzFAlchVHC6puO0eiHyV1JGSbN9xsUvRmTOQ2ldLFDQc+ko8l1Nw == From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 12/33] crypto/x509-utils: Add helper functions for DIAG 508 subcode 1 Date: Fri, 3 Jul 2026 13:00:09 -0400 Message-ID: <20260703170032.1893204-13-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXzeGU265Bl6L5 nReINMtDsxJAL2YwnO1WcUXSAWesDkfhs5lzoSeZ67P3CmeVwKwMktfW+jaWGmbRjogChfZzi2n IFLA4s3KMtLJ+pnW/I1YrYvzTWnWQA8OEhOmdXPUShyYb0iGGeoQ/z3RBu++zh5ybzWJilnnyYG lRAWWWijVWVgt74iXOZ917xuqB9N8joZky5p3qiWDilYAzMJIS+rmvUMmfxS2Rv5sdCYBRLaEJc THGqZeff9ovctP6FOfROdW3SDc/Wd9W0/A3o+cOA3OUMv+BQhOrQNB+ZAMhcg1XAiNrqZ9cG9Rh OtW0PzmbLgyeRNuPeXZEZPIn0B6HuR8inE2Q6JLmmUxIwcZH/mBXmSeE5W/VjP+ofRu1eUYLujc mtU+KPTdywQ8Ql2qTCmXKkHPY1pHBxQKifTbr5TntOlrGinmzmvRJ8fXi0bRLHe2WD62Gs5EyXy 8TpFNKzqinJNbXTUoRw== X-Authority-Analysis: v=2.4 cv=V45NF+ni c=1 sm=1 tr=0 ts=6a47eade cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=Ehcw9bocbOASTidboh8A:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 X-Proofpoint-ORIG-GUID: 7Adxots2MCey2gHZVWbrSRfySUaR8gGi X-Proofpoint-GUID: 7Adxots2MCey2gHZVWbrSRfySUaR8gGi X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX+qX2myLck/P6 S5ys4AUHIFbcm9sf+6YRimbBzy+btBir2vxWJj4q1Emp6we93HsYYTDWwEWa4PBt8whVpq8lXQm Ai/N5nGR4yP+WELIox+8aV32OV4Cubk= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 spamscore=0 suspectscore=0 lowpriorityscore=0 priorityscore=1501 adultscore=0 clxscore=1015 impostorscore=0 malwarescore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098196633158500 Introduce helper functions to support signature verification required by DIAG 508 subcode 1: qcrypto_pkcs7_convert_sig_pem() =E2=80=93 converts a signature from DER to = PEM format qcrypto_x509_verify_sig() =E2=80=93 verifies the provided data against the = given signature These functions enable basic signature verification support. Signed-off-by: Zhuoying Cai Acked-by: Daniel P. Berrang=C3=A9 Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Farhan Ali Reviewed-by: Thomas Huth --- crypto/x509-utils.c | 108 ++++++++++++++++++++++++++++++++++++ include/crypto/x509-utils.h | 41 ++++++++++++++ 2 files changed, 149 insertions(+) diff --git a/crypto/x509-utils.c b/crypto/x509-utils.c index d0e0384e9c..b23a5f0979 100644 --- a/crypto/x509-utils.c +++ b/crypto/x509-utils.c @@ -16,6 +16,7 @@ #include #include #include +#include =20 static const int qcrypto_to_gnutls_hash_alg_map[QCRYPTO_HASH_ALGO__MAX] = =3D { [QCRYPTO_HASH_ALGO_MD5] =3D GNUTLS_DIG_MD5, @@ -335,6 +336,96 @@ int qcrypto_x509_check_ecc_curve_p521(uint8_t *cert, s= ize_t size, Error **errp) return curve_id =3D=3D GNUTLS_ECC_CURVE_SECP521R1; } =20 +int qcrypto_pkcs7_convert_sig_pem(uint8_t *sig, size_t sig_size, + uint8_t **result, size_t *resultlen, + Error **errp) +{ + int ret =3D -1; + int rc; + gnutls_pkcs7_t signature; + gnutls_datum_t sig_datum_der =3D {.data =3D sig, .size =3D sig_size}; + gnutls_datum_t sig_datum_pem =3D {.data =3D NULL, .size =3D 0}; + + rc =3D gnutls_pkcs7_init(&signature); + if (rc < 0) { + error_setg(errp, "Failed to initialize pkcs7 data: %s", gnutls_str= error(rc)); + return ret; + } + + rc =3D gnutls_pkcs7_import(signature, &sig_datum_der, GNUTLS_X509_FMT_= DER); + if (rc !=3D 0) { + error_setg(errp, "Failed to import signature: %s", gnutls_strerror= (rc)); + goto cleanup; + } + + rc =3D gnutls_pkcs7_export2(signature, GNUTLS_X509_FMT_PEM, &sig_datum= _pem); + if (rc !=3D 0) { + error_setg(errp, "Failed to convert signature to PEM format: %s", + gnutls_strerror(rc)); + goto cleanup; + } + + *resultlen =3D sig_datum_pem.size; + *result =3D g_memdup2(sig_datum_pem.data, sig_datum_pem.size); + + ret =3D 0; + +cleanup: + gnutls_pkcs7_deinit(signature); + g_free(sig_datum_pem.data); + return ret; +} + +int qcrypto_x509_verify_sig(uint8_t *cert, size_t cert_size, + uint8_t *comp, size_t comp_size, + uint8_t *sig, size_t sig_size, Error **errp) +{ + int rc; + int ret =3D -1; + gnutls_x509_crt_t crt =3D NULL; + gnutls_pkcs7_t signature =3D NULL; + gnutls_datum_t cert_datum =3D {.data =3D cert, .size =3D cert_size}; + gnutls_datum_t data_datum =3D {.data =3D comp, .size =3D comp_size}; + gnutls_datum_t sig_datum =3D {.data =3D sig, .size =3D sig_size}; + + rc =3D gnutls_x509_crt_init(&crt); + if (rc < 0) { + error_setg(errp, "Failed to initialize certificate: %s", gnutls_st= rerror(rc)); + goto cleanup; + } + + rc =3D gnutls_x509_crt_import(crt, &cert_datum, GNUTLS_X509_FMT_PEM); + if (rc !=3D 0) { + error_setg(errp, "Failed to import certificate: %s", gnutls_strerr= or(rc)); + goto cleanup; + } + + rc =3D gnutls_pkcs7_init(&signature); + if (rc < 0) { + error_setg(errp, "Failed to initialize pkcs7 data: %s", gnutls_str= error(rc)); + goto cleanup; + } + + rc =3D gnutls_pkcs7_import(signature, &sig_datum , GNUTLS_X509_FMT_PEM= ); + if (rc !=3D 0) { + error_setg(errp, "Failed to import signature: %s", gnutls_strerror= (rc)); + goto cleanup; + } + + rc =3D gnutls_pkcs7_verify_direct(signature, crt, 0, &data_datum, 0); + if (rc !=3D 0) { + error_setg(errp, "Failed to verify signature: %s", gnutls_strerror= (rc)); + goto cleanup; + } + + ret =3D 0; + +cleanup: + gnutls_x509_crt_deinit(crt); + gnutls_pkcs7_deinit(signature); + return ret; +} + #else /* ! CONFIG_GNUTLS */ =20 int qcrypto_get_x509_cert_fingerprint(uint8_t *cert, size_t size, @@ -378,4 +469,21 @@ int qcrypto_x509_check_ecc_curve_p521(uint8_t *cert, s= ize_t size, Error **errp) return -1; } =20 +int qcrypto_pkcs7_convert_sig_pem(uint8_t *sig, size_t sig_size, + uint8_t **result, + size_t *resultlen, + Error **errp) +{ + error_setg(errp, "GNUTLS is required to export pkcs7 signature"); + return -1; +} + +int qcrypto_x509_verify_sig(uint8_t *cert, size_t cert_size, + uint8_t *comp, size_t comp_size, + uint8_t *sig, size_t sig_size, Error **errp) +{ + error_setg(errp, "GNUTLS is required for signature-verification suppor= t"); + return -1; +} + #endif /* ! CONFIG_GNUTLS */ diff --git a/include/crypto/x509-utils.h b/include/crypto/x509-utils.h index fcace73c49..c256d7bfad 100644 --- a/include/crypto/x509-utils.h +++ b/include/crypto/x509-utils.h @@ -91,4 +91,45 @@ int qcrypto_x509_get_cert_key_id(uint8_t *cert, size_t s= ize, */ int qcrypto_x509_check_ecc_curve_p521(uint8_t *cert, size_t size, Error **= errp); =20 +/** + * qcrypto_pkcs7_convert_sig_pem + * @sig: pointer to the PKCS#7 signature in DER format + * @sig_size: size of the signature + * @result: output location for the allocated buffer for the signature in + * PEM format + * (the function allocates memory which must be freed by the call= er) + * @resultlen: pointer to the size of the buffer + * (will be updated with the actual size of the PEM-encoded + * signature) + * @errp: error pointer + * + * Convert given PKCS#7 @sig from DER to PEM format. + * + * Returns: 0 if PEM-encoded signature was successfully stored in @result, + * -1 on error. + */ +int qcrypto_pkcs7_convert_sig_pem(uint8_t *sig, size_t sig_size, + uint8_t **result, + size_t *resultlen, + Error **errp); + +/** + * qcrypto_x509_verify_sig + * @cert: pointer to the raw certificate data + * @cert_size: size of the certificate + * @comp: pointer to the component to be verified + * @comp_size: size of the component + * @sig: pointer to the signature + * @sig_size: size of the signature + * @errp: error pointer + * + * Verify the provided @comp against the @sig and @cert. + * + * Returns: 0 on success, + * -1 on error. + */ +int qcrypto_x509_verify_sig(uint8_t *cert, size_t cert_size, + uint8_t *comp, size_t comp_size, + uint8_t *sig, size_t sig_size, Error **errp); + #endif --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098234; cv=none; d=zohomail.com; s=zohoarc; b=REaY8AJlmbkeMPS1mdv4rDBbWXqLXbVS8VqPvpSjXCLYXNp5cI3Ze5to9sZc5Q5EosjnxhSCDBJwbyCotZ9Vbi04rQk4XVA8tGiyqmjS7+cWG3tp27xERTdH7owtQrYbuvBpsdFrM12yJYO7VIFFHCR5rPL6iUKUG7zt4uPJrAI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098234; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lu3QbY+g0p0+jeLci7FBbk6h1r1LS24kIcCOmb97Vo4=; b=gmM1H4HPcdebX2w20IUOGk4GWMMZ7AeFDdGoz0MWlYWLzuplgky8w+5yNjTkdZJ8SnB3l2WoxG8SxB7v7dEeM9ujkyj6UJdDHcYZtPREykSaC+w2oFv1bUlPInltffofLZZxzgsX1ZqDB3SJfqEfx4JuHe068qBSl5bZ42N5+70= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098234066183.68785402633273; Fri, 3 Jul 2026 10:03:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHL-0000v1-Lb; Fri, 03 Jul 2026 13:02:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGb-0007o7-A0; Fri, 03 Jul 2026 13:01:38 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGW-00036n-69; Fri, 03 Jul 2026 13:01:26 -0400 Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIxHT3236885; Fri, 3 Jul 2026 17:01:21 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26rffmeq-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:20 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gnch1025854; Fri, 3 Jul 2026 17:01:20 GMT Received: from smtprelay02.dal12v.mail.ibm.com ([172.16.1.4]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2sukhqrc-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:20 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay02.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1IkB9700018 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:19 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id C05BB5805C; Fri, 3 Jul 2026 17:01:18 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id C816A58054; Fri, 3 Jul 2026 17:01:15 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:15 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=lu3QbY+g0p0+jeLci 7FBbk6h1r1LS24kIcCOmb97Vo4=; b=iCwYWR3V5hd5lDNABmGu3jexMHxQXB2y9 W/01huEspxAwBz4PFfBguvz7yqQrOXJ+0kf6YawauLLKfzZjtOQO6QzUk8ilCvPS 6X4/LdRiJnNZsbYY5bUkWg8jusY+pkFaauXePHH2H/QfLtqg9hUShySPa/XE5dMf HQmEg/FuWQ+OqzPMR865dg3Fzej/T4Nrx9gVkGXGH03+2YJgXSIdMh0LJq4MKnfA roATwmtgfiaMLJezrV4M8LdZveblD5M4ghFy4mgGfj1r5Yf5Gdvc/hH+XJqlEg4c 7JLSO/qy7T+QOmKImk26tuKeNlN8Qpzxb8q3uSQ22Uwf+vi4T6RAQ== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 13/33] s390x/diag: Generalize s390_ipl_read/write to accept void * Date: Fri, 3 Jul 2026 13:00:10 -0400 Message-ID: <20260703170032.1893204-14-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=a4kAM0SF c=1 sm=1 tr=0 ts=6a47eae0 cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VnNF1IyMAAAA:8 a=CkZHjoNxVx3BTC6vW7wA:9 X-Proofpoint-ORIG-GUID: rRKQhnLw3iquqxZXYFUJhrKxYIrlJOQO X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX8oI2tquT2+rT pvrcjHqXLoykHS9SjRJpMarVbI++EyjPkvWpRJZqe8mLjVkoI/PKABO44cW+eWUrHqKqov27/qg /OpUoxRQaGMfgT3rGEBMjYvIYDNvmnlr6HfBUDTiEY7Ac+awgn4xuj7mCAd9f5SFBI4lpNH4hjh SVG55v2pZ7Co/7eXmhPDmYxabcCO0eFXQ5mCjaR08DCviWXHBTKt7EKiEmtRq+8Xq8Ec94o1wRW 1tpsUqeHa3pec1ULFVp//CG/m+ImFZI6ZrlMwKypcW5eUPMv7OCTv6maTZ8U0jmZe5aKdCHbjjp 0aPjFxxv5sudzyvXiuJx7Nb9Mj/UII6gzlMT2B624rBeqWLrGVmOYTpZLFslvO0GKjwomeMDdar utdiiVimMjb0//buWdKj/5WceUIrsbUYy/YX8zERfAHA8viNsCS2FWmi0aLTvYMIbW/xbXlwE5p nchqPMv+vgH8p48DqTg== X-Proofpoint-GUID: rRKQhnLw3iquqxZXYFUJhrKxYIrlJOQO X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXyZYatqIzSVk9 BLZ14TTTiY4Ke25dXRdvX2NI0uKY+AKzkrUpAB5jYfq67i92m2DLJlA3RRRF/pghI3UHBBh0y1E 1//h2X7R9cvf8uH70bf962w1nM4pQPs= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 bulkscore=0 suspectscore=0 lowpriorityscore=0 impostorscore=0 spamscore=0 priorityscore=1501 adultscore=0 malwarescore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098235030158500 Content-Type: text/plain; charset="utf-8" Change the data parameter of s390_ipl_read() and s390_ipl_write() from IplParameterBlock * to void *, so the helpers can be reused beyond DIAG 308. Signed-off-by: Zhuoying Cai Reviewed-by: Jared Rossi Reviewed-by: Matthew Rosato --- target/s390x/diag.c | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/target/s390x/diag.c b/target/s390x/diag.c index 88f419b09c..73701360da 100644 --- a/target/s390x/diag.c +++ b/target/s390x/diag.c @@ -83,24 +83,24 @@ static int diag308_parm_check(CPUS390XState *env, uint6= 4_t r1, uint64_t addr, } =20 static void s390_ipl_read(CPUS390XState *env, uint64_t addr, - IplParameterBlock *iplb, size_t size) + void *data, size_t size) { if (s390_is_pv()) { - s390_cpu_pv_mem_read(env_archcpu(env), 0, iplb, size); + s390_cpu_pv_mem_read(env_archcpu(env), 0, data, size); } else { address_space_read(cpu_get_address_space(env_cpu(env), 0), addr, - MEMTXATTRS_UNSPECIFIED, iplb, size); + MEMTXATTRS_UNSPECIFIED, data, size); } } =20 static void s390_ipl_write(CPUS390XState *env, uint64_t addr, - IplParameterBlock *iplb, size_t size) + void *data, size_t size) { if (s390_is_pv()) { - s390_cpu_pv_mem_write(env_archcpu(env), 0, iplb, size); + s390_cpu_pv_mem_write(env_archcpu(env), 0, data, size); } else { address_space_write(cpu_get_address_space(env_cpu(env), 0), addr, - MEMTXATTRS_UNSPECIFIED, iplb, size); + MEMTXATTRS_UNSPECIFIED, data, size); } } =20 --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098167; cv=none; d=zohomail.com; s=zohoarc; b=KvoBkvh8dLW8XzbQAH4i5bFir2Lzt2O8i3PoFNNEFnR+iVyJdX6JDceNNb6mC8epNSOTtnHx9XwV8qdVFTQmuY5cUUjWDLFuDYRoUCv3hHamnHMMw/Szo51KgzW/H+cio6x9ho8fh6xcyONrZ2UTynBjEdj4CboiquEI5Z8A87E= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098167; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Cn7T5IY96pRzSXoiV/+vuzCIIiePz1WJo5owYRDGVj0=; b=XuO4w4I7DhK4KBkpqgKbfeBG+94Qdib8liPy+2bV6VKQSTVwCpGxOjmv5odQqJouIbtz+yADraeGGcWTUZ008B7qkXqw3xUKXQrETE6db+wEtoTCrsLVPw1QCqWMYcfFEbCnTf9XoOh+mlUh73xzuIxTJTvMguZ1qLzYl3o0ao4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098167374809.5683193486649; Fri, 3 Jul 2026 10:02:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhH9-0008PJ-A9; Fri, 03 Jul 2026 13:02:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGe-0007r8-He; Fri, 03 Jul 2026 13:01:38 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGb-0003CK-Bu; Fri, 03 Jul 2026 13:01:30 -0400 Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GKOTX3250211; Fri, 3 Jul 2026 17:01:24 GMT Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26qafsur-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:23 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnlBQ001538; Fri, 3 Jul 2026 17:01:23 GMT Received: from smtprelay05.dal12v.mail.ibm.com ([172.16.1.7]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2s7whtd0-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:23 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay05.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1LD133751346 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:22 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id CAF5258062; Fri, 3 Jul 2026 17:01:21 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 04FB55805A; Fri, 3 Jul 2026 17:01:19 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:18 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=Cn7T5IY96pRzSXoiV /+vuzCIIiePz1WJo5owYRDGVj0=; b=Wv9r+S4Qcqneit2VOffp2VOd7/f3XdnxV AgvLuPnKK/FCXU5VpaCcIdUnyDUc1AyDj7IEv4xGUKl4OkN/F5IWS8oq+OkMutin VTI+BSh/GtSW80j8eMLMpljaLQRJnD4i6k8rJejQcle49Ig4lK0V/7W/MT+m1VbM kkTym/y6y7bTbEK8ftplJbg1mh6AnNqf7ic6KsmZDZLs6mJ9am1b0RARrcxczyRS 2KU1oxKLf+384RO9yPPqF8UO9PU4W0YnB0OaNePuh+lb+aaqlhpOcMFHG1bCEz95 6WMHJ3qRvgVj0qhwdWgM6Y8IHPqPYnQQCEgVt8TijZIIaPux/1q8w== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 14/33] s390x/diag: Implement DIAG 508 subcode 1 for signature verification Date: Fri, 3 Jul 2026 13:00:11 -0400 Message-ID: <20260703170032.1893204-15-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX4k+p3SHCPTwW ltPT6l2gcOT1VrSgk6oh6Kspz+TRhMxgURf6q6MPkGHV+EXMn1IvH544APhci/KbQRTdZBIqfgK ifJ/0DmyUHf/L+rIjf72vogHY85QU+WnTvI9gZ+DIIQlE5E0nt+W+FWA96aec/YYGpE4bjyffX7 wKnLqkLR/eDskFa1It9MPhxv5/wEV2L/mYECYWyghZEBvKGRsD1TuiZHXXXrtr+1D7125cm+Uha 7YjF3W8l0KN5OZUCY0lsgax6J1i+EC7Sn5nFUHx+HoteaamE2QTlDqpknQffTSkpVw0qzlAnKTI J+aCioNSljW+YHDXXmlQDVqGQi2mmB4tNY1TkQ4budqlwaCtN7UaEZnoS+mLhjynuJ1puHp/RHW Zg+ZxwSjfHq0D7hPeDNNlvxQsWpjSPu9/MRk8lF1DLOi7IV99U8gJAxsjQGWWS7r5eevDyUDqtN uGwTyUG3+jy/Ag7uOLg== X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX4/gcPn5NXaEo ZdE5BxjlRk5Qdf9Kd4MFsY+ZcfxwqYyDLNmQR3XS6+yGPrgKAw01MjZJDqkjoOwQYpbYYxrXJt5 zhVlbHfLfQo0rQDrSCaGXBHBhENQZdw= X-Proofpoint-GUID: pbvcFrYt3mJ12EXfrEJGcQCS_ss9om8z X-Proofpoint-ORIG-GUID: pbvcFrYt3mJ12EXfrEJGcQCS_ss9om8z X-Authority-Analysis: v=2.4 cv=WZ88rUhX c=1 sm=1 tr=0 ts=6a47eae4 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=K66z3tz1c1WH2lCF3KIA:9 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 adultscore=0 phishscore=0 clxscore=1015 bulkscore=0 impostorscore=0 priorityscore=1501 lowpriorityscore=0 suspectscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098168630158500 Content-Type: text/plain; charset="utf-8" From: Collin Walling DIAG 508 subcode 1 performs signature-verification on signed components. A signed component may be a Linux kernel image, or any other signed binary. **Verification of initrd is not supported.** The instruction call expects two item-pairs: an address of a device component, an address of the analogous signature file (in PKCS#7 DER format= ), and their respective lengths. All of this data should be encapsulated within a Diag508SigVerifBlock. The DIAG handler will read from the provided addresses to retrieve the necessary data, parse the signature file, then perform the signature-verification. Because there is no way to correlate a specific certificate to a component, each certificate in the store is tried until either verification succeeds, or all certs have been exhausted. A return code of 1 indicates success, and the index and length of the corresponding certificate will be set in the Diag508SigVerifBlock. The following values indicate failure: 0x0102: no certificates are available in the store 0x0202: component data is invalid 0x0302: PKCS#7 format signature is invalid 0x0402: signature-verification failed 0x0502: length of Diag508SigVerifBlock is invalid Signed-off-by: Collin Walling Signed-off-by: Zhuoying Cai Reviewed-by: Thomas Huth Reviewed-by: Farhan Ali --- docs/specs/s390x-secure-ipl.rst | 17 +++++ include/hw/s390x/ipl/diag508.h | 30 +++++++++ target/s390x/diag.c | 111 +++++++++++++++++++++++++++++++- 3 files changed, 157 insertions(+), 1 deletion(-) diff --git a/docs/specs/s390x-secure-ipl.rst b/docs/specs/s390x-secure-ipl.= rst index 2198805b47..a8be863548 100644 --- a/docs/specs/s390x-secure-ipl.rst +++ b/docs/specs/s390x-secure-ipl.rst @@ -84,3 +84,20 @@ that requires assistance from QEMU. =20 Subcode 0 - query installed subcodes Returns a 64-bit mask indicating which subcodes are supported. + +Subcode 1 - perform signature verification + Perform signature-verification on a signed component, using certificat= es + from the certificate store and leveraging qcrypto libraries to perform + this operation. + + Note: verification of initrd is not supported. + + A return code of 1 indicates success, and the index and length of the + corresponding certificate will be set in the Diag508SigVerifBlock. + The following values indicate failure: + + * ``0x0102``: no certificates are available in the store + * ``0x0202``: component data is invalid + * ``0x0302``: PKCS#7 format signature is invalid + * ``0x0402``: signature-verification failed + * ``0x0502``: length of Diag508SigVerifBlock is invalid diff --git a/include/hw/s390x/ipl/diag508.h b/include/hw/s390x/ipl/diag508.h index 6281ad8299..8a147f32a0 100644 --- a/include/hw/s390x/ipl/diag508.h +++ b/include/hw/s390x/ipl/diag508.h @@ -11,5 +11,35 @@ #define S390X_DIAG508_H =20 #define DIAG_508_SUBC_QUERY_SUBC 0x0000 +#define DIAG_508_SUBC_SIG_VERIF 0x8000 + +#define DIAG_508_RC_OK 0x0001 +#define DIAG_508_RC_NO_CERTS 0x0102 +#define DIAG_508_RC_INVAL_COMP_DATA 0x0202 +#define DIAG_508_RC_INVAL_PKCS7_SIG 0x0302 +#define DIAG_508_RC_FAIL_VERIF 0x0402 +#define DIAG_508_RC_INVAL_LEN 0x0502 + +/* + * Maximum componenet and signature sizes for current secure boot implemen= tation + * Not architecturally defined and may need to revisit if increased + */ +#define DIAG_508_MAX_COMP_LEN 0x10000000 +#define DIAG_508_MAX_SIG_LEN 4096 + +struct Diag508SigVerifBlock { + uint32_t length; + uint8_t reserved0[3]; + uint8_t version; + uint32_t reserved[2]; + uint8_t cert_store_index; + uint8_t reserved1[7]; + uint64_t cert_len; + uint64_t comp_len; + uint64_t comp_addr; + uint64_t sig_len; + uint64_t sig_addr; +}; +typedef struct Diag508SigVerifBlock Diag508SigVerifBlock; =20 #endif diff --git a/target/s390x/diag.c b/target/s390x/diag.c index 73701360da..087c168d4d 100644 --- a/target/s390x/diag.c +++ b/target/s390x/diag.c @@ -620,9 +620,110 @@ void handle_diag_320(CPUS390XState *env, uint64_t r1,= uint64_t r3, uintptr_t ra) } } =20 +static bool diag_508_verify_sig(uint8_t *cert, size_t cert_size, + uint8_t *comp, size_t comp_size, + uint8_t *sig, size_t sig_size) +{ + g_autofree uint8_t *sig_pem =3D NULL; + size_t sig_size_pem; + int rc; + + /* + * PKCS#7 signature with DER format + * Convert to PEM format for signature verification + * + * Ignore errors during qcrypto signature format conversion and verifi= cation + * Return false on any error, treating it as a verification failure + */ + rc =3D qcrypto_pkcs7_convert_sig_pem(sig, sig_size, &sig_pem, &sig_siz= e_pem, NULL); + if (rc < 0) { + return false; + } + + rc =3D qcrypto_x509_verify_sig(cert, cert_size, + comp, comp_size, + sig_pem, sig_size_pem, NULL); + if (rc < 0) { + return false; + } + + return true; +} + +static int handle_diag508_sig_verif(CPUS390XState *env, uint64_t addr) +{ + int verified; + uint32_t svb_len; + uint64_t comp_len, comp_addr; + uint64_t sig_len, sig_addr; + g_autofree uint8_t *comp =3D NULL; + g_autofree uint8_t *sig =3D NULL; + g_autofree Diag508SigVerifBlock *svb =3D NULL; + size_t svb_size =3D sizeof(Diag508SigVerifBlock); + S390IPLCertificateStore *cs =3D s390_ipl_get_certificate_store(); + + if (!cs->count) { + return DIAG_508_RC_NO_CERTS; + } + + svb =3D g_new0(Diag508SigVerifBlock, 1); + s390_ipl_read(env, addr, svb, svb_size); + + svb_len =3D be32_to_cpu(svb->length); + if (svb_len !=3D svb_size) { + return DIAG_508_RC_INVAL_LEN; + } + + comp_len =3D be64_to_cpu(svb->comp_len); + comp_addr =3D be64_to_cpu(svb->comp_addr); + sig_len =3D be64_to_cpu(svb->sig_len); + sig_addr =3D be64_to_cpu(svb->sig_addr); + + if (!comp_len || !comp_addr || comp_len > DIAG_508_MAX_COMP_LEN) { + if (comp_len > DIAG_508_MAX_COMP_LEN) { + warn_report("DIAG 0x508: component length %lu exceeds current = maximum %u", + comp_len, DIAG_508_MAX_COMP_LEN); + } + return DIAG_508_RC_INVAL_COMP_DATA; + } + + if (!sig_len || !sig_addr || sig_len > DIAG_508_MAX_SIG_LEN) { + if (sig_len > DIAG_508_MAX_SIG_LEN) { + warn_report("DIAG 0x508: signature length %lu exceeds current = maximum %u", + sig_len, DIAG_508_MAX_SIG_LEN); + } + return DIAG_508_RC_INVAL_PKCS7_SIG; + } + + comp =3D g_malloc0(comp_len); + s390_ipl_read(env, comp_addr, comp, comp_len); + + sig =3D g_malloc0(sig_len); + s390_ipl_read(env, sig_addr, sig, sig_len); + + for (int i =3D 0; i < cs->count; i++) { + verified =3D diag_508_verify_sig(cs->certs[i].raw, + cs->certs[i].size, + comp, comp_len, + sig, sig_len); + if (verified) { + svb->cert_store_index =3D i; + svb->cert_len =3D cpu_to_be64(cs->certs[i].der_size); + s390_ipl_write(env, addr, svb, svb_size); + return DIAG_508_RC_OK; + } + } + + return DIAG_508_RC_FAIL_VERIF; +} + +QEMU_BUILD_BUG_MSG(sizeof(Diag508SigVerifBlock) !=3D 64, + "size of Diag508SigVerifBlock is wrong"); + void handle_diag_508(CPUS390XState *env, uint64_t r1, uint64_t r3, uintptr= _t ra) { uint64_t subcode =3D env->regs[r3]; + uint64_t addr =3D env->regs[r1]; int rc; =20 if (env->psw.mask & PSW_MASK_PSTATE) { @@ -637,7 +738,15 @@ void handle_diag_508(CPUS390XState *env, uint64_t r1, = uint64_t r3, uintptr_t ra) =20 switch (subcode) { case DIAG_508_SUBC_QUERY_SUBC: - rc =3D 0; + rc =3D DIAG_508_SUBC_SIG_VERIF; + break; + case DIAG_508_SUBC_SIG_VERIF: + if (!diag_parm_addr_valid(addr, sizeof(Diag508SigVerifBlock), true= )) { + s390_program_interrupt(env, PGM_ADDRESSING, ra); + return; + } + + rc =3D handle_diag508_sig_verif(env, addr); break; default: s390_program_interrupt(env, PGM_SPECIFICATION, ra); --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098208; cv=none; d=zohomail.com; s=zohoarc; b=Ua6kZ9E8fMnCjmfYEEdZeEEBIClwgS9nSOJk1KkSLLOygqXqmOx75VOn5r8ydqKhpunvpgyfF5a6j68Ze5dMhX654pYeNdSpfoXw/R2LGyQ3TllcwBLNNNx9TR0/L+p1b8/h9X2jWk6HAzlS4b7ZbS3QwnwGGuXuexR5PyztyrY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098208; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=5/C4+8Obu9t+F8Dno8hhZNl0p8nzU7MhbERiaRJZ0wY=; b=fAzMt/TnR/+O5h+SAZ6WZbHk3SosRkxNx/izfFab0XTrtt6eixlYKRg+d6sZIFHp1Z/lYwCOQrm2Iun0u0CeMwU7oDg9p8UbWNvXOwq2umSiejOcI1hFpNYUvBwSY4burz6gPznqfIj90HcO8wDlqWshj337vo0O5Ls13dwJgjA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098208018246.16029820690335; Fri, 3 Jul 2026 10:03:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHG-0000Gs-Ey; Fri, 03 Jul 2026 13:02:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGg-0007rL-JB; Fri, 03 Jul 2026 13:01:38 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGe-0003E4-KD; Fri, 03 Jul 2026 13:01:34 -0400 Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GJ8tq3237356; Fri, 3 Jul 2026 17:01:27 GMT Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26rffmf2-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:27 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gnavo020075; Fri, 3 Jul 2026 17:01:26 GMT Received: from smtprelay02.wdc07v.mail.ibm.com ([172.16.1.69]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2u2gsk61-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:26 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay02.