From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477531; cv=none; d=zohomail.com; s=zohoarc; b=dVuElJr2vIeILDlXEZOHWXrkNR7Rk4ujZC/xv36E0deonOc5C7YNNJlDlQJA3DT2ShIdX4ajxJ8TJv6+okHUlyqLTWKp9DCER4Vt9N8w16IJDR/TJO/5PailEGtnVe2ksE7OgIv8mDIh4IybrxKU7QRKA29+0DNVBaAwpgXGV5E= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477531; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lOIM/Cc14RzT2Ss1jXc7sxt3HuykJrKEV9sxrNWyD+s=; b=bKgbJQKLcSFnj3OOy2t5DRnmV8lR7etLRTbFaBQIjE3cja+YHd1X2ygUW7AeurDeBkEZD0V1UehFs4jwmAe79GZzusfLM+XslgAIxEaz9JgtToNz9sW8VuBu3TSw+yKG49CZ667pSbLjg/2xA3E2GX0fojswdBwGEZkCVS5XNLw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477531385967.910508106544; Thu, 30 Jul 2026 22:58:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFm-0002kT-CW; Fri, 31 Jul 2026 01:57:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM5-0005rF-Uj; Thu, 30 Jul 2026 23:56:18 -0400 Received: from [115.124.30.110] (helo=out30-110.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM0-0002HY-AD; Thu, 30 Jul 2026 23:56:17 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwNG_1785469833 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:37 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470153; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=lOIM/Cc14RzT2Ss1jXc7sxt3HuykJrKEV9sxrNWyD+s=; b=WNyZtZbRp0w85tD9OLoAi0SN76GaNn7vm9qYi+Vt/JjonCVYXUxuNlxoC1oelRmz+O9V0ukiOSnGXkK+amZtVQHcmDFCJ5hMNnMdWF5ZVgIVWaICzYCixQb3qBSQy9ATsiClGYyjEbqoZNQbwl9ALL7KUmgg/mM9H4sMlgIqVuw= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R121e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037026112; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwNG_1785469833; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 01/17] docs/system/riscv/virt: document the cove-vm machine option Date: Fri, 31 Jul 2026 11:49:55 +0800 Message-Id: <20260731035011.4178103-2-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.110 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.110; envelope-from=blduan@linux.alibaba.com; helo=out30-110.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477533364158500 Content-Type: text/plain; charset="utf-8" Describe the cove-vm option of the virt machine and how a CoVE TEE VM (TVM) differs from a regular KVM guest: its memory and vCPU state are owned by the TEE Security Manager (TSM), the guest images are measured before it starts, interrupts are delivered as MSIs only, there is no virtio-mmio transport and vhost cannot be used. The option itself is added by the following patches. Signed-off-by: Baolong Duan --- docs/system/riscv/virt.rst | 39 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 39 insertions(+) diff --git a/docs/system/riscv/virt.rst b/docs/system/riscv/virt.rst index 60850970ce..d053dbc300 100644 --- a/docs/system/riscv/virt.rst +++ b/docs/system/riscv/virt.rst @@ -146,6 +146,45 @@ The following machine-specific options are supported: =20 Enables the riscv-iommu-sys platform device. Defaults to 'off'. =20 +- cove-vm=3D[on|off] + + When this option is "on" the guest is created as a RISC-V CoVE + (Confidential VM Extension) TEE VM, or TVM. Defaults to "off". See + `Running a confidential VM`_ below. + +Running a confidential VM +------------------------- + +With "cove-vm=3Don" the ``virt`` machine creates a TEE VM (TVM) instead of= a +regular KVM guest. The memory and the vCPU state of a TVM are owned by the +TEE Security Manager (TSM) running in M-mode and are not accessible to the +host, which changes the machine in a few ways: + +- the kernel, the initrd and the device tree are added to the initial + measurement of the guest before it starts, so that the guest can be + attested later on; + +- interrupts are delivered as MSIs only. An IMSIC is therefore mandatory a= nd + "aia=3Daplic-imsic" is selected automatically when no AIA mode is reques= ted. + The APLIC is emulated by QEMU because KVM does not implement one for a T= VM; + +- no virtio-mmio transport is created. Devices have to be attached to the + PCIe host bridge, and they always negotiate VIRTIO_F_ACCESS_PLATFORM so + that DMA is bounced through memory the guest shares explicitly; + +- vhost cannot be used, as the kernel datapath has no access to guest memo= ry. + +This requires a host with CoVE support, both in the firmware and in KVM, a= nd +it only works with ``-accel kvm``. An example command line is: + +.. code-block:: bash + + $ qemu-system-riscv64 -M virt,cove-vm=3Don -accel kvm \ + -m 256M -smp 1 -nographic \ + -kernel Image -append "console=3DttyS0 root=3D/dev/vda" \ + -drive file=3Drootfs.ext4,format=3Draw,id=3Dhd0,if=3Dnone \ + -device virtio-blk-pci,drive=3Dhd0,disable-legacy=3Don + Running Linux kernel -------------------- =20 --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477592; cv=none; d=zohomail.com; s=zohoarc; b=Qk/4V3c+3+dib6XO13tWyy4zcHvfwebUNNWFr9Vap6YtNji36krTVMhoOPFwTxQdZx++22oO4VMUBSOmK6CU0vgTa3o9KHfQlKxe2lD1dTS6oOA5C8ePgx+dAEhCcJdxNBEgBE0KPoMTzqmbESAEqZm0vswsyq1i2K02KAqrcqA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477592; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VJWkJluchzKSNULaL74QEFDHFaTH5ibDQItbZKM6t28=; b=eP8P8V2YXJ8f7564T0YjYiPg6D7l5j16sLABwG8jOxhFqkP2RuzO6Sxba1eGwzvYwkqo7ucxDMZUTbv0B3ll546PgtJEj+u3pSsD83ROtA40TVTz6RP/iSvXK/+YsOqEb9x+bnfmKYEUM5jhb/P5WGaXB3WWjbkPi5or4gf3dJo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477592086336.07675846867085; Thu, 30 Jul 2026 22:59:52 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFY-0002bl-8B; Fri, 31 Jul 2026 01:57:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM5-0005qr-6J; Thu, 30 Jul 2026 23:56:18 -0400 Received: from [115.124.30.118] (helo=out30-118.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM0-0002Hn-78; Thu, 30 Jul 2026 23:56:16 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwOS_1785469837 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:45 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470157; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=VJWkJluchzKSNULaL74QEFDHFaTH5ibDQItbZKM6t28=; b=MAQhj9yWOj6ZlEWDXIavJfXKGwWWBXnZnMnuJziKsy5KletC3dXh7s/aSi6ZV3bF7FaAN89cKLtDrnz6r/2RSspzkkSbozBDKvDgGJ654sClyBMC2P+40E+LLlLNZP3keIA76weHP73aNeoEOy64+3eizfRGTYM9tBecMSyPPaA= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R121e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045098064; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwOS_1785469837; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 02/17] hw/riscv/virt: add the cove-vm machine property Date: Fri, 31 Jul 2026 11:49:56 +0800 Message-Id: <20260731035011.4178103-3-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.118 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.118; envelope-from=blduan@linux.alibaba.com; helo=out30-118.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:31 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477593588158500 Content-Type: text/plain; charset="utf-8" A RISC-V CoVE guest is a TEE VM (TVM) whose memory and vCPU state are owned by the TEE Security Manager (TSM) rather than by the host. Add a 'cove-vm' property to the virt machine to ask for one. Subsystems outside of hw/riscv/, such as the KVM accelerator and the virtio code, have to know whether the guest is a TVM. The state is therefore mirrored into target independent code and queried through riscv_cove_vm_active(); keeping the implementation in hw/core/machine.c avoids a link time dependency on target/riscv. Nothing looks at the property yet. Add a MAINTAINERS entry for the new header. Signed-off-by: Baolong Duan --- MAINTAINERS | 6 ++++++ hw/core/machine.c | 18 ++++++++++++++++++ hw/riscv/virt.c | 26 ++++++++++++++++++++++++++ include/hw/riscv/cove.h | 24 ++++++++++++++++++++++++ include/hw/riscv/virt.h | 1 + 5 files changed, 75 insertions(+) create mode 100644 include/hw/riscv/cove.h diff --git a/MAINTAINERS b/MAINTAINERS index 902db77218..dab130a45a 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -391,6 +391,12 @@ F: target/riscv/XVentanaCondOps.decode F: target/riscv/insn_trans/trans_xventanacondops.c.inc F: disas/riscv-xventana* =20 +RISC-V CoVE +M: Baolong Duan +L: qemu-riscv@nongnu.org +S: Maintained +F: include/hw/riscv/cove.h + RENESAS RX CPUs R: Yoshinori Sato S: Orphan diff --git a/hw/core/machine.c b/hw/core/machine.c index 73b4d82b4a..578a5cdde5 100644 --- a/hw/core/machine.c +++ b/hw/core/machine.c @@ -16,6 +16,7 @@ #include "system/replay.h" #include "hw/core/boards.h" #include "hw/core/loader.h" +#include "hw/riscv/cove.h" #include "qemu/error-report.h" #include "qapi/error.h" #include "qapi/qapi-visit-machine.h" @@ -1335,6 +1336,23 @@ bool machine_require_guest_memfd(MachineState *machi= ne) return machine->cgs && machine->cgs->require_guest_memfd; } =20 +/* + * Whether the machine runs as a RISC-V CoVE guest. This lives here, and n= ot + * in hw/riscv/, because target independent code has to query it and must = not + * depend on the RISC-V machine being linked in. + */ +static