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1PFL21955320 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:25 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 0B9B85805D; Fri, 3 Jul 2026 17:01:25 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 221655805A; Fri, 3 Jul 2026 17:01:22 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:21 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=5/C4+8 Obu9t+F8Dno8hhZNl0p8nzU7MhbERiaRJZ0wY=; b=RaP7S/TGo/zrTHeH4iBQf9 Z1CGjmOdUAzve4z+Ck7kkXeI1i+gwb24wH5HNCAen99LGFntQ78bLzRFxHEC0AsZ mlnRIHnyPsbT2JU8j3/u7JSvbeeERwv1vBoHZ3Lus5exKMrYib8VFntmf5394m62 19mmMQGjMSY98gZb/L1ZQq+CBUQGnFZ64IyvlwhGtr7uA59sXpx9BKniIkJ1QFAi ANXuqkPs0gazayHUZgGR/4Cn9PQpv/PGCRcCxe7ZhmaXe4szVIpJOnvfgatRiCt7 AEQToPcSsyxWCcYxrR+BFA5wE4MxxU5CPTyFXjsc2qoYGpMZyJLOdKhueG0fcFjQ == From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 15/33] s390x/ipl: Introduce IPL Information Report Block (IIRB) Date: Fri, 3 Jul 2026 13:00:12 -0400 Message-ID: <20260703170032.1893204-16-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=a4kAM0SF c=1 sm=1 tr=0 ts=6a47eae7 cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VnNF1IyMAAAA:8 a=1NTGDykL02WXTEG3Jz0A:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 X-Proofpoint-ORIG-GUID: epEsYLIF0PWiVlE4c5ZLl9HdDRZbpa4B X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX+5fO2W1VXzsF YWFFqWWZ3wp2J2DLbtKmNHTcL83lRKAsE1j9js9is+X+p3zaOABRQV+DCChIRP/k1sNCa2B+PjA OrhRFOtekGN+ESFs/Xdfa1M84v3IP4rSYhjscMoUFUJvFLdniI95vcEaXTEYS0AUBWO0dbgxJfP CgpyAFLnXxIXGXpOWLlMBkR3cUrPr71ibMi6GA31LAjLPk0FgqD8GzgVOONHMpGzNQ3ytB6nizO USySKWUOwDcsEGM+qI22WvE57o5T/kNWWtRNA8KzLp0G7DKFHzgLWlCgPq3+LBvTO0ftNaHr0AC nEDxHvrQeaam5Yd4D019GPW4fbfZzp6I1QON7u9reYwRuhqYGzGmKq5g0xdw64Rr7T1l5fTrDwQ ArMkfZFLKPQhulX8Jc2VtWiEcOzKgJiPRw8pQ8/0VYYdSJpjgnodDgwXOTfp/3eyzxpVwmfehvP jMZ9UApTLww7yMkEqkg== X-Proofpoint-GUID: epEsYLIF0PWiVlE4c5ZLl9HdDRZbpa4B X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXzVaE5Yk1h6mJ Ugu63QqQcG/S702K39Gn2uQ4bts5Guf5ArIEsZEW0UqtbNQtR2enBk34CNvFTKrDyQFoRQkfAKS AYwTqxYCk74qG/LF3KxlhbuVkMeBGrk= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 bulkscore=0 suspectscore=0 lowpriorityscore=0 impostorscore=0 spamscore=0 priorityscore=1501 adultscore=0 malwarescore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098208809158500 The IPL information report block (IIRB) contains information used to locate IPL records and to report the results of signature verification of one or more secure components of the load device. IIRB is stored immediately following the IPL Parameter Block. Results on component verification in any case (failure or success) are stored. The IIRB data is reserved and protected by the guest kernel during early boot to prevent it from being overwritten before the certificate data is permanently saved. Signed-off-by: Zhuoying Cai Reviewed-by: Farhan Ali Reviewed-by: Collin Walling --- docs/specs/s390x-secure-ipl.rst | 21 +++++++++++ include/hw/s390x/ipl/qipl.h | 62 +++++++++++++++++++++++++++++++++ 2 files changed, 83 insertions(+) diff --git a/docs/specs/s390x-secure-ipl.rst b/docs/specs/s390x-secure-ipl.= rst index a8be863548..850e4a7497 100644 --- a/docs/specs/s390x-secure-ipl.rst +++ b/docs/specs/s390x-secure-ipl.rst @@ -101,3 +101,24 @@ Subcode 1 - perform signature verification * ``0x0302``: PKCS#7 format signature is invalid * ``0x0402``: signature-verification failed * ``0x0502``: length of Diag508SigVerifBlock is invalid + +IPL Information Report Block +^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +The IPL Parameter Block (IPLB), utilized for IPL operation, is extended wi= th an +IPL Information Report Block (IIRB), which contains the results from secur= e IPL +operations such as: + +* component data +* verification results +* certificate data + +During early boot, the guest kernel reserves the memory region +containing the IIRB. This preserves the data while the guest kernel is +operating and during re-IPL. + +The guest kernel uses the contents in the IIRB for: + +* Boot logging: reports which components were loaded and verified. +* kexec operations: builds the next kernel=E2=80=99s IPL report from the e= xisting one. +* Keying: installs IPL certificates into the platform trusted keyring. diff --git a/include/hw/s390x/ipl/qipl.h b/include/hw/s390x/ipl/qipl.h index ed1a91182a..45d25264f4 100644 --- a/include/hw/s390x/ipl/qipl.h +++ b/include/hw/s390x/ipl/qipl.h @@ -32,6 +32,9 @@ typedef enum S390IplType S390IplType; #define QEMU_DEFAULT_IPL S390_IPL_TYPE_CCW =20 #define MAX_CERTIFICATES 64 +/* largest supported block size - same as VIRTIO_DASD_DEFAULT_BLOCK_SIZE */ +#define VIRTIO_MAX_BLOCK_SIZE 4096 +#define MAX_COMP_ENTRIES ((VIRTIO_MAX_BLOCK_SIZE - 32) / 32) =20 /* * The QEMU IPL Parameters will be stored at absolute address @@ -146,4 +149,63 @@ union IplParameterBlock { } QEMU_PACKED; typedef union IplParameterBlock IplParameterBlock; =20 +struct IplInfoReportBlockHeader { + uint32_t len; + uint8_t flags; + uint8_t reserved1[11]; +}; +typedef struct IplInfoReportBlockHeader IplInfoReportBlockHeader; + +struct IplInfoBlockHeader { + uint32_t len; + uint8_t type; + uint8_t reserved1[11]; +}; +typedef struct IplInfoBlockHeader IplInfoBlockHeader; + +enum IplInfoBlockType { + IPL_INFO_BLOCK_TYPE_CERTIFICATES =3D 1, + IPL_INFO_BLOCK_TYPE_COMPONENTS =3D 2, +}; + +struct IplSignatureCertificateEntry { + uint64_t addr; + uint64_t len; +}; +typedef struct IplSignatureCertificateEntry IplSignatureCertificateEntry; + +struct IplSignatureCertificateList { + IplInfoBlockHeader ipl_info_header; + IplSignatureCertificateEntry cert_entries[MAX_CERTIFICATES]; +}; +typedef struct IplSignatureCertificateList IplSignatureCertificateList; + +#define S390_IPL_DEV_COMP_FLAG_SC 0x80 +#define S390_IPL_DEV_COMP_FLAG_CSV 0x40 + +struct IplDeviceComponentEntry { + uint64_t addr; + uint64_t len; + uint8_t flags; + uint8_t reserved1[5]; + uint16_t cert_index; + uint8_t reserved2[8]; +}; +typedef struct IplDeviceComponentEntry IplDeviceComponentEntry; + +struct IplDeviceComponentList { + IplInfoBlockHeader ipl_info_header; + IplDeviceComponentEntry device_entries[MAX_COMP_ENTRIES]; +}; +typedef struct IplDeviceComponentList IplDeviceComponentList; + +#define COMP_LIST_MAX sizeof(IplDeviceComponentList) +#define CERT_LIST_MAX sizeof(IplSignatureCertificateList) + +struct IplInfoReportBlock { + IplInfoReportBlockHeader hdr; + uint8_t info_blks[COMP_LIST_MAX + CERT_LIST_MAX]; +}; +typedef struct IplInfoReportBlock IplInfoReportBlock; + #endif --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098149; cv=none; d=zohomail.com; s=zohoarc; b=hWQI8mhdouQr8J/6aG6e0ROr7/Y4b+dPP+6BW3x8/eR1Fv8W5417gwodfrCFPBBOYFf/vte1mEIjNOyy0fN/Z4Yf2mT/sX4q2M6HgpKCSr7QwCXry2S7kf3f6lXvaBAtARh3QGpbRBRNTzGF0zUNRbbtaRvjZG0DDybv2Dgl0P0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098149; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=X6HKAkf8RA3YZ51Ruq3a0g/ukNaNC9oVnBhA2kpOIww=; b=Lq8jjni8qnwEruNQoSqF8t/XBdm1j+8yttYJUUOYFg/YiisnZDvmEhdXK8/sGggHZhMeadRuJ1anSKIG2gMpsgKs8aqUGNKA0+M4Ua0P1sLcqyFVNz3CkY7wX7uvS86stBK9DATvjpXX7QPy9sqE0Yy9oH3H7KJE5o+kx2smYMw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098149863864.0380436044699; Fri, 3 Jul 2026 10:02:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHF-0000BV-KW; Fri, 03 Jul 2026 13:02:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGh-0007rN-2V; Fri, 03 Jul 2026 13:01:38 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGf-0003EP-9A; Fri, 03 Jul 2026 13:01:34 -0400 Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIxHV3236885; Fri, 3 Jul 2026 17:01:30 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26rffmf8-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:29 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gnad4025837; Fri, 3 Jul 2026 17:01:29 GMT Received: from smtprelay05.wdc07v.mail.ibm.com ([172.16.1.72]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2sukhqs8-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:29 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay05.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1SH934276062 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:28 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 13F435805D; Fri, 3 Jul 2026 17:01:28 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4A4F05805C; Fri, 3 Jul 2026 17:01:25 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:25 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=X6HKAkf8RA3YZ51Ru q3a0g/ukNaNC9oVnBhA2kpOIww=; b=RriFbvkg9O6/FM1eYZmLe/KNsIL3ycLoB Qk2wPQQ4I6At2axITyQFYRzEqRemKiYLgc6B+uljF3zfpglBTAuKWh5y/4SEoGLf FZ5T6qbjbWIJZbMxiM460WI1GVorq4e7j85T3+zo139KsbUVnQnxbTSPqGKrOb1t rJOYQHXqN38PakI895Ghbp6PrOOCAJiTLUUwK0XH2aoiQ5YsaNnv4RJ/zfTorkrB PPguRsJ8rok25lqTqJdImhQY+EATlGaq/9iLU6irKTFOfQsRMKd22ARijAdozivq 3c6ckhglTcWOHA8ofWlp5VgzR/sWxRkTy6AplbBEvgCJaZhP5rCcw== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 16/33] pc-bios/s390-ccw: Define memory for IPLB and convert IPLB to pointers Date: Fri, 3 Jul 2026 13:00:13 -0400 Message-ID: <20260703170032.1893204-17-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=a4kAM0SF c=1 sm=1 tr=0 ts=6a47eae9 cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=_GZQR2ZoBes7ElOevS0A:9 X-Proofpoint-ORIG-GUID: N_oa4Pa9McXJRtJ7i6dy88G3BLxSHV3y X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXzAQzTbaEq1B3 zJdX8OA0DSZxjRuKVoz2TAFDDWzHJ4nL8pNQrhbBoMrgc2WSUMRrVARYSwZDwgd+lU9AASEfeYe p4i6wYhygkaS0vwHYv54Tbs3Zwj1U5ZExxX4fV9JFo0C5FpXa94onxXsNFSy4+iny37wuZXevAS VVZnUIi5OEwsvphg22rIOa1yQYMmmFiQMQ+I8TYLMryBsTQaFRcw3Z3nHeZ9k54IFdmmo+F9Mek doqIbWOAVVCoJGVqtBS2ZCjQgTe0G5Ho1npYQ2o+ZAQpDib3qdMHNZSxdsr0Yvd6zxSbDJlq38f 0r8zq8ooBkFL/TJ2UGAKizL1gpvEhkDM5ttYbQGTX3YVGxTYFgYtLd8EpAq1qMtwA8y/Vz6skko 5YU3oGnnnGWf5HGTZZUET48YuElgyXLh7Dqz2DjNp9rN+yaoE5n+9Gx5NA9lNdwuTUZg4Rjkxqc qpe1hpGotj/nx6G92mQ== X-Proofpoint-GUID: N_oa4Pa9McXJRtJ7i6dy88G3BLxSHV3y X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX0bQNfP4tljwh BlZQn+icMn3MRsEMZN8jkL3DTcivlLJf2uNVJEeFi9ID2mn3tEZA4ePvGJzDxxVlh3+bYeFjiDB HLMSpbOgONka3nV5tYXupGPLo7iN9n0= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 bulkscore=0 suspectscore=0 lowpriorityscore=0 impostorscore=0 spamscore=0 priorityscore=1501 adultscore=0 malwarescore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098150302158500 Content-Type: text/plain; charset="utf-8" Define a memory space for both IPL Parameter Block (IPLB) and IPL Information Report Block (IIRB) since IIRB is stored immediately following IPLB. Convert IPLB to pointer and it points to the start of the defined memory sp= ace. IIRB points to the end of IPLB. Signed-off-by: Zhuoying Cai Reviewed-by: Thomas Huth Reviewed-by: Farhan Ali Reviewed-by: Jared Rossi --- include/hw/s390x/ipl/qipl.h | 6 ++++++ pc-bios/s390-ccw/iplb.h | 5 +++-- pc-bios/s390-ccw/jump2ipl.c | 6 +++--- pc-bios/s390-ccw/main.c | 34 +++++++++++++++++++--------------- pc-bios/s390-ccw/netmain.c | 8 ++++---- 5 files changed, 35 insertions(+), 24 deletions(-) diff --git a/include/hw/s390x/ipl/qipl.h b/include/hw/s390x/ipl/qipl.h index 45d25264f4..9940f1457c 100644 --- a/include/hw/s390x/ipl/qipl.h +++ b/include/hw/s390x/ipl/qipl.h @@ -208,4 +208,10 @@ struct IplInfoReportBlock { }; typedef struct IplInfoReportBlock IplInfoReportBlock; =20 +struct IplBlocks { + IplParameterBlock iplb; + IplInfoReportBlock iirb; +}; +typedef struct IplBlocks IplBlocks; + #endif diff --git a/pc-bios/s390-ccw/iplb.h b/pc-bios/s390-ccw/iplb.h index 926e8eed5d..c92a3d0f0c 100644 --- a/pc-bios/s390-ccw/iplb.h +++ b/pc-bios/s390-ccw/iplb.h @@ -20,8 +20,9 @@ #include =20 extern QemuIplParameters qipl; -extern IplParameterBlock iplb __attribute__((__aligned__(PAGE_SIZE))); +extern IplParameterBlock *iplb; extern bool have_iplb; +extern IplBlocks ipl_blocks; =20 static inline bool manage_iplb(IplParameterBlock *iplb, bool store) { @@ -61,7 +62,7 @@ static inline bool load_next_iplb(void) =20 qipl.index++; next_iplb =3D (IplParameterBlock *) qipl.next_iplb; - memcpy(&iplb, next_iplb, sizeof(IplParameterBlock)); + memcpy(iplb, next_iplb, sizeof(IplParameterBlock)); =20 qipl.chain_len--; qipl.next_iplb =3D qipl.next_iplb + sizeof(IplParameterBlock); diff --git a/pc-bios/s390-ccw/jump2ipl.c b/pc-bios/s390-ccw/jump2ipl.c index 86321d0f46..fa2ca5cbe1 100644 --- a/pc-bios/s390-ccw/jump2ipl.c +++ b/pc-bios/s390-ccw/jump2ipl.c @@ -43,11 +43,11 @@ int jump_to_IPL_code(uint64_t address) * The IPLB for QEMU SCSI type devices must be rebuilt during re-ipl. = The * iplb.devno is set to the boot position of the target SCSI device. */ - if (iplb.pbt =3D=3D S390_IPL_TYPE_QEMU_SCSI) { - iplb.devno =3D qipl.index; + if (iplb->pbt =3D=3D S390_IPL_TYPE_QEMU_SCSI) { + iplb->devno =3D qipl.index; } =20 - if (have_iplb && !set_iplb(&iplb)) { + if (have_iplb && !set_iplb(iplb)) { panic("Failed to set IPLB"); } =20 diff --git a/pc-bios/s390-ccw/main.c b/pc-bios/s390-ccw/main.c index 26287cfd81..b8f836c682 100644 --- a/pc-bios/s390-ccw/main.c +++ b/pc-bios/s390-ccw/main.c @@ -24,7 +24,9 @@ static SubChannelId blk_schid =3D { .one =3D 1 }; static char loadparm_str[LOADPARM_LEN + 1]; QemuIplParameters qipl; -IplParameterBlock iplb __attribute__((__aligned__(PAGE_SIZE))); +/* Ensure that IPLB and IIRB are page aligned and sequential in memory */ +IplBlocks ipl_blocks __attribute__((__aligned__(PAGE_SIZE))); +IplParameterBlock *iplb; bool have_iplb; static uint16_t cutype; LowCore *lowcore; /* Yes, this *is* a pointer to address 0 */ @@ -53,7 +55,7 @@ void write_subsystem_identification(void) void write_iplb_location(void) { if (cutype =3D=3D CU_TYPE_VIRTIO && virtio_get_device_type() !=3D VIRT= IO_ID_NET) { - lowcore->ptr_iplb =3D ptr2u32(&iplb); + lowcore->ptr_iplb =3D ptr2u32(iplb); } } =20 @@ -213,14 +215,14 @@ static void boot_setup(void) char lpmsg[] =3D "LOADPARM=3D[________]\n"; VDev *vdev =3D virtio_get_device(); =20 - if (have_iplb && memcmp(iplb.loadparm, NO_LOADPARM, LOADPARM_LEN) !=3D= 0) { - ebcdic_to_ascii((char *) iplb.loadparm, loadparm_str, LOADPARM_LEN= ); + if (have_iplb && memcmp(iplb->loadparm, NO_LOADPARM, LOADPARM_LEN) != =3D 0) { + ebcdic_to_ascii((char *) iplb->loadparm, loadparm_str, LOADPARM_LE= N); } else { sclp_get_loadparm_ascii(loadparm_str); } =20 if (have_iplb) { - vdev->ipl_type =3D iplb.pbt; + vdev->ipl_type =3D iplb->pbt; menu_setup(vdev); } else { vdev->ipl_type =3D QEMU_DEFAULT_IPL; @@ -244,21 +246,21 @@ static bool find_boot_device(void) switch (vdev->ipl_type) { case S390_IPL_TYPE_CCW: vdev->scsi_device_selected =3D false; - debug_print_int("device no. ", iplb.ccw.devno); - blk_schid.ssid =3D iplb.ccw.ssid & 0x3; + debug_print_int("device no. ", iplb->ccw.devno); + blk_schid.ssid =3D iplb->ccw.ssid & 0x3; debug_print_int("ssid ", blk_schid.ssid); - found =3D find_subch(iplb.ccw.devno); + found =3D find_subch(iplb->ccw.devno); break; case S390_IPL_TYPE_QEMU_SCSI: vdev->scsi_device_selected =3D true; - vdev->selected_scsi_device.channel =3D iplb.scsi.channel; - vdev->selected_scsi_device.target =3D iplb.scsi.target; - vdev->selected_scsi_device.lun =3D iplb.scsi.lun; - blk_schid.ssid =3D iplb.scsi.ssid & 0x3; - found =3D find_subch(iplb.scsi.devno); + vdev->selected_scsi_device.channel =3D iplb->scsi.channel; + vdev->selected_scsi_device.target =3D iplb->scsi.target; + vdev->selected_scsi_device.lun =3D iplb->scsi.lun; + blk_schid.ssid =3D iplb->scsi.ssid & 0x3; + found =3D find_subch(iplb->scsi.devno); break; case S390_IPL_TYPE_PCI: - found =3D find_fid(iplb.pci.fid); + found =3D find_fid(iplb->pci.fid); break; default: puts("Unsupported IPLB"); @@ -377,10 +379,12 @@ static void probe_boot_device(void) =20 void main(void) { + iplb =3D &ipl_blocks.iplb; + copy_qipl(); sclp_setup(); css_setup(); - have_iplb =3D store_iplb(&iplb); + have_iplb =3D store_iplb(iplb); if (!have_iplb) { boot_setup(); probe_boot_device(); diff --git a/pc-bios/s390-ccw/netmain.c b/pc-bios/s390-ccw/netmain.c index 651cedf6ef..9b4dfd4638 100644 --- a/pc-bios/s390-ccw/netmain.c +++ b/pc-bios/s390-ccw/netmain.c @@ -528,11 +528,11 @@ static bool virtio_setup(void) */ enable_mss_facility(); =20 - if (have_iplb || store_iplb(&iplb)) { - IPL_assert(iplb.pbt =3D=3D S390_IPL_TYPE_CCW, "IPL_TYPE_CCW expect= ed"); - dev_no =3D iplb.ccw.devno; + if (have_iplb || store_iplb(iplb)) { + IPL_assert(iplb->pbt =3D=3D S390_IPL_TYPE_CCW, "IPL_TYPE_CCW expec= ted"); + dev_no =3D iplb->ccw.devno; debug_print_int("device no. ", dev_no); - net_schid.ssid =3D iplb.ccw.ssid & 0x3; + net_schid.ssid =3D iplb->ccw.ssid & 0x3; debug_print_int("ssid ", net_schid.ssid); found =3D find_net_dev(&schib, dev_no); } else { --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098357; cv=none; d=zohomail.com; s=zohoarc; b=MxmROOQ7RqnWXi9QplbxgzNg6jdCrMqM9w5tchgH6/C2Tm5BAK+ZB9fY4EaqXNsqH5nihV/DFsgq6gBkuy2lxqcRkdxR684Zhfa4Djx1LvSnaNxRUAbgw0e8eAEiuyba+MRdMVgve8z1nfx/c7mW0njhyyOQuOdvJslzrkS69AY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098357; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bfOshnfnLjcMxaDNVafW2X6etk7uW6LTS1pBWI+FBc0=; b=ZhHnIIai1HH+wpTP3Q5O5BewvLNAwdrVYTF3BXK8v0Pdz6uApTB2DKlK1thzVVe/sA6VmHUy02zZo/TeBbdhXyIYJQ1IltS7LvCyQ7yNbQrG9JawD57Yc0y7SbsLnMCITX8Ss710y/qCVzrenTXv8qfSm3NYU521xB9X3DIngT8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098357458318.34247123426076; Fri, 3 Jul 2026 10:05:57 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHM-0000z4-Af; Fri, 03 Jul 2026 13:02:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGo-0007wK-Rr; Fri, 03 Jul 2026 13:01:44 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGm-0003Hu-Ve; Fri, 03 Jul 2026 13:01:42 -0400 Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIu5C3303118; Fri, 3 Jul 2026 17:01:33 GMT Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26n688xq-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:33 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnbLT019653; Fri, 3 Jul 2026 17:01:32 GMT Received: from smtprelay02.dal12v.mail.ibm.com ([172.16.1.4]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2ruqsy49-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:32 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay02.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1ViI65601920 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:31 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3F8CF5805C; Fri, 3 Jul 2026 17:01:31 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 57BE15805A; Fri, 3 Jul 2026 17:01:28 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:28 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=bfOshnfnLjcMxaDNV afW2X6etk7uW6LTS1pBWI+FBc0=; b=n+d0fa1g56tqKcEpJvRghhGxdTRSTlROK fe8lnnneBHL093RVc6pwKVgt0fvsxyIMYnZCiaJ3U64xZ3ZhTov/kJDoMc+zSMV5 Nqje1JIBGk/dswGoFh5oK6zgotc8ua14dyQMQ9oiEx7GGU7YRoMwf2PXwQAuK1Jk T3CLMD/HnQo1XpBHcsG2L+7Gfk8P7wf82k2BSv5wU5v53XwPLLhqj0TxQPrsBaJQ KcXxJ5wJid+p2YHXtcXHzfc7+1uvRoAYgE+yEwF2n6z8v1YI/lC0GpYCD9IvOT9z PUjSiV0CSc8+oz0WvCMrtyk4h1bSkA/JfBAMyYFkGWoJcE9E0bavg== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 17/33] hw/s390x/ipl: Add IPIB flags to IPL Parameter Block Date: Fri, 3 Jul 2026 13:00:14 -0400 Message-ID: <20260703170032.1893204-18-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXwqG6Hvkjata1 40XOYqPkCQ3wL4ejaNKzaTJiKbOFqcW7IyTofzmr5FLk9yzzqHRmjCrQmIA4+AbGr7QxPRFXg3O ROKuNDLxqRVjdOEZIEeFW1U0ZF0D/L+yRoip4tGG/075u1j4R0bO563UmdUTPyBubNHYoR4nrXV ct/GEsGgfnnby+VMLgn/z8wKG2rXl1EwMU29GuZkNZPEjkkikjjG279qK6mjOuhnaNWSFgCSwhm EJbBUyo0e6+X8sQUD4uJ9zOF1REq2yK14tUG2R0B7415ghpppZCWiim+b/3yg0pMPNMkRUOYkrB TvoH6mh+2l9IiXLZ9xDeDM+Yb2o0tM/7DlpSxtt1/vUd8nTGVtRp+XWiQkAtdL6BdNB8bzc+EEI GgG9vSDwE74kEEt6xpDhn7TItBNq0YhX078N/shqHUWnFShYHS2DQTVVpbYCjUP1hmNEY5j6ere cRbCYTnlTpZCH3Hvjfg== X-Authority-Analysis: v=2.4 cv=V45NF+ni c=1 sm=1 tr=0 ts=6a47eaed cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=ZDXLRS20C3ackK2NFGcA:9 X-Proofpoint-ORIG-GUID: bXRelzGgFyb0jpx3ROBWcp5jAo7gJGr8 X-Proofpoint-GUID: bXRelzGgFyb0jpx3ROBWcp5jAo7gJGr8 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXwV8BAHaTeL7Z rHKqvklk1TfFyACvYVxiLvOmgJS52/FkZYKjWuFOpF3ZJb3tGsQVw4nGJ3OateSgye3nYk3m81N 5K5xDpLb+EGJcMPMsdKSoquJYn2qfjI= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 spamscore=0 suspectscore=0 lowpriorityscore=0 priorityscore=1501 adultscore=0 clxscore=1015 impostorscore=0 malwarescore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098358168158500 Content-Type: text/plain; charset="utf-8" Add IPIB flags to IPL Parameter Block to determine if IPL needs to perform securely and if IPL Information Report Block (IIRB) exists. Move DIAG308 flags to a separated header file and add flags for secure IPL. Move IPLB length related definitions to include/hw/s390x/ipl/qipl.h and add a maximum length constant to support secure IPL. Secure boot in audit mode will perform if certificate(s) exist in the key store. IIRB will exist and results of verification will be stored in IIRB. To ensure proper alignment of the IIRB and prevent overlap, set iplb->len to the maximum length of the IPLB, allowing alignment constraints to be determined based on its size. Signed-off-by: Zhuoying Cai Reviewed-by: Thomas Huth Reviewed-by: Collin Walling Reviewed-by: Jared Rossi --- hw/s390x/ipl.c | 36 ++++++++++++++++++++++++++++++++++ hw/s390x/ipl.h | 24 ----------------------- include/hw/s390x/ipl/diag308.h | 34 ++++++++++++++++++++++++++++++++ include/hw/s390x/ipl/qipl.h | 13 +++++++++++- 4 files changed, 82 insertions(+), 25 deletions(-) create mode 100644 include/hw/s390x/ipl/diag308.h diff --git a/hw/s390x/ipl.c b/hw/s390x/ipl.c index 09c24203c7..f9f14d7b67 100644 --- a/hw/s390x/ipl.c +++ b/hw/s390x/ipl.c @@ -461,6 +461,34 @@ S390IPLCertificateStore *s390_ipl_get_certificate_stor= e(void) return &ipl->cert_store; } =20 +static bool s390_has_certificate(void) +{ + S390IPLState *ipl =3D get_ipl_device(); + + return ipl->cert_store.count > 0; +} + +static void s390_set_secure_boot_flags(IplParameterBlock *iplb, + bool audit_mode) +{ + if (!audit_mode) { + return; + } + + /* + * For audit mode, enable the IPL Information + * Report (IPLIR) flag so that the firmware generates an IPL + * Information Report Block (IIRB). + * + * Results of secure boot will be stored in IIRB. + * + * Extend the IPL parameter block to its maximum length to ensure + * sufficient space for the BIOS to populate the IIRB. + */ + iplb->hdr_flags |=3D DIAG308_IPIB_FLAGS_IPLIR; + iplb->len =3D cpu_to_be32(S390_IPLB_MAX_LEN); +} + static bool s390_build_iplb(DeviceState *dev_st, IplParameterBlock *iplb) { CcwDevice *ccw_dev =3D NULL; @@ -517,6 +545,8 @@ static bool s390_build_iplb(DeviceState *dev_st, IplPar= ameterBlock *iplb) s390_ipl_convert_loadparm((char *)lp, iplb->loadparm); iplb->flags |=3D DIAG308_FLAGS_LP_VALID; =20 + s390_set_secure_boot_flags(iplb, s390_has_certificate()); + return true; } =20 @@ -653,6 +683,12 @@ void s390_ipl_update_diag308(IplParameterBlock *iplb) } else { ipl->iplb =3D *iplb; ipl->iplb_valid =3D true; + + /* + * The kernel does not preserve secure boot flags across a reboot. + * Re-apply them here based on the current machine configuration. + */ + s390_set_secure_boot_flags(&ipl->iplb, s390_has_certificate()); } =20 update_machine_ipl_properties(iplb); diff --git a/hw/s390x/ipl.h b/hw/s390x/ipl.h index f5a49a4431..9807ef18f2 100644 --- a/hw/s390x/ipl.h +++ b/hw/s390x/ipl.h @@ -23,7 +23,6 @@ #include "qom/object.h" #include "target/s390x/kvm/pv.h" =20 -#define DIAG308_FLAGS_LP_VALID 0x80 #define MAX_BOOT_DEVS 8 /* Max number of devices that may have a bootindex= */ =20 void s390_ipl_convert_loadparm(char *ascii_lp, uint8_t *ebcdic_lp); @@ -90,29 +89,6 @@ struct S390IPLState { }; QEMU_BUILD_BUG_MSG(offsetof(S390IPLState, iplb) & 3, "alignment of iplb wr= ong"); =20 -#define DIAG_308_RC_OK 0x0001 -#define DIAG_308_RC_NO_CONF 0x0102 -#define DIAG_308_RC_INVALID 0x0402 -#define DIAG_308_RC_NO_PV_CONF 0x0902 -#define DIAG_308_RC_INVAL_FOR_PV 0x0a02 - -#define DIAG308_RESET_MOD_CLR 0 -#define DIAG308_RESET_LOAD_NORM 1 -#define DIAG308_LOAD_CLEAR 3 -#define DIAG308_LOAD_NORMAL_DUMP 4 -#define DIAG308_SET 5 -#define DIAG308_STORE 6 -#define DIAG308_PV_SET 8 -#define DIAG308_PV_STORE 9 -#define DIAG308_PV_START 10 - -#define S390_IPLB_HEADER_LEN 8 -#define S390_IPLB_MIN_PV_LEN 148 -#define S390_IPLB_MIN_CCW_LEN 200 -#define S390_IPLB_MIN_FCP_LEN 384 -#define S390_IPLB_MIN_PCI_LEN 376 -#define S390_IPLB_MIN_QEMU_SCSI_LEN 200 - static inline bool iplb_valid_len(IplParameterBlock *iplb) { return be32_to_cpu(iplb->len) <=3D sizeof(IplParameterBlock); diff --git a/include/hw/s390x/ipl/diag308.h b/include/hw/s390x/ipl/diag308.h new file mode 100644 index 0000000000..6e62f29215 --- /dev/null +++ b/include/hw/s390x/ipl/diag308.h @@ -0,0 +1,34 @@ +/* + * S/390 DIAGNOSE 308 definitions and structures + * + * Copyright 2025 IBM Corp. + * Author(s): Zhuoying Cai + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#ifndef S390X_DIAG308_H +#define S390X_DIAG308_H + +#define DIAG_308_RC_OK 0x0001 +#define DIAG_308_RC_NO_CONF 0x0102 +#define DIAG_308_RC_INVALID 0x0402 +#define DIAG_308_RC_NO_PV_CONF 0x0902 +#define DIAG_308_RC_INVAL_FOR_PV 0x0a02 + +#define DIAG308_RESET_MOD_CLR 0 +#define DIAG308_RESET_LOAD_NORM 1 +#define DIAG308_LOAD_CLEAR 3 +#define DIAG308_LOAD_NORMAL_DUMP 4 +#define DIAG308_SET 5 +#define DIAG308_STORE 6 +#define DIAG308_PV_SET 8 +#define DIAG308_PV_STORE 9 +#define DIAG308_PV_START 10 + +#define DIAG308_FLAGS_LP_VALID 0x80 + +#define DIAG308_IPIB_FLAGS_SIPL 0x40 +#define DIAG308_IPIB_FLAGS_IPLIR 0x20 + +#endif diff --git a/include/hw/s390x/ipl/qipl.h b/include/hw/s390x/ipl/qipl.h index 9940f1457c..a2180719b1 100644 --- a/include/hw/s390x/ipl/qipl.h +++ b/include/hw/s390x/ipl/qipl.h @@ -12,6 +12,8 @@ #ifndef S390X_QIPL_H #define S390X_QIPL_H =20 +#include "diag308.h" + /* Boot Menu flags */ #define QIPL_FLAG_BM_OPTS_CMD 0x80 #define QIPL_FLAG_BM_OPTS_ZIPL 0x40 @@ -31,6 +33,14 @@ typedef enum S390IplType S390IplType; =20 #define QEMU_DEFAULT_IPL S390_IPL_TYPE_CCW =20 +#define S390_IPLB_HEADER_LEN 8 +#define S390_IPLB_MIN_PV_LEN 148 +#define S390_IPLB_MIN_CCW_LEN 200 +#define S390_IPLB_MIN_FCP_LEN 384 +#define S390_IPLB_MIN_PCI_LEN 376 +#define S390_IPLB_MIN_QEMU_SCSI_LEN 200 +#define S390_IPLB_MAX_LEN 4096 + #define MAX_CERTIFICATES 64 /* largest supported block size - same as VIRTIO_DASD_DEFAULT_BLOCK_SIZE */ #define VIRTIO_MAX_BLOCK_SIZE 4096 @@ -125,7 +135,8 @@ typedef struct IplBlockPci IplBlockPci; union IplParameterBlock { struct { uint32_t len; - uint8_t reserved0[3]; + uint8_t hdr_flags; + uint8_t reserved0[2]; uint8_t version; uint32_t blk0_len; uint8_t pbt; --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098228; cv=none; d=zohomail.com; s=zohoarc; b=c+ELgH66edz0mzRFIan9FiTNlf9B8q7R9NOo8kYpTdG6cZytR4nT+HqhAWc4lAMgkoahNG7q3MlyiBEjSbS5Fl5/lhnurbECt3S6hjZgYMdwfV0sn7esIVqfr3l+qoHDQdCf22aRKtP9fs68/U0/hvjXMHFNSvBqG/X7bGahErY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098228; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ctJOhT22+/282MyIPiIB02l71QB2ubOQvkaLw2y81eg=; b=g6K86rcSdZTeq/JaxFEaci8uKLEx87XDKcYC5vUBrvpMEBL1+RXUmlLMh9D607i7QZe2+g7sK4Qg+KOk/4Hlv9Oy1ceMVk+uqqRK8se1PSA4IWZXSvu+XwOxRxi7LshlppdeIuLeW6JMKrujArOHDI2WBlMaJVB2EsA6vxplhks= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098228182353.47310853171564; Fri, 3 Jul 2026 10:03:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHO-0001BK-8R; Fri, 03 Jul 2026 13:02:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGo-0007wJ-Q5; Fri, 03 Jul 2026 13:01:44 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGn-0003I9-08; Fri, 03 Jul 2026 13:01:42 -0400 Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GJC8C3237374; Fri, 3 Jul 2026 17:01:36 GMT Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26rffmfj-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:36 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnlNv031533; Fri, 3 Jul 2026 17:01:35 GMT Received: from smtprelay05.dal12v.mail.ibm.com ([172.16.1.7]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2uhysgbc-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:35 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay05.