bool riscv_cove_vm; + +bool riscv_cove_vm_active(void) +{ + return riscv_cove_vm; +} + +void riscv_cove_vm_set_active(bool active) +{ + riscv_cove_vm =3D active; +} + static char *cpu_slot_to_string(const CPUArchId *cpu) { GString *s =3D g_string_new(NULL); diff --git a/hw/riscv/virt.c b/hw/riscv/virt.c index 51bac47a91..a76587d362 100644 --- a/hw/riscv/virt.c +++ b/hw/riscv/virt.c @@ -35,6 +35,7 @@ #include "hw/riscv/riscv-iommu-bits.h" #include "hw/riscv/virt.h" #include "hw/riscv/boot.h" +#include "hw/riscv/cove.h" #include "hw/riscv/fdt-common.h" #include "hw/riscv/machines-qom.h" #include "hw/riscv/numa.h" @@ -1321,6 +1322,11 @@ static void virt_machine_init(MachineState *machine) exit(1); } =20 + if (s->cove_vm && !kvm_enabled()) { + error_report("'cove-vm' is only available with KVM acceleration"); + exit(1); + } + /* Initialize sockets */ mmio_irqchip =3D virtio_irqchip =3D pcie_irqchip =3D NULL; for (i =3D 0; i < socket_count; i++) { @@ -1652,6 +1658,21 @@ static void virt_set_iommu_sys(Object *obj, Visitor = *v, const char *name, visit_type_OnOffAuto(v, name, &s->iommu_sys, errp); } =20 +static bool virt_get_cove_vm(Object *obj, Error **errp) +{ + RISCVVirtState *s =3D RISCV_VIRT_MACHINE(obj); + + return s->cove_vm; +} + +static void virt_set_cove_vm(Object *obj, bool value, Error **errp) +{ + RISCVVirtState *s =3D RISCV_VIRT_MACHINE(obj); + + s->cove_vm =3D value; + riscv_cove_vm_set_active(value); +} + bool virt_is_acpi_enabled(RISCVVirtState *s) { return s->acpi !=3D ON_OFF_AUTO_OFF; @@ -1780,6 +1801,11 @@ static void virt_machine_class_init(ObjectClass *oc,= const void *data) NULL, NULL); object_class_property_set_description(oc, "iommu-sys", "Enable IOMMU platform device"); + + object_class_property_add_bool(oc, "cove-vm", virt_get_cove_vm, + virt_set_cove_vm); + object_class_property_set_description(oc, "cove-vm", + "Enable CoVE confidential VM"); } =20 static const TypeInfo virt_machine_typeinfo =3D { diff --git a/include/hw/riscv/cove.h b/include/hw/riscv/cove.h new file mode 100644 index 0000000000..0b29a00786 --- /dev/null +++ b/include/hw/riscv/cove.h @@ -0,0 +1,24 @@ +/* + * RISC-V Confidential VM Extension (CoVE) + * + * Copyright (c) 2026 Alibaba Group + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#ifndef HW_RISCV_COVE_H +#define HW_RISCV_COVE_H + +/* + * A CoVE guest is a TEE VM (TVM) whose memory and vCPU state are owned by + * the TEE Security Manager (TSM) instead of the host. Subsystems outside = of + * hw/riscv/ have to behave differently for such a guest, so the state is + * kept in target independent code. + * + * riscv_cove_vm_set_active() is called by the machine that implements CoVE + * while its properties are parsed, before any device is created. + */ +bool riscv_cove_vm_active(void); +void riscv_cove_vm_set_active(bool active); + +#endif /* HW_RISCV_COVE_H */ diff --git a/include/hw/riscv/virt.h b/include/hw/riscv/virt.h index 36a2def410..99e073ef9a 100644 --- a/include/hw/riscv/virt.h +++ b/include/hw/riscv/virt.h @@ -60,6 +60,7 @@ struct RISCVVirtState { char *oem_id; char *oem_table_id; OnOffAuto acpi; + bool cove_vm; const MemMapEntry *memmap; struct GPEXHost *gpex_host; OnOffAuto iommu_sys; --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477559; cv=none; d=zohomail.com; s=zohoarc; b=E53SXUKt/wFKwcifBPtiMmzZ/czkmRtnpybV6li0WmPmzTP2kBRQOsPIMi0YSHnvBHGDNcrU1vlsiPnvKA7J2+G36Deb9U1fFiN8TYj23mBxXaz3flSKdZGn1ntWm4P70Z361pKY6Rjd3n+GwoK6fKxMJ0YW5f+PSJcjCwNqUtU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477559; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ZI+3bdJq7tVDDsPgbwtKOM++Fn1hHx+vxSYYlZlVEQg=; b=WoL07IxSwDMhhlMsb4K440QnGKMUaWZeq6pyjfeJ3HdZvd09ccRS0oJUP7/uf7ww+JJoywkNGGU0MS8m6WPiA0L1EHWz0cTWzFRenvl4GF7O7U+1Nq6Lq5FuRcch6bVLX/slKpp4bLHfVK2ALW5F3h8OanYFFl1v6TdRhmb/T5c= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477558956466.37234292481673; Thu, 30 Jul 2026 22:59:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFn-0002kq-AS; Fri, 31 Jul 2026 01:57:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM8-0005u8-TL; Thu, 30 Jul 2026 23:56:20 -0400 Received: from [115.124.30.130] (helo=out30-130.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM0-0002Hz-7n; Thu, 30 Jul 2026 23:56:20 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwRP_1785469846 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:48 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470160; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=ZI+3bdJq7tVDDsPgbwtKOM++Fn1hHx+vxSYYlZlVEQg=; b=cFnjnZXyEq5OFc/dPDHWkkAZFWoxgOYbgLDYxFBWuuLfqvJJLHNPjcOwY2Yq5peCRqnzgoBte4K1fASIZp7EfZNmNwsc/yUfDAbNFGZxWPEYHro+ZjtLjPrh/K5Ldhhgsvn9K65Su+L0kRUWmdXkhdmsUlU5n27zPdIERaS+qUU= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R131e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033032089153; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwRP_1785469846; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 03/17] target/riscv/kvm: create and measure a CoVE TEE VM Date: Fri, 31 Jul 2026 11:49:57 +0800 Message-Id: <20260731035011.4178103-4-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.130 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.130; envelope-from=blduan@linux.alibaba.com; helo=out30-130.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477561582158500 Content-Type: text/plain; charset="utf-8" Ask KVM for a TEE VM (TVM) instead of a regular guest when the machine runs in CoVE mode, and add kvm_riscv_cove_measure_region() to add a memory region to the initial measurement of that TVM. The measurement is what allows a CoVE guest to be attested later on, so failing to add a region to it is fatal. The KVM ABI this relies on is not part of an upstream Linux release yet, so KVM_VM_TYPE_RISCV_COVE and KVM_RISCV_COVE_MEASURE_REGION are defined here rather than imported into linux-headers/. They have to be replaced by a regular scripts/update-linux-headers.sh run once the kernel side has been merged. Signed-off-by: Baolong Duan --- target/riscv/kvm/kvm-cpu.c | 46 ++++++++++++++++++++++++++++++++++++ target/riscv/kvm/kvm_riscv.h | 10 ++++++++ 2 files changed, 56 insertions(+) diff --git a/target/riscv/kvm/kvm-cpu.c b/target/riscv/kvm/kvm-cpu.c index 495cb42dc8..67c99d68ce 100644 --- a/target/riscv/kvm/kvm-cpu.c +++ b/target/riscv/kvm/kvm-cpu.c @@ -48,10 +48,27 @@ #include "migration/misc.h" #include "system/runstate.h" #include "hw/riscv/numa.h" +#include "hw/riscv/cove.h" =20 #define PR_RISCV_V_SET_CONTROL 69 #define PR_RISCV_V_VSTATE_CTRL_ON 2 =20 +/* + * CoVE KVM ABI. These definitions are not part of an upstream Linux rele= ase + * yet, so they cannot be imported into linux-headers/ and are kept here u= ntil + * the kernel side has been merged. + */ +#define KVM_VM_TYPE_RISCV_COVE (1UL << 9) + +struct kvm_riscv_cove_measure_region { + uint64_t user_addr; + uint64_t gpa; + uint64_t size; +}; + +#define KVM_RISCV_COVE_MEASURE_REGION \ + _IOR(KVMIO, 0xb5, struct kvm_riscv_cove_measure_region) + void riscv_kvm_aplic_request(void *opaque, int irq, int level) { kvm_set_irq(kvm_state, irq, !!level); @@ -1549,6 +1566,9 @@ int kvm_arch_add_msi_route_post(struct kvm_irq_routin= g_entry *route, =20 int kvm_arch_get_default_type(MachineState *ms) { + if (riscv_cove_vm_active()) { + return KVM_VM_TYPE_RISCV_COVE; + } return 0; } =20 @@ -1829,6 +1849,32 @@ void kvm_arch_accel_class_init(ObjectClass *oc) "auto"); } =20 +/* + * Add the contents of a memory region to the initial measurement of the T= VM. + * Nothing is measured for a guest that is not confidential. + */ +void kvm_riscv_cove_measure_region(uint64_t user_addr, uint64_t gpa, + uint64_t size) +{ + struct kvm_riscv_cove_measure_region mr; + int ret; + + if (!riscv_cove_vm_active()) { + return; + } + + mr.user_addr =3D user_addr; + mr.gpa =3D gpa; + mr.size =3D size; + + ret =3D kvm_vm_ioctl(kvm_state, KVM_RISCV_COVE_MEASURE_REGION, &mr); + if (ret < 0) { + error_report("Unable to measure CoVE region at 0x%" PRIx64 ": %s", + gpa, strerror(-ret)); + exit(EXIT_FAILURE); + } +} + void kvm_riscv_aia_create(MachineState *machine, uint64_t group_shift, uint64_t aia_irq_num, uint64_t aia_msi_num, uint64_t aplic_base, uint64_t imsic_base, diff --git a/target/riscv/kvm/kvm_riscv.h b/target/riscv/kvm/kvm_riscv.h index b2bcd1041f..cd45f1266b 100644 --- a/target/riscv/kvm/kvm_riscv.h +++ b/target/riscv/kvm/kvm_riscv.h @@ -23,6 +23,16 @@ =20 void kvm_riscv_reset_vcpu(RISCVCPU *cpu); void kvm_riscv_set_irq(RISCVCPU *cpu, int irq, int level); +#ifdef CONFIG_KVM +void kvm_riscv_cove_measure_region(uint64_t user_addr, uint64_t gpa, + uint64_t size); +#else +static inline void kvm_riscv_cove_measure_region(uint64_t user_addr, + uint64_t gpa, uint64_t si= ze) +{ + /* A CoVE guest cannot be created without KVM, nothing to measure. */ +} +#endif void kvm_riscv_aia_create(MachineState *machine, uint64_t group_shift, uint64_t aia_irq_num, uint64_t aia_msi_num, uint64_t aplic_base, uint64_t imsic_base, --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477499; cv=none; d=zohomail.com; s=zohoarc; b=Y1SRv6z62+B4T2RtZ9BAQ8VS4JWII6GTETXIBilm0/sL38xiUze4iARfU7sYQ10KZgaqXq1+A6AzPgLKEmsn67P0jb0pRX4bxRBZ4vOxpGNUcG4DaSuvkfm6CNbruhLopvgtnW1AS3yKpGggXAK0FLKwddD9N0ktebJVPFnuR98= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477499; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=15tpbU1mysjnRBqCkIU57nhoO42MnKRFA/va3zirTrU=; b=Wp/H4OYi26NWRS6EWXivTz2JTef8sIr4G8Fhk/QivNPSOTU5pKPuJvYHMW3FzkDPg4CmbFCIQkD9QgB5Bhz666yjaVaqQh0CQatCnoSnEdmZ5Pl3UozlMIpg4agtJCudVB/5yN/R2htcq3cY9owmVfK31bOyI9tSOxnawVKGzVk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477499204576.7783501517163; Thu, 30 Jul 2026 22:58:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFe-0002hJ-Os; Fri, 31 Jul 2026 01:57:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM5-0005rD-T3; Thu, 30 Jul 2026 23:56:18 -0400 Received: from [115.124.30.110] (helo=out30-110.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM0-0002Hx-Dm; Thu, 30 Jul 2026 23:56:17 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwRu_1785469848 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:49 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470160; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=15tpbU1mysjnRBqCkIU57nhoO42MnKRFA/va3zirTrU=; b=VSmTtRMZvWR9SdOeFy5R0kDUZFi64Kkk3gbRKjnmVWmDlm5aXmbwzn2Jsn4xTNJ7boVb0cr3E5OTr6KGxH479L7cl0dvQ+kTOCGPi1I9jMzXGWPhaIQFDVVJgSast0g38EFZpJ4k3MwM6dTbrjxN0JiTThqxHwRxv3PrFK+8SaI= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R131e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045133197; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwRu_1785469848; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 04/17] accel/kvm: add kvm_gpa_to_userspace_addr() Date: Fri, 31 Jul 2026 11:49:58 +0800 Message-Id: <20260731035011.4178103-5-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.110 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.110; envelope-from=blduan@linux.alibaba.com; helo=out30-110.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:32 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477501276158500 Content-Type: text/plain; charset="utf-8" Translate a guest physical address into the host userspace address backing it by walking the memory slots of the accelerator. The RISC-V CoVE code needs this to tell the TSM which host memory holds the guest images that have to be measured. Signed-off-by: Baolong Duan --- accel/kvm/kvm-all.c | 21 +++++++++++++++++++++ include/system/kvm.h | 18 ++++++++++++++++++ 2 files changed, 39 insertions(+) diff --git a/accel/kvm/kvm-all.c b/accel/kvm/kvm-all.c index 83cbd120a8..005abb1c54 100644 --- a/accel/kvm/kvm-all.c +++ b/accel/kvm/kvm-all.c @@ -366,6 +366,27 @@ int kvm_physical_memory_addr_from_host(KVMState *s, vo= id *ram, return ret; } =20 +void *kvm_gpa_to_userspace_addr(KVMState *s, hwaddr gpa) +{ + KVMMemoryListener *kml =3D &s->memory_listener; + void *result =3D NULL; + int i; + KVMSlot *mem; + + kvm_slots_lock(); + for (i =3D 0; i < kml->nr_slots_allocated; i++) { + mem =3D &kml->slots[i]; + if (gpa >=3D mem->start_addr && + gpa < mem->start_addr + mem->memory_size) { + result =3D mem->ram + (gpa - mem->start_addr); + break; + } + } + kvm_slots_unlock(); + + return result; +} + static int kvm_set_user_memory_region(KVMMemoryListener *kml, KVMSlot *slo= t, bool new) { KVMState *s =3D kvm_state; diff --git a/include/system/kvm.h b/include/system/kvm.h index 714b8c7b01..67a0b9f7ac 100644 --- a/include/system/kvm.h +++ b/include/system/kvm.h @@ -454,6 +454,24 @@ void kvm_set_sigmask_len(KVMState *s, unsigned int sig= mask_len); int kvm_physical_memory_addr_from_host(KVMState *s, void *ram_addr, hwaddr *phys_addr); =20 +/** + * kvm_gpa_to_userspace_addr: + * @s: #KVMState + * @gpa: guest physical address + * + * Returns the host userspace address @gpa is backed by, or NULL if @gpa is + * not covered by any memory slot. + */ +#ifdef CONFIG_KVM +void *kvm_gpa_to_userspace_addr(KVMState *s, hwaddr gpa); +#else +static inline void *kvm_gpa_to_userspace_addr(KVMState *s, hwaddr gpa) +{ + /* Without KVM there are no memory slots to look up. */ + return NULL; +} +#endif + #endif /* COMPILING_PER_TARGET */ =20 bool kvm_arch_supports_vmfd_change(void); --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477666; cv=none; d=zohomail.com; s=zohoarc; b=ad2ld+L8wJW9szyViBSe9kIgbZGXf7/ZJ0nJhxWb8zp6Felw/Lm1iFgSziIo8N/2cVJOw4N/Qp9Auovb0xMx0+T1MdLqnqo0haG8UTfvBCeGdli2/7m+23KpXpdgqh3fSh6l68qrW7H4Q53ZbrapSm3m2xwngY5Fq+LAsz9DVsg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477666; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=zT65bYWPtx05OTO3AKdQnA1RvR6F8IODJEuPlw9LxxA=; b=Zibt3qgFuy9M6ZHi6BkYMWlCd6LTnkIxzO82fIMfMqDHmH3fuOgBD2SoTSj30QFTAEYdMy0qrcbCiswjT7g0iyPjiQDo9OQZ4wvoyh41CRC7C+pszKO5S39OIlBKb3XBkkahXQFvMmpELvvVYwh0pHaPrh89b5BcAjNEiOq3h9A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477666129214.78593437094958; Thu, 30 Jul 2026 23:01:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFn-0002l7-Jn; Fri, 31 Jul 2026 01:57:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM7-0005u3-T3; Thu, 30 Jul 2026 23:56:19 -0400 Received: from [115.124.30.133] (helo=out30-133.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM0-0002IQ-DO; Thu, 30 Jul 2026 23:56:19 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwSN_1785469850 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:51 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470165; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=zT65bYWPtx05OTO3AKdQnA1RvR6F8IODJEuPlw9LxxA=; b=Cr1naZdjlfc4iLTPAqJxPybu1NIXLJLjh0GUUuaJhNsXsD2XeVaRlRlMS+PGgg76tLt9UFZ6xwCT5lLQ38W8T+dKUENIMrWSUGVF3U50m6QJlWHxyNqSc7NHY9E59sERhJYYP7GHaEKwkVMLgW9AYyJ5upmFBq0H29YDZjyk4tc= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R731e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037009110; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwSN_1785469850; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 05/17] hw/riscv/boot: load and measure the images of a CoVE guest Date: Fri, 31 Jul 2026 11:49:59 +0800 Message-Id: <20260731035011.4178103-6-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.133 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.133; envelope-from=blduan@linux.alibaba.com; helo=out30-133.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477668243158500 Content-Type: text/plain; charset="utf-8" The kernel and the initrd of a CoVE guest are part of the initial measurement of the TEE VM, which means they have to be written to guest memory and measured before the guest is started. Add riscv_cove_load_kernel(), which handles ELF, uImage and raw images, and measure the initrd as well when one is given. The host address of a loaded image is derived from the RAM memory region because the memory slots of a TVM cannot be used for that this early during machine initialisation. Signed-off-by: Baolong Duan --- hw/riscv/boot.c | 91 +++++++++++++++++++++++++++++++++++++++++++ hw/riscv/trace-events | 4 ++ 2 files changed, 95 insertions(+) diff --git a/hw/riscv/boot.c b/hw/riscv/boot.c index 5e2dfa091a..70c4009a66 100644 --- a/hw/riscv/boot.c +++ b/hw/riscv/boot.c @@ -27,11 +27,14 @@ #include "hw/core/loader.h" #include "hw/riscv/boot.h" #include "hw/riscv/boot_opensbi.h" +#include "hw/riscv/cove.h" +#include "kvm/kvm_riscv.h" #include "elf.h" #include "system/device_tree.h" #include "system/qtest.h" #include "system/kvm.h" #include "system/reset.h" +#include "trace.h" =20 #include =20 @@ -261,6 +264,86 @@ static void riscv_load_initrd(MachineState *machine, R= ISCVBootInfo *info) qemu_fdt_setprop_u64(fdt, "/chosen", "linux,initrd-start", start); qemu_fdt_setprop_u64(fdt, "/chosen", "linux,initrd-end", end); } + + /* The initrd is part of the initial measurement of a CoVE guest. */ + if (riscv_cove_vm_active()) { + void *initrd_host =3D kvm_gpa_to_userspace_addr(kvm_state, start); + uint64_t aligned_size =3D ROUND_UP(size, 4 * KiB); + + trace_riscv_cove_measure_initrd(start, aligned_size); + kvm_riscv_cove_measure_region((uint64_t)(uintptr_t)initrd_host, + start, aligned_size); + } +} + +/* Load address of a raw kernel image, relative to the base of the RAM. */ +#define RISCV_COVE_KERNEL_OFFSET 0x200000 + +/* + * Load the kernel of a CoVE guest and add it to the initial measurement of + * the TVM. ELF, uImage and raw images are supported. + * + * Unlike riscv_load_kernel(), the host address of the loaded image has to= be + * computed from the RAM memory region: the KVM memory slots of a TVM are = not + * usable for that yet at this point of the machine initialisation. + * + * Returns the guest physical address to start the guest from. + */ +static uint64_t riscv_cove_load_kernel(MachineState *machine, + const char *kernel_filename, + uint64_t mem_size, + symbol_fn_t sym_cb) +{ + MemoryRegion *ram =3D machine->ram; + void *ram_base =3D memory_region_get_ram_ptr(ram); + uint64_t elf_entry, elf_low, elf_high; + hwaddr