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1YsD24969864 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:34 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4143A58064; Fri, 3 Jul 2026 17:01:34 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 7B8EE5805D; Fri, 3 Jul 2026 17:01:31 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:31 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=ctJOhT22+/282MyIP iIB02l71QB2ubOQvkaLw2y81eg=; b=kHnSHv+PSHSfkIQ/wfQHEvMTaoiYJquuG DnLDpvHHPZpSPOPSpGzYBN7N0CzrFKlWw5/rjJn5nLcDqSJ2GteVntvnys7IWZLH wsS1yTl5KWvvcjKuI6q8O6wi/ZNm3FIPBukKjkmaP1ufukYviquDXeYjrP8VyRDf HsmmaiAoKbqCIvad4UeLWUy8o1P0wA1m9vZMqy9pNAunIEdn003LSKFdsxXV2smt yjbTkp6Lvi3WEtFQPlOy8OLFIs9nMWVx3mNMmW91xUwoRFe2sHYw1MdWCtoeTqbU cKKMTh4h65LdiwSw2EEmBBkNKllq09WX8X9ixsX0V18N2L10IaYew== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 18/33] hw/s390x/ipl: Rework s390_ipl_map_iplb_chain for certificate storage Date: Fri, 3 Jul 2026 13:00:15 -0400 Message-ID: <20260703170032.1893204-19-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=a4kAM0SF c=1 sm=1 tr=0 ts=6a47eaf0 cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VnNF1IyMAAAA:8 a=6n7imOYxnT_JOqVJOMMA:9 X-Proofpoint-ORIG-GUID: CXjJoy4biltOPI-mkJ0Yk7xUH5EsQRTM X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX+KSnlbGa9KdB SsOf726yvfdTMcbFdX02CV4WQnnrm3jeheBe3dF9p2Kmh82onpBxknt7KJLUFn8z5LYaiwpx40h zIRNIlN7S6UP+g4zJf0jzWTQaICzi+3rO3ciRSofIMjv+T4x9+r5PXgHufQSdDv1I1jsXnKN+jD G/ssjfUUjkKPWjUnhgFIndybqHFU5Hrw9P39uCve5FxeoDpMRi8skG0Bji8CbU9cD4BCHKbXvWk Eq96MHkS2LLXAJvfrg2xi5QyzdtKslCajqkcweKnnRrro7pQ9+ugJooStR0Dnr+ua/gufVEvubL quvOJybNVAD8VX+ORcgf5rpXT+nj2rcREyAZxYTmN8TcAae3I0/jzGosNLfQhCrWTol4gG4GnYF WA1X7H8P0ClKvyEgJx8TyIy9WQeEL9/FMG0uD1a1SEvSH60ulmbgX1JCRK7xWnDOkydkaWDHo3c 2PoKMGtTbMmi+ENJDeg== X-Proofpoint-GUID: CXjJoy4biltOPI-mkJ0Yk7xUH5EsQRTM X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX68o5tRa4TG3e PAtzpfoRAsZImhUYSHrzuSyXCCbEBQivbi80Uvk0YettqH7s9PgehVWuBmvxE7KdxGGp5BNVdI/ GGlte0E8glJ+BrfrX+pAqeAPI84pmT8= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 bulkscore=0 suspectscore=0 lowpriorityscore=0 impostorscore=0 spamscore=0 priorityscore=1501 adultscore=0 malwarescore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098229016158500 Content-Type: text/plain; charset="utf-8" Rework s390_ipl_map_iplb_chain to always allocate maximum memory for the IPLB chain, regardless of the number of boot devices. This space is also used to store certificates during secure boot, providing a safe location for certificates until the kernel reads them during boot. Rename next_iplb to ipl_data to better reflect its multiple purposes: storing both IPLB chains and certificate data. Signed-off-by: Zhuoying Cai Reviewed-by: Eric Farman Reviewed-by: Matthew Rosato --- hw/s390x/ipl.c | 17 +++++++++++++---- include/hw/s390x/ipl/qipl.h | 3 ++- pc-bios/s390-ccw/iplb.h | 4 ++-- 3 files changed, 17 insertions(+), 7 deletions(-) diff --git a/hw/s390x/ipl.c b/hw/s390x/ipl.c index f9f14d7b67..af89005790 100644 --- a/hw/s390x/ipl.c +++ b/hw/s390x/ipl.c @@ -425,10 +425,9 @@ static S390PCIBusDevice *s390_get_pci_device(DeviceSta= te *dev_st, int *devtype) return pbdev; } =20 -static uint64_t s390_ipl_map_iplb_chain(IplParameterBlock *iplb_chain) +static uint64_t s390_ipl_map_iplb_chain(IplParameterBlock *iplb_chain, uin= t16_t count) { S390IPLState *ipl =3D get_ipl_device(); - uint16_t count =3D be16_to_cpu(ipl->qipl.chain_len); uint64_t len =3D sizeof(IplParameterBlock) * count; uint64_t chain_addr =3D find_iplb_chain_addr(ipl->bios_start_addr, cou= nt); =20 @@ -592,7 +591,7 @@ void s390_rebuild_iplb(uint16_t dev_index, IplParameter= Block *iplb) static bool s390_init_all_iplbs(S390IPLState *ipl) { int iplb_num =3D 0; - IplParameterBlock iplb_chain[7]; + IplParameterBlock iplb_chain[MAX_BOOT_DEVS - 1] =3D { 0 }; DeviceState *dev_st =3D get_boot_device(0); Object *machine =3D qdev_get_machine(); =20 @@ -638,12 +637,22 @@ static bool s390_init_all_iplbs(S390IPLState *ipl) dev_st =3D get_boot_device(i); s390_build_iplb(dev_st, &iplb_chain[i - 1]); } + } =20 - ipl->qipl.next_iplb =3D cpu_to_be64(s390_ipl_map_iplb_chain(iplb_c= hain)); + /* + * Allocate maximum space for IPLB chain and/or certificate storage. + * Once a valid boot device is found, this space will be used to store + * certificates if secure boot is enabled. + */ + if (iplb_num > 1 || s390_has_certificate()) { + ipl->qipl.ipl_data =3D cpu_to_be64(s390_ipl_map_iplb_chain(iplb_ch= ain, + MAX_BOOT_= DEVS - 1)); } =20 return iplb_num; } +QEMU_BUILD_BUG_MSG(sizeof(IplParameterBlock) * (MAX_BOOT_DEVS - 1) !=3D CE= RT_BUF_SIZE, + "certificate buffer size is wrong"); =20 static void update_machine_ipl_properties(IplParameterBlock *iplb) { diff --git a/include/hw/s390x/ipl/qipl.h b/include/hw/s390x/ipl/qipl.h index a2180719b1..58329fb5bc 100644 --- a/include/hw/s390x/ipl/qipl.h +++ b/include/hw/s390x/ipl/qipl.h @@ -42,6 +42,7 @@ typedef enum S390IplType S390IplType; #define S390_IPLB_MAX_LEN 4096 =20 #define MAX_CERTIFICATES 64 +#define CERT_BUF_SIZE (7 * 4096) /* largest supported block size - same as VIRTIO_DASD_DEFAULT_BLOCK_SIZE */ #define VIRTIO_MAX_BLOCK_SIZE 4096 #define MAX_COMP_ENTRIES ((VIRTIO_MAX_BLOCK_SIZE - 32) / 32) @@ -61,7 +62,7 @@ struct QemuIplParameters { uint32_t boot_menu_timeout; uint8_t reserved3[2]; uint16_t chain_len; - uint64_t next_iplb; + uint64_t ipl_data; } QEMU_PACKED; typedef struct QemuIplParameters QemuIplParameters; =20 diff --git a/pc-bios/s390-ccw/iplb.h b/pc-bios/s390-ccw/iplb.h index c92a3d0f0c..c807e7f49b 100644 --- a/pc-bios/s390-ccw/iplb.h +++ b/pc-bios/s390-ccw/iplb.h @@ -61,11 +61,11 @@ static inline bool load_next_iplb(void) } =20 qipl.index++; - next_iplb =3D (IplParameterBlock *) qipl.next_iplb; + next_iplb =3D (IplParameterBlock *) qipl.ipl_data; memcpy(iplb, next_iplb, sizeof(IplParameterBlock)); =20 qipl.chain_len--; - qipl.next_iplb =3D qipl.next_iplb + sizeof(IplParameterBlock); + qipl.ipl_data =3D qipl.ipl_data + sizeof(IplParameterBlock); =20 return true; } --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098196; cv=none; d=zohomail.com; s=zohoarc; b=jnH03g2obiQSk1zjvnNaDZUxVRPKSmTCbiVZ7uxAoWqoYfBLJAAZhuspwPkStR+6VCgJ5B5NkvmC9bZ7su5i4rLXo0F5iyraKXMHRfPy/0eurdRjp0HzF7drB2hFdkd1jGRbtTWlwlDkUiOCqjpBn5JcGOvjY+U5urzOPwa6bjY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098196; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=NAicq5uOLykXnygWzmTg96eZ5hFzE9v0Y9FC2UsYLCY=; b=DusLCYTgS9pqLD38xxtwJqEyG1ZkiGVExkXekk1bF56eZMRUMONyl+8cm9wzTnh4E2hNaZba8Fn45cNfz2MBSFzM/nnoZSJtN1RUJyB2YfeFiB4qYleSWuZYfZdE8Tf+CpJGQRvQLNc7v4EVMHvSm48ZMEm/8ILGxW1qFegh/o4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098196510292.9871573737885; Fri, 3 Jul 2026 10:03:16 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHJ-0000dn-JS; Fri, 03 Jul 2026 13:02:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGu-00082S-33; Fri, 03 Jul 2026 13:01:52 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGq-0003L8-0l; Fri, 03 Jul 2026 13:01:47 -0400 Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIbma3382863; Fri, 3 Jul 2026 17:01:40 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26pegadk-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:39 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gnf7i025868; Fri, 3 Jul 2026 17:01:38 GMT Received: from smtprelay01.wdc07v.mail.ibm.com ([172.16.1.68]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2sukhqsx-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:38 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay01.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1bLt57016744 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:37 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4AE1B5805C; Fri, 3 Jul 2026 17:01:37 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 7B8CA5805A; Fri, 3 Jul 2026 17:01:34 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:34 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=NAicq5uOLykXnygWz mTg96eZ5hFzE9v0Y9FC2UsYLCY=; b=Ue35uSTvwt3i5yEvZXlg3cSreRbzlkArY fx0yPjKF1m5fI7mjBBnKVoGEIu0brFs6VNWQhFap/jtaAeGgLMdnbeVHrU29jboV 5KyYH2jS8Xz85xeYmYzS5MFBZcNlZEPoVtYhgDWdzi4np1kOU7WyXT9XofmuMuzJ tpBgP4SgcBGtDuLBnA5d4L2fk+qJHWK00s8w75Ge8vSoFZ0OdmoEGfqq8jUDHnnB JByqlOeSr7O7UQaAj4kx+9quBK5pqvlwVEQH6XI7Ut662P1sEDRRgyNq4FFnK3eh aa5K/fhjVX7aWHV8WatCbh3hiamKUmxCY78nL9E9c1Pyw6CbB6d/A== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 19/33] s390x: Guest support for Secure-IPL Facility Date: Fri, 3 Jul 2026 13:00:16 -0400 Message-ID: <20260703170032.1893204-20-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: 1xv-vAmRCroDpElbEtv5aw5ilm0eS8aB X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX8VcC/XSVD2Ih FR8+0nBo3kpDen5OhlKe/zM36qC911iinCy2nqrrc64OSvNKbCXn7OLIfVsyF6TyEw83FBI3xZg lpEAYtPgSCKoXMRKkf2p649Xrxe4yQw= X-Authority-Analysis: v=2.4 cv=edsNubEH c=1 sm=1 tr=0 ts=6a47eaf3 cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=Bichc5AjJS213ZhIJUEA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX2w3B8O4QML43 vqzg9X7bQPbdvh+ok+q/j+C1fI3EIyZswZe2Nmn+xSq3jpNPeGg1GLAFBPi4orvN0ttlKlUYOFI CzXkL3fVpmZfGCnmlbHz4BkzADw4cBdBt1fdxU3BBGOypkrQ12LhSGjMq5gq/7orHgFGQDNnxGU xz6ugkhSSRveT6wAsyYGEaSNjp/27GZbQZAmQXqCLV7e3sIpOy02qPJD0QkqsetvRUL1DiyCvW4 MYTvefnw4uPnzHVDaiWKpwbBufyhVmBzEslt+5NyK3dCsGNgUcc541h+2bR6QIUsmVDzb23oPC4 Tjl0xUt+dtdVv73mg0APUIInOzCWOem/0e2pbRAhC5y1XifPksnd+x1mADaD8R3vHYiS3X0KXHe HGrceWlUCCGgFhy6NIOgDHv/RZ5DWPhHEEr8RmR9udYsEoYIBBIO4Vx+DWRfBelJBEBBi4rYF0q kxf8t6Oihr7C84iZ3Gw== X-Proofpoint-ORIG-GUID: 1xv-vAmRCroDpElbEtv5aw5ilm0eS8aB X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 adultscore=0 impostorscore=0 bulkscore=0 spamscore=0 suspectscore=0 clxscore=1015 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098198881158500 Content-Type: text/plain; charset="utf-8" Introduce Secure-IPL (SIPL) facility. Use fac_ipl to represent bytes 136 and 137 for IPL device facilities of the SCLP Read Info block. Availability of SIPL facility is determined by byte 136 bit 1 of the SCLP Read Info block. Byte 136's facilities cannot be represented without the availability of the extended-length-SCCB, so add it as a check for consistency. Secure IPL is not available for guests under protected virtualization. This feature is available starting with the gen16 CPU model. Signed-off-by: Zhuoying Cai Reviewed-by: Collin Walling Reviewed-by: Thomas Huth Reviewed-by: Matthew Rosato --- hw/s390x/sclp.c | 2 ++ include/hw/s390x/sclp.h | 4 +++- target/s390x/cpu_features.c | 4 ++++ target/s390x/cpu_features.h | 1 + target/s390x/cpu_features_def.h.inc | 3 +++ target/s390x/cpu_models.c | 2 ++ target/s390x/gen-features.c | 2 ++ target/s390x/kvm/kvm.c | 3 +++ 8 files changed, 20 insertions(+), 1 deletion(-) diff --git a/hw/s390x/sclp.c b/hw/s390x/sclp.c index b9c3983df1..666bae33f0 100644 --- a/hw/s390x/sclp.c +++ b/hw/s390x/sclp.c @@ -146,6 +146,8 @@ static void read_SCP_info(SCLPDevice *sclp, SCCB *sccb) if (s390_has_feat(S390_FEAT_EXTENDED_LENGTH_SCCB)) { s390_get_feat_block(S390_FEAT_TYPE_SCLP_FAC134, &read_info->fac134); + s390_get_feat_block(S390_FEAT_TYPE_SCLP_FAC_IPL, + read_info->fac_ipl); } =20 read_info->facilities =3D cpu_to_be64(SCLP_HAS_CPU_INFO | diff --git a/include/hw/s390x/sclp.h b/include/hw/s390x/sclp.h index ddc61f1c21..a9595d8007 100644 --- a/include/hw/s390x/sclp.h +++ b/include/hw/s390x/sclp.h @@ -136,7 +136,9 @@ typedef struct ReadInfo { uint32_t hmfai; uint8_t _reserved7[134 - 128]; /* 128-133 */ uint8_t fac134; - uint8_t _reserved8[144 - 135]; /* 135-143 */ + uint8_t _reserved8; + uint8_t fac_ipl[2]; /* 136-137 */ + uint8_t _reserved9[144 - 138]; /* 138-143 */ struct CPUEntry entries[]; /* * When the Extended-Length SCCB (ELS) feature is enabled the diff --git a/target/s390x/cpu_features.c b/target/s390x/cpu_features.c index 436471f4b4..200bd8c15b 100644 --- a/target/s390x/cpu_features.c +++ b/target/s390x/cpu_features.c @@ -119,6 +119,7 @@ void s390_fill_feat_block(const S390FeatBitmap features= , S390FeatType type, * Some facilities are not available for CPUs in protected mode: * - All SIE facilities because SIE is not available * - DIAG318 + * - Secure IPL Facility * * As VMs can move in and out of protected mode the CPU model * doesn't protect us from that problem because it is only @@ -149,6 +150,9 @@ void s390_fill_feat_block(const S390FeatBitmap features= , S390FeatType type, clear_be_bit(s390_feat_def(S390_FEAT_DIAG_318)->bit, data); clear_be_bit(s390_feat_def(S390_FEAT_CERT_STORE)->bit, data); break; + case S390_FEAT_TYPE_SCLP_FAC_IPL: + clear_be_bit(s390_feat_def(S390_FEAT_SIPL)->bit, data); + break; default: return; } diff --git a/target/s390x/cpu_features.h b/target/s390x/cpu_features.h index 5635839d03..b038198555 100644 --- a/target/s390x/cpu_features.h +++ b/target/s390x/cpu_features.h @@ -24,6 +24,7 @@ typedef enum { S390_FEAT_TYPE_SCLP_CONF_CHAR, S390_FEAT_TYPE_SCLP_CONF_CHAR_EXT, S390_FEAT_TYPE_SCLP_FAC134, + S390_FEAT_TYPE_SCLP_FAC_IPL, S390_FEAT_TYPE_SCLP_CPU, S390_FEAT_TYPE_MISC, S390_FEAT_TYPE_PLO, diff --git a/target/s390x/cpu_features_def.h.inc b/target/s390x/cpu_feature= s_def.h.inc index 2976ecd0ee..bcf8a666e4 100644 --- a/target/s390x/cpu_features_def.h.inc +++ b/target/s390x/cpu_features_def.h.inc @@ -140,6 +140,9 @@ DEF_FEAT(SIE_IBS, "ibs", SCLP_CONF_CHAR_EXT, 10, "SIE: = Interlock-and-broadcast-s DEF_FEAT(DIAG_318, "diag318", SCLP_FAC134, 0, "Control program name and ve= rsion codes") DEF_FEAT(CERT_STORE, "cstore", SCLP_FAC134, 5, "Certificate Store function= s") =20 +/* Features exposed via SCLP SCCB Facilities byte 136 - 137 (bit numbers r= elative to byte-136) */ +DEF_FEAT(SIPL, "sipl", SCLP_FAC_IPL, 1, "Secure-IPL facility") + /* Features exposed via SCLP CPU info. */ DEF_FEAT(SIE_F2, "sief2", SCLP_CPU, 4, "SIE: interception format 2 (Virtua= l SIE)") DEF_FEAT(SIE_SKEY, "skey", SCLP_CPU, 5, "SIE: Storage-key facility") diff --git a/target/s390x/cpu_models.c b/target/s390x/cpu_models.c index 962f135f42..a52e34aa95 100644 --- a/target/s390x/cpu_models.c +++ b/target/s390x/cpu_models.c @@ -263,6 +263,7 @@ bool s390_has_feat(S390Feat feat) case S390_FEAT_SIE_CMMA: case S390_FEAT_SIE_PFMFI: case S390_FEAT_SIE_IBS: + case S390_FEAT_SIPL: case S390_FEAT_CONFIGURATION_TOPOLOGY: return false; break; @@ -507,6 +508,7 @@ static void check_consistency(const S390CPUModel *model) { S390_FEAT_AP_QUEUE_INTERRUPT_CONTROL, S390_FEAT_AP }, { S390_FEAT_DIAG_318, S390_FEAT_EXTENDED_LENGTH_SCCB }, { S390_FEAT_CERT_STORE, S390_FEAT_EXTENDED_LENGTH_SCCB }, + { S390_FEAT_SIPL, S390_FEAT_EXTENDED_LENGTH_SCCB }, { S390_FEAT_NNPA, S390_FEAT_VECTOR }, { S390_FEAT_RDP, S390_FEAT_LOCAL_TLB_CLEARING }, { S390_FEAT_UV_FEAT_AP, S390_FEAT_AP }, diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index 6c20c3a862..bd2060ab93 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -721,6 +721,7 @@ static uint16_t full_GEN16_GA1[] =3D { S390_FEAT_UV_FEAT_AP, S390_FEAT_UV_FEAT_AP_INTR, S390_FEAT_CERT_STORE, + S390_FEAT_SIPL, }; =20 static uint16_t full_GEN17_GA1[] =3D { @@ -922,6 +923,7 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_PRNO_TRNG, S390_FEAT_EXTENDED_LENGTH_SCCB, S390_FEAT_CERT_STORE, + S390_FEAT_SIPL, }; =20 /****** END FEATURE DEFS ******/ diff --git a/target/s390x/kvm/kvm.c b/target/s390x/kvm/kvm.c index 56795837f5..61ac6c84a0 100644 --- a/target/s390x/kvm/kvm.c +++ b/target/s390x/kvm/kvm.c @@ -2501,6 +2501,9 @@ bool kvm_s390_get_host_cpu_model(S390CPUModel *model,= Error **errp) =20 set_bit(S390_FEAT_CERT_STORE, model->features); =20 + /* Some Secure IPL facilities are emulated by QEMU */ + set_bit(S390_FEAT_SIPL, model->features); + /* Test for Ultravisor features that influence secure guest behavior */ query_uv_feat_guest(model->features); =20 --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098167; cv=none; d=zohomail.com; s=zohoarc; b=BRIDvVqd9vpOcow0kYfGoA5j8W1ccYlVZ1n9cKBPZ1LYCpLFPrKyb3453YEfFF+WypUSNJ9HSi6pSuzO9utFBpfgKN9uMzZfI/4m8ydXrchoorxSFkLxjgHyFduskYG15+AIiWUELt68Dior1SvWIlvpgx8GEZYCd2qgSEuUtjE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098167; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YZsz+3Sw2LgxbyYlnLsi1LzrSQj0K5ETutA/Sq2xLrk=; b=ehL3Pf1ioKKg7pztkNgbyVoavGlVbuIB/KYzr8w+1JYVMs/A8/FZwwaM1r+vEBTiQNjKoTE0ELr4L1iWrH6cdB8xv9fyUAYwgmu3Z4M3Px2pK+hmmliYNomAiB1DgJMrButZGbeAfgGna9ymKmFtUFml+qmPCyvaYEmBb+3v65g= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098167344798.5161588690272; Fri, 3 Jul 2026 10:02:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHH-0000Sb-TD; Fri, 03 Jul 2026 13:02:11 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGv-00082U-8G; Fri, 03 Jul 2026 13:01:52 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGt-0003LT-C2; Fri, 03 Jul 2026 13:01:48 -0400 Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIZlE3302409; Fri, 3 Jul 2026 17:01:43 GMT Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26n688y7-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:42 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gnie5001524; Fri, 3 Jul 2026 17:01:41 GMT Received: from smtprelay04.wdc07v.mail.ibm.com ([172.16.1.71]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2s7whted-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:41 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay04.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1eQ534013760 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:40 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 5358658054; Fri, 3 Jul 2026 17:01:40 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 83CAE5805D; Fri, 3 Jul 2026 17:01:37 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:37 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=YZsz+3 Sw2LgxbyYlnLsi1LzrSQj0K5ETutA/Sq2xLrk=; b=bK5Dd/VYsSlNNwPvpcUwMt xoq3VVO08zQ7x5ndPs/0B7GVKK6tHoxuPDGo8w2P99PVcbFirIn9ABQ0SK4DF6Zq 5zyO1kp4GaTFSiewkCCOuK2QYiodIxhRyRuOAHd8pItBoVQJ9jDZHMA9lfNlrA32 3NflziVuzF1cYARGm+6SJBvKABvhYdjRVlnX9W9teoLADPsHOKK+2QjN3fO3UCfw TDYY0Pfu3efeWvIkTc7wgps+1wttYyReMHnzu97wlugpn2RyxKelVJN4rjELP/A8 m3sWiU/S7PPDGPzEbwqNco0SwcKYs9WUoHP/rZbbyVnvPQB8641iT1IW457YJPjw == From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 20/33] pc-bios/s390-ccw: Refactor zipl_run() Date: Fri, 3 Jul 2026 13:00:17 -0400 Message-ID: <20260703170032.1893204-21-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXz8KNlmI1indw xJ/Mm+NX++W++ev3gTUmxjLnPj+F0h57j9OMpZxeu7pN35rgXHeY+PT76gnJB/2SyeUqFI+qzEz 1G7na9OJBoHRIrbVtl5YogqSo0GrR0XOwVI48wb3vx12NtWyamaiJ7Lpw+y5qmheskFE8XEu8iq 4rK8whvbN1GiwUM/kG0sHvKI5FK2T4TtPMlN8/C6kaAkDWvsgI8lUh2ejvXF9ErHZBaJ9WDhxdc 4xMtDBl4c9rnW8TK8NSYuthzDGT1mo7JYjz5JqfhNoY2wo5sG/FX2JeLRqERAgOgpCnQhgK9/Iv 5t6c0WGabGsydWQpumRXMbavY6ykYFP/UzSEU49VNerXOBmdnd8v0/1V6vxxWcYn6qddALoMeB4 C4GATxTi8tH7h4TgdUMg1zDF+3bjHm5Zgqzr025fbyUM9Obp9wbaZbLFzAmDKOSH4gjqrNB/aZT vtLByHBKuD/bOiRehOQ== X-Authority-Analysis: v=2.4 cv=V45NF+ni c=1 sm=1 tr=0 ts=6a47eaf6 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=EUspDBNiAAAA:8 a=aJVrDPNlQ3gWXBXSk9UA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 X-Proofpoint-ORIG-GUID: w89oWrqMYtWkwCwUbLOb5z955gKPIYs_ X-Proofpoint-GUID: w89oWrqMYtWkwCwUbLOb5z955gKPIYs_ X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXyxe82qP6BIvc nMOpv2uwYcPBVDl5B1EPbOCsifBjZzsPsgBkZQoTBtJ7zYQH5TxC+MygoqzySLjZbn4yvG8d6AJ OTfg05cUo2vmjjzHv7DT4aqYJS+DwUg= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 spamscore=0 suspectscore=0 lowpriorityscore=0 priorityscore=1501 adultscore=0 clxscore=1015 impostorscore=0 malwarescore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098168536158500 Refactor to enhance readability before enabling secure IPL in later patches. Signed-off-by: Zhuoying Cai Reviewed-by: Thomas Huth Reviewed-by: Jared Rossi Reviewed-by: Collin Walling Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- pc-bios/s390-ccw/bootmap.c | 51 ++++++++++++++++++++++++-------------- 1 file changed, 33 insertions(+), 18 deletions(-) diff --git a/pc-bios/s390-ccw/bootmap.c b/pc-bios/s390-ccw/bootmap.c index 420ee32eff..03841672be 100644 --- a/pc-bios/s390-ccw/bootmap.c +++ b/pc-bios/s390-ccw/bootmap.c @@ -674,12 +674,42 @@ static int zipl_load_segment(ComponentEntry *entry) return 0; } =20 +static int zipl_run_normal(ComponentEntry **entry_ptr, const uint8_t *tmp_= sec) +{ + ComponentEntry *entry =3D *entry_ptr; + + while (entry->component_type =3D=3D ZIPL_COMP_ENTRY_LOAD || + entry->component_type =3D=3D ZIPL_COMP_ENTRY_SIGNATURE) { + + /* Secure boot is off, so we skip signature entries */ + if (entry->component_type =3D=3D ZIPL_COMP_ENTRY_SIGNATURE) { + entry++; + continue; + } + + if (zipl_load_segment(entry)) { + return -1; + } + + entry++; + + if ((uint8_t *)&entry[1] > tmp_sec + MAX_SECTOR_SIZE) { + puts("Wrong entry value"); + return -EINVAL; + } + } + + *entry_ptr =3D entry; + return 0; +} + /* Run a zipl program */ static int zipl_run(ScsiBlockPtr *pte) { ComponentHeader *header; ComponentEntry *entry; uint8_t tmp_sec[MAX_SECTOR_SIZE]; + int rc; =20 if (virtio_read(pte->blockno, tmp_sec)) { puts("Cannot read header"); @@ -700,25 +730,10 @@ static int zipl_run(ScsiBlockPtr *pte) =20 /* Load image(s) into RAM */ entry =3D (ComponentEntry *)(&header[1]); - while (entry->component_type =3D=3D ZIPL_COMP_ENTRY_LOAD || - entry->component_type =3D=3D ZIPL_COMP_ENTRY_SIGNATURE) { - - /* We don't support secure boot yet, so we skip signature entries = */ - if (entry->component_type =3D=3D ZIPL_COMP_ENTRY_SIGNATURE) { - entry++; - continue; - } - - if (zipl_load_segment(entry)) { - return -1; - } =20 - entry++; - - if ((uint8_t *)(&entry[1]) > (tmp_sec + MAX_SECTOR_SIZE)) { - puts("Wrong entry value"); - return -EINVAL; - } + rc =3D zipl_run_normal(&entry, tmp_sec); + if (rc) { + return rc; } =20 if (entry->component_type !=3D ZIPL_COMP_ENTRY_EXEC) { --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098201; cv=none; d=zohomail.com; s=zohoarc; b=M01wldZ+X3xqkUsbw+aA5zxUtj3BTk9e+mbwC1ERar8rOijJGz2GpeXnhZaPONejkZXSYWu2CswFpQtTGKR2ulVq9T7JXnDYLXnYDHkyjB8SHKXBgnEdCskorwdPnZFVGUO6qev8Y4YEsYV2RGS/nasMJMgTA8hq6cYd6ttNDg4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098201; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=5Ky+fnX6oF5CPabK0sIsR4Ty2MY5COE6puS0MLlcNhY=; b=WKv0ZRT/n+NnlZ09V4wTbd/Q1+jKhla3vl4zTn1h48O+UlUL1ZTo0uGzUTwSjp3QJwf+o6AczkIHaDWtO8XY6KX+tLrOk3bubNxzk++Z8mHAjiOUX1uzYRT+Mgbh1pRNbYLczUhenZpwl8xToULlB/tCw+2Lvtzx84omh79DOac= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098201520394.2684532816588; Fri, 3 Jul 2026 10:03:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHL-0000vB-Nx; Fri, 03 Jul 2026 13:02:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhH0-00089f-77; Fri, 03 Jul 2026 13:01:55 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGw-0003M1-84; Fri, 03 Jul 2026 13:01:53 -0400 Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIXXF3497167; Fri, 3 Jul 2026 17:01:46 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26qgg6we-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:45 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GncBr025844; Fri, 3 Jul 2026 17:01:44 GMT Received: from smtprelay07.wdc07v.mail.ibm.com ([172.16.1.74]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2sukhqtt-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:44 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay07.