uimage_ep, uimage_loadaddr; + hwaddr kernel_gpa; + ssize_t size; + + size =3D load_elf_ram_sym(kernel_filename, NULL, NULL, NULL, + &elf_entry, &elf_low, &elf_high, + NULL, 0, EM_RISCV, 1, 0, + NULL, false, sym_cb); + if (size > 0) { + trace_riscv_cove_measure_kernel("ELF", elf_low, elf_high - elf_low= ); + kvm_riscv_cove_measure_region((uint64_t)(uintptr_t)ram_base + + (elf_low - ram->addr), + elf_low, elf_high - elf_low); + return elf_entry; + } + + uimage_loadaddr =3D LOAD_UIMAGE_LOADADDR_INVALID; + size =3D load_uimage_as(kernel_filename, &uimage_ep, &uimage_loadaddr, + NULL, NULL, NULL, NULL); + if (size > 0) { + trace_riscv_cove_measure_kernel("uImage", uimage_loadaddr, size); + kvm_riscv_cove_measure_region((uint64_t)(uintptr_t)ram_base + + (uimage_loadaddr - ram->addr), + uimage_loadaddr, size); + return uimage_ep; + } + + /* + * Read the image straight into RAM: load_image_targphys_as() would + * register a ROM blob, whose contents are only written to guest memory + * when the machine is reset, long after the measurement has been take= n. + */ + kernel_gpa =3D ram->addr + RISCV_COVE_KERNEL_OFFSET; + size =3D load_image_size(kernel_filename, + (char *)ram_base + RISCV_COVE_KERNEL_OFFSET, + mem_size - RISCV_COVE_KERNEL_OFFSET); + if (size < 0) { + error_report("could not load kernel '%s': %s", kernel_filename, + strerror(errno)); + exit(1); + } + + trace_riscv_cove_measure_kernel("raw", kernel_gpa, size); + kvm_riscv_cove_measure_region((uint64_t)(uintptr_t)ram_base + + RISCV_COVE_KERNEL_OFFSET, + kernel_gpa, size); + return kernel_gpa; } =20 void riscv_load_kernel(MachineState *machine, @@ -276,6 +359,14 @@ void riscv_load_kernel(MachineState *machine, =20 g_assert(kernel_filename !=3D NULL); =20 + /* A CoVE guest is loaded and measured before the TVM is finalised. */ + if (riscv_cove_vm_active()) { + info->image_low_addr =3D riscv_cove_load_kernel(machine, kernel_fi= lename, + mem_size, sym_cb); + info->image_high_addr =3D info->image_low_addr; + goto out; + } + /* * NB: Use low address not ELF entry point to ensure that the fw_dynam= ic * behaviour when loading an ELF matches the fw_payload, fw_jump and B= BL diff --git a/hw/riscv/trace-events b/hw/riscv/trace-events index b50b14a654..04f4b90efa 100644 --- a/hw/riscv/trace-events +++ b/hw/riscv/trace-events @@ -24,3 +24,7 @@ riscv_iommu_hpm_incr_ctr(uint64_t cntr_val) "cntr_val 0x%= "PRIx64 riscv_iommu_hpm_iocntinh_cy(bool prev_cy_inh) "prev_cy_inh %d" riscv_iommu_hpm_cycle_write(uint32_t ovf, uint64_t val) "ovf 0x%x val 0x%"= PRIx64 riscv_iommu_hpm_evt_write(uint32_t ctr_idx, uint32_t ovf, uint64_t val) "c= tr_idx 0x%x ovf 0x%x val 0x%"PRIx64 + +# boot.c +riscv_cove_measure_kernel(const char *format, uint64_t gpa, uint64_t size)= "%s kernel gpa 0x%"PRIx64" size 0x%"PRIx64 +riscv_cove_measure_initrd(uint64_t gpa, uint64_t size) "initrd gpa 0x%"PRI= x64" size 0x%"PRIx64 --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477480; cv=none; d=zohomail.com; s=zohoarc; b=kDib4nlD/2pGMVujcAW3ReunTsCc8UPMmWZTnRml2XvMzzMPLKf7/jglRS3AcHhwg/+QuCZfeYDJOgXBcbZslWbdXmvANPoY89DsL/R3Y8PhL2JJupQ150PdB4eVckIhoJK9mEbT2zV4z4dAt/wrLerTbDiXnhAJr3rAQOtbAXc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477480; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/IMVwNB06KOv98G3TbtOzyWq7d49eCbIfTpVOyNYHPw=; b=a0ZYbEQT/WWX6B9fveYonIDX9ngUJFLmfW8Lmsf5eH+/8R+iyadAXEHO8dBbemX0j2nZ/UY7M66gV9L4FsTer/AhvBU1xg0l2xCwBS/bHmybM/QsiAG5irWka/cQ6InljXIDiXDTXAZXR0I8qEj9vvR3+agNBKUo/MliE2T5Hho= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477480407296.8013131421816; Thu, 30 Jul 2026 22:58:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFX-0002XC-Jr; Fri, 31 Jul 2026 01:57:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM7-0005tf-3M; Thu, 30 Jul 2026 23:56:19 -0400 Received: from [115.124.30.118] (helo=out30-118.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM0-0002IC-7N; Thu, 30 Jul 2026 23:56:18 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwSr_1785469851 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:52 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470163; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=/IMVwNB06KOv98G3TbtOzyWq7d49eCbIfTpVOyNYHPw=; b=ryCmZ6O1WKiGXa21BR+DK0MlMzIBQOYM0rw7CxgfPyu68yx9hZ9JXj82GvNEiufy0FnmWnSnLOVmoVH4hTVW+g3zSps00Zn1oW3QuzRS4lz7lK3nZxkpAGEzcN0+OqWwTNyBIT5tP6ASRkDOgGW3ldHcehUnKO/3muZ4wQBjNW0= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R361e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045098064; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwSr_1785469851; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 06/17] hw/riscv/virt: measure the device tree of a CoVE guest Date: Fri, 31 Jul 2026 11:50:00 +0800 Message-Id: <20260731035011.4178103-7-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.118 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.118; envelope-from=blduan@linux.alibaba.com; helo=out30-118.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:32 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477481222158500 Content-Type: text/plain; charset="utf-8" The device tree is the last piece of guest state that has to be part of the initial measurement of a TEE VM. The ROM blob holding it is only written to guest memory when the machine is reset, which is too late, so copy it into RAM and measure it right after its address is known. Signed-off-by: Baolong Duan --- hw/riscv/virt.c | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/hw/riscv/virt.c b/hw/riscv/virt.c index a76587d362..c15d8859ce 100644 --- a/hw/riscv/virt.c +++ b/hw/riscv/virt.c @@ -1277,6 +1277,24 @@ static void virt_machine_done(Notifier *notifier, vo= id *data) machine, &boot_info); riscv_load_fdt(fdt_load_addr, machine->fdt); =20 + /* + * The device tree is part of the initial measurement of a TVM. The ROM + * blobs holding it are not written to guest memory before the machine= is + * reset, so copy it into RAM now to be able to measure it. + */ + if (s->cove_vm) { + void *ram_base =3D memory_region_get_ram_ptr(machine->ram); + hwaddr fdt_offset =3D fdt_load_addr - s->memmap[VIRT_DRAM].base; + void *fdt_host; + + memcpy((char *)ram_base + fdt_offset, machine->fdt, s->fdt_size); + + fdt_host =3D kvm_gpa_to_userspace_addr(kvm_state, fdt_load_addr); + kvm_riscv_cove_measure_region((uint64_t)(uintptr_t)fdt_host, + fdt_load_addr, + ROUND_UP(s->fdt_size, 4 * KiB)); + } + /* load the reset vector */ riscv_setup_rom_reset_vec(machine, &s->soc[0], start_addr, s->memmap[VIRT_MROM].base, --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477630; cv=none; d=zohomail.com; s=zohoarc; b=Tys6D8etQkMTE3ii0sPNcFhZhS9fgMSAUn9n5HHNoUAmJB7LGl2H3I44zH7UFjGaZ81ikfLhwOGiCUlUjaW+bMh1FToYrEJrX+SbdUtuK4xUK5+jbDP7jw4sV1mEjupUSlKbfifwQjxnifOS3emzG5f5Z0cwI5L4XDfJA73HT64= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477630; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=dPDYKHG01bvX3ps8+/geGQfs9dBDTNN+rHrp9+MeVIA=; b=jM3gNldmWKFHWDGALrFgIhugsxrplaVsoJ0E1gAz8xIbjMNKaXwnM8UZ6AcX3kxwQXsKql7PeVhgrH420GtCcf/Supoj99xzsUADIHc+C17v4sNYHrIr2hhowqEqpxM0eim42nrU7UDGD4oh37s/bXRnv+4pmuWRD0vyFbsVlIM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477630563490.60962005823626; Thu, 30 Jul 2026 23:00:30 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFg-0002hZ-56; Fri, 31 Jul 2026 01:57:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM7-0005u1-Oe; Thu, 30 Jul 2026 23:56:19 -0400 Received: from [115.124.30.99] (helo=out30-99.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM0-0002IR-ED; Thu, 30 Jul 2026 23:56:19 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwT7_1785469852 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:53 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470165; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=dPDYKHG01bvX3ps8+/geGQfs9dBDTNN+rHrp9+MeVIA=; b=v8HvEqPna0eE6v/N5DVEfzdNvXhSBdz+EvSiQUtkiBomiNmoVWRAPTccZQTBm6hpaRlcRCCQYrQej9SAvFdqpl6Rjgd8LmxEyMiU548jsePHpYLa4z3SUlb8xge/Ofa4AfrP9n6kBdyYXEaJ4Ou0sNKg+O81kjm14TMiBeWzszY= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R311e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037033178; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwT7_1785469852; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 07/17] hw/riscv: adapt the device tree of a CoVE guest Date: Fri, 31 Jul 2026 11:50:01 +0800 Message-Id: <20260731035011.4178103-8-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.99 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.99; envelope-from=blduan@linux.alibaba.com; helo=out30-99.