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1hQb33489540 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:43 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 6E89058054; Fri, 3 Jul 2026 17:01:43 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8D82C5805A; Fri, 3 Jul 2026 17:01:40 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:40 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=5Ky+fnX6oF5CPabK0 sIsR4Ty2MY5COE6puS0MLlcNhY=; b=dnyTQtyUVzmGZoOpsZhbOonjCJD7sbTWQ DlEFyaCffEAeZAwgxj+D92/J1POLgy2lpwpHYkwl03V03fR2lHUULJD05lNrToOd 43176G5jDH4BPJEiUCdOqUGkYqIYebw+Nmr6FwLT7dPhwdWT9z2YlXJYLvcrFf4r op7iusqmFAEWSxlDap4LmuPHFJ7glLVJ49Z37YUGJNQhoG5oH5lHLWMVG9wh/OeA ukQbPV6fb5Svs3ox+ZFdM8qvqFVB+b+6mgz4ydNQOIct1VVo77HnhJRCw29rI4qf v+BpcL8qtkDAOw8UdF/6PZK+hz2aCmeRFWuauBB+wKDDI3omGkC7w== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 21/33] pc-bios/s390-ccw: Rework zipl_load_segment function Date: Fri, 3 Jul 2026 13:00:18 -0400 Message-ID: <20260703170032.1893204-22-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=RYqgzVtv c=1 sm=1 tr=0 ts=6a47eaf9 cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=uL_FI9FW9AP7juJAwn4A:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX+tzpkD+8Yx7o Uf3mIQ5YF1PhvCk8UQjf3/Iz4Sb5C12+0U18++0XtBbQkradbUJZdqStAS2sU/0O4x27flj0wBu I8sRu5c5xhqnOh8eBSW9reOWX3uG70E= X-Proofpoint-GUID: h6BQKHP5Jxe9tX4qck62Vs2VMDxMD6Yx X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX6B+pHG85eGGI /QXYBA26gb/oMkmx/M3v9DgD7m5wfT8lOfmNiKc4amVrfguAYRedk4dd6ClapopH6f+BrxYuINE tT/cmB4XEUrntYt/wa0qTqRlD7EFygkuyY3+EtdoN2PRJ2qODIZcP1g3wBcT/hwGAjdMCC2xAhY s20vPDMqtTIuvr6cZxVOQaWN3M8evR/DHD1TjnONsJX5Cs/RO1DXNe8GHTO4LABOoneL9HKJp2A vvWlCkxFWtqMEF/tOSB6pcHYGcT1xG4+tYFKXEy4g1f9crV48oJQhTP0ULC/Yj8hHfV+gGaGue0 Zo9arXWr0ry7psk26rv/6KS6pCJVerXhkl7KwI41jbypKqI+h5kBc3M4PzoFJZe51B0N5zmN6A7 sdQCo79jQruF4c+svs6uNKcAnso959EBQPFDQdex0+9uel/QO6IjsHVXcSv7S+AC7CoGBdCGeqK /8JB4XSvAgk+QwEuZig== X-Proofpoint-ORIG-GUID: h6BQKHP5Jxe9tX4qck62Vs2VMDxMD6Yx X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 impostorscore=0 malwarescore=0 spamscore=0 lowpriorityscore=0 adultscore=0 priorityscore=1501 suspectscore=0 bulkscore=0 clxscore=1015 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098202731158500 Content-Type: text/plain; charset="utf-8" Change zipl_load_segment() to accept explicit blockno and address parameters instead of ComponentEntry pointer and return segment length. Modify this function to allow the caller to specify a memory address where segment data should be loaded into. seg_len variable is necessary to store the calculated segment length and is used during signature verification. Return the length on success, or a negative return code on failure. Remove static qualifier and add function declaration to bootmap.h to make it accessible to other modules. Signed-off-by: Zhuoying Cai Reviewed-by: Thomas Huth Reviewed-by: Collin Walling Reviewed-by: Jared Rossi --- pc-bios/s390-ccw/bootmap.c | 14 ++++++-------- pc-bios/s390-ccw/bootmap.h | 13 +++++++++++++ 2 files changed, 19 insertions(+), 8 deletions(-) diff --git a/pc-bios/s390-ccw/bootmap.c b/pc-bios/s390-ccw/bootmap.c index 03841672be..d0ac97795d 100644 --- a/pc-bios/s390-ccw/bootmap.c +++ b/pc-bios/s390-ccw/bootmap.c @@ -613,19 +613,15 @@ static int ipl_eckd(void) * IPL a SCSI disk */ =20 -static int zipl_load_segment(ComponentEntry *entry) +int zipl_load_segment(block_number_t blockno, uint64_t address) { const int max_entries =3D (MAX_SECTOR_SIZE / sizeof(ScsiBlockPtr)); ScsiBlockPtr *bprs =3D (void *)sec; const int bprs_size =3D sizeof(sec); - block_number_t blockno; - uint64_t address; int i; char err_msg[] =3D "zIPL failed to read BPRS at 0xZZZZZZZZZZZZZZZZ"; char *blk_no =3D &err_msg[30]; /* where to print blockno in (those ZZs= ) */ - - blockno =3D entry->data.blockno; - address =3D entry->compdat.load_addr; + int seg_len =3D 0; =20 debug_print_int("loading segment at block", blockno); debug_print_int("addr", address); @@ -668,10 +664,12 @@ static int zipl_load_segment(ComponentEntry *entry) puts("zIPL load segment failed"); return -EIO; } + + seg_len +=3D bprs->size * (bprs[i].blockct + 1); } } while (blockno); =20 - return 0; + return seg_len; } =20 static int zipl_run_normal(ComponentEntry **entry_ptr, const uint8_t *tmp_= sec) @@ -687,7 +685,7 @@ static int zipl_run_normal(ComponentEntry **entry_ptr, = const uint8_t *tmp_sec) continue; } =20 - if (zipl_load_segment(entry)) { + if (zipl_load_segment(entry->data.blockno, entry->compdat.load_add= r) < 0) { return -1; } =20 diff --git a/pc-bios/s390-ccw/bootmap.h b/pc-bios/s390-ccw/bootmap.h index 95943441d3..40580600b5 100644 --- a/pc-bios/s390-ccw/bootmap.h +++ b/pc-bios/s390-ccw/bootmap.h @@ -113,6 +113,19 @@ typedef struct ScsiMbr { ScsiBlockPtr pt; /* block pointer to program table */ } __attribute__ ((packed)) ScsiMbr; =20 +/** + * zipl_load_segment + * @blockno: block number of the first BPRS describing the segment. + * @address: guest physical address at which to load the segment. + * + * Walks the BPRS chain starting at @blockno, loading each data block + * into guest memory at @address. + * + * Returns: length of the segment on success, + * negative value on error. + */ +int zipl_load_segment(block_number_t blockno, uint64_t address); + #define ZIPL_MAGIC "zIPL" #define ZIPL_MAGIC_EBCDIC "\xa9\xc9\xd7\xd3" #define IPL1_MAGIC "\xc9\xd7\xd3\xf1" /* =3D=3D "IPL1" in EBCDIC */ --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098370; cv=none; d=zohomail.com; s=zohoarc; b=W6rkZnsZK1hY/NUjGbpedp+MqBtiZKSR3tRZiGvfA4MDxPgvKQOmrfaROWQY7cgwaA4F2ux3WtFcJNwAfYt0U7I5eithwKnymbfUkcwKm3P9PYXxq5RavemS4tX97QfrffMqG5u8rhkP0bLWlb0nVh8+cbhWN+R4GiA69DTHalE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098370; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gBHr+IlvuTOTuLwlegrAoznZYuaxIyK7Qqeyi0dAHNI=; b=mY2myQCZoAsUCLCl5jIAWrD1bU3qr03NVFBFgucIkO4s3doLnAVfmqIJfl7A9up9tWBGsAmTAwWfY2blzhbBsTQFeS6ShMm4Im1jXrJtYKTz5EkdF8Gh0h84l4iKOjevigawNLUChQZP/XkZbHKbM+dVKx+RW0LlreSY6iWGcH8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098370363869.1696996705657; Fri, 3 Jul 2026 10:06:10 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHO-0001FR-VE; Fri, 03 Jul 2026 13:02:19 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhH1-0008FC-V6; Fri, 03 Jul 2026 13:01:57 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhGy-0003MI-RH; Fri, 03 Jul 2026 13:01:55 -0400 Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIcDS3382914; Fri, 3 Jul 2026 17:01:48 GMT Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26pegae6-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:48 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnlUK020290; Fri, 3 Jul 2026 17:01:47 GMT Received: from smtprelay04.dal12v.mail.ibm.com ([172.16.1.6]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2u2gsk8x-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:47 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay04.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1kWF26935968 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:46 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 834F65805A; Fri, 3 Jul 2026 17:01:46 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id A84BF58054; Fri, 3 Jul 2026 17:01:43 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:43 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=gBHr+IlvuTOTuLwle grAoznZYuaxIyK7Qqeyi0dAHNI=; b=MuaunqfrZeUkOSqs3+xnUBTdu00QOujYU K/ofxwhxrtbKkYo9aX7/aWwzp05XAk0keUIohX2UBqWQvv/tiicLOGldsWuM/f0B ujRUZiOVr702ZwCXz78iMILYlpO4iccaz9Uu4BqO+BhIVa0NI3ehSisn6+PPi672 0spXU6dSy6+EvCDMZT80Z5TvooTsHwEL9upzU7sdGUnC21A5iGtRioBT88KUGgEr uG44Mu/qHBtkdlaXHrduym5ZyY3SW1Uk1lb9t8y/oOwLSRCZN2cIPUj+VHza1plU vJStPSSSvQsnZOB1kckiC8qrtcMQhOXIh0OExkV37Yn+UjC5xd6Zg== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 22/33] pc-bios/s390-ccw: Introduce ZiplBootMode enum for IPL mode selection Date: Fri, 3 Jul 2026 13:00:19 -0400 Message-ID: <20260703170032.1893204-23-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: S5oaGpsPx9E3JDAIkcPNddhtmqLhT_yA X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX7d72borlG9IX GIkD6XkO/H/YOBkB/c/bMEDtFdabEZ32JBhXqMtb5WiT16MU2+p1RyFJcbjH5ACkrtu0M7jMSAa UZ2cYVNoTQ2K+fMg1ZFIeEX5WZF/ewo= X-Authority-Analysis: v=2.4 cv=edsNubEH c=1 sm=1 tr=0 ts=6a47eafc cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=OEmD_Q5Wy55prwwHBkMA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX1IzTNhIIlzus 3zV4+4380RoKQa6K58Fob2iPPqMvF5IQ0HHWTzFCTM8X6FJM4ebY0744nucEzu43+mRqm7dlZo8 6oSU4Fs2eSdHlo9N4SMQs9eH1Ce765jgKNp/ac5pCIF3LOUS6ss9VPz9zxB+w19Mz2H81VoWsRa hHqze+RPMdTOs9H7UWM1ybrOyFO6Ks8oMTh3Wd55evqweQliWb1XYsnr5Kf1tNC6XfhDjRBeVKc /b8YaYHYJaRtNEZ9dMScwGrz3O0L7XbsJeqjCRRRtyDjs0NHdG07UO3Awv0QeGjMfmruTC8+dNx SJ11qIcpXnHWkWK1DPeukNzbJP1bVoRzbwe1xzF2QujItNJixJ7WU/749cBja0KyWQhCtEaQlpL sL4yRXdU8Nt5jkqTMDPTCh/TxvvB1pUYNc85tFYf2gBaf5igQRU+TJ6TrekGH4h2i/IBe0cnZhd GPoMNlwodTT8zuPDjkw== X-Proofpoint-ORIG-GUID: S5oaGpsPx9E3JDAIkcPNddhtmqLhT_yA X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 adultscore=0 impostorscore=0 bulkscore=0 spamscore=0 suspectscore=0 clxscore=1015 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098372273158501 Content-Type: text/plain; charset="utf-8" Add ZiplBootMode enumeration to support multiple IPL boot configurations. Boot modes differentiate between normal boot and secure IPL operations, enabled based on boot certificates specified via the boot-certs option. Normal Mode: IPL when no certificates are provided. No signature verification is performed. This prepares for future secure IPL modes requiring signature verification. Signed-off-by: Zhuoying Cai Reviewed-by: Collin Walling Reviewed-by: Jared Rossi --- docs/system/s390x/secure-ipl.rst | 21 +++++++++++++++++++++ pc-bios/s390-ccw/bootmap.c | 16 +++++++++++++++- pc-bios/s390-ccw/main.c | 6 ++++++ pc-bios/s390-ccw/s390-ccw.h | 6 ++++++ 4 files changed, 48 insertions(+), 1 deletion(-) diff --git a/docs/system/s390x/secure-ipl.rst b/docs/system/s390x/secure-ip= l.rst index 88df52ce2f..9d7d33f5ed 100644 --- a/docs/system/s390x/secure-ipl.rst +++ b/docs/system/s390x/secure-ipl.rst @@ -18,3 +18,24 @@ Note: certificate files must have a .pem extension. .. code-block:: shell =20 qemu-system-s390x -machine s390-ccw-virtio,boot-certs.0.path=3D/.../qe= mu/certs,boot-certs.1.path=3D/another/path/cert.pem ... + + +IPL Modes +--------- + +Multiple IPL modes are available to differentiate between the various IPL +configurations. These modes are mutually exclusive and enabled based on the +``boot-certs`` option on the QEMU command line. + +Normal Mode +^^^^^^^^^^^ + +The absence of certificates will attempt to IPL a guest without secure IPL +operations. No checks are performed, and no warnings/errors are reported. +This is the default mode. + +Configuration: + +.. code-block:: shell + + qemu-system-s390x -machine s390-ccw-virtio ... diff --git a/pc-bios/s390-ccw/bootmap.c b/pc-bios/s390-ccw/bootmap.c index d0ac97795d..b724152644 100644 --- a/pc-bios/s390-ccw/bootmap.c +++ b/pc-bios/s390-ccw/bootmap.c @@ -729,7 +729,14 @@ static int zipl_run(ScsiBlockPtr *pte) /* Load image(s) into RAM */ entry =3D (ComponentEntry *)(&header[1]); =20 - rc =3D zipl_run_normal(&entry, tmp_sec); + switch (boot_mode) { + case ZIPL_BOOT_MODE_NORMAL: + rc =3D zipl_run_normal(&entry, tmp_sec); + break; + default: + panic("Unknown boot mode"); + } + if (rc) { return rc; } @@ -1101,12 +1108,16 @@ void zipl_load(void) VDev *vdev =3D virtio_get_device(); =20 if (vdev->is_cdrom) { + IPL_assert((boot_mode =3D=3D ZIPL_BOOT_MODE_NORMAL), + "Secure boot from ISO image is not supported!"); ipl_iso_el_torito(); puts("Failed to IPL this ISO image!"); return; } =20 if (virtio_get_device_type() =3D=3D VIRTIO_ID_NET) { + IPL_assert((boot_mode =3D=3D ZIPL_BOOT_MODE_NORMAL), + "Virtio net boot device does not support secure boot!"= ); netmain(); puts("Failed to IPL from this network!"); return; @@ -1117,6 +1128,9 @@ void zipl_load(void) return; } =20 + IPL_assert((boot_mode =3D=3D ZIPL_BOOT_MODE_NORMAL), + "Secure boot with the ECKD scheme is not supported!"); + switch (virtio_get_device_type()) { case VIRTIO_ID_BLOCK: zipl_load_vblk(); diff --git a/pc-bios/s390-ccw/main.c b/pc-bios/s390-ccw/main.c index b8f836c682..cd3d0776b0 100644 --- a/pc-bios/s390-ccw/main.c +++ b/pc-bios/s390-ccw/main.c @@ -30,6 +30,7 @@ IplParameterBlock *iplb; bool have_iplb; static uint16_t cutype; LowCore *lowcore; /* Yes, this *is* a pointer to address 0 */ +ZiplBootMode boot_mode; =20 #define LOADPARM_PROMPT "PROMPT " #define LOADPARM_EMPTY " " @@ -303,6 +304,9 @@ static void ipl_ccw_device(void) switch (cutype) { case CU_TYPE_DASD_3990: case CU_TYPE_DASD_2107: + IPL_assert((boot_mode =3D=3D ZIPL_BOOT_MODE_NORMAL), + "Passthrough (vfio) CCW device does not support secure= boot!"); + dasd_ipl(blk_schid, cutype); break; case CU_TYPE_VIRTIO: @@ -390,6 +394,8 @@ void main(void) probe_boot_device(); } =20 + boot_mode =3D ZIPL_BOOT_MODE_NORMAL; + while (have_iplb) { boot_setup(); if (have_iplb && find_boot_device()) { diff --git a/pc-bios/s390-ccw/s390-ccw.h b/pc-bios/s390-ccw/s390-ccw.h index 1e1f71775e..5420443ad2 100644 --- a/pc-bios/s390-ccw/s390-ccw.h +++ b/pc-bios/s390-ccw/s390-ccw.h @@ -69,6 +69,12 @@ int sclp_read(char *str, size_t count); /* bootmap.c */ void zipl_load(void); =20 +typedef enum ZiplBootMode { + ZIPL_BOOT_MODE_NORMAL =3D 0, +} ZiplBootMode; + +extern ZiplBootMode boot_mode; + /* jump2ipl.c */ void write_reset_psw(uint64_t psw); int jump_to_IPL_code(uint64_t address); --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098360; cv=none; d=zohomail.com; s=zohoarc; b=QXnFvWxwUbOv/35Hh1pOyTI+jPf6G+RdTQkm9R95cp2nLVj11r6sSR+nnHxDz3BuHpYhGbP5jZHwJYcAS326MId4IFrhuKQNQsmUubcE6bw73BfFJRYpQG4NxPWBHtKF8c/VhohENAworg65VZvyR/ZhBJCeG8kU7Rp4yj4pSYo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098360; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Ihv2pOyFmUFWKAq6gr4uo5uXdTZ2kd53deDer58KU4Q=; b=mUvYeBzoG/7jYjYc9EdYRCrHNV94kKWF2EY1JnueOe+24oRrQTTXnrrAqTPtODeQ8yuSQf55rIQhft6O+psXRMYBAHoypxyxzPrnU9BptlcDaKbgfuehgrsInRmnGEFdvlTnxnipyBdM3EYPgwyN3AcnHMt8Jyudj5sFT7iHAY0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178309836068943.367907471238254; Fri, 3 Jul 2026 10:06:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHI-0000YC-Rk; Fri, 03 Jul 2026 13:02:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhH7-0008Jz-AK; Fri, 03 Jul 2026 13:02:02 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhH3-0003NW-RX; Fri, 03 Jul 2026 13:02:01 -0400 Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIWSD3302307; Fri, 3 Jul 2026 17:01:52 GMT Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26n688yu-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:52 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gncm1031490; Fri, 3 Jul 2026 17:01:51 GMT Received: from smtprelay07.dal12v.mail.ibm.com ([172.16.1.9]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2uhysgdw-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:51 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay07.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1n2m1508082 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:50 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id CB46A5805D; Fri, 3 Jul 2026 17:01:49 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id BBDA95805C; Fri, 3 Jul 2026 17:01:46 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:46 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=Ihv2pOyFmUFWKAq6g r4uo5uXdTZ2kd53deDer58KU4Q=; b=h4ma0tyQfu9jILuw/gL85flMmC4oCt0nk Ur5nRjt3sLy8jjI+qS+I9ehJm6qik2Ppye775spSCpIvzInMxluqVCoBQ3G/nukG 5AmFXca+7XksJYTNx5tYg+0QZ+2g9B2D90HnSxozuRlPwKaEx3/t7qCdI2xFWAtr ZRgut821aLcy4tTz0bQSK/Phkp4Kau38Ga7nxIPDmqPmF3g1lc7KEyXoZMnPJbmV ieDMyYKA5mSlbjuuau629htdcOm5iu0ZDpTDZWKMBYjiHdW7b5ZvyylGTC2XBnV3 7TOzkHAZ5i/a7UatwiE8+33FTKs2S/VwJvo+UWjSnYAA/YjJ4Jffg== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 23/33] pc-bios/s390-ccw: Add signature verification for secure IPL in audit mode Date: Fri, 3 Jul 2026 13:00:20 -0400 Message-ID: <20260703170032.1893204-24-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX84889pQ2ZtV0 93nngYJO2rXpJYSUZgylAVW0M8n75MkAiDbGtinnm2ycK9OFw51UB5cT7Trihp2WmJLDdFIOgKQ BLFmV1LiPXLrJJe1ByIOzoeexZumDB3OH9jHjriw8WbUzXcnF7hsUb6DsLjuHTP92yc2bPPFnRI tihet3Tq6n9sjONo90E7COolQJPNoRwAsdfnV7fsMgg0oCJr/sdFf4dxyvvPvV+nzjuO93yNMzf z2CPQAr5wK2k6E+V61DpFMqDxFpnHtH0pHS5ujm1Ik9OoFmlAA5XOTC6v1oDQYO3x+xbLAA+KYX RoWX7zEnHTkrqnm+U1t93i4lF7kN0V2EaJ1Odw+kAcqHYdbqNDeSZ1W2XT+FUMugW/Y/EMlSkLA QW8ylvNxA2rOR9KomlWxmZqg0YwAiw/lpcQbx2bLWnKKZuRbsqH2UkpxctDgT+ePJh9FQBhrltA TqG5XNW/0/U9zk1breQ== X-Authority-Analysis: v=2.4 cv=V45NF+ni c=1 sm=1 tr=0 ts=6a47eb00 cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=Tktb4ypIQN7ojq7NPMkA:9 X-Proofpoint-ORIG-GUID: arXrhKYir9RfD36fGaNr3cw2VQp7Plrf X-Proofpoint-GUID: arXrhKYir9RfD36fGaNr3cw2VQp7Plrf X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXwDD0cre8fykn 5LaSuMffYtN3aKb3yqK2TCpQN7SWl+mcm8Axakpf4npIZ8f/nL7QYJwW7et+S+H1NszDZ1jvliK xy3gD22kNGlrMsNG561B0NR5FzilsXs= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 spamscore=0 suspectscore=0 lowpriorityscore=0 priorityscore=1501 adultscore=0 clxscore=1015 impostorscore=0 malwarescore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098362274158500 Content-Type: text/plain; charset="utf-8" Enable secure IPL in audit mode, which performs signature verification, but any error does not terminate the boot process. Only warnings will be logged to the console instead. Secure IPL in audit mode requires at least one certificate provided in the key store along with necessary facilities (Secure IPL Facility, Certificate Store Facility and secure IPL extension support). Note: Secure IPL in audit mode is implemented for the SCSI scheme of virtio-blk/virtio-scsi devices. Signed-off-by: Zhuoying Cai Reviewed-by: Eric Farman --- docs/system/s390x/secure-ipl.rst | 15 ++ hw/s390x/ipl.c | 9 + pc-bios/s390-ccw/Makefile | 2 +- pc-bios/s390-ccw/bootmap.c | 27 +++ pc-bios/s390-ccw/bootmap.h | 9 + pc-bios/s390-ccw/jump2ipl.c | 7 + pc-bios/s390-ccw/main.c | 19 +- pc-bios/s390-ccw/s390-ccw.h | 20 ++ pc-bios/s390-ccw/sclp.c | 27 +++ pc-bios/s390-ccw/sclp.h | 6 + pc-bios/s390-ccw/secure-ipl.c | 363 +++++++++++++++++++++++++++++++ pc-bios/s390-ccw/secure-ipl.h | 115 ++++++++++ 12 files changed, 617 insertions(+), 2 deletions(-) create mode 100644 pc-bios/s390-ccw/secure-ipl.c create mode 100644 pc-bios/s390-ccw/secure-ipl.h diff --git a/docs/system/s390x/secure-ipl.rst b/docs/system/s390x/secure-ip= l.rst index 9d7d33f5ed..cf6ccf5d57 100644 --- a/docs/system/s390x/secure-ipl.rst +++ b/docs/system/s390x/secure-ipl.rst @@ -39,3 +39,18 @@ Configuration: .. code-block:: shell =20 qemu-system-s390x -machine s390-ccw-virtio ... + +Audit Mode +^^^^^^^^^^ + +When the certificate store is populated with at least one certificate +and no additional secure IPL parameters are provided on the command +line, then secure IPL will proceed in "audit mode". All secure IPL +operations will be performed with signature verification errors reported +as non-disruptive warnings. + +Configuration: + +.. code-block:: shell + + qemu-system-s390x -machine s390-ccw-virtio,boot-certs.0.path=3D/.../qe= mu/certs,boot-certs.1.path=3D/another/path/cert.pem ... diff --git a/hw/s390x/ipl.c b/hw/s390x/ipl.c index af89005790..cd80e3057c 100644 --- a/hw/s390x/ipl.c +++ b/hw/s390x/ipl.c @@ -826,6 +826,15 @@ void s390_ipl_prepare_cpu(S390CPU *cpu) cpu->env.psw.addr =3D ipl->bios_start_addr; if (!ipl->iplb_valid) { ipl->iplb_valid =3D s390_init_all_iplbs(ipl); + + /* + * Secure IPL without specifying a boot device. + * IPLB is not generated if no boot device is defined. + */ + if (s390_has_certificate() && !ipl->iplb_valid) { + error_report("No boot device defined for Secure IPL"); + exit(1); + } } else { ipl->qipl.chain_len =3D 0; } diff --git a/pc-bios/s390-ccw/Makefile b/pc-bios/s390-ccw/Makefile index 3e5dfb64d5..2109d16781 100644 --- a/pc-bios/s390-ccw/Makefile +++ b/pc-bios/s390-ccw/Makefile @@ -35,7 +35,7 @@ QEMU_DGFLAGS =3D -MMD -MP -MT $@ -MF $(@D)/$(*F).d =20 OBJECTS =3D start.o main.o bootmap.o jump2ipl.o sclp.o menu.o netmain.o \ virtio.o virtio-net.o virtio-scsi.o virtio-blkdev.o cio.o dasd-ipl.o \ - virtio-ccw.o clp.o pci.o virtio-pci.o + virtio-ccw.o clp.o pci.o virtio-pci.o secure-ipl.o =20 SLOF_DIR :=3D $(SRC_PATH)/../../roms/SLOF =20 diff --git a/pc-bios/s390-ccw/bootmap.c b/pc-bios/s390-ccw/bootmap.c index b724152644..7cdeec7064 100644 --- a/pc-bios/s390-ccw/bootmap.c +++ b/pc-bios/s390-ccw/bootmap.c @@ -10,11 +10,13 @@ =20 #include #include +#include #include "s390-ccw.h" #include "s390-arch.h" #include "bootmap.h" #include "virtio.h" #include "bswap.h" +#include "secure-ipl.h" =20 #ifdef DEBUG /* #define DEBUG_FALLBACK */ @@ -707,6 +709,9 @@ static int zipl_run(ScsiBlockPtr *pte) ComponentHeader *header; ComponentEntry *entry; uint8_t tmp_sec[MAX_SECTOR_SIZE]; + IplDeviceComponentList comp_list =3D { 0 }; + IplSignatureCertificateList cert_list =3D { 0 }; + uint8_t *tmp_cert_buf =3D NULL; int rc; =20 if (virtio_read(pte->blockno, tmp_sec)) { @@ -733,6 +738,9 @@ static int zipl_run(ScsiBlockPtr *pte) case ZIPL_BOOT_MODE_NORMAL: rc =3D zipl_run_normal(&entry, tmp_sec); break; + case ZIPL_BOOT_MODE_SECURE_AUDIT: + rc =3D zipl_run_secure(&entry, tmp_sec, &comp_list, &cert_list, &t= mp_cert_buf); + break; default: panic("Unknown boot mode"); } @@ -748,6 +756,13 @@ static int zipl_run(ScsiBlockPtr *pte) =20 /* should not return */ write_reset_psw(entry->compdat.load_psw); + + if (boot_mode =3D=3D ZIPL_BOOT_MODE_SECURE_AUDIT) { + update_cert_list(&cert_list); + update_iirb(&comp_list, &cert_list); + free(tmp_cert_buf); + } + jump_to_IPL_code(0); return -1; } @@ -1103,6 +1118,18 @@ static int zipl_load_vscsi(void) * IPL starts here */ =20 +ZiplBootMode get_boot_mode(uint8_t hdr_flags) +{ + bool sipl_set =3D hdr_flags & DIAG308_IPIB_FLAGS_SIPL; + bool iplir_set =3D hdr_flags & DIAG308_IPIB_FLAGS_IPLIR; + + if (!sipl_set && iplir_set) { + return ZIPL_BOOT_MODE_SECURE_AUDIT; + } + + return ZIPL_BOOT_MODE_NORMAL; +} + void zipl_load(void) { VDev *vdev =3D virtio_get_device(); diff --git a/pc-bios/s390-ccw/bootmap.h b/pc-bios/s390-ccw/bootmap.h index 40580600b5..e1f4130752 100644 --- a/pc-bios/s390-ccw/bootmap.h +++ b/pc-bios/s390-ccw/bootmap.h @@ -88,9 +88,18 @@ typedef struct BootMapTable { BootMapPointer entry[]; } __attribute__ ((packed)) BootMapTable; =20 +#define DER_SIGNATURE_FORMAT 1 + +typedef struct SignatureInformation { + uint8_t format; + uint8_t reserved[3]; + uint32_t sig_len; +} SignatureInformation; + typedef union ComponentEntryData { uint64_t load_psw; uint64_t load_addr; + SignatureInformation sig_info; } ComponentEntryData; =20 typedef struct ComponentEntry { diff --git a/pc-bios/s390-ccw/jump2ipl.c b/pc-bios/s390-ccw/jump2ipl.c index fa2ca5cbe1..8e87c566f9 100644 --- a/pc-bios/s390-ccw/jump2ipl.c +++ b/pc-bios/s390-ccw/jump2ipl.c @@ -75,6 +75,13 @@ int jump_to_IPL_code(uint64_t address) "diag %%r1,%%r1,0x308\n\t" : : : "1", "memory"); puts("IPL code jump failed"); + + /* + * A failed jump only occurs in extreme conditions, so abort the IPL e= ntirely. + * This also prevents attempts to boot from the chain area if it has b= een + * overwritten with component data. + */ + qipl.chain_len =3D 0; return -1; } =20 diff --git a/pc-bios/s390-ccw/main.c b/pc-bios/s390-ccw/main.c index cd3d0776b0..b94a08e7bf 100644 --- a/pc-bios/s390-ccw/main.c +++ b/pc-bios/s390-ccw/main.c @@ -20,6 +20,7 @@ #include "dasd-ipl.h" #include "clp.h" #include "virtio-pci.h" +#include "secure-ipl.h" =20 static SubChannelId blk_schid =3D { .one =3D 1 }; static char loadparm_str[LOADPARM_LEN + 1]; @@ -383,6 +384,8 @@ static void probe_boot_device(void) =20 void main(void) { + int vcssb_len; + iplb =3D &ipl_blocks.iplb; =20 copy_qipl(); @@ -394,7 +397,21 @@ void main(void) probe_boot_device(); } =20 - boot_mode =3D ZIPL_BOOT_MODE_NORMAL; + boot_mode =3D get_boot_mode(iplb->hdr_flags); + switch (boot_mode) { + case ZIPL_BOOT_MODE_SECURE_AUDIT: + if (!secure_ipl_supported()) { + panic("Unable to boot in audit mode"); + } + + vcssb_len =3D zipl_secure_get_vcssb(); + if (vcssb_len =3D=3D 0) { + panic("Failed to query certificate storage information!"); + } + break; + default: + break; + } =20 while (have_iplb) { boot_setup(); diff --git a/pc-bios/s390-ccw/s390-ccw.h b/pc-bios/s390-ccw/s390-ccw.h index 5420443ad2..ca2737054d 100644 --- a/pc-bios/s390-ccw/s390-ccw.h +++ b/pc-bios/s390-ccw/s390-ccw.h @@ -40,6 +40,22 @@ typedef unsigned long long u64; ((b) =3D=3D 0 ? (a) : (MIN(a, b)))) #endif =20 +/* + * Round number down to multiple. Requires that d be a power of 2. + * Works even if d is a smaller type than n. + */ +#ifndef ROUND_DOWN +#define ROUND_DOWN(n, d) ((n) & -(0 ? (n) : (d))) +#endif + +/* + * Round number up to multiple. Requires that d be a power of 2. + * Works even if d is a smaller type than n. + */ +#ifndef ROUND_UP +#define ROUND_UP(n, d) ROUND_DOWN((n) + (d) - 1, (d)) +#endif + #define ARRAY_SIZE(a) (sizeof(a) / sizeof((a)[0])) =20 #include "cio.h" @@ -64,6 +80,8 @@ void sclp_print(const char *string); void sclp_set_write_mask(uint32_t receive_mask, uint32_t send_mask); void sclp_setup(void); void sclp_get_loadparm_ascii(char *loadparm); +bool sclp_is_diag320_on(void); +bool sclp_is_fac_ipl_flag_on(uint16_t fac_ipl_flag); int sclp_read(char *str, size_t count); =20 /* bootmap.c */ @@ -71,9 +89,11 @@ void zipl_load(void); =20 typedef enum ZiplBootMode { ZIPL_BOOT_MODE_NORMAL =3D 0, + ZIPL_BOOT_MODE_SECURE_AUDIT =3D 1, } ZiplBootMode; =20 extern ZiplBootMode boot_mode; +ZiplBootMode get_boot_mode(uint8_t hdr_flags); =20 /* jump2ipl.c */ void write_reset_psw(uint64_t psw); diff --git a/pc-bios/s390-ccw/sclp.c b/pc-bios/s390-ccw/sclp.c index 4a07de018d..48bdfedf1f 100644 --- a/pc-bios/s390-ccw/sclp.c +++ b/pc-bios/s390-ccw/sclp.c @@ -113,6 +113,33 @@ void sclp_get_loadparm_ascii(char *loadparm) } } =20 +bool sclp_is_diag320_on(void) +{ + ReadInfo *sccb =3D (void *)_sccb; + + memset((char *)_sccb, 0, sizeof(ReadInfo)); + sccb->h.length =3D SCCB_SIZE; + if (!sclp_service_call(SCLP_CMDW_READ_SCP_INFO, sccb)) { + return sccb->fac134 & SCCB_FAC134_DIAG320_BIT; + } + + return 0; +} + +/* check if specified IPL facility flag is enabled */ +bool sclp_is_fac_ipl_flag_on(uint16_t fac_ipl_flag) +{ + ReadInfo *sccb =3D (void *)_sccb; + + memset((char *)_sccb, 0, sizeof(ReadInfo)); + sccb->h.length =3D SCCB_SIZE; + if (!sclp_service_call(SCLP_CMDW_READ_SCP_INFO, sccb)) { + return sccb->fac_ipl & fac_ipl_flag; + } + + return 0; +} + int sclp_read(char *str, size_t count) { ReadEventData *sccb =3D (void *)_sccb; diff --git a/pc-bios/s390-ccw/sclp.h b/pc-bios/s390-ccw/sclp.h index 64b53cad29..a8a41cd004 100644 --- a/pc-bios/s390-ccw/sclp.h +++ b/pc-bios/s390-ccw/sclp.h @@ -50,6 +50,8 @@ typedef struct SCCBHeader { } __attribute__((packed)) SCCBHeader; =20 #define SCCB_DATA_LEN (SCCB_SIZE - sizeof(SCCBHeader)) +#define SCCB_FAC134_DIAG320_BIT 0x4 +#define SCCB_FAC_IPL_SIPL_BIT 0x4000 =20 typedef struct ReadInfo { SCCBHeader h; @@ -57,6 +59,10 @@ typedef struct ReadInfo { uint8_t rnsize; uint8_t reserved[13]; uint8_t loadparm[LOADPARM_LEN]; + uint8_t reserved1[102]; + uint8_t fac134; + uint8_t reserved2; + uint16_t fac_ipl; } __attribute__((packed)) ReadInfo; =20 typedef struct SCCB { diff --git a/pc-bios/s390-ccw/secure-ipl.c b/pc-bios/s390-ccw/secure-ipl.c new file mode 100644 index 0000000000..1ab41e5543 --- /dev/null +++ b/pc-bios/s390-ccw/secure-ipl.c @@ -0,0 +1,363 @@ +/* + * S/390 Secure IPL + * + * Functions to support IPL in secure boot mode (DIAG 320, DIAG 508, + * signature verification, and certificate handling). + * + * For secure IPL overview: docs/system/s390x/secure-ipl.rst + * For secure IPL technical: docs/specs/s390x-secure-ipl.rst + * + * Copyright 2025 IBM Corp. + * Author(s): Zhuoying Cai + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#include +#include +#include +#include "s390-ccw.h" +#include "sclp.h" +#include "secure-ipl.h" + +static VCStorageSizeBlock vcssb __attribute__((__aligned__(8))); + +#define for_each_rb_entry(entry, list) \ + for (entry =3D (void *)(list) + sizeof((list)->ipl_info_header); \ + (void *)(entry) + sizeof(*(entry)) <=3D \ + (void *)(list) + (list)->ipl_info_header.len; \ + entry++) + +int zipl_secure_get_vcssb(void) +{ + /* avoid retrieving vcssb multiple times */ + if (vcssb.length =3D=3D VCSSB_LEN_VALID) { + goto out; + } + + vcssb.length =3D VCSSB_LEN_VALID; + if (_diag320(&vcssb, DIAG_320_SUBC_QUERY_VCSI) !=3D DIAG_320_RC_OK) { + vcssb.length =3D 0; + } + +out: + return vcssb.length; +} + +static uint32_t request_certificate(uint8_t *cert_buf, uint8_t index) +{ + VCEntryHeader *vce_hdr; + struct vcb { + VCBlockHeader vcb_hdr; + struct vce { + VCEntryHeader vce_hdr; + uint8_t cert_buf[CERT_BUF_MAX_LEN]; + } vce; + } __attribute__((__aligned__(PAGE_SIZE))) vcb =3D { 0 }; + + /* + * Request single entry + * Fill input fields of single-entry VCB + * + * First and last index must be equal because only one + * VCE per VCB is currently supported + */ + vcb.vcb_hdr.in_len =3D ROUND_UP(vcssb.max_single_vcb_len, PAGE_SIZE); + vcb.vcb_hdr.first_vc_index =3D index; + vcb.vcb_hdr.last_vc_index =3D index; + + if (_diag320(&vcb, DIAG_320_SUBC_STORE_VC) !=3D DIAG_320_RC_OK) { + puts("Could not get certificate"); + return 0; + } + + if (vcb.vcb_hdr.out_len =3D=3D sizeof(VCBlockHeader)) { + puts("No certificate entry"); + return 0; + } + + if (vcb.vcb_hdr.remain_ct !=3D 0) { + panic("Not enough memory to store requested certificate"); + } + + vce_hdr =3D &vcb.vce.vce_hdr; + if (!(vce_hdr->flags & DIAG_320_VCE_FLAGS_VALID)) { + puts("Invalid certificate"); + return 0; + } + + memcpy(cert_buf, (uint8_t *)&vcb.vce + vce_hdr->cert_offset, vce_hdr->= cert_len); + + return vce_hdr->cert_len; +} + +static int cert_list_add(IplSignatureCertificateList *cert_list, + IplSignatureCertificateEntry cert_entry) +{ + int cert_entry_idx; + + cert_entry_idx =3D (cert_list->ipl_info_header.len - sizeof(IplInfoBlo= ckHeader)) / + sizeof(IplSignatureCertificateEntry); + + cert_list->cert_entries[cert_entry_idx] =3D cert_entry; + cert_list->ipl_info_header.len +=3D sizeof(IplSignatureCertificateEntr= y); + + return cert_entry_idx; +} + +static void comp_list_add(IplDeviceComponentList *comp_list, + IplDeviceComponentEntry comp_entry) +{ + int comp_entry_idx; + + comp_entry_idx =3D (comp_list->ipl_info_header.len - sizeof(IplInfoBlo= ckHeader)) / + sizeof(IplDeviceComponentEntry); + if (comp_entry_idx > MAX_COMP_ENTRIES - 1) { + printf("Warning: only %d component entries are supported\n", + MAX_COMP_ENTRIES); + panic("The device component list has reached its maximum capacity"= ); + } + + comp_list->device_entries[comp_entry_idx] =3D comp_entry; + comp_list->ipl_info_header.len +=3D sizeof(IplDeviceComponentEntry); +} + +void update_iirb(IplDeviceComponentList *comp_list, + IplSignatureCertificateList *cert_list) +{ + IplInfoReportBlock *iirb; + IplDeviceComponentList *iirb_comps; + IplSignatureCertificateList *iirb_certs; + uint32_t iirb_hdr_len; + uint32_t comps_len; + uint32_t certs_len; + + if (iplb->len % 8 !=3D 0) { + panic("IPL parameter block length field value is not multiple of 8= bytes"); + } + + iirb_hdr_len =3D sizeof(IplInfoReportBlockHeader); + comps_len =3D comp_list->ipl_info_header.len; + certs_len =3D cert_list->ipl_info_header.len; + if ((comps_len + certs_len + iirb_hdr_len) > sizeof(IplInfoReportBlock= )) { + panic("Not enough space to hold all components and certificates in= IIRB"); + } + + /* IIRB immediately follows IPLB */ + iirb =3D &ipl_blocks.iirb; + iirb->hdr.len =3D iirb_hdr_len; + + /* Copy IPL device component list after IIRB Header */ + iirb_comps =3D (IplDeviceComponentList *) iirb->info_blks; + memcpy(iirb_comps, comp_list, comps_len); + + /* Update IIRB length */ + iirb->hdr.len +=3D comps_len; + + /* Copy IPL sig cert list after IPL device component list */ + iirb_certs =3D (IplSignatureCertificateList *) (iirb->info_blks + + iirb_comps->ipl_info_hea= der.len); + memcpy(iirb_certs, cert_list, certs_len); + + /* Update IIRB length */ + iirb->hdr.len +=3D certs_len; +} + +bool secure_ipl_supported(void) +{ + if (!sclp_is_fac_ipl_flag_on(SCCB_FAC_IPL_SIPL_BIT)) { + puts("Secure IPL Facility is not supported by the hypervisor!"); + return false; + } + + if (!is_signature_verif_supported()) { + puts("Secure IPL extensions are not supported by the hypervisor!"); + return false; + } + + if (!is_cert_store_facility_supported()) { + puts("Certificate Store Facility is not supported by the hyperviso= r!"); + return false; + } + + return true; +} + +static void init_lists(IplDeviceComponentList *comp_list, + IplSignatureCertificateList *cert_list) +{ + comp_list->ipl_info_header.type =3D IPL_INFO_BLOCK_TYPE_COMPONENTS; + comp_list->ipl_info_header.len =3D sizeof(IplInfoBlockHeader); + + cert_list->ipl_info_header.type =3D IPL_INFO_BLOCK_TYPE_CERTIFICATES; + cert_list->ipl_info_header.len =3D sizeof(IplInfoBlockHeader); +} + +static int zipl_load_signature(ComponentEntry *entry, uint64_t sig) +{ + if (entry->compdat.sig_info.format !=3D DER_SIGNATURE_FORMAT) { + puts("Signature is not in DER format"); + return -1; + } + + if (zipl_load_segment(entry->data.blockno, sig) < 0) { + return -1; + } + + return entry->compdat.sig_info.sig_len; +} + +void update_cert_list(IplSignatureCertificateList *cert_list) +{ + IplSignatureCertificateEntry *cert_entry; + uint8_t *cert_buf; + + /* Recover the original base address of ipl_data for cert storage */ + cert_buf =3D (uint8_t *)qipl.ipl_data - qipl.index * sizeof(IplParamet= erBlock); + + for_each_rb_entry(cert_entry, cert_list) { + memcpy(cert_buf, (uint8_t *)cert_entry->addr, cert_entry->len); + cert_entry->addr =3D (uint64_t)cert_buf; + cert_buf +=3D cert_entry->len; + } +} + +int zipl_run_secure(ComponentEntry **entry_ptr, const uint8_t *tmp_sec, + IplDeviceComponentList *comp_list, + IplSignatureCertificateList *cert_list, + uint8_t **tmp_cert_buf) +{ + /* + * Keep track of which certificate store indices correspond to the + * certificate data entries within the IplSignatureCertificateList to + * prevent allocating space for the same certificate multiple times. + * + * The array index corresponds to the certificate's cert-store index. + * + * The array value corresponds to the certificate's entry within the + * IplSignatureCertificateList (with a value of -1 denoting no entry + * exists for the certificate). + */ + int cert_list_table[vcssb.total_vc_ct + 1]; + IplSignatureCertificateEntry sig_entry =3D { 0 }; + IplSignatureCertificateEntry cert_entry; + IplDeviceComponentEntry comp_entry; + ComponentEntry *entry =3D *entry_ptr; + int rc =3D -1; + int sig_len =3D 0; + int comp_len; + int cert_entry_idx; + uint64_t comp_addr; + uint8_t cert_table_idx; + uint8_t *tmp_buf; + bool verified; + bool signed_found =3D false; + + if ((MAX_SIGNED_COMP * CERT_BUF_MAX_LEN) > CERT_BUF_SIZE) { + panic("Not enough memory to store certificates"); + } + *tmp_cert_buf =3D malloc(CERT_BUF_SIZE); + tmp_buf =3D *tmp_cert_buf; + + init_lists(comp_list, cert_list); + sig_entry.addr =3D (uint64_t)malloc(MAX_SECTOR_SIZE); + memset(cert_list_table, -1, sizeof(cert_list_table)); + + while (entry->component_type !=3D ZIPL_COMP_ENTRY_EXEC) { + switch (entry->component_type) { + case ZIPL_COMP_ENTRY_SIGNATURE: + if (sig_entry.len) { + goto error; + } + + sig_len =3D zipl_load_signature(entry, sig_entry.addr); + if (sig_len < 0) { + goto error; + } + + sig_entry.len =3D sig_len; + break; + case ZIPL_COMP_ENTRY_LOAD: + comp_addr =3D entry->compdat.load_addr; + comp_len =3D zipl_load_segment(entry->data.blockno, comp_addr); + if (comp_len < 0) { + goto error; + } + + comp_entry =3D (IplDeviceComponentEntry){ 0 }; + comp_entry.addr =3D comp_addr; + comp_entry.len =3D (uint64_t)comp_len; + + /* no signature present (unsigned component) */ + if (!sig_entry.len) { + comp_list_add(comp_list, comp_entry); + break; + } + + /* + * Initialize with SC flag (signed component) + * CSV flag set upon successful verification + */ + comp_entry.flags =3D S390_IPL_DEV_COMP_FLAG_SC; + signed_found =3D true; + + cert_entry =3D (IplSignatureCertificateEntry) { 0 }; + verified =3D verify_signature(comp_entry, sig_entry, + &cert_entry.len, &cert_table_idx); + + if (verified) { + if (cert_list_table[cert_table_idx] =3D=3D -1) { + if (!request_certificate(tmp_buf, cert_table_idx)) { + puts("Could not get certificate"); + goto error; + } + + cert_entry.addr =3D (uint64_t)tmp_buf; + cert_entry_idx =3D cert_list_add(cert_list, cert_entry= ); + /* map cert-store index to cert-list entry index */ + cert_list_table[cert_table_idx] =3D cert_entry_idx; + /* increment for the next certificate */ + tmp_buf +=3D cert_entry.len; + } + + comp_entry.cert_index =3D cert_list_table[cert_table_idx]; + comp_entry.flags |=3D S390_IPL_DEV_COMP_FLAG_CSV; + puts("Verified component"); + } else { + zipl_secure_error("Could not verify component"); + } + + comp_list_add(comp_list, comp_entry); + + /* After a signature is used another new one can be accepted */ + sig_entry.len =3D 0; + break; + default: + puts("Unknown component entry type"); + goto error; + } + + entry++; + + if ((uint8_t *)(&entry[1]) > tmp_sec + MAX_SECTOR_SIZE) { + puts("Wrong entry value"); + rc =3D -EINVAL; + goto error; + } + } + + if (!signed_found) { + zipl_secure_error("Secure boot is on, but components are not signe= d"); + } + + *entry_ptr =3D entry; + free((void *)sig_entry.addr); + + return 0; +error: + free(*tmp_cert_buf); + *tmp_cert_buf =3D NULL; + free((void *)sig_entry.addr); + + return rc; +} diff --git a/pc-bios/s390-ccw/secure-ipl.h b/pc-bios/s390-ccw/secure-ipl.h new file mode 100644 index 0000000000..e192f8b61d --- /dev/null +++ b/pc-bios/s390-ccw/secure-ipl.h @@ -0,0 +1,115 @@ +/* + * S/390 Secure IPL + * + * Copyright 2025 IBM Corp. + * Author(s): Zhuoying Cai + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#ifndef _PC_BIOS_S390_CCW_SECURE_IPL_H +#define _PC_BIOS_S390_CCW_SECURE_IPL_H + +#include "bootmap.h" +#include +#include + +#define MAX_SIGNED_COMP 3 + +int zipl_secure_get_vcssb(void); +bool secure_ipl_supported(void); +void update_iirb(IplDeviceComponentList *comp_list, + IplSignatureCertificateList *cert_list); +void update_cert_list(IplSignatureCertificateList *cert_list); +int zipl_run_secure(ComponentEntry **entry_ptr, const uint8_t *tmp_sec, + IplDeviceComponentList *comp_list, + IplSignatureCertificateList *cert_list, + uint8_t **tmp_cert_buf); + +static inline void zipl_secure_error(const char *message) +{ + switch (boot_mode) { + case ZIPL_BOOT_MODE_SECURE_AUDIT: + printf("AUDIT MODE WARNING: %s\n", message); + break; + default: + break; + } +} + +static inline uint64_t _diag320(void *data, unsigned long subcode) +{ + register unsigned long addr asm("0") =3D (unsigned long)data; + register unsigned long rc asm("1") =3D 0; + + asm volatile ("diag %0,%2,0x320\n" + : "+d" (addr), "+d" (rc) + : "d" (subcode) + : "memory", "cc"); + return rc; +} + +static inline bool is_cert_store_facility_supported(void) +{ + uint32_t d320_ism; + + if (!sclp_is_diag320_on()) { + return false; + } + + if (_diag320(&d320_ism, DIAG_320_SUBC_QUERY_ISM) !=3D DIAG_320_RC_OK) { + return false; + } + + return d320_ism & (DIAG_320_ISM_QUERY_VCSI | DIAG_320_ISM_STORE_VC); +} + +static inline uint64_t _diag508(void *data, unsigned long subcode) +{ + register unsigned long addr asm("0") =3D (unsigned long)data; + register unsigned long rc asm("1") =3D 0; + + asm volatile ("diag %0,%2,0x508\n" + : "+d" (addr), "+d" (rc) + : "d" (subcode) + : "memory", "cc"); + return rc; +} + +static inline bool is_signature_verif_supported(void) +{ + uint64_t d508_subcodes; + + d508_subcodes =3D _diag508(NULL, DIAG_508_SUBC_QUERY_SUBC); + return d508_subcodes & DIAG_508_SUBC_SIG_VERIF; +} + +static inline bool verify_signature(IplDeviceComponentEntry comp_entry, + IplSignatureCertificateEntry sig_entry, + uint64_t *cert_len, uint8_t *cert_idx) +{ + Diag508SigVerifBlock svb; + + svb.length =3D sizeof(Diag508SigVerifBlock); + svb.version =3D 0; + svb.comp_len =3D comp_entry.len; + svb.comp_addr =3D comp_entry.addr; + svb.sig_len =3D sig_entry.len; + svb.sig_addr =3D sig_entry.addr; + + if (_diag508(&svb, DIAG_508_SUBC_SIG_VERIF) =3D=3D DIAG_508_RC_OK) { + *cert_len =3D svb.cert_len; + /* + * DIAG 508 utilizes an index origin of 0 when indexing the cert s= tore. + * The cert_idx will be used for DIAG 320 data structures, which e= xpects + * an index origin of 1. Account for the offset here so it's easie= r to + * manage later. + */ + *cert_idx =3D svb.cert_store_index + 1; + return true; + } + + return false; +} + +#endif /* _PC_BIOS_S390_CCW_SECURE_IPL_H */ --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098239; cv=none; d=zohomail.com; s=zohoarc; b=HBar0rdmZaRanrg1spT7T1b1IHbAKYEm2QD8vqMeWerGrKppH2kgzB31OMO1RWM3f5M1HfvTDFXFfkI6p94ZNQHK+QM7qUmJyIkHrsXLdsCRt0LrHyyD54uxKS7adGUsFqHZxVBZPDamt2CGHgT7j2GT7NCm8RyOufoUkcM/BZc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098239; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LCBTSV20szCOOkKYftSkm0Q4QHSJtnqz/w6MLD4bgG8=; b=EHA/u3as7UgGrvhGG5Y0I4PopbzjJSPNvCtaGOknK4Ty6o7iaskYyXriH4URNGgF5oledevVAxz0hUDx4P0cGJ317EUzDepYZGzCgeyilol9VvzNCoJ2keYlrzb37Hz5gPHN2D6/GGJ6zjd63+8LhKcYs0jmG7vGDDfb2q9STKI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098239424549.3511152456143; Fri, 3 Jul 2026 10:03:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHO-0001D9-Lb; Fri, 03 Jul 2026 13:02:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhH7-0008LU-KC; Fri, 03 Jul 2026 13:02:02 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhH5-0003OO-OK; Fri, 03 Jul 2026 13:02:01 -0400 Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GJGPl3218224; Fri, 3 Jul 2026 17:01:55 GMT Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26mk7rt3-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:54 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnlBd001538; Fri, 3 Jul 2026 17:01:54 GMT Received: from smtprelay04.wdc07v.mail.ibm.com ([172.16.1.71]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2s7whtg5-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:54 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay04.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1rAv51642832 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:53 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 067245805D; Fri, 3 Jul 2026 17:01:53 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 0E88958054; Fri, 3 Jul 2026 17:01:50 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:49 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=LCBTSV20szCOOkKYf tSkm0Q4QHSJtnqz/w6MLD4bgG8=; b=cz+qVOlmyrykezhif/mQEwQFIuiExvXqm K7fZijcd24MVOkvYKD404/OIrqC2iUMtxr5weQvzc1z27kxpd3FWhtQB7ZATQsQn CSXxxSy4Q0Ul6QXzrO6AgxLhZ6ntIzSoeQjr4BJCvo31wPXbs938DnIcVyVJpmSD 8e39x9tshwJCKH/pKfSmOigZeIfJPZ1pA1Er647bszNkFAu4j6ndwczFUECUeu9a Hz9pcnEFiybWWxKbffU0ScVdIEDBTuGhTU28Lpmy4ApE20uxXrd3AWGagUd0VDnI dihbEY4YJfh15tAbY7Rwuo/u0Vd4HEDRnDEdZVCWaquQF7fwGHXdQ== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 24/33] pc-bios/s390-ccw: Add signed component address overlap checks Date: Fri, 3 Jul 2026 13:00:21 -0400 Message-ID: <20260703170032.1893204-25-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX45zuZQR0X8Zp vDg94ePggcbJrU4C3yihnQ2bQZT4cpuJbIN/UGc9JvoQe06LYVD229XYTbkIMRbL9pK63CpPUJS imL/Cw+GO9fQsfizku1kmQlRLfCexY5vQ8WhQCyBqchvw/HVplYi7tcd73GemiKzQvOvbNohl+h nqQxR9wRctdZUxr2I8C7K4NnnLtLAl32C1WVEWyp2BAlTRfQXhOSGWIF2uYULrRrX4Sz9Nzo6/O 5pM6JAedZ/T1pCCUz2UCv5QNlWnLWs54n+cTuuaPFoG9tldmzfHDVP2IxyWUMwcHIXxGY6QFSBw p0HsfKX8UhRaaQIuDN7hFFJ7N3UxmkI26E9WP2oHdjPVPA7KxQlRGiL5bX5HuE65rzfg27+mrnx S1NZL10oIDOz9/FkIQQlJ//Ty58Ti/Czexz7mPeC5CQ8YIc2OPJHsZ87ehOVxYBU6q9AdS5KNy+ eg3LyqRDT1M5seTT8SA== X-Proofpoint-GUID: Esm3lTMOHXOIwCX36nYwV8MK_eGXeydq X-Authority-Analysis: v=2.4 cv=Z8bc2nRA c=1 sm=1 tr=0 ts=6a47eb02 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=G58Pgg4fZqxeurqYNSYA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX22Wb1Nya+Sfc nN7U+oLeqxmP61WNfjORtcIPDF3kqc8hFpF/37k3WTT2vwxYTpCkCwkLZvctlWbGDTqOTAUy2r/ sI/FSV75gN0wb1+rP9UlAYd8BGl6CP0= X-Proofpoint-ORIG-GUID: Esm3lTMOHXOIwCX36nYwV8MK_eGXeydq X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 adultscore=0 spamscore=0 priorityscore=1501 impostorscore=0 malwarescore=0 phishscore=0 bulkscore=0 lowpriorityscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098241096158500 Content-Type: text/plain; charset="utf-8" Add address range tracking and overlap checks to ensure that no component overlaps with a signed component during secure IPL. Signed-off-by: Zhuoying Cai Reviewed-by: Jared Rossi Reviewed-by: Matthew Rosato --- pc-bios/s390-ccw/secure-ipl.c | 19 +++++++++++++++++++ pc-bios/s390-ccw/secure-ipl.h | 6 ++++++ 2 files changed, 25 insertions(+) diff --git a/pc-bios/s390-ccw/secure-ipl.c b/pc-bios/s390-ccw/secure-ipl.c index 1ab41e5543..cd2d18bfa0 100644 --- a/pc-bios/s390-ccw/secure-ipl.c +++ b/pc-bios/s390-ccw/secure-ipl.c @@ -193,6 +193,23 @@ static void init_lists(IplDeviceComponentList *comp_li= st, cert_list->ipl_info_header.len =3D sizeof(IplInfoBlockHeader); } =20 +static void check_comp_overlap(IplDeviceComponentList *comp_list, + IplDeviceComponentEntry comp_entry) +{ + IplDeviceComponentEntry *comp; + + /* + * Check component's address range does not overlap with any + * signed component's address range. + */ + for_each_rb_entry(comp, comp_list) { + if (comp->flags & S390_IPL_DEV_COMP_FLAG_SC && + intersects(comp->addr, comp->len, comp_entry.addr, comp_entry.= len)) { + zipl_secure_error("Component addresses overlap"); + } + } +} + static int zipl_load_signature(ComponentEntry *entry, uint64_t sig) { if (entry->compdat.sig_info.format !=3D DER_SIGNATURE_FORMAT) { @@ -288,6 +305,8 @@ int zipl_run_secure(ComponentEntry **entry_ptr, const u= int8_t *tmp_sec, comp_entry.addr =3D comp_addr; comp_entry.len =3D (uint64_t)comp_len; =20 + check_comp_overlap(comp_list, comp_entry); + /* no signature present (unsigned component) */ if (!sig_entry.len) { comp_list_add(comp_list, comp_entry); diff --git a/pc-bios/s390-ccw/secure-ipl.h b/pc-bios/s390-ccw/secure-ipl.h index e192f8b61d..7c698cd157 100644 --- a/pc-bios/s390-ccw/secure-ipl.h +++ b/pc-bios/s390-ccw/secure-ipl.h @@ -112,4 +112,10 @@ static inline bool verify_signature(IplDeviceComponent= Entry comp_entry, return false; } =20 +static inline bool intersects(uint64_t addr0, uint64_t size0, + uint64_t addr1, uint64_t size1) +{ + return addr0 + size0 > addr1 && addr1 + size1 > addr0; +} + #endif /* _PC_BIOS_S390_CCW_SECURE_IPL_H */ --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098360; cv=none; d=zohomail.com; s=zohoarc; b=IcAQD9LwikQRzzWpd5iLD+gW2/2Yb08cbEjpaZly1XxmGDUjqkPmxS3EsFFS+cbTg+r6qkEH6yOS4Fzvq4rjVWNZcA+bJeFx15mjnYYQevg8estaaP3Fa9X9CsK0i7ww6mycw53rXbrSsY3aw2GxVq2Y4W27KY8LsbfVumQXlA8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098360; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=WJxjjX9wJkKZ3CWNCqWWebknA9krziv1TvE/B3vHlBk=; b=aaDMEgSGS4mc0cOaLbYsS4vwXxjA2Y60doPgUKU4GyvUgK6A28uPU1wwHmD1iPTziFr13M8fnmhKDVTjPUljo1x3XpL8mz8Cj67xG7zjMLwmQh8JF5zTuNdxyjfwq1DegvdYOUbpM2kEmeUMZ3xoGi0rT4IRzBbHe254A4oGxnw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098360219312.13610279189834; Fri, 3 Jul 2026 10:06:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHM-00010M-Ji; Fri, 03 Jul 2026 13:02:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHB-00006H-HQ; Fri, 03 Jul 2026 13:02:08 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhH8-0003P8-UU; Fri, 03 Jul 2026 13:02:04 -0400 Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIoHg3497809; Fri, 3 Jul 2026 17:01:58 GMT Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26qgg6xd-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:58 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnZWA031457; Fri, 3 Jul 2026 17:01:57 GMT Received: from smtprelay07.wdc07v.mail.ibm.com ([172.16.1.74]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2uhysgem-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:01:57 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay07.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1unC13894316 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:56 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 1073758054; Fri, 3 Jul 2026 17:01:56 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 40AB85805A; Fri, 3 Jul 2026 17:01:53 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:53 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=WJxjjX 9wJkKZ3CWNCqWWebknA9krziv1TvE/B3vHlBk=; b=oAONU3zARJqUW/s3ju/gQT Qe7AkL2XK9HXM9g1OYpOFh3mreBSqdV9cN5huJIE2SfTDCwYYZtGFTPogZo0pUTX te8zkK3ratHrTKkIxqsSYPOsSx19hTK5cPO7uz44hAi1A8FfrD2xQsW0eOFUIpzJ b9c/7ZHO4IEQuTIRJx8Uk7wpsVlLFcK75qQsi/nexT/w9MCbCbw6vRtEnw6uk4KJ Nu5465SAgSzTohiG0Gf5ynjxaqhIIW0EodAuZ6yvpO+Wn88rY93sb4GodlXafOij S7wba/4xLxT8gGF3mirtO3xjTxXKc0U0UMdwkw93SRsoLLV5H/SibMKKQ+Ed1BQQ == From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 25/33] s390x: Guest support for Secure-IPL Code Loading Attributes Facility (SCLAF) Date: Fri, 3 Jul 2026 13:00:22 -0400 Message-ID: <20260703170032.1893204-26-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=RYqgzVtv c=1 sm=1 tr=0 ts=6a47eb06 cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=s2GHSiDfQs-ooOV4uGMA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX0NfnF2xq7SV5 rVECKIox26/lQKQlQyyniMPOskyM5rPtqiM8cWi+KfVxwqtVCNWz6g80C4c1uvNsEw8Td+VeRlL 5QAsVeTwrW7W5Dytl5uYUSbLFZaM5j4= X-Proofpoint-GUID: _I0aIsnPpMG5-O_EP4BjdutdxHTn4cyT X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX0lbyLO8sxqJe EL5IvPaEoIjzCj61LTO88AgPeA7jYN1KgCyowckmyTD1OoW6/KG0gEbSTV8z/prQarecW/ZtRyD gMHtKX3L2zfLgEUgpzvW5falJVvmpyNaBqkYkGQpmge1xCkDU5yfyaVlDxwegsoXAQSxyrRJe8Y /fvt3ZI/7e33HzqTHGq5zrCiyx9VCPNRHuVnhMWoDbVQNJbTjn1jz+X0IbdHz4xjcLRwJ943ipi L5mVgTfnGKJ4YqIpwLbnuHBO8tIC5nvACMHf+gJzl8DALjsKt5waFBbTN6DxYEd9Zw1d6eBvZ3A AoDQiLgHP4Hy2IC5jG7g8/SPON5VmuAaTbxUdQbZobYo3Uf45EcfFR7ru1EO6rHsZ+rQAv7JuZD CRRK4Llb/3tUrwdvQcqNU2OhMcnWahVwtCcfKUf9aVS0/rHJZ4ZCayxRLO5uqOTL+hHERBAvEuy CWG+1+bkxfi6F4JHGnA== X-Proofpoint-ORIG-GUID: _I0aIsnPpMG5-O_EP4BjdutdxHTn4cyT X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 impostorscore=0 malwarescore=0 spamscore=0 lowpriorityscore=0 adultscore=0 priorityscore=1501 suspectscore=0 bulkscore=0 clxscore=1015 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098362231158500 The secure-IPL-code-loading-attributes facility (SCLAF) provides additional security during secure IPL. Availability of SCLAF is determined by byte 136 bit 3 of the SCLP Read Info block. This feature is available starting with the gen16 CPU model. Signed-off-by: Zhuoying Cai Reviewed-by: Collin Walling Reviewed-by: Matthew Rosato --- docs/specs/s390x-secure-ipl.rst | 18 ++++++++++++++++++ target/s390x/cpu_features.c | 2 ++ target/s390x/cpu_features_def.h.inc | 1 + target/s390x/cpu_models.c | 3 +++ target/s390x/gen-features.c | 2 ++ target/s390x/kvm/kvm.c | 1 + 6 files changed, 27 insertions(+) diff --git a/docs/specs/s390x-secure-ipl.rst b/docs/specs/s390x-secure-ipl.