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:32 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477632009158500 Content-Type: text/plain; charset="utf-8" A CoVE guest has neither wired interrupts nor a virtio-mmio transport, and the TSM does not expose Zicboz to it, so drop the corresponding device tree properties and nodes. The kernel command line has to be added here as well: a CoVE guest does not use the generic riscv_load_kernel() path that normally does it, and the command line has to be in the device tree before it is measured. Signed-off-by: Baolong Duan --- hw/riscv/fdt-common.c | 4 ++- hw/riscv/virt.c | 62 +++++++++++++++++++++++++++++++------------ 2 files changed, 48 insertions(+), 18 deletions(-) diff --git a/hw/riscv/fdt-common.c b/hw/riscv/fdt-common.c index aa143a618b..c065724be4 100644 --- a/hw/riscv/fdt-common.c +++ b/hw/riscv/fdt-common.c @@ -11,6 +11,7 @@ #include "qemu/error-report.h" #include "system/device_tree.h" #include "hw/core/boards.h" +#include "hw/riscv/cove.h" #include "hw/riscv/fdt-common.h" #include "target/riscv/cpu_bits.h" =20 @@ -132,7 +133,8 @@ create_fdt_socket_cpu_internal(void *fdt, char *clust_n= ame, RISCVCPU *cpu_ptr, cpu_ptr->cfg.cbom_blocksize); } =20 - if (cpu_ptr->cfg.ext_zicboz) { + /* The TSM does not expose Zicboz to a CoVE guest. */ + if (cpu_ptr->cfg.ext_zicboz && !riscv_cove_vm_active()) { qemu_fdt_setprop_cell(fdt, cpu_name, "riscv,cboz-block-size", cpu_ptr->cfg.cboz_blocksize); } diff --git a/hw/riscv/virt.c b/hw/riscv/virt.c index c15d8859ce..777859baa2 100644 --- a/hw/riscv/virt.c +++ b/hw/riscv/virt.c @@ -225,12 +225,15 @@ static void create_pcie_irq_map(RISCVVirtState *s, vo= id *fdt, char *nodename, } } =20 - qemu_fdt_setprop(fdt, nodename, "interrupt-map", full_irq_map, - PCI_NUM_PINS * PCI_NUM_PINS * - irq_map_stride * sizeof(uint32_t)); - - qemu_fdt_setprop_cells(fdt, nodename, "interrupt-map-mask", - 0x1800, 0, 0, 0x7); + /* A CoVE guest only supports MSIs, so it has no interrupt map. */ + if (!s->cove_vm) { + qemu_fdt_setprop(fdt, nodename, "interrupt-map", full_irq_map, + PCI_NUM_PINS * PCI_NUM_PINS * + irq_map_stride * sizeof(uint32_t)); + + qemu_fdt_setprop_cells(fdt, nodename, "interrupt-map-mask", + 0x1800, 0, 0, 0x7); + } } =20 static void create_fdt_socket_aclint(RISCVVirtState *s, @@ -697,6 +700,14 @@ static void create_fdt_virtio(RISCVVirtState *s, uint3= 2_t irq_virtio_phandle) MachineState *ms =3D MACHINE(s); hwaddr virtio_base =3D s->memmap[VIRT_VIRTIO].base; =20 + /* + * A CoVE guest has no virtio-mmio transport, its virtio devices are + * attached to the PCIe host bridge instead. + */ + if (s->cove_vm) { + return; + } + for (i =3D 0; i < VIRTIO_COUNT; i++) { g_autofree char *name =3D NULL; uint64_t size =3D s->memmap[VIRT_VIRTIO].size; @@ -819,11 +830,15 @@ static void create_fdt_uart(RISCVVirtState *s, 2, s->memmap[VIRT_UART0].base, 2, s->memmap[VIRT_UART0].size); qemu_fdt_setprop_cell(ms->fdt, name, "clock-frequency", 3686400); - qemu_fdt_setprop_cell(ms->fdt, name, "interrupt-parent", irq_mmio_phan= dle); - if (s->aia_type =3D=3D VIRT_AIA_TYPE_NONE) { - qemu_fdt_setprop_cell(ms->fdt, name, "interrupts", UART0_IRQ); - } else { - qemu_fdt_setprop_cells(ms->fdt, name, "interrupts", UART0_IRQ, 0x4= ); + /* A CoVE guest has no wired interrupts, the UART is polled. */ + if (!s->cove_vm) { + qemu_fdt_setprop_cell(ms->fdt, name, "interrupt-parent", + irq_mmio_phandle); + if (s->aia_type =3D=3D VIRT_AIA_TYPE_NONE) { + qemu_fdt_setprop_cell(ms->fdt, name, "interrupts", UART0_IRQ); + } else { + qemu_fdt_setprop_cells(ms->fdt, name, "interrupts", UART0_IRQ,= 0x4); + } } =20 qemu_fdt_setprop_string(ms->fdt, "/chosen", "stdout-path", name); @@ -844,12 +859,15 @@ static void create_fdt_rtc(RISCVVirtState *s, qemu_fdt_setprop_sized_cells(ms->fdt, name, "reg", 2, s->memmap[VIRT_RTC].base, 2, s->memmap[VIRT_RTC].size); - qemu_fdt_setprop_cell(ms->fdt, name, "interrupt-parent", - irq_mmio_phandle); - if (s->aia_type =3D=3D VIRT_AIA_TYPE_NONE) { - qemu_fdt_setprop_cell(ms->fdt, name, "interrupts", RTC_IRQ); - } else { - qemu_fdt_setprop_cells(ms->fdt, name, "interrupts", RTC_IRQ, 0x4); + /* A CoVE guest has no wired interrupts, the RTC is polled. */ + if (!s->cove_vm) { + qemu_fdt_setprop_cell(ms->fdt, name, "interrupt-parent", + irq_mmio_phandle); + if (s->aia_type =3D=3D VIRT_AIA_TYPE_NONE) { + qemu_fdt_setprop_cell(ms->fdt, name, "interrupts", RTC_IRQ); + } else { + qemu_fdt_setprop_cells(ms->fdt, name, "interrupts", RTC_IRQ, 0= x4); + } } } =20 @@ -1021,6 +1039,16 @@ static void create_fdt(RISCVVirtState *s) =20 qemu_fdt_add_subnode(ms->fdt, "/chosen"); =20 + /* + * The kernel command line of a CoVE guest has to be part of the device + * tree before it is measured, so it cannot be added by the generic + * riscv_load_kernel() path. + */ + if (s->cove_vm && ms->kernel_cmdline && *ms->kernel_cmdline) { + qemu_fdt_setprop_string(ms->fdt, "/chosen", "bootargs", + ms->kernel_cmdline); + } + /* Pass seed to RNG */ qemu_guest_getrandom_nofail(rng_seed, sizeof(rng_seed)); qemu_fdt_setprop(ms->fdt, "/chosen", "rng-seed", --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477483; cv=none; d=zohomail.com; s=zohoarc; b=KfUuMPm9BrDBvq/PK6Ji5Qlj+wULniEYtOX2HXewfy6QebDCyX/vSwoGhbNvEW/i79hVF6EnyPExdaIPW4PtIAa4oOLs1Sp3GJ5MXTjZ61tRBF022vR0M2qn6WvRxwCrNVjJX2cK/ufjAYTR/SVqRFANf0o+Bc1x5on0R/vVZz0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477483; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=pE7LnGD3kxaTjc6naK4cdM+8ju7a+qGPqFIRWrBQppU=; b=ACgC706vFZ7H4krlhkbMhFRo8VcWoK0TwskQ4gZ4i7sGjvXEmQrfK++8Bj9Rq4j1j/bnB/Zu1O+pIP8Zw06ZCTEPvqKS3+qH59NRkl0V72wWU284DEwOCEeFAoKid1dONDDp0tHjbDnIDXyvYdd3IDHfLYc8A9TzwG1oUURrI+c= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477483726798.8512540537471; Thu, 30 Jul 2026 22:58:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFa-0002db-0v; Fri, 31 Jul 2026 01:57:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM7-0005u0-JE; Thu, 30 Jul 2026 23:56:19 -0400 Received: from [115.124.30.111] (helo=out30-111.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM0-0002IS-C5; Thu, 30 Jul 2026 23:56:19 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwTV_1785469853 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:54 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470165; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=pE7LnGD3kxaTjc6naK4cdM+8ju7a+qGPqFIRWrBQppU=; b=HGT3Gpekuf9ZwfmC9PfXb6PqH1bqVTPdEZ04+VlvqoUElcq43VJdkqLhrFsStATY0lMItQd3G32NJzZPE3y4Rno755ufB4MCA+Vmq2yDQ+UM9H4blt92UpyHXVR/oyp3Y+sJTWEaVN2ipia6qLCnyEm50iIe0wPfnksuuEGpcw4= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R151e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045098064; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwTV_1785469853; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 08/17] hw/riscv/virt: use MSIs only for a CoVE guest Date: Fri, 31 Jul 2026 11:50:02 +0800 Message-Id: <20260731035011.4178103-9-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.111 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.111; envelope-from=blduan@linux.alibaba.com; helo=out30-111.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477485056158502 Content-Type: text/plain; charset="utf-8" Interrupts of a CoVE guest can only be delivered as MSIs, so an IMSIC is mandatory: without one PCIe devices have no interrupt source at all and their drivers fail to probe. Select aia=3Daplic-imsic when no AIA mode has been requested. Also stop creating the virtio-mmio transports, which a CoVE guest cannot use; its devices are attached to the PCIe host bridge instead. Signed-off-by: Baolong Duan --- hw/riscv/virt.c | 21 +++++++++++++++++---- 1 file changed, 17 insertions(+), 4 deletions(-) diff --git a/hw/riscv/virt.c b/hw/riscv/virt.c index 777859baa2..dbb82bbd21 100644 --- a/hw/riscv/virt.c +++ b/hw/riscv/virt.c @@ -1373,6 +1373,16 @@ static void virt_machine_init(MachineState *machine) exit(1); } =20 + /* + * A CoVE guest can only receive MSIs, so an IMSIC is mandatory: witho= ut + * it PCIe devices have no interrupt source at all and their drivers f= ail + * to probe. + */ + if (s->cove_vm && s->aia_type =3D=3D VIRT_AIA_TYPE_NONE) { + s->aia_type =3D VIRT_AIA_TYPE_APLIC_IMSIC; + warn_report("CoVE VM: forcing aia=3Daplic-imsic"); + } + /* Initialize sockets */ mmio_irqchip =3D virtio_irqchip =3D pcie_irqchip =3D NULL; for (i =3D 0; i < socket_count; i++) { @@ -1524,10 +1534,13 @@ static void virt_machine_init(MachineState *machine) sifive_test_create(s->memmap[VIRT_TEST].base); =20 /* VirtIO MMIO devices */ - for (i =3D 0; i < VIRTIO_COUNT; i++) { - sysbus_create_simple("virtio-mmio", - s->memmap[VIRT_VIRTIO].base + i * s->memmap[VIRT_VIRTIO].size, - qdev_get_gpio_in(virtio_irqchip, VIRTIO_IRQ + i)); + /* A CoVE guest has no virtio-mmio transport, see create_fdt_virtio().