= rst index 850e4a7497..db60c2262f 100644 --- a/docs/specs/s390x-secure-ipl.rst +++ b/docs/specs/s390x-secure-ipl.rst @@ -122,3 +122,21 @@ The guest kernel uses the contents in the IIRB for: * Boot logging: reports which components were loaded and verified. * kexec operations: builds the next kernel=E2=80=99s IPL report from the e= xisting one. * Keying: installs IPL certificates into the platform trusted keyring. + +Secure Code Loading Attributes Facility +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +The Secure Code Loading Attributes Facility (SCLAF) enhances system securi= ty +during the IPL by enforcing additional verification rules. + +When SCLAF is available, its behavior depends on the IPL mode. It introduc= es +verification of both signed and unsigned components to help ensure that on= ly +authorized code is loaded during the IPL process. Any errors detected by S= CLAF +are reported in the IIRB. + +Unsigned components are restricted to load addresses at or above absolute +storage address ``0x2000``. + +Signed components must include a Secure Code Loading Attribute Block (SCLA= B), +which is appended at the very end of the component. The SCLAB defines secu= rity +attributes for handling the signed code. diff --git a/target/s390x/cpu_features.c b/target/s390x/cpu_features.c index 200bd8c15b..29ea3bfec2 100644 --- a/target/s390x/cpu_features.c +++ b/target/s390x/cpu_features.c @@ -120,6 +120,7 @@ void s390_fill_feat_block(const S390FeatBitmap features= , S390FeatType type, * - All SIE facilities because SIE is not available * - DIAG318 * - Secure IPL Facility + * - Secure IPL Code Loading Attributes Facility * * As VMs can move in and out of protected mode the CPU model * doesn't protect us from that problem because it is only @@ -152,6 +153,7 @@ void s390_fill_feat_block(const S390FeatBitmap features= , S390FeatType type, break; case S390_FEAT_TYPE_SCLP_FAC_IPL: clear_be_bit(s390_feat_def(S390_FEAT_SIPL)->bit, data); + clear_be_bit(s390_feat_def(S390_FEAT_SCLAF)->bit, data); break; default: return; diff --git a/target/s390x/cpu_features_def.h.inc b/target/s390x/cpu_feature= s_def.h.inc index bcf8a666e4..f6ba9e87e1 100644 --- a/target/s390x/cpu_features_def.h.inc +++ b/target/s390x/cpu_features_def.h.inc @@ -142,6 +142,7 @@ DEF_FEAT(CERT_STORE, "cstore", SCLP_FAC134, 5, "Certifi= cate Store functions") =20 /* Features exposed via SCLP SCCB Facilities byte 136 - 137 (bit numbers r= elative to byte-136) */ DEF_FEAT(SIPL, "sipl", SCLP_FAC_IPL, 1, "Secure-IPL facility") +DEF_FEAT(SCLAF, "sclaf", SCLP_FAC_IPL, 3, "Secure-IPL-code-loading-attribu= tes facility") =20 /* Features exposed via SCLP CPU info. */ DEF_FEAT(SIE_F2, "sief2", SCLP_CPU, 4, "SIE: interception format 2 (Virtua= l SIE)") diff --git a/target/s390x/cpu_models.c b/target/s390x/cpu_models.c index a52e34aa95..7de727a256 100644 --- a/target/s390x/cpu_models.c +++ b/target/s390x/cpu_models.c @@ -264,6 +264,7 @@ bool s390_has_feat(S390Feat feat) case S390_FEAT_SIE_PFMFI: case S390_FEAT_SIE_IBS: case S390_FEAT_SIPL: + case S390_FEAT_SCLAF: case S390_FEAT_CONFIGURATION_TOPOLOGY: return false; break; @@ -509,6 +510,8 @@ static void check_consistency(const S390CPUModel *model) { S390_FEAT_DIAG_318, S390_FEAT_EXTENDED_LENGTH_SCCB }, { S390_FEAT_CERT_STORE, S390_FEAT_EXTENDED_LENGTH_SCCB }, { S390_FEAT_SIPL, S390_FEAT_EXTENDED_LENGTH_SCCB }, + { S390_FEAT_SCLAF, S390_FEAT_EXTENDED_LENGTH_SCCB }, + { S390_FEAT_SCLAF, S390_FEAT_SIPL }, { S390_FEAT_NNPA, S390_FEAT_VECTOR }, { S390_FEAT_RDP, S390_FEAT_LOCAL_TLB_CLEARING }, { S390_FEAT_UV_FEAT_AP, S390_FEAT_AP }, diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index bd2060ab93..c3e0c6ceff 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -722,6 +722,7 @@ static uint16_t full_GEN16_GA1[] =3D { S390_FEAT_UV_FEAT_AP_INTR, S390_FEAT_CERT_STORE, S390_FEAT_SIPL, + S390_FEAT_SCLAF, }; =20 static uint16_t full_GEN17_GA1[] =3D { @@ -924,6 +925,7 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_EXTENDED_LENGTH_SCCB, S390_FEAT_CERT_STORE, S390_FEAT_SIPL, + S390_FEAT_SCLAF, }; =20 /****** END FEATURE DEFS ******/ diff --git a/target/s390x/kvm/kvm.c b/target/s390x/kvm/kvm.c index 61ac6c84a0..52bbd560bd 100644 --- a/target/s390x/kvm/kvm.c +++ b/target/s390x/kvm/kvm.c @@ -2503,6 +2503,7 @@ bool kvm_s390_get_host_cpu_model(S390CPUModel *model,= Error **errp) =20 /* Some Secure IPL facilities are emulated by QEMU */ set_bit(S390_FEAT_SIPL, model->features); + set_bit(S390_FEAT_SCLAF, model->features); =20 /* Test for Ultravisor features that influence secure guest behavior */ query_uv_feat_guest(model->features); --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098302; cv=none; d=zohomail.com; s=zohoarc; b=lj6NkA95jVLFvkROpemJ/PfAkLlddFA9w7c8apc9LQoHH1MypNOuF76UrGkcECTxsBB5BzUCc/hrkUfG3xY6wYHcxRZMtSBo1eJiJKgOatgjppmGZSKRTzKfuBKkTu/DhwdY0Dl4g94rbckiZxHZmWSjdtymUR6nkymUcxnBWbU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098302; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4PVngt8ZwCzAkuYybK3P1NV8sm+JyHUIKQYbtMJybj0=; b=Rs5mb2Q8bHDfb8RZin6NZUcwjOreVnHv31RsBy0JMZ5boLm4xZS6slo7QDEAhSDkWjXeca4HjMg57Y26gvmvPrpRYzYC0pWBW9lXr5oJe3GgSV42m0gTPxMRyES2qlcTnLtXuNBgaL+20uctwh7xotX3ruc5a4Isgo5WhCSFZzs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098302308807.5624625147977; Fri, 3 Jul 2026 10:05:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHP-0001HG-CS; Fri, 03 Jul 2026 13:02:19 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHD-00006J-UN; Fri, 03 Jul 2026 13:02:08 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHB-0003PV-Fe; Fri, 03 Jul 2026 13:02:07 -0400 Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GJCim3218123; Fri, 3 Jul 2026 17:02:01 GMT Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26mk7rtr-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:01 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GncWe003072; Fri, 3 Jul 2026 17:02:00 GMT Received: from smtprelay04.dal12v.mail.ibm.com ([172.16.1.6]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2tbhsnj7-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:00 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay04.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1xG919333776 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:59 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4C4FD5805D; Fri, 3 Jul 2026 17:01:59 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 491DA58054; Fri, 3 Jul 2026 17:01:56 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:56 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=4PVngt8ZwCzAkuYyb K3P1NV8sm+JyHUIKQYbtMJybj0=; b=QEY1OW5YQAbSxmLAY4k9VaT1FWUkE3fyS 9Dukft8LMfwJCE5WwEAHRj/Qeh/KySLtAxCEK+dfql3BObNAIbOpBvnxvfPcXDra U/hfep10bGtUExw1II6QZTFbS8Y6VKfKpH51cqCgx9Pv8zeTrmt6PcK3jjC7BiiU DFhJKf8KahLDjvIbrPS09gTcg1kw391218+mOnfoUxH0uOOHmXSHhOmWYFpa9PV/ uwuOmQ0JF9A8pBuTIhKTvUHmAahl9m315ompswYIeodlJy4+LFOV5TxyIke03PgK AnKN9WNlcueI591CmWQtwvfv85jrHz/CS4wF6MRzj/gmg02LIAABw== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 26/33] pc-bios/s390-ccw: Add additional security checks for secure boot Date: Fri, 3 Jul 2026 13:00:23 -0400 Message-ID: <20260703170032.1893204-27-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX1C+632Fi+Ivr LGciR9melLj0GwdDEPitrA/OzmbmhP45z4U2bx0lShPacO6itZIkn3DIo+aaJgPJTJPa8lXClaw IX66WnxmXge6p8kntkPNzb02r9ljiN7z/rsYmUNIddSF9b0/f8Fgy5dHC/dLduXSyAn8k2HjMsx ZfGF7twmHPEwlyhmod7jllQKH/JhAUPS8sUK9P2FkmmRKc83yhHtSkypwhLNjrsWB4QNQDWYqne jRqKV+/uHXRTrrod+t4Qr6VRtZvR29Bo9qVW9B3uKpYECIrycj7exNsF4fcjEl/WDfVw+evvDDG Q/sDUFsXoZ5G12YSOZ7VzJdPNMbuqcGrQLtUlGegIpK8F947/J1h2R1HCz1ghqeABQTQDDj4cxv yZTfboTTSRqbf/qJ4XO/DZrRtgroOZWX3slKmLlyRfDsfB+bizSbrrvhvVVlSu4rAVeRXU0DhDB /ys3SgM+/JpRs2Jtn7A== X-Proofpoint-GUID: nU2IPoJjoHl09X2ZMk35lT-tjCGLr_Tj X-Authority-Analysis: v=2.4 cv=Z8bc2nRA c=1 sm=1 tr=0 ts=6a47eb09 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=s9pCXNYtFNHZQuK5kQYA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX5n4htP3i9al0 /MHrG5wg2MxTXBCSY961NE8/fq9yQmHa554N5bqCaJX1r4zIdqxqXSl6UWbj1DjHTgfbHSuDpHH FsINluZG9BaV/WVs6ehkmilBLWsg8vo= X-Proofpoint-ORIG-GUID: nU2IPoJjoHl09X2ZMk35lT-tjCGLr_Tj X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 adultscore=0 spamscore=0 priorityscore=1501 impostorscore=0 malwarescore=0 phishscore=0 bulkscore=0 lowpriorityscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098303772158500 Content-Type: text/plain; charset="utf-8" Add additional checks to ensure that components do not overlap with signed components when loaded into memory. Add additional checks to ensure the load addresses of unsigned components are greater than or equal to 0x2000. When the secure IPL code loading attributes facility (SCLAF) is installed, all signed components must contain a secure code loading attributes block (SCLAB). The SCLAB provides further validation of information on where to load the signed binary code from the load device, and where to start the execution of the loaded OS code. When SCLAF is installed, its content must be evaluated during secure IPL. Add IPL Information Error Indicators (IIEI) and Component Error Indicators (CEI) for IPL Information Report Block (IIRB). When SCLAF is installed, additional secure boot checks are performed during zipl and store results of verification into IIRB. Signed-off-by: Zhuoying Cai Reviewed-by: Eric Farman --- include/hw/s390x/ipl/qipl.h | 29 +++++- pc-bios/s390-ccw/sclp.h | 1 + pc-bios/s390-ccw/secure-ipl.c | 179 +++++++++++++++++++++++++++++++++- pc-bios/s390-ccw/secure-ipl.h | 51 ++++++++++ 4 files changed, 255 insertions(+), 5 deletions(-) diff --git a/include/hw/s390x/ipl/qipl.h b/include/hw/s390x/ipl/qipl.h index 58329fb5bc..61e4ac40f9 100644 --- a/include/hw/s390x/ipl/qipl.h +++ b/include/hw/s390x/ipl/qipl.h @@ -168,10 +168,20 @@ struct IplInfoReportBlockHeader { }; typedef struct IplInfoReportBlockHeader IplInfoReportBlockHeader; =20 +/* IPL Info Error Indicators */ +#define S390_IIEI_NO_SIGNED_COMP 0x8000 /* bit 0 */ +#define S390_IIEI_NO_SCLAB 0x4000 /* bit 1 */ +#define S390_IIEI_NO_GLOBAL_SCLAB 0x2000 /* bit 2 */ +#define S390_IIEI_MORE_GLOBAL_SCLAB 0x1000 /* bit 3 */ +#define S390_IIEI_FOUND_UNSIGNED_COMP 0x800 /* bit 4 */ +#define S390_IIEI_MORE_SIGNED_COMP 0x400 /* bit 5 */ + struct IplInfoBlockHeader { uint32_t len; uint8_t type; - uint8_t reserved1[11]; + uint8_t reserved1[3]; + uint16_t iiei; + uint8_t reserved2[6]; }; typedef struct IplInfoBlockHeader IplInfoBlockHeader; =20 @@ -195,13 +205,28 @@ typedef struct IplSignatureCertificateList IplSignatu= reCertificateList; #define S390_IPL_DEV_COMP_FLAG_SC 0x80 #define S390_IPL_DEV_COMP_FLAG_CSV 0x40 =20 +/* IPL Device Component Error Indicators */ +#define S390_CEI_INVALID_SCLAB 0x80000000 /* bit 0 */ +#define S390_CEI_INVALID_SCLAB_LEN 0x40000000 /* bit 1 */ +#define S390_CEI_INVALID_SCLAB_FORMAT 0x20000000 /* bit 2 */ +#define S390_CEI_UNMATCHED_SCLAB_LOAD_ADDR 0x10000000 /* bit 3 */ +#define S390_CEI_UNMATCHED_SCLAB_LOAD_PSW 0x8000000 /* bit 4 */ +#define S390_CEI_INVALID_LOAD_PSW 0x4000000 /* bit 5 */ +#define S390_CEI_NUC_NOT_IN_GLOBAL_SCLAB 0x2000000 /* bit 6 */ +#define S390_CEI_SCLAB_OLA_NOT_ONE 0x1000000 /* bit 7 */ +#define S390_CEI_SC_NOT_IN_GLOBAL_SCLAB 0x800000 /* bit 8 */ +#define S390_CEI_SCLAB_LOAD_ADDR_NOT_ZERO 0x400000 /* bit 9 */ +#define S390_CEI_SCLAB_LOAD_PSW_NOT_ZERO 0x200000 /* bit 10 */ +#define S390_CEI_INVALID_UNSIGNED_ADDR 0x100000 /* bit 11 */ + struct IplDeviceComponentEntry { uint64_t addr; uint64_t len; uint8_t flags; uint8_t reserved1[5]; uint16_t cert_index; - uint8_t reserved2[8]; + uint32_t cei; + uint8_t reserved2[4]; }; typedef struct IplDeviceComponentEntry IplDeviceComponentEntry; =20 diff --git a/pc-bios/s390-ccw/sclp.h b/pc-bios/s390-ccw/sclp.h index a8a41cd004..cae65b29b5 100644 --- a/pc-bios/s390-ccw/sclp.h +++ b/pc-bios/s390-ccw/sclp.h @@ -52,6 +52,7 @@ typedef struct SCCBHeader { #define SCCB_DATA_LEN (SCCB_SIZE - sizeof(SCCBHeader)) #define SCCB_FAC134_DIAG320_BIT 0x4 #define SCCB_FAC_IPL_SIPL_BIT 0x4000 +#define SCCB_FAC_IPL_SCLAF_BIT 0x1000 =20 typedef struct ReadInfo { SCCBHeader h; diff --git a/pc-bios/s390-ccw/secure-ipl.c b/pc-bios/s390-ccw/secure-ipl.c index cd2d18bfa0..8989e9aba5 100644 --- a/pc-bios/s390-ccw/secure-ipl.c +++ b/pc-bios/s390-ccw/secure-ipl.c @@ -180,6 +180,12 @@ bool secure_ipl_supported(void) return false; } =20 + if (!sclp_is_fac_ipl_flag_on(SCCB_FAC_IPL_SCLAF_BIT)) { + puts("Secure IPL Code Loading Attributes Facility is not supported= by" + " the hypervisor!"); + return false; + } + return true; } =20 @@ -210,6 +216,156 @@ static void check_comp_overlap(IplDeviceComponentList= *comp_list, } } =20 +static bool is_psw_valid(uint64_t psw, IplDeviceComponentEntry *comp) +{ + uint32_t addr =3D psw & 0x7fffffff; + + /* + * PSW points within a signed binary code component + * + * Check addr falls within [comp->addr, comp->addr + comp->len - 2], + * ensuring at least 2 bytes (minimum instruction length) remain. + */ + return intersects(addr, 1, comp->addr, comp->len - 1); +} + +void check_global_sclab(const SclaBlock *global_sclab, + IplDeviceComponentEntry *comp_entry, + IplDeviceComponentList *comp_list) +{ + bool psw_valid =3D false; + bool global_psw_valid =3D false; + int signed_count =3D 0; + int unsigned_count =3D 0; + IplDeviceComponentEntry *comp; + + if (!global_sclab) { + comp_list->ipl_info_header.iiei |=3D S390_IIEI_NO_GLOBAL_SCLAB; + zipl_secure_error("Global SCLAB does not exist"); + return; + } + + for_each_rb_entry(comp, comp_list) { + if (comp->flags & S390_IPL_DEV_COMP_FLAG_SC) { + psw_valid |=3D is_psw_valid(comp_entry->addr, comp); + global_psw_valid |=3D is_psw_valid(global_sclab->load_psw, com= p); + signed_count +=3D 1; + } else { + unsigned_count +=3D 1; + } + } + + /* validate load PSW with PSW specified in the final entry */ + zipl_secure_validate(psw_valid && global_psw_valid, &comp_entry->cei, + S390_CEI_INVALID_LOAD_PSW, "Invalid PSW"); + + /* compare load PSW with the PSW specified in component */ + zipl_secure_validate(global_sclab->load_psw =3D=3D comp_entry->addr, + &comp_entry->cei, S390_CEI_UNMATCHED_SCLAB_LOAD_P= SW, + "Load PSW does not match with PSW in component"); + + /* Unsigned components are not allowed if NUC flag is set in the globa= l SCLAB */ + if ((global_sclab->flags & S390_SCLAB_NUC) && unsigned_count > 0) { + comp_list->ipl_info_header.iiei |=3D S390_IIEI_FOUND_UNSIGNED_COMP; + zipl_secure_error("Unsigned components are not allowed"); + } + + /* + * Only one signed component is allowed if SC flag is set in the globa= l SCLAB + * More than one component in the component table is not allowed + */ + if ((global_sclab->flags & S390_SCLAB_SC) && + (signed_count !=3D 1 || unsigned_count !=3D 0)) { + comp_list->ipl_info_header.iiei |=3D S390_IIEI_MORE_SIGNED_COMP; + zipl_secure_error("Only one signed component is allowed"); + } +} + +static void check_sclab(SclaBlock **global_sclab, + IplDeviceComponentEntry *comp_entry, + IplInfoBlockHeader *comp_list_hdr) +{ + SclabOriginLocator *sclab_locator; + SclaBlock *sclab; + + /* must be large enough to locate the sclab locator, else implies inva= lid SCLAB */ + zipl_secure_validate(comp_entry->len >=3D 8, &comp_entry->cei, + S390_CEI_INVALID_SCLAB, + "Signed component too short to contain SCLAB loca= tor"); + + if (comp_entry->cei & S390_CEI_INVALID_SCLAB) { + return; + } + + /* sclab locator is located at the last 8 bytes of the signed comp */ + sclab_locator =3D (SclabOriginLocator *)(comp_entry->addr + + comp_entry->len - 8); + + /* return early if sclab does not exist */ + zipl_secure_validate(magic_match(sclab_locator->magic, ZIPL_MAGIC), + &comp_entry->cei, S390_CEI_INVALID_SCLAB, + "Magic does not match. SCLAB does not exist"); + + if (comp_entry->cei & S390_CEI_INVALID_SCLAB) { + return; + } + + zipl_secure_validate(sclab_locator->len >=3D S390_SCLAB_MIN_LEN, &comp= _entry->cei, + S390_CEI_INVALID_SCLAB_LEN | S390_CEI_INVALID_SCL= AB, + "Invalid SCLAB length"); + + /* return early if sclab is invalid */ + if (comp_entry->cei & S390_CEI_INVALID_SCLAB) { + return; + } + + sclab =3D (SclaBlock *)(comp_entry->addr + comp_entry->len - + sclab_locator->len); + + zipl_secure_validate(sclab->format =3D=3D 0, &comp_entry->cei, + S390_CEI_INVALID_SCLAB_FORMAT, + "Format-0 SCLAB is not being used"); + + if (!(sclab->flags & S390_SCLAB_OPSW)) { + /* OPSW =3D 0 - Load PSW field in SCLAB must contain zeros */ + zipl_secure_validate(sclab->load_psw =3D=3D 0, &comp_entry->cei, + S390_CEI_SCLAB_LOAD_PSW_NOT_ZERO, + "Load PSW is not zero when Override PSW bit i= s zero"); + } else { + /* OPSW =3D 1 indicating global SCLAB */ + if (*global_sclab) { + comp_list_hdr->iiei |=3D S390_IIEI_MORE_GLOBAL_SCLAB; + zipl_secure_error("More than one global SCLAB"); + } + *global_sclab =3D sclab; + + /* override load address flag must set to one */ + zipl_secure_validate(sclab->flags & S390_SCLAB_OLA, &comp_entry->c= ei, + S390_CEI_SCLAB_OLA_NOT_ONE, + "OLA flag is not set to one in the global SCL= AB"); + } + + if (!(sclab->flags & S390_SCLAB_OLA)) { + /* OLA =3D 0 - Load address field in SCLAB must contain zeros */ + zipl_secure_validate(sclab->load_addr =3D=3D 0, &comp_entry->cei, + S390_CEI_SCLAB_LOAD_ADDR_NOT_ZERO, + "Load Address is not zero when OLA flag is ze= ro"); + } else { + /* OLA =3D 1 - Load address field must match storage address of th= e component */ + zipl_secure_validate(sclab->load_addr =3D=3D comp_entry->addr, &co= mp_entry->cei, + S390_CEI_UNMATCHED_SCLAB_LOAD_ADDR, + "Load Address does not match with component l= oad address"); + } + + zipl_secure_validate(~sclab->flags & S390_SCLAB_NUC || sclab->flags & = S390_SCLAB_OPSW, + &comp_entry->cei, S390_CEI_NUC_NOT_IN_GLOBAL_SCLA= B, + "NUC bit is set, but not in the global SCLAB"); + + zipl_secure_validate(~sclab->flags & S390_SCLAB_SC || sclab->flags & S= 390_SCLAB_OPSW, + &comp_entry->cei, S390_CEI_SC_NOT_IN_GLOBAL_SCLAB, + "SC bit is set, but not in the global SCLAB"); +} + static int zipl_load_signature(ComponentEntry *entry, uint64_t sig) { if (entry->compdat.sig_info.format !=3D DER_SIGNATURE_FORMAT) { @@ -269,6 +425,8 @@ int zipl_run_secure(ComponentEntry **entry_ptr, const u= int8_t *tmp_sec, uint8_t *tmp_buf; bool verified; bool signed_found =3D false; + bool sclab_found =3D false; + SclaBlock *global_sclab =3D NULL; =20 if ((MAX_SIGNED_COMP * CERT_BUF_MAX_LEN) > CERT_BUF_SIZE) { panic("Not enough memory to store certificates"); @@ -309,6 +467,10 @@ int zipl_run_secure(ComponentEntry **entry_ptr, const = uint8_t *tmp_sec, =20 /* no signature present (unsigned component) */ if (!sig_entry.len) { + zipl_secure_validate(comp_entry.addr >=3D S390_UNSIGNED_MI= N_ADDR, + &comp_entry.cei, S390_CEI_INVALID_UNSIGNED_ADD= R, + "Load address for unsigned component is less t= han 0x2000"); + comp_list_add(comp_list, comp_entry); break; } @@ -320,6 +482,9 @@ int zipl_run_secure(ComponentEntry **entry_ptr, const u= int8_t *tmp_sec, comp_entry.flags =3D S390_IPL_DEV_COMP_FLAG_SC; signed_found =3D true; =20 + check_sclab(&global_sclab, &comp_entry, &comp_list->ipl_info_h= eader); + sclab_found |=3D !(comp_entry.cei & S390_CEI_INVALID_SCLAB); + cert_entry =3D (IplSignatureCertificateEntry) { 0 }; verified =3D verify_signature(comp_entry, sig_entry, &cert_entry.len, &cert_table_idx); @@ -365,9 +530,17 @@ int zipl_run_secure(ComponentEntry **entry_ptr, const = uint8_t *tmp_sec, } } =20 - if (!signed_found) { - zipl_secure_error("Secure boot is on, but components are not signe= d"); - } + zipl_secure_validate(signed_found, &comp_list->ipl_info_header.iiei, + S390_IIEI_NO_SIGNED_COMP, + "Secure boot is on, but components are not signed= "); + + zipl_secure_validate(sclab_found, &comp_list->ipl_info_header.iiei, + S390_IIEI_NO_SCLAB, "No recognizable SCLAB"); + + comp_entry =3D (IplDeviceComponentEntry){ 0 }; + comp_entry.addr =3D entry->compdat.load_psw; + check_global_sclab(global_sclab, &comp_entry, comp_list); + comp_list_add(comp_list, comp_entry); =20 *entry_ptr =3D entry; free((void *)sig_entry.addr); diff --git a/pc-bios/s390-ccw/secure-ipl.h b/pc-bios/s390-ccw/secure-ipl.h index 7c698cd157..4030ef8480 100644 --- a/pc-bios/s390-ccw/secure-ipl.h +++ b/pc-bios/s390-ccw/secure-ipl.h @@ -26,6 +26,33 @@ int zipl_run_secure(ComponentEntry **entry_ptr, const ui= nt8_t *tmp_sec, IplSignatureCertificateList *cert_list, uint8_t **tmp_cert_buf); =20 +#define S390_SCLAB_OPSW 0x8000 /* override PSW flag */ +#define S390_SCLAB_OLA 0x4000 /* override load address flag */ +#define S390_SCLAB_NUC 0x2000 /* no unsigned components flag */ +#define S390_SCLAB_SC 0x1000 /* single component flag */ + +#define S390_SCLAB_MIN_LEN 32 +#define S390_UNSIGNED_MIN_ADDR 0x2000 + +/* Secure Code Loading Attributes Block */ +struct SclaBlock { + uint8_t format; + uint8_t reserved1; + uint16_t flags; + uint8_t reserved2[4]; + uint64_t load_psw; + uint64_t load_addr; + uint64_t reserved3[]; +} __attribute__ ((packed)); +typedef struct SclaBlock SclaBlock; + +struct SclabOriginLocator { + uint8_t reserved[2]; + uint16_t len; + uint8_t magic[4]; +} __attribute__ ((packed)); +typedef struct SclabOriginLocator SclabOriginLocator; + static inline void zipl_secure_error(const char *message) { switch (boot_mode) { @@ -37,6 +64,30 @@ static inline void zipl_secure_error(const char *message) } } =20 +static inline void zipl_secure_validate_u16(bool condition, uint16_t *flag= s, + uint16_t flag, const char *mes= sage) +{ + if (!condition) { + *flags |=3D flag; + zipl_secure_error(message); + } +} + +static inline void zipl_secure_validate_u32(bool condition, uint32_t *flag= s, + uint32_t flag, const char *mes= sage) +{ + if (!condition) { + *flags |=3D flag; + zipl_secure_error(message); + } +} + +#define zipl_secure_validate(condition, flags, flag, message) \ + _Generic((flags), \ + uint16_t * : zipl_secure_validate_u16, \ + uint32_t * : zipl_secure_validate_u32 \ + )(condition, flags, flag, message) + static inline uint64_t _diag320(void *data, unsigned long subcode) { register unsigned long addr asm("0") =3D (unsigned long)data; --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098234; cv=none; d=zohomail.com; s=zohoarc; b=LJ6+vwLhd7twPceTkvpxNZLZepMm88PHWZdFa+y4J/deZ3US4sXHVfy17RpJB7w4kItB+0MIbVp62PLs+/9OU0YZbYhUyrSDrJfo5DX3lBEIzaVogrcqjAEEaC8tvm9Xx54bvZNCIhVDVfRn4iB2uPOmGTVEu5Krc6NBH/Jb08Y= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098234; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Xye2EmfX3DC4gEdABPm3/dJNBk10sPUQzoPJsAOwf40=; b=V8+LTAROUkGGqwsavavHmu4L5IHIZUyjAvxLrX8H+SwbHlLx4DloQ3EBVPQKQb+GdKIwyxpgMzhnF+CQRqkMkPRV/bH2LtDmLc5DOzQbTStLnane1vifD3akWp8gPw321Fi4rwBOaAymxmKIVgit+8Unw38/uTX8U138NAp+Z8w= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098234095356.73770410326154; Fri, 3 Jul 2026 10:03:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHJ-0000ch-EJ; Fri, 03 Jul 2026 13:02:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHG-0000HR-EV; Fri, 03 Jul 2026 13:02:10 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHE-0003Py-5M; Fri, 03 Jul 2026 13:02:10 -0400 Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GJdrj3305166; Fri, 3 Jul 2026 17:02:04 GMT Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26n68911-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:04 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GncVI019659; Fri, 3 Jul 2026 17:02:03 GMT Received: from smtprelay07.dal12v.mail.ibm.com ([172.16.1.9]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2ruqsy7h-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:03 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay07.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H228g21234238 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:02:02 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 54C795805A; Fri, 3 Jul 2026 17:02:02 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8280E5805C; Fri, 3 Jul 2026 17:01:59 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:01:59 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=Xye2EmfX3DC4gEdAB Pm3/dJNBk10sPUQzoPJsAOwf40=; b=taIZ3chinhhQyOdV51cQDX3NeKBuei0vp 50BkDWbNmrotMzAUE/4j3pRBa7ydRsUENsduqDDEi329alQ7AcfsiZbkaXSjbGdJ a3ZGBXStwfuvKAeFTE/ARNjX5tYg7tU1iRVd2zMW04js19G2f4y6G0glh4VvYNi6 vFsEhtToloVqYcsWQZtvvtmMDiEFZuvQPspC8/XaQ09JCCOOedSeejg+RezUs+7w YACYnFqBh6ZieV7LKMpCjZOKLVY2mffpgDsqnOt7MpD9AxhRy0YMK9GtKuXHI0aE gpdKWY3A/jbhNZkw/omwvXuJ3+aWezG23U+S3ormMj1iiVbpan2Rw== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 27/33] Add secure-boot to s390-ccw-virtio machine type option Date: Fri, 3 Jul 2026 13:00:24 -0400 Message-ID: <20260703170032.1893204-28-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXzoFlG56B2xqJ 40EVKniqStUI+lv2pAtqlYJsRPP3AFiFUlsSeZA1bj9TXOinB3+DGlqXXrVhd1ssHmbZNRd7dgy QUNI+UbaISi0yuDLVy4vO//0QC4WugbRTUcEohEDuUn9HTE64yr95dfg+KFyoY9NVucWTm2rVt9 Dv+FrqUYy5K8qiz2HSUBTRbpiG6Ooyk8qV4WwTt/WU5sUUR7LKCIwqiNp3qoPjQR+be++cZakhN LyLBeP2gAepRCmIz9rhtEvv/ZM95FtGtBUwLz3p8NveVb2q/2DPEFtMbtR3KRWNAGo7w0tvt/tv 6wp+OPlPXyIXVN9IZAgb/Ue3qTMSawBmUHyNFV3zajfuQwjE/nyKGS6n9wCrVvqrxxUq0qTGI4h bGQbDr0f6gDXOOxTSkpuwmonMqN3EBhXm4USTZO0Rn/PLd2pafrBdYvNos3UweQCg4f1LNvn50c oQjXTTDTj5oopUeeVVg== X-Authority-Analysis: v=2.4 cv=V45NF+ni c=1 sm=1 tr=0 ts=6a47eb0c cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=ZvnaDWGK54Hqr3b-QrcA:9 X-Proofpoint-ORIG-GUID: X0YVnxfORqT5c3IzubvlbUWd5gPIbvfF X-Proofpoint-GUID: X0YVnxfORqT5c3IzubvlbUWd5gPIbvfF X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX5rw+5AUX5lA7 diZetxitFuTNorpOy5OE2eQOQ6xr33Bus5phfAE6NBLkn8+3iT9crJuD01S9Hh82AOMJzSeaUs2 eEi57zMLswISabH7qu8sZal+X6CMO5o= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 spamscore=0 suspectscore=0 lowpriorityscore=0 priorityscore=1501 adultscore=0 clxscore=1015 impostorscore=0 malwarescore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098235129158500 Content-Type: text/plain; charset="utf-8" Add secure-boot as a parameter of s390-ccw-virtio machine type option. The `secure-boot=3Don|off` parameter is implemented to enable secure IPL. By default, secure-boot is set to false if not specified in the command line. Signed-off-by: Zhuoying Cai Reviewed-by: Thomas Huth Reviewed-by: Collin Walling --- docs/system/s390x/secure-ipl.rst | 22 +++++++++++++++++----- hw/s390x/s390-virtio-ccw.c | 30 ++++++++++++++++++++++++++++++ include/hw/s390x/s390-virtio-ccw.h | 2 ++ qemu-options.hx | 6 +++++- 4 files changed, 54 insertions(+), 6 deletions(-) diff --git a/docs/system/s390x/secure-ipl.rst b/docs/system/s390x/secure-ip= l.rst index cf6ccf5d57..9e3955f8fc 100644 --- a/docs/system/s390x/secure-ipl.rst +++ b/docs/system/s390x/secure-ipl.rst @@ -19,20 +19,32 @@ Note: certificate files must have a .pem extension. =20 qemu-system-s390x -machine s390-ccw-virtio,boot-certs.0.path=3D/.../qe= mu/certs,boot-certs.1.path=3D/another/path/cert.pem ... =20 +Enabling Secure IPL +^^^^^^^^^^^^^^^^^^^ + +Secure IPL is enabled by explicitly setting ``secure-boot=3Don``; if not +specified, secure boot is considered off. + +.. code-block:: shell + + qemu-system-s390x -machine s390-ccw-virtio,secure-boot=3Don|off + =20 IPL Modes --------- =20 Multiple IPL modes are available to differentiate between the various IPL -configurations. These modes are mutually exclusive and enabled based on the -``boot-certs`` option on the QEMU command line. +configurations. These modes are mutually exclusive and enabled based on sp= ecific +combinations of the ``secure-boot`` and ``boot-certs`` options on the QEMU +command line. =20 Normal Mode ^^^^^^^^^^^ =20 -The absence of certificates will attempt to IPL a guest without secure IPL -operations. No checks are performed, and no warnings/errors are reported. -This is the default mode. +The absence of both certificates and the ``secure-boot`` option will attem= pt to +IPL a guest without secure IPL operations. No checks are performed, and no +warnings/errors are reported. This is the default mode, and can be explic= itly +enabled with ``secure-boot=3Doff``. =20 Configuration: =20 diff --git a/hw/s390x/s390-virtio-ccw.c b/hw/s390x/s390-virtio-ccw.c index c68a760f75..ea94169a1e 100644 --- a/hw/s390x/s390-virtio-ccw.c +++ b/hw/s390x/s390-virtio-ccw.c @@ -819,6 +819,27 @@ static void machine_set_boot_certs(Object *obj, Visito= r *v, const char *name, ms->boot_certs =3D cert_list; } =20 +static inline bool machine_get_secure_boot(Object *obj, Error **errp) +{ + S390CcwMachineState *ms =3D S390_CCW_MACHINE(obj); + + return ms->secure_boot; +} + +static inline void machine_set_secure_boot(Object *obj, bool value, + Error **errp) +{ + S390CcwMachineClass *s390mc =3D S390_CCW_MACHINE_GET_CLASS(obj); + S390CcwMachineState *ms =3D S390_CCW_MACHINE(obj); + + if (!s390mc->use_secure) { + error_setg(errp, "secure-boot is not supported by this machine ver= sion"); + return; + } + + ms->secure_boot =3D value; +} + /* * S390x-specific global compatibility properties. * @@ -845,6 +866,7 @@ static void ccw_machine_class_init(ObjectClass *oc, con= st void *data) s390mc->max_threads =3D 1; s390mc->use_cpi =3D true; s390mc->use_certs =3D true; + s390mc->use_secure =3D true; mc->reset =3D s390_machine_reset; mc->block_default_type =3D IF_VIRTIO; mc->no_cdrom =3D 1; @@ -893,6 +915,13 @@ static void ccw_machine_class_init(ObjectClass *oc, co= nst void *data) machine_get_boot_certs, machine_set_boot_cer= ts, NULL, NULL); object_class_property_set_description(oc, "boot-certs", "provide paths to a directory and/or a certificate file for se= cure boot"); + + object_class_property_add_bool(oc, "secure-boot", + machine_get_secure_boot, + machine_set_secure_boot); + object_class_property_set_description(oc, "secure-boot", + "enable/disable secure boot"); + } =20 static inline void s390_machine_initfn(Object *obj) @@ -981,6 +1010,7 @@ static void ccw_machine_11_0_class_options(MachineClas= s *mc) S390CcwMachineClass *s390mc =3D S390_CCW_MACHINE_CLASS(mc); =20 s390mc->use_certs =3D false; + s390mc->use_secure =3D false; /* * Preserve v11.0 and older version behavior: * keep legacy virtio-pci enabled. diff --git a/include/hw/s390x/s390-virtio-ccw.h b/include/hw/s390x/s390-vir= tio-ccw.h index d30f1fcc4c..dcac486bc4 100644 --- a/include/hw/s390x/s390-virtio-ccw.h +++ b/include/hw/s390x/s390-virtio-ccw.h @@ -29,6 +29,7 @@ struct S390CcwMachineState { bool aes_key_wrap; bool dea_key_wrap; bool pv; + bool secure_boot; uint8_t loadparm[8]; uint64_t memory_limit; uint64_t max_pagesize; @@ -58,6 +59,7 @@ struct S390CcwMachineClass { int max_threads; bool use_cpi; bool use_certs; + bool use_secure; }; =20 #endif diff --git a/qemu-options.hx b/qemu-options.hx index 83915bd7ef..d37fd8595c 100644 --- a/qemu-options.hx +++ b/qemu-options.hx @@ -47,7 +47,8 @@ DEF("machine", HAS_ARG, QEMU_OPTION_machine, \ " cxl-fmw.0.targets.0=3Dfirsttarget,cxl-fmw.0.targets.1= =3Dsecondtarget,cxl-fmw.0.size=3Dsize[,cxl-fmw.0.interleave-granularity=3Dg= ranularity]\n" " sgx-epc.0.memdev=3Dmemid,sgx-epc.0.node=3Dnumaid\n" " smp-cache.0.cache=3Dcachename,smp-cache.0.topology=3D= topologylevel\n" - " boot-certs.0.path=3D/path/directory,boot-certs.1.path= =3D/path/file provides paths to a directory and/or a certificate file\n", + " boot-certs.0.path=3D/path/directory,boot-certs.1.path= =3D/path/file provides paths to a directory and/or a certificate file\n" + " secure-boot=3Don|off enable/disable secure boot (defa= ult=3Doff) \n", QEMU_ARCH_ALL) SRST ``-machine [type=3D]name[,prop=3Dvalue[,...]]`` @@ -218,6 +219,9 @@ SRST =20 ``boot-certs.0.path=3D/path/directory,boot-certs.1.path=3D/path/file`` Provide paths to a directory and/or a certificate file on the host= [s390x only]. + + ``secure-boot=3Don|off`` + Enables or disables secure boot on s390-ccw guest. The default is = off. ERST =20 DEF("M", HAS_ARG, QEMU_OPTION_M, --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098269; cv=none; d=zohomail.com; s=zohoarc; b=Gn1sQe0U/r458NGdCSqJwGyq+n9T5UaxKOGAaLZmSglKPgZEnR1KpZjAZU5VdJPBu/m7GFaSwD6CjkFOY3Po5uw9Ok/o3Hp5DqcC6FlUi9y613HyfzftE6oYlLm7XSITeICGzffrxWbIfpg9makdtweLbfYk3GFmCoc7yWhTl6E= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098269; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=txdTEYrvtT1ygS0XdfiIeqSulEJRZdmxymBSb2Ff7T4=; b=gv+ZWDAg2Ab4jP3z9vatHnxy0Stb4mFUNdQQz0eM9ACFXG8qQoEFs1tO/HyRqdWXMRUXAvYCevhTP/9Mf/90j1UVTHTUGR/m9vtM63WbqkDPHVNnUWr5Fj1JugnKzu/VkhVpW0ckHEF6/furj1V/0/8tQqqzzIDIZ45qc0h7wXU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098268998888.0733570840323; Fri, 3 Jul 2026 10:04:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHN-00017B-4Y; Fri, 03 Jul 2026 13:02:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHJ-0000hl-Vx; Fri, 03 Jul 2026 13:02:14 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHI-0003QU-4P; Fri, 03 Jul 2026 13:02:13 -0400 Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GJoER3218889; Fri, 3 Jul 2026 17:02:08 GMT Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26mk7rue-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:07 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gndgj031499; Fri, 3 Jul 2026 17:02:07 GMT Received: from smtprelay03.wdc07v.mail.ibm.com ([172.16.1.70]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2uhysgfh-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:07 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay03.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1WlW52691230 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:32 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 70B7458062; Fri, 3 Jul 2026 17:02:05 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8D75D58054; Fri, 3 Jul 2026 17:02:02 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:02:02 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=txdTEYrvtT1ygS0Xd fiIeqSulEJRZdmxymBSb2Ff7T4=; b=Av38PHDfBFrWRekGAfmWXWHoPCbHUmOzT EUd3yEOJc8jHMiX8p4RL9K6K5V0a9fLou1nWPoO1X6O25wjtuT63Oi7WQVmJScs2 V2y2RpOyjwom26XUAXcP7YM7lM4+bUrJXy/h503U1DVXprSTChXapsSw9ctRzNaq /mj257xUaMT//PzHxpf7L+D4HsirH0Ce6+kcB120vw6Xxr0LNxSn5ERMpVYb7PgL jY0gBXmm51r/H6uWK9Tl5ZM0zByQRM0Ldb3c6Xj9y6dA0hl7exeADcWwSUFbUuIK VZWhvSEWcixKAk2MxJATPO3VDMulKTRDwaXgGAssiMpDuNUE1Mx3Q== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 28/33] hw/s390x/ipl: Set IPIB flags for secure IPL Date: Fri, 3 Jul 2026 13:00:25 -0400 Message-ID: <20260703170032.1893204-29-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXwER/ah4YhrAw YNAK/lkjNJQ+MMiz3Tg6CSx82tMCH8JAR62QYJdLXqaAs+o679Db5Uwiq4kRm1LerPcMgSFSa5G CfFY3r4cQCjgYEIqMr11Xgwxe6HDCaGqC8z/RLHrPnBcvl7K7tiWptT5iH3V/wFPy108JbVGT4B 4V25KSL8ysilAUFB1qNc8ZPHrLJkz73jXl0amh6BShAlEgDYjzkfBmazN6Gwk9XyaPg6G0Nd5e0 WUE8YIqIbqu8m7ZWo8FHXBrKDtThHRyoffwke+CHNwGIcStSjR49moVvEGk30XH7pWMrXUNXOas AFdRfZQ2IY4gXoWECEzMaCAnzg24ISEVPkuvVb9Ov/xDC1+/wNs1P71bGWqlwB27wajnhHCAM8O natVzhtg0pk5pkMDGafYSwkDUI45JD+bYpusnCKW0Zv+o5eJTVSJBM/EnwbzX82M8Pz62ROiZxN 9YQhOg3XmPFSTEcmb4Q== X-Proofpoint-GUID: VgPH_Z93OZUOQYs5XOeR2VzEAADmN_t5 X-Authority-Analysis: v=2.4 cv=Z8bc2nRA c=1 sm=1 tr=0 ts=6a47eb0f cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=MUQpW0jNMHjpGy_Q9scA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX0XkkLdcaw4KO XF+Y7UMFx38XKnoasoqFoiwNcn7i3cUgqM2qwHufRqxBVfNf0ezitjK7QstQihtUe70MRYmGiO2 3DRz2W52areRyqEImKrVV7+87yuUP7E= X-Proofpoint-ORIG-GUID: VgPH_Z93OZUOQYs5XOeR2VzEAADmN_t5 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 adultscore=0 spamscore=0 priorityscore=1501 impostorscore=0 malwarescore=0 phishscore=0 bulkscore=0 lowpriorityscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098269359158502 Content-Type: text/plain; charset="utf-8" If `-M secure-boot=3Don` is specified on the command line option, indicating true secure IPL enabled, set Secure-IPL bit and IPL-Information-Report bit on in IPIB Flags field, and trigger true secure IPL in the S390 BIOS. Any error that occurs during true secure IPL will cause the IPL to terminate. Signed-off-by: Zhuoying Cai Reviewed-by: Thomas Huth Reviewed-by: Collin Walling --- hw/s390x/ipl.c | 28 +++++++++++++++++++++++----- 1 file changed, 23 insertions(+), 5 deletions(-) diff --git a/hw/s390x/ipl.c b/hw/s390x/ipl.c index cd80e3057c..62a3c60530 100644 --- a/hw/s390x/ipl.c +++ b/hw/s390x/ipl.c @@ -467,15 +467,30 @@ static bool s390_has_certificate(void) return ipl->cert_store.count > 0; } =20 +static bool s390_secure_boot_enabled(void) +{ + return S390_CCW_MACHINE(qdev_get_machine())->secure_boot; +} + static void s390_set_secure_boot_flags(IplParameterBlock *iplb, - bool audit_mode) + bool secure_boot, bool audit_mode) { - if (!audit_mode) { + if (!secure_boot && !audit_mode) { return; } =20 /* - * For audit mode, enable the IPL Information + * If secure-boot is enabled, then toggle the secure IPL flags (SIPL) = to + * trigger secure boot in the s390 BIOS. + * + * Boot process will terminate if any error occurs during secure boot. + */ + if (secure_boot) { + iplb->hdr_flags |=3D DIAG308_IPIB_FLAGS_SIPL; + } + + /* + * For both secure boot and audit mode, enable the IPL Information * Report (IPLIR) flag so that the firmware generates an IPL * Information Report Block (IIRB). * @@ -544,7 +559,8 @@ static bool s390_build_iplb(DeviceState *dev_st, IplPar= ameterBlock *iplb) s390_ipl_convert_loadparm((char *)lp, iplb->loadparm); iplb->flags |=3D DIAG308_FLAGS_LP_VALID; =20 - s390_set_secure_boot_flags(iplb, s390_has_certificate()); + s390_set_secure_boot_flags(iplb, s390_secure_boot_enabled(), + s390_has_certificate()); =20 return true; } @@ -697,7 +713,9 @@ void s390_ipl_update_diag308(IplParameterBlock *iplb) * The kernel does not preserve secure boot flags across a reboot. * Re-apply them here based on the current machine configuration. */ - s390_set_secure_boot_flags(&ipl->iplb, s390_has_certificate()); + s390_set_secure_boot_flags(&ipl->iplb, + s390_secure_boot_enabled(), + s390_has_certificate()); } =20 update_machine_ipl_properties(iplb); --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098192; cv=none; d=zohomail.com; s=zohoarc; b=FqgF/it2QvGmDULYDnPCkYBc0C8+tpmwLh2iet1pmnm6b7iNF+UmlvHajB2fkICN6R5bNoYfRYyzUaLzHq7Ev35cUtDsU8i8l2N4Nx5kd/JCNLL7+E4YNOiXCaOnN77KRxi97zKxlLOF7smXcL/xYRmpJp7tXBgLYa92BS9FPNA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098192; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=q/F8oskhqbM+ZYkGP/O6XSARqFPsB4v2VUvHiKnBaiU=; b=COKKcw5hJGoHetpzHJZ4Nm91PBH1+9bRE2tW0XaNeA55JfxScP+QhDHIEZ1+c81O2uaB6JNkNUVYqpyx6VBDID+PgFme25rhVTRReb4vGAyJBBaCPCOb/EkEmAcDpyNKx+SfA9Iw+eTQrXp97fvCEvBqDvlQ3ei++4Xt6w3j42w= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098192006654.4398942291075; Fri, 3 Jul 2026 10:03:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHQ-0001V0-OF; Fri, 03 Jul 2026 13:02:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHM-000154-Pr; Fri, 03 Jul 2026 13:02:16 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHK-0003SB-LR; Fri, 03 Jul 2026 13:02:16 -0400 Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GImpn3236637; Fri, 3 Jul 2026 17:02:11 GMT Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26rffmhu-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:11 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnaSt019636; Fri, 3 Jul 2026 17:02:10 GMT Received: from smtprelay06.wdc07v.mail.ibm.com ([172.16.1.73]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2ruqsy86-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:10 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay06.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H28o224707756 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:02:08 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id BED3358054; Fri, 3 Jul 2026 17:02:08 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id AAFCE5805C; Fri, 3 Jul 2026 17:02:05 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:02:05 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=q/F8oskhqbM+ZYkGP /O6XSARqFPsB4v2VUvHiKnBaiU=; b=s4g++oDU11N5UXoI9m5q5H9+Qi9iIDYxE gkaCMfMaZe90r3jIfBi6ePweZ/y57evC8bckcoF0KRWrHQ43pwwfv+VV24+fhEDL CIZs139BBkukvYwygnjNS4yWWU+Ir36CSN0GCLyZD7rbbImK2jvfdLTc4cpKA85o TWwmi31sy1QpHPCTho5yMqcNrvKy0FeEvMZMCjribzinLdFD9z0dX4rFEGGgB8Bx Ap8RtcUr3McCJf8Ug75/MNyK3xhmQz8FM2ebIkUoQ4yDRvsJ6m2fKPjdDnV0+qiS +XKW10l22JqSZ7+q1asRvzRYvXN1OsxfFizSjVhgH3cOg+QlOTE/Q== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 29/33] pc-bios/s390-ccw: Handle true secure IPL mode Date: Fri, 3 Jul 2026 13:00:26 -0400 Message-ID: <20260703170032.1893204-30-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=a4kAM0SF c=1 sm=1 tr=0 ts=6a47eb13 cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VnNF1IyMAAAA:8 a=7NyXUy-cZM7U7AFZmwYA:9 X-Proofpoint-ORIG-GUID: svt8O4AGr1Eu4bLz27GWCv7bOGYxHC02 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX9Hf2voEGLxX0 nYtv9Yk0Ktry1OQlDEx15M1Z4pFCvwfbxCZMjnrH0e+VYKmUwJYOxxI0+zXNROW71f2799Vecnb UNUdrGwhI7tDMxa6FgCHpd2BHPRRC6RQXiKU6mbOTuADOLkUfMa7XFSnjvyHEGjYQv5khAaVf/0 dyjiebDr2BDQFZHSkhVNBGqRdsdqmhbqh+yrBeDxw0AEhAg12TFJXC8k+jHrJRkQc/pIb1OffB4 gho25rpxG6FKhx+1qqPSia24oXQ90X71XRa+mpLZTw3pOUyJmFL8MBgMOlAHF6jQHowa5Y4w4jN Jz7f0dI+/ZmBAXuDM2FLanp0+ZGmJhvh0v8ijpdRLUAekxygIdu9H0X9xWPQLPtZMfmmp3afi8y R8jNBeNtjvKizKOdU9eATb1sDK1prxxjNTokNXqLaA1j4qasXpJLbsDckpZVz9HxSF2UKPFca8t 8i6ct0cdYJYVuYSZ/9g== X-Proofpoint-GUID: svt8O4AGr1Eu4bLz27GWCv7bOGYxHC02 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX8u8s1ZY9mGgQ 5XZ/P1HsCNqa1FdQsWIIcB8n9dCUW1FhQGU0VcoxNtz7dImj9yZmNFjwnaklRn4c2LoqMXkvDqO TJGrjg6NJuceS9Aog7r+Xu5R4TyOIWM= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 bulkscore=0 suspectscore=0 lowpriorityscore=0 impostorscore=0 spamscore=0 priorityscore=1501 adultscore=0 malwarescore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098194866158501 Content-Type: text/plain; charset="utf-8" When secure boot is enabled (-secure-boot on) and certificate(s) are provided, the boot operates in True Secure IPL mode. Any verification error during True Secure IPL mode will cause the entire boot process to terminate. Secure IPL in audit mode requires at least one certificate provided in the key store along with necessary facilities. If secure boot is enabled but no certificate is provided, the boot process will also terminate, as this is not a valid secure boot configuration. Note: True Secure IPL mode is implemented for the SCSI scheme of virtio-blk/virtio-scsi devices. Signed-off-by: Zhuoying Cai Reviewed-by: Collin Walling Reviewed-by: Matthew Rosato --- docs/system/s390x/secure-ipl.rst | 13 +++++++++++++ hw/s390x/ipl.c | 3 ++- pc-bios/s390-ccw/bootmap.c | 6 +++++- pc-bios/s390-ccw/main.c | 7 ++++++- pc-bios/s390-ccw/s390-ccw.h | 1 + pc-bios/s390-ccw/secure-ipl.h | 3 +++ 6 files changed, 30 insertions(+), 3 deletions(-) diff --git a/docs/system/s390x/secure-ipl.rst b/docs/system/s390x/secure-ip= l.rst index 9e3955f8fc..c8fb887ac0 100644 --- a/docs/system/s390x/secure-ipl.rst +++ b/docs/system/s390x/secure-ipl.rst @@ -66,3 +66,16 @@ Configuration: .. code-block:: shell =20 qemu-system-s390x -machine s390-ccw-virtio,boot-certs.0.path=3D/.../qe= mu/certs,boot-certs.1.path=3D/another/path/cert.pem ... + +Secure Mode +^^^^^^^^^^^ + +When the ``secure-boot=3Don`` option is set and certificates are provided, +a secure boot is performed with error reporting enabled. The boot process = aborts +if any error occurs. + +Configuration: + +.. code-block:: shell + + qemu-system-s390x -machine s390-ccw-virtio,secure-boot=3Don,boot-certs= .0.path=3D/.../qemu/certs,boot-certs.1.path=3D/another/path/cert.pem ... diff --git a/hw/s390x/ipl.c b/hw/s390x/ipl.c index 62a3c60530..a99d3e3306 100644 --- a/hw/s390x/ipl.c +++ b/hw/s390x/ipl.c @@ -849,7 +849,8 @@ void s390_ipl_prepare_cpu(S390CPU *cpu) * Secure IPL without specifying a boot device. * IPLB is not generated if no boot device is defined. */ - if (s390_has_certificate() && !ipl->iplb_valid) { + if ((s390_has_certificate() || s390_secure_boot_enabled()) && + !ipl->iplb_valid) { error_report("No boot device defined for Secure IPL"); exit(1); } diff --git a/pc-bios/s390-ccw/bootmap.c b/pc-bios/s390-ccw/bootmap.c index 7cdeec7064..b2c9f4a7b9 100644 --- a/pc-bios/s390-ccw/bootmap.c +++ b/pc-bios/s390-ccw/bootmap.c @@ -738,6 +738,7 @@ static int zipl_run(ScsiBlockPtr *pte) case ZIPL_BOOT_MODE_NORMAL: rc =3D zipl_run_normal(&entry, tmp_sec); break; + case ZIPL_BOOT_MODE_SECURE: case ZIPL_BOOT_MODE_SECURE_AUDIT: rc =3D zipl_run_secure(&entry, tmp_sec, &comp_list, &cert_list, &t= mp_cert_buf); break; @@ -757,7 +758,8 @@ static int zipl_run(ScsiBlockPtr *pte) /* should not return */ write_reset_psw(entry->compdat.load_psw); =20 - if (boot_mode =3D=3D ZIPL_BOOT_MODE_SECURE_AUDIT) { + if (boot_mode =3D=3D ZIPL_BOOT_MODE_SECURE || + boot_mode =3D=3D ZIPL_BOOT_MODE_SECURE_AUDIT) { update_cert_list(&cert_list); update_iirb(&comp_list, &cert_list); free(tmp_cert_buf); @@ -1125,6 +1127,8 @@ ZiplBootMode get_boot_mode(uint8_t hdr_flags) =20 if (!sipl_set && iplir_set) { return ZIPL_BOOT_MODE_SECURE_AUDIT; + } else if (sipl_set && iplir_set) { + return ZIPL_BOOT_MODE_SECURE; } =20 return ZIPL_BOOT_MODE_NORMAL; diff --git a/pc-bios/s390-ccw/main.c b/pc-bios/s390-ccw/main.c index b94a08e7bf..1bf77d1594 100644 --- a/pc-bios/s390-ccw/main.c +++ b/pc-bios/s390-ccw/main.c @@ -399,15 +399,20 @@ void main(void) =20 boot_mode =3D get_boot_mode(iplb->hdr_flags); switch (boot_mode) { + case ZIPL_BOOT_MODE_SECURE: case ZIPL_BOOT_MODE_SECURE_AUDIT: if (!secure_ipl_supported()) { - panic("Unable to boot in audit mode"); + panic("Unable to boot in secure/audit mode"); } =20 vcssb_len =3D zipl_secure_get_vcssb(); if (vcssb_len =3D=3D 0) { panic("Failed to query certificate storage information!"); } + + if (vcssb_len =3D=3D VCSSB_NO_VC) { + panic("Need at least one certificate for secure boot!"); + } break; default: break; diff --git a/pc-bios/s390-ccw/s390-ccw.h b/pc-bios/s390-ccw/s390-ccw.h index ca2737054d..0ea4810f1f 100644 --- a/pc-bios/s390-ccw/s390-ccw.h +++ b/pc-bios/s390-ccw/s390-ccw.h @@ -90,6 +90,7 @@ void zipl_load(void); typedef enum ZiplBootMode { ZIPL_BOOT_MODE_NORMAL =3D 0, ZIPL_BOOT_MODE_SECURE_AUDIT =3D 1, + ZIPL_BOOT_MODE_SECURE =3D 2, } ZiplBootMode; =20 extern ZiplBootMode boot_mode; diff --git a/pc-bios/s390-ccw/secure-ipl.h b/pc-bios/s390-ccw/secure-ipl.h index 4030ef8480..b80533bc31 100644 --- a/pc-bios/s390-ccw/secure-ipl.h +++ b/pc-bios/s390-ccw/secure-ipl.h @@ -59,6 +59,9 @@ static inline void zipl_secure_error(const char *message) case ZIPL_BOOT_MODE_SECURE_AUDIT: printf("AUDIT MODE WARNING: %s\n", message); break; + case ZIPL_BOOT_MODE_SECURE: + panic(message); + break; default: break; } --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098337; cv=none; d=zohomail.com; s=zohoarc; b=FdJI71DEY5+8yfDq0HcZUfk6RmOHMU9mCHMrVGJbiMN9m0ME8Hoz+iTCcdIw+QCTzPdbI53ji/5jVTJ0gvV9yaKyv/aCzMmss/rt/X481aL/5F/MRvvgJkJ5FoFDGplPag2etWecKFqd0ttw77D+EwlhZ9T1VUA4LiUQub76Eo4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098337; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=0tRrXI+I1z+661/MOdlzZWSYaFNneyZuHHQqK5PBfkE=; b=Kpx7hTFMVoBQqNq7vWsInQEGDdAXZ4DELt1qj3O4T6ACAN0uIBDnbon0WeFwRbEwSlykykQ8Z0n5553mnIocb1saO2VHlyK6w0Y9FtEtG5aTHIy6p7kUSF+96oc4zk3xGn4ydgpxKhCgRs8iIHoAWF0T4idY7UgYD/UjgoHorBQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098337407190.19480126815677; Fri, 3 Jul 2026 10:05:37 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHR-0001Yb-TK; Fri, 03 Jul 2026 13:02:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHP-0001HU-Ao; Fri, 03 Jul 2026 13:02:19 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHN-0003Uu-Nv; Fri, 03 Jul 2026 13:02:19 -0400 Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GJ3DY3246599; Fri, 3 Jul 2026 17:02:14 GMT Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26qafsxx-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:14 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnlBr001538; Fri, 3 Jul 2026 17:02:13 GMT Received: from smtprelay04.dal12v.mail.ibm.com ([172.16.1.6]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2s7whtjq-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:13 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay04.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H2Cb74260542 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:02:12 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id F147E5805C; Fri, 3 Jul 2026 17:02:11 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 0E84F58054; Fri, 3 Jul 2026 17:02:09 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:02:08 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=0tRrXI+I1z+661/MO dlzZWSYaFNneyZuHHQqK5PBfkE=; b=oHP4S6foMIEfeY8eHrJUojCd2GNUbZKx8 hTnlNO/FZRtNHe7YbXhPPENvENxqD8ow9cVPmKd13iSxIE2/BFT0idoMTo+oCBEW vU57dT70PtArzPTi4C4kHUpYxBLOPijS+yGbaPsu/YpZaJcLI+4C3xRjKOKMoZ+j YM6dwKAYzCeEYQyEx7BejEMCi2rtptKPspIwNM7ZgP388sfxfcYdLfqBjRgqG2q6 /DIdgKnYjbkDVQpcf2SPZSvwnW0tiiRRmd7HQzAcBSVVQk5Alsd2vJFksPAbNrL2 J0MKEHyHUQ6H8alEVay/Rn3er6YXoLx7rM+UFs+px4dob6vC8zcDA== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 30/33] hw/s390x/ipl: Handle secure boot with multiple boot devices Date: Fri, 3 Jul 2026 13:00:27 -0400 Message-ID: <20260703170032.1893204-31-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX1H7oDtQVBu+h /RT2TgJ2zpE0cQWydzL17W3K4+3ZvZ4PqVCoLafK9VKL4WPpbyuFOZ3SZ+K/Jje0FPutlEIXeP0 Wuw4YfmgjDQxwYFMJ6LrAlxNY5AejztCjjtSgBjgWoITBu+7S50C6wQmbf37INgHgpbMZ1zxkoy 8fkSJH8149L0ABIrZkxbh+0kPP3r6EqGGlrHMkakpGLdKHWx+4buYuSb2DG54F4V+r3RVdupOLw +l9f53WBEMghgS5E1wDdSohB9+Kxw+Vhnwr/kaqDoyrMUq1M1FtJ/Z7aOpkCymmMXN16LnXHoV1 QqyZCV8MvisUIcXlupt0IkllntsZqV9nHrFIYY0dQa8nF7yx13cnvNNDwkk1+ik6WxCVAyz19sf AIFBLMz1JznSEdFmaJRCkO9l1xMKj2a5VWwG++XymTbyE22+mXJRObhfcAiFPdEHOW6SPrKOIf2 Aq5dRzXwsR0MOr4gVbg== X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXyae9MfDtwzez 1R9PRsU7vxQnSernjtIy0jk/CkweTrmYJeRBaTtAu0ZhoM/XuEDorJM2jPBjNkVi1nH5Rmu24YE Hc6fig82r26iZo8e1TwIi13vc8VrH1U= X-Proofpoint-GUID: 8Q-8j5AKtJ5AR1g1Ez1crBX-442jX5-l X-Proofpoint-ORIG-GUID: 8Q-8j5AKtJ5AR1g1Ez1crBX-442jX5-l X-Authority-Analysis: v=2.4 cv=WZ88rUhX c=1 sm=1 tr=0 ts=6a47eb16 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=20KFwNOVAAAA:8 a=3-8onZzmVqWz2BGYPZQA:9 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 adultscore=0 phishscore=0 clxscore=1015 bulkscore=0 impostorscore=0 priorityscore=1501 lowpriorityscore=0 suspectscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098337981158500 Content-Type: text/plain; charset="utf-8" The current approach to enable secure boot relies on providing secure-boot and boot-certs parameters of s390-ccw-virtio machine type option, which apply to all boot devices. With the possibility of multiple boot devices, secure boot expects all provided devices to be supported and eligible (e.g., virtio-blk/virtio-scsi using the SCSI scheme). If multiple boot devices are provided and include an unsupported (e.g., ECKD, VFIO) or a non-eligible (e.g., Net) device, the boot process will terminate with an error logged to the console. Signed-off-by: Zhuoying Cai Reviewed-by: Thomas Huth Reviewed-by: Matthew Rosato --- hw/s390x/ipl.c | 35 +++++++++++++++++++++++++++++++++-- pc-bios/s390-ccw/main.c | 3 --- 2 files changed, 33 insertions(+), 5 deletions(-) diff --git a/hw/s390x/ipl.c b/hw/s390x/ipl.c index a99d3e3306..1c9ae4d019 100644 --- a/hw/s390x/ipl.c +++ b/hw/s390x/ipl.c @@ -503,6 +503,37 @@ static void s390_set_secure_boot_flags(IplParameterBlo= ck *iplb, iplb->len =3D cpu_to_be32(S390_IPLB_MAX_LEN); } =20 +static bool s390_validate_secure_boot_device(int devtype, Error **errp) +{ + switch (devtype) { + case CCW_DEVTYPE_VFIO: + error_setg(errp, "Passthrough (vfio) CCW device does not support se= cure boot!"); + return false; + case CCW_DEVTYPE_VIRTIO_NET: + error_setg(errp, "Virtio net boot device does not support secure bo= ot!"); + return false; + default: + return true; + } +} + +static void s390_apply_secure_boot(IplParameterBlock *iplb, int devtype, + bool secure_boot, bool audit_mode) +{ + Error *local_error =3D NULL; + + if (!secure_boot && !audit_mode) { + return; + } + + if (!s390_validate_secure_boot_device(devtype, &local_error)) { + error_report_err(local_error); + exit(1); + } + + s390_set_secure_boot_flags(iplb, secure_boot, audit_mode); +} + static bool s390_build_iplb(DeviceState *dev_st, IplParameterBlock *iplb) { CcwDevice *ccw_dev =3D NULL; @@ -559,8 +590,8 @@ static bool s390_build_iplb(DeviceState *dev_st, IplPar= ameterBlock *iplb) s390_ipl_convert_loadparm((char *)lp, iplb->loadparm); iplb->flags |=3D DIAG308_FLAGS_LP_VALID; =20 - s390_set_secure_boot_flags(iplb, s390_secure_boot_enabled(), - s390_has_certificate()); + s390_apply_secure_boot(iplb, devtype, s390_secure_boot_enabled(), + s390_has_certificate()); =20 return true; } diff --git a/pc-bios/s390-ccw/main.c b/pc-bios/s390-ccw/main.c index 1bf77d1594..9623d5320f 100644 --- a/pc-bios/s390-ccw/main.c +++ b/pc-bios/s390-ccw/main.c @@ -305,9 +305,6 @@ static void ipl_ccw_device(void) switch (cutype) { case CU_TYPE_DASD_3990: case CU_TYPE_DASD_2107: - IPL_assert((boot_mode =3D=3D ZIPL_BOOT_MODE_NORMAL), - "Passthrough (vfio) CCW device does not support secure= boot!"); - dasd_ipl(blk_schid, cutype); break; case CU_TYPE_VIRTIO: --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098196; cv=none; d=zohomail.com; s=zohoarc; b=P5MEzacU3lReneFOy6ml+8kSzcmweurzVoxRidtZ84K298CkWPxNCrVD5p8zHfy/P1Az/Fvj5B6LZtUG/iFt9GOCCYIdt4p+f81NYsdsxdk55j43EQDm+/R3LRY10y61i3FWT3jNthcY223bJbIf6D4ul8UYW27l/9GR19qhvAA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098196; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=OSDJjncHzyRzVr+4Qd8GFDtzAmwzc+bLwKS6KTWueXU=; b=ODW1edhEVVip5K0MbxfpRJq+WLqKhSs/GgZ6t9/QZDj5X74NA5xCdpCSNpmugR3FSIatT66UXEWlJF9DoHOAxZrK7v6lQLrwcGYB2oeL9dtehPqDCOcKjxJp7N4tA8cyMeChXX8W62JJdjnyU/fTqi61W+IykWzyNH0PKpnTOtI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098196634616.1131804659735; Fri, 3 Jul 2026 10:03:16 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHX-0002Cf-EC; Fri, 03 Jul 2026 13:02:27 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHU-0001ve-Kk; Fri, 03 Jul 2026 13:02:24 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHS-0003VQ-AR; Fri, 03 Jul 2026 13:02:24 -0400 Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIu5I3303118; Fri, 3 Jul 2026 17:02:17 GMT Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26n6891v-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:17 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnbQd001499; Fri, 3 Jul 2026 17:02:16 GMT Received: from smtprelay07.dal12v.mail.ibm.com ([172.16.1.9]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2s7whtkd-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:16 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay07.