= */ + if (!s->cove_vm) { + for (i =3D 0; i < VIRTIO_COUNT; i++) { + sysbus_create_simple("virtio-mmio", + s->memmap[VIRT_VIRTIO].base + i * s->memmap[VIRT_VIRTIO].s= ize, + qdev_get_gpio_in(virtio_irqchip, VIRTIO_IRQ + i)); + } } =20 gpex_pcie_init(system_memory, pcie_irqchip, s); --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477617; cv=none; d=zohomail.com; s=zohoarc; b=byTbtJjVYA8TFytbaQzE/rwEdugktmxW5co1pjMu1AwH8XvugldKaNh6K19P2lEsEboeJqth/RalDn6aiLWdH8V4bj2rGz17o+RG980xvANyUb7vM7WsEFYCkBgXKKZjex6Ipq8g05kOH0UrPaz3W1X2REKi4W14EUuf8KPdixM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477617; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YaMOXhMK+4204mX9njUvyFccbt16zqb7oJOy5G7LF9Y=; b=PdPOaIgKaSxhYw/F+A+Hq+IVBfLXifgEfBxKrpYBSCzf+RuYqI7e0yFOMKL5aQUi0uDAqTqlN0+TBsPN67dSJ4AK3S1OlwuinZFEz6Cv43Q2lmaZjZTJx65MEUD4CGbX9TLIjLRDIVt40HZPgRmb9WHsL5AJZagysC2JdJd9PrQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477617449262.4615662150293; Thu, 30 Jul 2026 23:00:17 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFa-0002fE-Nw; Fri, 31 Jul 2026 01:57:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM9-0005uu-5R; Thu, 30 Jul 2026 23:56:22 -0400 Received: from [115.124.30.97] (helo=out30-97.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM2-0002Ii-Dc; Thu, 30 Jul 2026 23:56:20 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwTx_1785469855 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:55 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470169; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=YaMOXhMK+4204mX9njUvyFccbt16zqb7oJOy5G7LF9Y=; b=XfVGqfWh1GLmCOQm/3gK3QtXrtgJ9GohamDVTj0bZiXRLuIrF3C+MZXD/7yM40F0M7l3ty82Yb/sNYnNlibnZXDdlXs6NntI7UA28iGb0qDNS4QNdn+BDGEn5CHR4/vQ1tmC7QX57rVEvBes8W9rij9x7Uh8YxurqvQQpLP/Q3M= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R191e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045133197; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwTx_1785469855; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 09/17] hw/intc/riscv_aplic: emulate the APLIC for a CoVE guest Date: Fri, 31 Jul 2026 11:50:03 +0800 Message-Id: <20260731035011.4178103-10-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.97 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.97; envelope-from=blduan@linux.alibaba.com; helo=out30-97.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477617737158501 Content-Type: text/plain; charset="utf-8" KVM does not implement an APLIC for a TEE VM, so emulate it in QEMU while still using the in-kernel IMSIC, exactly like in split irqchip mode. Signed-off-by: Baolong Duan --- hw/intc/riscv_aplic.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/hw/intc/riscv_aplic.c b/hw/intc/riscv_aplic.c index 84606e9f3d..897147c2d5 100644 --- a/hw/intc/riscv_aplic.c +++ b/hw/intc/riscv_aplic.c @@ -36,6 +36,7 @@ #include "kvm/kvm_riscv.h" #include "migration/vmstate.h" #include "trace.h" +#include "hw/riscv/cove.h" =20 #define APLIC_MAX_IDC (1UL << 14) #define APLIC_MAX_SOURCE 1024 @@ -172,6 +173,14 @@ bool riscv_use_emulated_aplic(bool msimode) return true; } =20 + /* + * KVM does not implement an APLIC for a CoVE guest, so emulate it in + * QEMU while still using the in-kernel IMSIC, like in split mode. + */ + if (riscv_cove_vm_active()) { + return true; + } + if (!riscv_is_kvm_aia_aplic_imsic(msimode)) { return true; } --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477602; cv=none; d=zohomail.com; s=zohoarc; b=BHkKMDIrTeZwfWuLFZVRld0uWkZN8JR8kROokd5VpQslX2lvwn2iPBtL0YaJ8Hlr/NXuae1PoKDV8JjDWzpfFtY9W5portK7QTIYa/x/YnfsjV/MgA+pHWLETSWVulFjNYqLa6N/lrOhwkLShQkOiVLnIUUa8wlDsM2UJpuxSK8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477602; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=niXZVhC6dZEmlpUlZukHv4t50+0oDWItTHBANrdas1g=; b=EpHBKF50FjT+JIg4O+aWuYEmvjdDt2Wm2J7QcoQSOqUJaKKp/pFD4CHc8uLYf67lo31Z7OdEhLNM7FWgOTaWwb0OWl1FT4MZO/9tPsbYW32au4dbLO4pDZEqFvvUzNtME4rZhEMn77+khB/iEUGQL10WPmLVRS0hS97+eD46ahQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477602711345.4912603069414; Thu, 30 Jul 2026 23:00:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFY-0002cf-Ud; Fri, 31 Jul 2026 01:57:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM5-0005rE-Sh; Thu, 30 Jul 2026 23:56:18 -0400 Received: from [115.124.30.119] (helo=out30-119.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM0-0002Id-8L; Thu, 30 Jul 2026 23:56:17 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwUT_1785469856 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:57 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470168; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=niXZVhC6dZEmlpUlZukHv4t50+0oDWItTHBANrdas1g=; b=MYBj0xYNxOBLil091XudCcgj/ObhEpeJ38WfYEjWmtApEtYKaVL4c5bnVrrUBRq9KWZQe++Zcr5jys1GZFH986GNk6ieDdkYPUwOuCQkbIfWp3NIhFK5J01LTsMY33iWrfE5iG5leFkh2uAvnqzvahiX8nSiu61zugatf4HmX8M= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R171e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037026112; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwUT_1785469856; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 10/17] target/riscv/kvm: skip unsupported KVM requests for a CoVE guest Date: Fri, 31 Jul 2026 11:50:04 +0800 Message-Id: <20260731035011.4178103-11-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.119 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.119; envelope-from=blduan@linux.alibaba.com; helo=out30-119.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477603577158500 Content-Type: text/plain; charset="utf-8" A TEE VM has no APLIC and no PLIC, and its timer state lives inside the TVM where the host cannot read it. Skip the KVM requests that would fail or return meaningless data: reading the timer back, injecting a wired interrupt, and the APLIC part of the in-kernel AIA setup. Note that kvm_mark_guest_state_protected(), which SEV and TDX use, would cover the vCPU state part of this generically. It is not used here because it also changes the reset and migration paths, which have not been evaluated for CoVE yet. Signed-off-by: Baolong Duan --- target/riscv/kvm/kvm-cpu.c | 21 +++++++++++++++++++-- 1 file changed, 19 insertions(+), 2 deletions(-) diff --git a/target/riscv/kvm/kvm-cpu.c b/target/riscv/kvm/kvm-cpu.c index 67c99d68ce..23c2ae2214 100644 --- a/target/riscv/kvm/kvm-cpu.c +++ b/target/riscv/kvm/kvm-cpu.c @@ -1477,7 +1477,13 @@ static void kvm_riscv_vm_state_change(void *opaque, = bool running, if (running) { kvm_riscv_put_regs_timer(cs); } else { - kvm_riscv_get_regs_timer(cs); + /* + * The timer state of a CoVE guest is kept inside the TVM and cann= ot + * be read back by the host. + */ + if (!riscv_cove_vm_active()) { + kvm_riscv_get_regs_timer(cs); + } } } =20 @@ -1791,6 +1797,14 @@ void kvm_riscv_set_irq(RISCVCPU *cpu, int irq, int l= evel) int ret; unsigned virq =3D level ? KVM_INTERRUPT_SET : KVM_INTERRUPT_UNSET; =20 + /* + * A CoVE guest has neither APLIC nor PLIC, so there is no wired + * interrupt to inject. + */ + if (riscv_cove_vm_active()) { + return; + } + if (irq !=3D IRQ_S_EXT) { perror("kvm riscv set irq !=3D IRQ_S_EXT\n"); abort(); @@ -1924,8 +1938,11 @@ void kvm_riscv_aia_create(MachineState *machine, uin= t64_t group_shift, * This is done by leaving KVM_DEV_RISCV_AIA_CONFIG_SRCS * unset. We can also skip KVM_DEV_RISCV_AIA_ADDR_APLIC * since KVM won't be using it. + * + * The same applies to a CoVE guest: KVM does not implement an + * APLIC for a TVM, only the IMSIC is used. */ - if (!kvm_kernel_irqchip_split()) { + if (!kvm_kernel_irqchip_split() && !riscv_cove_vm_active()) { ret =3D kvm_device_access(aia_fd, KVM_DEV_RISCV_AIA_GRP_CONFIG, KVM_DEV_RISCV_AIA_CONFIG_SRCS, &aia_irq_num, true, NULL); --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477633; cv=none; d=zohomail.com; s=zohoarc; b=FJWVlG7rO3JjiwzIgtOgYXyveWvx2ONOlF/FKIanjYre5Q1xR/S5epiQx+qGdg2J4IcMSy/K549bK6SJTLd1yOXw02WgOX1LbvnxzkUYcfngwmbQEWudDHYIfA0uWJPo54rYvt+O5d1IIWAVysynGve6VsWG+1j945qoqMNTR5M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477633; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=g0QlwMTJgF93LRCAL5WkuhLzxPKgvA6nP6b0CC6j0SM=; b=OWW4gMCRsRO+2vo8FfqTXoVazRWI/cpSWgZ3TlT/bxtB79Nz6tG0pepVfoJeUQ1elkxwnQn/Lx8cc+rmE6CIs2dUnm21psZnOFsh85BiDwBZJPmIxA5Y7Vr6CY2KKJp4U6JSZYSLo8yh/llIgxAIgdaiXlFHoPptOxYJH+ExP8w= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477633215317.53853885391675; Thu, 30 Jul 2026 23:00:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFo-0002lE-0Z; Fri, 31 Jul 2026 01:57:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM7-0005u2-Po; Thu, 30 Jul 2026 23:56:19 -0400 Received: from [115.124.30.112] (helo=out30-112.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM1-0002Il-Td; Thu, 30 Jul 2026 23:56:19 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwUk_1785469857 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:58 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470170; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=g0QlwMTJgF93LRCAL5WkuhLzxPKgvA6nP6b0CC6j0SM=; b=VG9m03NaXvG3afWPmzSYG4tHPtVgWKF1GOFOatLsRY60jNfNu7bT70ivOu1F5lSttg/BsVgHzSrHF5pBicdPoIcpm6UQMPTqt2/0CLZmpu5IXkjZwo6tX9DU7WXotqVYoG7ct9HXtivcdkUontHaW3GkLcxemfcppzz0Rx+mOa8= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R451e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045098064; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwUk_1785469857; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 11/17] hw/virtio: force modern virtio for a CoVE guest Date: Fri, 31 Jul 2026 11:50:05 +0800 Message-Id: <20260731035011.4178103-12-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.112 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.112; envelope-from=blduan@linux.alibaba.com; helo=out30-112.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:34 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477633862158500 Content-Type: text/plain; charset="utf-8" Devices have no direct access to the memory of a CoVE guest, so DMA has to be bounced through buffers that the guest shares explicitly. Offer VIRTIO_F_ACCESS_PLATFORM unconditionally, together with VIRTIO_F_VERSION_1 which Linux requires whenever ACCESS_PLATFORM is offered. Such a device therefore always negotiates in modern mode, so the legacy IOMMU_PLATFORM check in virtio-pci does not apply to it either. Signed-off-by: Baolong Duan --- hw/virtio/virtio-bus.c | 12 ++++++++++++ hw/virtio/virtio-pci.c | 9 ++++++++- 2 files changed, 20 insertions(+), 1 deletion(-) diff --git a/hw/virtio/virtio-bus.c b/hw/virtio/virtio-bus.c index 9b545acda3..2e2917236f 100644 --- a/hw/virtio/virtio-bus.c +++ b/hw/virtio/virtio-bus.c @@ -29,6 +29,7 @@ #include "hw/virtio/virtio-bus.h" #include "hw/virtio/virtio.h" #include "system/address-spaces.h" +#include "hw/riscv/cove.h" =20 /* #define DEBUG_VIRTIO_BUS */ =20 @@ -75,6 +76,17 @@ void virtio_bus_device_plugged(VirtIODevice *vdev, Error= **errp) return; } =20 + /* + * Devices cannot access the memory of a CoVE guest directly, so all D= MA + * has to be bounced through buffers the guest shares explicitly: offer + * VIRTIO_F_ACCESS_PLATFORM unconditionally. VIRTIO_F_VERSION_1 has to= be + * offered as well because Linux refuses ACCESS_PLATFORM without it. + */ + if (riscv_cove_vm_active()) { + vdev->host_features |=3D 1ULL << VIRTIO_F_ACCESS_PLATFORM; + vdev->host_features |=3D 1ULL << VIRTIO_F_VERSION_1; + } + if (klass->device_plugged !=3D NULL) { klass->device_plugged(qbus->parent, &local_err); } diff --git a/hw/virtio/virtio-pci.c b/hw/virtio/virtio-pci.c index 6f5db5fc42..b257d4a09f 100644 --- a/hw/virtio/virtio-pci.c +++ b/hw/virtio/virtio-pci.c @@ -34,6 +34,7 @@ #include "hw/pci/msi.h" #include "hw/pci/msix.h" #include "hw/core/loader.h" +#include "hw/riscv/cove.h" #include "system/accel-irq.h" #include "system/kvm.h" #include "hw/virtio/virtio-pci.h" @@ -2048,7 +2049,13 @@ static void virtio_pci_device_plugged(DeviceState *d= , Error **errp) return; } } - if (virtio_host_has_feature(vdev, VIRTIO_F_IOMMU_PLATFORM)) { + /* + * A CoVE guest always negotiates in modern mode: ACCESS_PLATFORM, + * which shares its feature bit with IOMMU_PLATFORM, is forced + * together with VERSION_1, so this check does not apply. + */ + if (virtio_host_has_feature(vdev, VIRTIO_F_IOMMU_PLATFORM) && + !riscv_cove_vm_active()) { error_setg(errp, "VIRTIO_F_IOMMU_PLATFORM was supported by" " neither legacy nor transitional device"); return; --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477618; cv=none; d=zohomail.com; s=zohoarc; b=CP5guQddJXBTocL+THvXex3uMMR5ZEjhUo0zI53yWV7W/INABGHUx2M/Md0FVVELFKQRlSBMrMGiVWDmY1u+p/da3aFebV/H3E00f7tEMFNP5/iMD2zVEd4w2oipfy/S/p97uvdqQHw4+3jDvXff5zqytKAM4dAb9PiqPHppl2g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477618; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GQ/4VXmOCNFDf0yhmuSdsBqHH33B0VAJ2TNmvzzIRV0=; b=k95IA/ekyln4xm++Clg2uXho9kMCecKI/Jr/AIQfa8a3K/MBk5bnnzDC6hoXMos3vKz1BqKvexG3HIL9buUduvKcyzeFIg8rYRXHmRIFEHdN/a1RrlxQCGY3ZkKj+ep4ghp8L6w/lyErBWNAiEtL0nFooB+zWbas8OlGdtbCfVI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477618036780.130630485909; Thu, 30 Jul 2026 23:00:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFo-0002ll-Hc; Fri, 31 Jul 2026 01:57:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM8-0005u7-SV; Thu, 30 Jul 2026 23:56:20 -0400 Received: from [115.124.30.112] (helo=out30-112.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM4-0002Io-L1; Thu, 30 Jul 2026 23:56:20 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwVB_1785469858 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:50:59 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470171; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=GQ/4VXmOCNFDf0yhmuSdsBqHH33B0VAJ2TNmvzzIRV0=; b=Ks+KPtX+SrBjPJ9epnoi3SwmAasSar4vft7wrOGqOx+wDe+lvplWeAo9ZkQfwxuq2t1K2d+la0dMe+5Jb9wKjcmiEkM8h5SjqR3hEKrJBZBZ7jdi4TYR8C2USnvL7I2cCYWmPdjQCIPuYvQJfkujPWQ0DQP3H9TLMUxO14/TypY= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R171e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033032089153; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwVB_1785469858; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 12/17] hw/net/virtio-net: do not use vhost for a CoVE guest Date: Fri, 31 Jul 2026 11:50:06 +0800 Message-Id: <20260731035011.4178103-13-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.112 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.112; envelope-from=blduan@linux.alibaba.com; helo=out30-112.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477619744158500 Content-Type: text/plain; charset="utf-8" The in-kernel vhost datapath has no access to the memory of a TEE VM, so it cannot be used. Signed-off-by: Baolong Duan --- hw/net/virtio-net.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/hw/net/virtio-net.c b/hw/net/virtio-net.c index 814b99a43d..4f8db1a1aa 100644 --- a/hw/net/virtio-net.c +++ b/hw/net/virtio-net.c @@ -28,6 +28,7 @@ #include "qemu/config-file.h" #include "qobject/qdict.h" #include "hw/virtio/virtio-net.h" +#include "hw/riscv/cove.h" #include "net/vhost_net.h" #include "net/announce.h" #include "hw/virtio/virtio-bus.h" @@ -326,6 +327,14 @@ static void virtio_net_vhost_status(VirtIONet *n, uint= 8_t status) } } =20 + /* + * vhost cannot be used with a CoVE guest: the kernel datapath has= no + * access to the memory of the TVM. + */ + if (riscv_cove_vm_active()) { + return; + } + n->vhost_started =3D 1; r =3D vhost_net_start(vdev, n->nic->ncs, queue_pairs, cvq); if (r < 0) { --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477630; cv=none; d=zohomail.com; s=zohoarc; b=NwqcC8nvYQmABwVyPiHCd8txmF4TdCEsydnqgDr958doZGlNKgajeFAdf4h8dB4huGebtsANPgdapX45ApQAqQi5hAXAgw9g4V8gd8M6QlGJ3aIkmIxf8+Y3bs+d3Azx3+ZDQVfv8P9YQmxU7jHGe2mHxhrETyMjmsKPsvlRhHQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477630; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RAtJ32hEdTI4Y88GDT5CEtSyJ9YBee4mz+bhPMzq8kI=; b=ZzN+Bc+JVHgS/QzS/iA3pLiEftqM8+bhUHbwlqGPdDdrGYGg6nr6BD+17Ly+/3wE0pZcBNv0i+C0bt9rMKNJS3cLWWSDDdjLl9hMZCC1pD1Tx8UA0pljckWlAvOrvqS4UmGydXZ2Lf9Ke94MORb5KOoDQNUSPu24u07NaaBUzsU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477630402682.8377590966875; Thu, 30 Jul 2026 23:00:30 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFo-0002lY-9C; Fri, 31 Jul 2026 01:57:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM9-0005uy-US; Thu, 30 Jul 2026 23:56:22 -0400 Received: from [115.124.30.119] (helo=out30-119.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM7-0002Jc-I0; Thu, 30 Jul 2026 23:56:21 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwVc_1785469860 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:51:01 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470176; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=RAtJ32hEdTI4Y88GDT5CEtSyJ9YBee4mz+bhPMzq8kI=; b=moM1uPHFhELmS8dLk31r1wpX0mFDisxajJ4JoW3eLkO/vRnBEy7gxEgwEEaoN608xPyOFdq+G0zRw8nx3G5drdZb9A9leZfTSTcJrqSwh9UXP2W8Nq33gQJADMgpqmUWwbZLO+whfgtAg38nrlH9aT7HXnxIErj1HsN1GCCWCmk= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R181e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033032089153; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwVc_1785469860; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 13/17] accel/kvm: only register the DRAM slot of a CoVE guest Date: Fri, 31 Jul 2026 11:50:07 +0800 Message-Id: <20260731035011.4178103-14-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.119 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.119; envelope-from=blduan@linux.alibaba.com; helo=out30-119.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477631942158500 Content-Type: text/plain; charset="utf-8" The TSM tracks the confidential region of a TEE VM itself. Registering the remaining memory slots of the machine, such as the mask ROM or the flash, overwrites that region and the guest fails to start. Filtering them by slot number is a workaround rather than a solution: the machine should describe which regions belong to the confidential guest instead. Suggestions on how to express that are very welcome. Signed-off-by: Baolong Duan --- accel/kvm/kvm-all.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/accel/kvm/kvm-all.c b/accel/kvm/kvm-all.c index 005abb1c54..2753bf8b8b 100644 --- a/accel/kvm/kvm-all.c +++ b/accel/kvm/kvm-all.c @@ -26,6 +26,7 @@ #include "qapi/error.h" #include "hw/pci/msi.h" #include "hw/pci/msix.h" +#include "hw/riscv/cove.h" #include "hw/s390x/adapter.h" #include "gdbstub/enums.h" #include "system/kvm_int.h" @@ -393,6 +394,16 @@ static int kvm_set_user_memory_region(KVMMemoryListene= r *kml, KVMSlot *slot, boo struct kvm_userspace_memory_region2 mem =3D {}; int ret; =20 + /* + * Only the DRAM slot is registered with KVM for a CoVE guest: the TSM + * tracks the confidential region of the TVM itself and registering the + * other slots (MROM, flash, ...) would overwrite it. + */ + if (riscv_cove_vm_active() && (slot->slot & 0xffff) !