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H2FRN32244376 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:02:15 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 0675F58054; Fri, 3 Jul 2026 17:02:15 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 35DCB5805A; Fri, 3 Jul 2026 17:02:12 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:02:12 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=OSDJjncHzyRzVr+4Q d8GFDtzAmwzc+bLwKS6KTWueXU=; b=jQoHGN5vjVFUxGlGerwt1SuVcTEDQvXEt yc4jVeGK95ftscSK2P348dQPhGxH7vreQztJGcM43xxhuh8VChdMMG5lycEeuysZ D2YqF4Wh4nZo4pPoCBYjWIG4OVQnX97FqmttWbt4dehwobari4t78KgJVLfuhpbp 9cBr/88ni5zciphDT9UD50lx4NhWJ28RYzG03ra0UcCAb8ibf3hm59jf6Tziwtjc RhB0fvynrzRwaeBy0mQiiSoIRFziG0M6s+ghbIzUAa/Xcm5YOQQIOLvb4+lgGK5U E0C/H1+JL6PJJkALi60TO1vlx0VqLZ73iJuSxQoEqxsnEVOslt3xw== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 31/33] tests/functional/s390x: Add secure IPL functional test Date: Fri, 3 Jul 2026 13:00:28 -0400 Message-ID: <20260703170032.1893204-32-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXxzhfwa6eKccU V+7IKyq2GJcHan217MoqAnB86sGg/dGTFlll6Hs8BAmtTRgRp4yA2Q+46UmTGB2CoOWItYCUcvc jvwy0eHc3TaYo5f767OL3YIgXbLIYzsguAryQtYv0cazWkjn2yWIx9SvfLi/ZAPfKz+hxwcVArM 9OQn5AoCgjwX6CXshxR9uOWHPitZjaUAFVn2eqkLzwADHuYa0oOAYOjMHF3zAJ04e/LuSHEHq0f CwhXKiOys5N73G0zEG75GdVRldtO7Qgvozlt47RjIorrdsEjdKXp5y+/63umWMaC9L4kwpcgJW6 3OszN24oCQKJZTXMC0DzUl+ZuP2jkIWKepAxjlfwS5uu8bk79hk0XmplnvY2cbLqFlkxZHd9CpJ IX8Xsf9IcdgoGow7iwnVcJ9zBkytqRjVhmL4ukq17K2ExNiB8oH0zcWqi2WlpWUTD0azX0XEOgF PmAsUlmwd6BOleG6F2g== X-Authority-Analysis: v=2.4 cv=V45NF+ni c=1 sm=1 tr=0 ts=6a47eb19 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=vTr9H3xdAAAA:8 a=VnNF1IyMAAAA:8 a=WP5zsaevAAAA:8 a=vvdW6g1Vg8v77fwKLDIA:9 a=t8Kx07QrZZTALmIZmm-o:22 X-Proofpoint-ORIG-GUID: px_jmJgVjrMqIXFKtLmp6Wrjk3t0CGXz X-Proofpoint-GUID: px_jmJgVjrMqIXFKtLmp6Wrjk3t0CGXz X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfXzVJ0sHY3YOkJ zcc9OjZDy/e6b85KmaRjx0IFBEP4c2LrleEKsYg6IpJpFalEZphnVz+fOYjdxUjSuZ6/KMH50eP 0D2G8/iZFT53MQwqB/HG/kqkxwKh8ng= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 spamscore=0 suspectscore=0 lowpriorityscore=0 priorityscore=1501 adultscore=0 clxscore=1015 impostorscore=0 malwarescore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098198896158500 Content-Type: text/plain; charset="utf-8" Add functional test for secure IPL. Signed-off-by: Zhuoying Cai Reviewed-by: Matthew Rosato --- tests/functional/s390x/meson.build | 2 + tests/functional/s390x/test_secure_ipl.py | 172 ++++++++++++++++++++++ 2 files changed, 174 insertions(+) create mode 100755 tests/functional/s390x/test_secure_ipl.py diff --git a/tests/functional/s390x/meson.build b/tests/functional/s390x/me= son.build index b065b666bc..16da5f0054 100644 --- a/tests/functional/s390x/meson.build +++ b/tests/functional/s390x/meson.build @@ -2,6 +2,7 @@ =20 test_s390x_timeouts =3D { 'ccw_virtio' : 420, + 'secure_ipl' : 360, } =20 tests_s390x_system_quick =3D [ @@ -14,6 +15,7 @@ tests_s390x_system_thorough =3D [ 'ccw_virtio', 'pxelinux', 'replay', + 'secure_ipl', 'topology', 'tuxrun', ] diff --git a/tests/functional/s390x/test_secure_ipl.py b/tests/functional/s= 390x/test_secure_ipl.py new file mode 100755 index 0000000000..06fc93e404 --- /dev/null +++ b/tests/functional/s390x/test_secure_ipl.py @@ -0,0 +1,172 @@ +#!/usr/bin/env python3 +# +# SPDX-License-Identifier: GPL-2.0-or-later +""" +s390x Secure IPL functional test. + +Validates s390x secure boot by preparing a signed guest image, booting with +secure-boot enabled, and verifying cryptographic validation results. +""" + +from subprocess import check_call, DEVNULL + +from qemu_test import QemuSystemTest, Asset, get_qemu_img +from qemu_test import exec_command_and_wait_for_pattern, exec_command +from qemu_test import wait_for_console_pattern, skipBigDataTest + +class S390xSecureIpl(QemuSystemTest): + """Test s390x Secure IPL (secure boot) functionality.""" + ASSET_F40_QCOW2 =3D Asset( + ('https://archives.fedoraproject.org/pub/archive/' + 'fedora-secondary/releases/40/Server/s390x/images/' + 'Fedora-Server-KVM-40-1.14.s390x.qcow2'), + '091c232a7301be14e19c76ce9a0c1cbd2be2c4157884a731e1fc4f89e7455a5f') + + def __init__(self, *args, **kwargs): + super().__init__(*args, **kwargs) + self.root_password =3D None + self.qcow2_path =3D None + self.cert_path =3D None + self.prompt =3D None + + def _create_certificate(self, vm): + """Generate x509 certificate""" + exec_command_and_wait_for_pattern(self, + 'openssl version', 'OpenSSL 3.2.= 1 30', + vm=3Dvm) + exec_command_and_wait_for_pattern(self, + 'openssl req -new -x509 -newkey rsa:2048 ' + '-keyout mykey.pem -outform PEM -out mycert.pe= m ' + '-days 36500 -subj "/CN=3DMy Name/" -nodes -ve= rbose', + 'Writing private key to \'mykey.pem\'', vm=3Dv= m) + + def _sign_binaries(self, vm): + """Sign stage3 binary and kernel""" + # Install kernel-devel (needed for sign-file) + exec_command_and_wait_for_pattern(self, + 'sudo dnf install kernel-devel-$(uname -r)= -y', + 'Complete!', vm=3Dvm) + wait_for_console_pattern(self, self.prompt, vm=3Dvm) + exec_command_and_wait_for_pattern(self, + 'ls /usr/src/kernels/$(uname -r)/scrip= ts/', + 'sign-file', vm=3Dvm) + + # Sign stage3 binary and kernel + exec_command(self, '/usr/src/kernels/$(uname -r)/scripts/sign-file= ' + 'sha256 mykey.pem mycert.pem /lib/s390-tools/stage3.bi= n', + vm=3Dvm) + wait_for_console_pattern(self, self.prompt, vm=3Dvm) + exec_command(self, '/usr/src/kernels/$(uname -r)/scripts/sign-file= ' + 'sha256 mykey.pem mycert.pem /boot/vmlinuz-$(uname -r)= ', + vm=3Dvm) + wait_for_console_pattern(self, self.prompt, vm=3Dvm) + + def _run_zipl_secure(self, vm): + """Run zipl to prepare for secure boot""" + exec_command_and_wait_for_pattern(self, 'zipl --secure 1 -VV', 'Do= ne.', + vm=3Dvm) + + def _extract_certificate(self, vm): + """Extract certificate from VM to host filesystem""" + out =3D exec_command_and_wait_for_pattern(self, 'cat mycert.pem', + '-----END CERTIFICATE-----= ', + vm=3Dvm) + # strip first line to avoid console echo artifacts + cert =3D "\n".join(out.decode("utf-8").splitlines()[1:]) + self.log.info("%s", cert) + + self.cert_path =3D self.scratch_file("mycert.pem") + + with open(self.cert_path, 'w', encoding=3D"utf-8") as file_object: + file_object.write(cert) + + def setup_s390x_secure_ipl(self): + """ + Prepare a secure boot-enabled guest image. + + Boots a temporary VM to generate a certificate, sign boot componen= ts + (stage3 and kernel), run zipl, and extract the certificate to host. + """ + self.require_netdev('user') + + temp_vm =3D self.get_vm(name=3D'sipl_setup') + temp_vm.set_machine('s390-ccw-virtio') + + asset_path =3D self.ASSET_F40_QCOW2.fetch() + self.qcow2_path =3D self.scratch_file('f40.qcow2') + qemu_img =3D get_qemu_img(self) + check_call([qemu_img, 'create', '-f', 'qcow2', '-b', asset_path, + '-F', 'qcow2', self.qcow2_path], stdout=3DDEVNULL, std= err=3DDEVNULL) + + temp_vm.set_console() + temp_vm.add_args('-nographic', + '-accel', 'kvm', + '-m', '1024', + '-drive', + f'id=3Ddrive0,if=3Dnone,format=3Dqcow2,file=3D{se= lf.qcow2_path}', + '-device', 'virtio-blk-ccw,drive=3Ddrive0,bootind= ex=3D1') + temp_vm.launch() + + # Initial root account setup (Fedora first boot screen) + self.root_password =3D 'fedora40password' + wait_for_console_pattern(self, 'Please make a selection from the a= bove', + vm=3Dtemp_vm) + exec_command_and_wait_for_pattern(self, '4', 'Password:', vm=3Dtem= p_vm) + exec_command_and_wait_for_pattern(self, self.root_password, + 'Password (confirm):', vm=3Dtemp= _vm) + exec_command_and_wait_for_pattern(self, self.root_password, + 'Please make a selection from the abov= e', + vm=3Dtemp_vm) + + # Login as root + self.prompt =3D '[root@localhost ~]#' + exec_command_and_wait_for_pattern(self, 'c', 'localhost login:', v= m=3Dtemp_vm) + exec_command_and_wait_for_pattern(self, 'root', 'Password:', vm=3D= temp_vm) + exec_command_and_wait_for_pattern(self, self.root_password, self.p= rompt, + vm=3Dtemp_vm) + + self._create_certificate(temp_vm) + self._sign_binaries(temp_vm) + self._run_zipl_secure(temp_vm) + self._extract_certificate(temp_vm) + + # Shutdown temp vm + temp_vm.shutdown() + + @skipBigDataTest() + def test_s390x_secure_ipl(self): + """ + Verify secure boot validation during s390x guest boot. + + Expects two "Verified component" messages and confirms + /sys/firmware/ipl/secure reports secure boot is active. + """ + self.require_accelerator('kvm') + self.setup_s390x_secure_ipl() + + self.set_machine('s390-ccw-virtio') + + self.vm.set_console() + self.vm.add_args('-nographic', + '-machine', 's390-ccw-virtio,secure-boot=3Don,' + f'boot-certs.0.path=3D{self.cert_path}', + '-accel', 'kvm', + '-m', '1024', + '-drive', + f'id=3Ddrive1,if=3Dnone,format=3Dqcow2,file=3D{se= lf.qcow2_path}', + '-device', 'virtio-blk-ccw,drive=3Ddrive1,bootind= ex=3D1') + self.vm.launch() + + # Expect two verified components + verified_output =3D "Verified component" + wait_for_console_pattern(self, verified_output) + wait_for_console_pattern(self, verified_output) + + # Login and verify the vm is booted using secure boot + wait_for_console_pattern(self, 'localhost login:') + exec_command_and_wait_for_pattern(self, 'root', 'Password:') + exec_command_and_wait_for_pattern(self, self.root_password, self.p= rompt) + exec_command_and_wait_for_pattern(self, 'cat /sys/firmware/ipl/sec= ure', '1') + +if __name__ =3D=3D '__main__': + QemuSystemTest.main() --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098312; cv=none; d=zohomail.com; s=zohoarc; b=FFis4YLmX1UE7vV8IfdEZ6bNYgsdHoBa2oTiMJJgERMUj0Zpk0XAzcdtHp7SAnXnP6wZI6PJnXpe+8v4DZDUiwe+Uc6ZObpJ2jSR8qx9lhbyHI1pHuoY32mfNdP7u5CMlCJOzxoUCW5DyBdfFYqO6LYVpUNtcaJs5c1gW0U+bVE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098312; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=msK2ymhbX4mceiZVL8mPqeKiaC1qXvKagqwZM3qszgQ=; b=ZvQoAv3Vrwx/XrEkl01XgTzm9+PNEiHz1EdydK/xDT6AewkuVG2ZckHCsbk1lEAe+nCfi8rEJxmyc1OhaJ1bv72tH+Gv4+WgbPpa/8AoGNxwioC19vnqKxieGYfUVkhMNpWkZ61XrF+vaC7cmDiLu6N382FG+BS6DKsST0jSQpU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098312368344.65752940518064; Fri, 3 Jul 2026 10:05:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHY-0002Jg-CY; Fri, 03 Jul 2026 13:02:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHV-00023C-Kv; Fri, 03 Jul 2026 13:02:26 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHT-0003Vb-W7; Fri, 03 Jul 2026 13:02:25 -0400 Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GJBvp3218109; Fri, 3 Jul 2026 17:02:20 GMT Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26mk7rvg-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:19 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663Gnbej001494; Fri, 3 Jul 2026 17:02:19 GMT Received: from smtprelay03.wdc07v.mail.ibm.com ([172.16.1.70]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2s7whtm9-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:19 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay03.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H1iQn10945262 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:01:44 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 1B33C5805A; Fri, 3 Jul 2026 17:02:18 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3FB2458062; Fri, 3 Jul 2026 17:02:15 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:02:15 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=msK2ymhbX4mceiZVL 8mPqeKiaC1qXvKagqwZM3qszgQ=; b=VSVk+6ksbuxhUV3NYmeSDEB9gm8HBXqC7 mEwidb8MXcCxorcTrI9sESgUWncqdA7fPuVdd8lOFGm2AcjbtPAL8DmjhL/fAQ13 V5N1tOfV/9xn+lX0/cp4xBzv0tnfxT3KGH+YLC6X14mSAywLBVNfuq7XL2PpYiju fL10olfQ1sssh2jaF05UCRHESDc5Dapfyuc55NqmwxoYWHbiz4LkYnygo0u9wk9o JSSjm8RuMf0aTBTt3ftfaVxn23GjAto8pn6k1aj3K+k3Hc0mXzp3kAgZTaDisK8j gBc9TJDWCBYUHWwz0b5uSOeSAEkpDIcyVgBxW/+cM9KRBP5dIShKA== From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 32/33] docs/specs: Add secure IPL documentation Date: Fri, 3 Jul 2026 13:00:29 -0400 Message-ID: <20260703170032.1893204-33-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX+wn/yUXXtfAb fGj6SlgqHjo4LQzc/qQvkIsu3C6OyfwrjcTIcN0JtdlXS7Zb3H3BCy9pAOajDvPghXWVJDY4c5v B7fSI4ACawJxcsUVJ+Anc3jdMuxkGx6pF1VXuxvliuJqCq+goDj5a6Fjhh7xlGzMPZs/j2kd1Kc /fRjCdJWSUFBNCu2eH8GFL1q3xBJM5Ds2KnPGpDNFW8zVeglR4dyOhOTF28xlP8xsjIp1tSxUCF MDjTIGbkjvHd8h4wcm1xcSeQBM3m3mJm5QzEnCZ36AMV6dc9laWF2+/Tsw6F6J4AfCluZyolI+F ppnBReNd50XC3BRmjEQ7hL2LWRKp1Hsln2w93vt6FcZ5Zkdk6zOWMBt1f7X5zat/VKCDCo3myCN 1Uf3Tzs6L26iCKmX1kjVq66ejpafv3adZrYjmOTzbDlFE8HHCkIXrfYBb6zkX7lOl7UUlV1U/nG KiRxkIMnco5YF2BBQmw== X-Proofpoint-GUID: XjRIBLwTo81nMR_p4Cq1wqJZ6hevNyro X-Authority-Analysis: v=2.4 cv=Z8bc2nRA c=1 sm=1 tr=0 ts=6a47eb1c cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=bKBM-sKadDDPLvLHMR0A:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX+ElUR/mBdaTe 6U/DRRMRCgvsSP+F4JvHqAuYdSSC4nUOr7YT3lh4awx8CQPUF3B/NgunJMd7mApvgtzVPPkLX9s /jaai1c1Ep9utfH1WolnAN4smEpNPwk= X-Proofpoint-ORIG-GUID: XjRIBLwTo81nMR_p4Cq1wqJZ6hevNyro X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 adultscore=0 spamscore=0 priorityscore=1501 impostorscore=0 malwarescore=0 phishscore=0 bulkscore=0 lowpriorityscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098313783158500 Content-Type: text/plain; charset="utf-8" Add documentation for secure IPL Signed-off-by: Collin Walling Signed-off-by: Zhuoying Cai Reviewed-by: Matthew Rosato --- docs/specs/s390x-secure-ipl.rst | 55 +++++++++++++++++++++++++++++++++ 1 file changed, 55 insertions(+) diff --git a/docs/specs/s390x-secure-ipl.rst b/docs/specs/s390x-secure-ipl.= rst index db60c2262f..9d633413ae 100644 --- a/docs/specs/s390x-secure-ipl.rst +++ b/docs/specs/s390x-secure-ipl.rst @@ -1,5 +1,60 @@ .. SPDX-License-Identifier: GPL-2.0-or-later =20 +s390 Secure IPL +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +Secure IPL (a.k.a. secure boot) enables s390-ccw virtual machines to +leverage qcrypto libraries and z/Architecture emulation to verify the +integrity of signed kernels. The qcrypto libraries are used to perform +certificate validation and signature-verification, whereas the +z/Architecture emulation is used to ensure secure IPL data has not +been tampered with, convey data between QEMU and guest code, and set up +the relevant secure IPL data structures with verification results. + +To find out more about using this feature, see +:doc:`documentation `. + +Note that "guest code" will refer to the s390-ccw BIOS unless stated +otherwise. + +Both QEMU and guest code work in cooperation to perform secure IPL. The Se= cure +Code Loading Attributes Facility (SCLAF) is used to check the Secure Code +Loading Attribute Block (SCLAB) and ensure that secure IPL data has not +been tampered with. DIAGNOSE 'X'320' is invoked by guest code to query +the certificate store info and retrieve specific certificates from QEMU. +DIAGNOSE 'X'508' is used by guest code to leverage qcrypto libraries to +perform signature-verification in QEMU. Lastly, guest code generates and +appends an IPL Information Report Block (IIRB) at the end of the IPL +Parameter Block (IPLB), which is used by the kernel to store signed and +verified entries. + +The logical steps are as follows: + +- guest code reads data payload from disk (e.g. stage3 boot loader, kernel) +- guest code checks the validity of the SCLAB +- guest code invokes DIAG 508 subcode 1 and provides the payload +- QEMU handles DIAG 508 request by reading the payload and retrieving the + certificate store +- QEMU DIAG 508 utilizes handler qcrypto libraries to perform + signature-verification on the payload, attempting with each cert in the = store + (until success or exhausted) +- QEMU DIAG 508 returns: + + - success: index of cert used to verify payload + - failure: error code + +- guest code is expected to respond to this operation by: + + - success: retrieves cert from store via DIAG 320 using returned index + - failure: reports with warning (audit mode), aborts with error (secure = mode) + +- guest code appends IIRB at the end of the IPLB +- guest code kicks off IPL + +More information regarding the respective DIAGNOSE commands and IPL data +structures are outlined within this document. + + s390 Certificate Store and Functions ------------------------------------ =20 --=20 2.54.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783098203; cv=none; d=zohomail.com; s=zohoarc; b=hJfY5RNUUXHfbeYclDui/3MY9576teaTTV78wHnBen0B6Lj0wmgcqt2ojJxtiUmaVOg3CMTkpP/BGOJO6cCaXFZhmcoWpq0d9cutZ5Txe2De2pHUK5zvzyKTALaPHMrL48zMqoFSMgVwZLhK2dMemRkTEzVnUY4GUugwHh+bbUQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783098203; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=jv18yst7qaP0DLP5c+LuJvnW5VF+SH9SY83Jw4PKyMQ=; b=NoZx+JmECt5RZVR8aORsQK7hu723T0POvHjD/F08E0phCVjISJYHerDvkH8E0ehIPPJ8shFMImxCU744aCHX/Df4GX7+D+iEQbUlsYJJg4/Irxu1ChAE4zJaCgjS4Zbyot53Y4mf1jo+UfhMFQrBoE1Jz16HEsKh/5r3qxyso9Y= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783098203159926.6755974002474; Fri, 3 Jul 2026 10:03:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfhHc-0002kW-0y; Fri, 03 Jul 2026 13:02:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHa-0002WA-J1; Fri, 03 Jul 2026 13:02:30 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfhHY-0003W7-Lq; Fri, 03 Jul 2026 13:02:30 -0400 Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 663GIYe03497174; Fri, 3 Jul 2026 17:02:24 GMT Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26qgg706-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:23 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 663GnhTX019683; Fri, 3 Jul 2026 17:02:22 GMT Received: from smtprelay06.wdc07v.mail.ibm.com ([172.16.1.73]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f2ruqsyb3-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 03 Jul 2026 17:02:22 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (smtpav03.wdc07v.mail.ibm.com [10.39.53.230]) by smtprelay06.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 663H2LOI66453830 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 3 Jul 2026 17:02:21 GMT Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 227C558066; Fri, 3 Jul 2026 17:02:21 +0000 (GMT) Received: from smtpav03.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 545415805C; Fri, 3 Jul 2026 17:02:18 +0000 (GMT) Received: from fedora-workstation.lan (unknown [9.61.75.28]) by smtpav03.wdc07v.mail.ibm.com (Postfix) with ESMTP; Fri, 3 Jul 2026 17:02:18 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=jv18ys t7qaP0DLP5c+LuJvnW5VF+SH9SY83Jw4PKyMQ=; b=PypTC8UWQXrQT58k4/ISs7 9QbsKpuin1WlvrLdmd1y3Yun3iP2OeyQ7mQJp9JlrX2K3fQmwPUQZ1qFFPHqhyr8 +GJitrFR/AorrWvo1p1xrTrFjeWRmDIUlbdI3/eRxjUEJiis5nTmAjxixhaVTpyB +uZf8KAJUxOrrZ6qswBM8OQq5a8YQCpU46sQstXrfer7JmMFPzFn03PpKNUYlnNs nuxqHEBCNdT7ze69cwOBz4MRo/4yKt034K1fGZfq6fPTI6XBSZMtkHRYjXZSkQYF NkgJwKgODOr4kp2QuP3vbUwYvO1sjRtZhwWgFOYcSkCLCqhqLnM/8JMVlHdZcBuQ == From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v14 33/33] docs/system/s390x: Add secure IPL documentation Date: Fri, 3 Jul 2026 13:00:30 -0400 Message-ID: <20260703170032.1893204-34-zycai@linux.ibm.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260703170032.1893204-1-zycai@linux.ibm.com> References: <20260703170032.1893204-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=RYqgzVtv c=1 sm=1 tr=0 ts=6a47eb1f cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=q5T4S90kAAAA:8 a=xOmL8MRHFtDrr2fuNQ0A:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=LnBBZQxPVJ0Z7KJyRdxh:22 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX+2XkBDfEPvcc VPUkcu7hDYKfPiOZaL6p5Xt9vqoSHauKPHwGBRKLiJGnSXKFEBDqdmV9AObohI5a24/qsRBSrn8 BoQFNcWc3GL3G86FbI4q3K7RcjzNz5s= X-Proofpoint-GUID: zREqeW6JEutelxQVzUIEPHbN0Ia-27j0 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAzMDE2NyBTYWx0ZWRfX+4T9MlD/ZNrA AvEUSWPGgd+k03Qsxjt2ulZqxa12YVGFqXQ0P5/zz2uFaNKLcLR0kv3MUOQDIp3DcLCuvZ/Sq6R G0usfJzFnQjCJtm8uigXHMvLozwwjJkhOkuNmdyf1RdX3UNvKBmvldlowF/xXhoeAz9hr/BStzo vLMwlwQ8prswhMvh3OIE91jG/c6kI5PJyj58B4dKcIS9+/jILeZvrIZmCr82bgUiCHh9zorHTs2 zHLcT45Ux1ZdnR3fW3KPh5lscyDwyNzl5BCIHDCKWbJxpw8IaE14j9K19eX25GTkeRZas84JDiH Zp63OJLT0TW/mWV+SyE+EjYw0uPyL/JFX1gAkL3zyv4YRiOAIf8KALPxecyecm21B1a6aoQaJHY s6hBtmOSq8vdtKOc8c6wcI+MgYU1tfMbnZV3jBz1hOQJOtJxgavbmrFAMJIhrAzteDYKayWbNye cRKU5CR8G1tYvX/UUlw== X-Proofpoint-ORIG-GUID: zREqeW6JEutelxQVzUIEPHbN0Ia-27j0 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-03_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 impostorscore=0 malwarescore=0 spamscore=0 lowpriorityscore=0 adultscore=0 priorityscore=1501 suspectscore=0 bulkscore=0 clxscore=1015 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607030167 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=zycai@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783098204763158500 Add documentation for secure IPL Signed-off-by: Collin Walling Signed-off-by: Zhuoying Cai Reviewed-by: Joshua Daley Reviewed-by: Matthew Rosato --- docs/system/s390x/secure-ipl.rst | 103 +++++++++++++++++++++++++++++++ 1 file changed, 103 insertions(+) diff --git a/docs/system/s390x/secure-ipl.rst b/docs/system/s390x/secure-ip= l.rst index c8fb887ac0..67de20f47a 100644 --- a/docs/system/s390x/secure-ipl.rst +++ b/docs/system/s390x/secure-ipl.rst @@ -1,5 +1,22 @@ .. SPDX-License-Identifier: GPL-2.0-or-later =20 +s390 Secure IPL +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +Secure IPL, also known as secure boot, enables s390-ccw virtual machines to +verify the integrity of guest kernels. + +For technical details of this feature, see the +:doc:`specs document `. + +This document explains how to use secure IPL with s390x in QEMU. It covers +the command line options for providing certificates and enabling secure IP= L, +the different IPL modes (Normal, Audit, and Secure), and system requiremen= ts. + +A quickstart guide is provided to demonstrate how to generate certificates, +sign images, and start a guest in Secure Mode. + + Secure IPL Command Line Options ------------------------------- =20 @@ -79,3 +96,89 @@ Configuration: .. code-block:: shell =20 qemu-system-s390x -machine s390-ccw-virtio,secure-boot=3Don,boot-certs= .0.path=3D/.../qemu/certs,boot-certs.1.path=3D/another/path/cert.pem ... + + +Constraints +----------- + +The following constraints apply when attempting to boot an s390x guest in = secure +mode: + +- z16 or "qemu" CPU model +- certificates must be in X.509 PEM format +- only support for SCSI scheme of virtio-blk/virtio-scsi devices +- a boot device must be specified +- any unsupported devices (e.g., ECKD and VFIO) or non-eligible devices (e= .g., + network) will cause the entire boot process to terminate early, with an = error + logged to the console. + + +Secure IPL Quickstart +--------------------- + +Build QEMU with gnutls enabled +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +.. code-block:: shell + + ./configure =E2=80=A6 --enable-gnutls + +Generate certificate (e.g. via certtool) +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +A private key is required before generating a certificate. This key must b= e kept +secure and confidential. + +Use an RSA private key for signing. + +.. code-block:: shell + + certtool --generate-privkey > key.pem + +A self-signed certificate requires the organization name. Use the ``cert.i= nfo`` +template to pre-fill values and avoid interactive prompts from certtool. + +.. code-block:: shell + + cat > cert.info <