=3D 0 && + slot->memory_size > 0) { + return 0; + } + mem.slot =3D slot->slot | (kml->as_id << 16); mem.guest_phys_addr =3D slot->start_addr; mem.userspace_addr =3D (unsigned long)slot->ram; --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477486; cv=none; d=zohomail.com; s=zohoarc; b=ZzVcLUCaPqK0i4eq2W4WY7zNasCVqPIjXMq4jPnEwSlDj6sOUl5DZJReefe5DXaCX9/CJI4YSjAeh54S7gYGyqzbDJnF4kpKlD3809STu33ly6fZSbsgYI4AFDH6dTss89LGxVmAN1vBpRDEaGxabZ/Yuz7cQXnS+jrl245iLQE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477486; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=q8r2wtLQFHdzEHI/kxOb7YyAqow/IMbUFtZQEKGwFVE=; b=i2UeyykViGem8KfXXcbzL7MMSnSmdsaDpU73/8/o4OA00x8s/s22PDfSkHApMUy/AfJtyzz3r/jjozxUeYmxHRmjcZEy3Y+5h3N6IAYMWL9YliFvSqwzN4auO2fM/eIhe7aPPFMVfRzWDoITOp0MPVLXGeCuEz4JQgPK+mK9bc8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477486218778.6571159588893; Thu, 30 Jul 2026 22:58:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFY-0002br-8d; Fri, 31 Jul 2026 01:57:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM8-0005u6-RZ; Thu, 30 Jul 2026 23:56:20 -0400 Received: from [115.124.30.112] (helo=out30-112.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM5-0002JG-PZ; Thu, 30 Jul 2026 23:56:20 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwW8_1785469861 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:51:02 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470173; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=q8r2wtLQFHdzEHI/kxOb7YyAqow/IMbUFtZQEKGwFVE=; b=Ol8nH/n3vN4nI4VMz42JT2Mv99MqfVCLSwyDX3L/xtZXAZZ9agD/L6pAgwTaVVo+trVS0HZP6c081rHPHdQjzMnWehMXTXpTBU8FdNvBA8eUYgGX1Q3KD79b7rdStPDDO8LL/LahmnO2WtOWYbPgcvA6hXUZPWYlW45jjKDZkrU= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R121e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045098064; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwW8_1785469861; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 14/17] accel/kvm: skip MSI route updates for a CoVE guest Date: Fri, 31 Jul 2026 11:50:08 +0800 Message-Id: <20260731035011.4178103-15-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.112 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.112; envelope-from=blduan@linux.alibaba.com; helo=out30-112.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:34 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477487202158500 Content-Type: text/plain; charset="utf-8" A CoVE guest has no in-kernel APLIC, so there is no MSI route for KVM to update and KVM_SET_GSI_ROUTING fails. This is a workaround: the accelerator should rather be told that GSI routing is unavailable than have CoVE special cased here. Signed-off-by: Baolong Duan --- accel/kvm/kvm-all.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/accel/kvm/kvm-all.c b/accel/kvm/kvm-all.c index 2753bf8b8b..aaaa88bd2b 100644 --- a/accel/kvm/kvm-all.c +++ b/accel/kvm/kvm-all.c @@ -2448,6 +2448,14 @@ int kvm_irqchip_update_msi_route(KVMState *s, int vi= rq, MSIMessage msg, { struct kvm_irq_routing_entry kroute =3D {}; =20 + /* + * A CoVE guest has no in-kernel APLIC, so there is no MSI route for K= VM + * to update. + */ + if (riscv_cove_vm_active()) { + return 0; + } + if (kvm_gsi_direct_mapping()) { return 0; } --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477658; cv=none; d=zohomail.com; s=zohoarc; b=CduKjrI6YB6FF0+9qqZIlDRL88871cK56gu3sPijyvU+OffHF+JibdDqAuMQFmzHZaHgoL/WLHCjmMnl1nhwL6gYC7tqVupEw+rMaa278B73Pqw5CXzIFCo8A0IFU/jqzMA4kPwvNZP9yqLuO9ruJxMqdzxTO6qMwTP2cX4Hwq0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477658; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=62yiwq8K+mIfvMr+HXg569sklzBPLTqpmFcv2kAbwZ0=; b=eAZM7wZKUEEwLSAUpIWCWANj3gzKgEsMEpFJo16mntm5b+mypye8qjBlFYOKNa1ferRGf3TVmKJkGrMHRQ3zJTDw9MnXpj1qSUwAliGg5QPS9ti0x8OyyxSHq2Wmp3ct9fu/hvbwkRP03Ivn8xO0hidM0SJxTulQq88MUVn6CIU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477658397645.5614275408753; Thu, 30 Jul 2026 23:00:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFa-0002df-2n; Fri, 31 Jul 2026 01:57:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeMA-0005v0-Cn; Thu, 30 Jul 2026 23:56:22 -0400 Received: from [115.124.30.111] (helo=out30-111.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM8-0002Jw-FE; Thu, 30 Jul 2026 23:56:22 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwWs_1785469862 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:51:03 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470175; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=62yiwq8K+mIfvMr+HXg569sklzBPLTqpmFcv2kAbwZ0=; b=JfO0xUKkqkQReqcZM2R1p2Tc1iLE02+DjoTNqbSfZcN0/ST8oSbBLmx3r8Vch1Koz+JC3zp5eKCk2NJIvzPufq8j7ePWCF+gVuK55E2CK2ajNzGRFwAdzVUMeKvHS3YrNoUg2DcpsJHktRUJHTHIG2JNeK5OuWdLxEIYMnCceBE= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R181e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037026112; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwWs_1785469862; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 15/17] accel/kvm: pin the vCPU threads of a CoVE guest Date: Fri, 31 Jul 2026 11:50:09 +0800 Message-Id: <20260731035011.4178103-16-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.111 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.111; envelope-from=blduan@linux.alibaba.com; helo=out30-111.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477660094158500 Content-Type: text/plain; charset="utf-8" The TSM binds a TVM vCPU to the hart it first runs on, so the thread running it has to stay on that host CPU. With every host CPU running a pinned vCPU thread the host is then starved, which shows up as RCU stalls, hence the short sleep after each KVM_RUN. Both are workarounds that do not belong in target independent code: thread placement is normally left to the user or to the management layer, and the sleep papers over a host scheduling problem. Guidance on how to express the TSM requirement properly would be appreciated. Signed-off-by: Baolong Duan --- accel/kvm/kvm-accel-ops.c | 16 ++++++++++++++++ accel/kvm/kvm-all.c | 9 +++++++++ 2 files changed, 25 insertions(+) diff --git a/accel/kvm/kvm-accel-ops.c b/accel/kvm/kvm-accel-ops.c index c8e7aa3870..30e1cb181c 100644 --- a/accel/kvm/kvm-accel-ops.c +++ b/accel/kvm/kvm-accel-ops.c @@ -24,6 +24,7 @@ #include "system/cpus.h" #include "qemu/guest-random.h" #include "qapi/error.h" +#include "hw/riscv/cove.h" =20 #include #include "kvm-cpus.h" @@ -43,6 +44,21 @@ static void *kvm_vcpu_thread_fn(void *arg) r =3D kvm_init_vcpu(cpu, &error_fatal); kvm_init_cpu_signals(cpu); =20 + /* + * The TSM binds a TVM vCPU to the hart it first runs on, so pin vCPU N + * to host CPU N before the first KVM_RUN. + */ + if (riscv_cove_vm_active()) { + cpu_set_t cpuset; + + CPU_ZERO(&cpuset); + CPU_SET(cpu->cpu_index, &cpuset); + if (sched_setaffinity(0, sizeof(cpuset), &cpuset) < 0) { + error_report("Unable to pin vCPU %d: %s", cpu->cpu_index, + strerror(errno)); + } + } + /* signal CPU creation */ cpu_thread_signal_created(cpu); qemu_guest_random_seed_thread_part2(cpu->random_seed); diff --git a/accel/kvm/kvm-all.c b/accel/kvm/kvm-all.c index aaaa88bd2b..7b33a9aa3a 100644 --- a/accel/kvm/kvm-all.c +++ b/accel/kvm/kvm-all.c @@ -3510,6 +3510,15 @@ int kvm_cpu_exec(CPUState *cpu) * as true, cpu->exit_request will always read as true. */ =20 + /* + * Yield briefly after each KVM_RUN of a CoVE guest: with one pinn= ed + * vCPU thread per host CPU the host is otherwise starved and repo= rts + * RCU stalls. + */ + if (riscv_cove_vm_active()) { + usleep(100); + } + attrs =3D kvm_arch_post_run(cpu, run); =20 #ifdef KVM_HAVE_MCE_INJECTION --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477632; cv=none; d=zohomail.com; s=zohoarc; b=AmRxxuYLduO9U7o+stqTxUFsBMzX1KI//2YTpTZ1Mciv/eFd06IbeZqclVZRPlybZEzrvycVcLzr09PuG8B1BWqS4llRLSOetNHUKgsaXYJjD/S+0ft2D20Q6VJefEjUa9c7fXFSy/g3Axoq2uwi5WJHxrN9NoKBhBetnONsgOc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477632; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=g1senpRrIBKAyuBFOowp2ZlL3plOZU6OwVUYin/8o/Q=; b=RLhP3N+ucBzIkvUDhGa3OztmMkJKphxbG7vGeVG2jI30SFYiPhiuk/fGd6fPljPBxbUVGpeb5Tv2HeOf6AuViBJ7gO6+7KDDdvt091uAxV28ZmXJUtkg2fjnFeVUr/a3ASQTr+CCw9fclMZ2P7fFtNFBX3OyAwAD1XxY/p8CFP8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477632653936.2988356111354; Thu, 30 Jul 2026 23:00:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFe-0002hL-P6; Fri, 31 Jul 2026 01:57:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeMA-0005v1-EM; Thu, 30 Jul 2026 23:56:22 -0400 Received: from [115.124.30.110] (helo=out30-110.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM8-0002Jd-Mp; Thu, 30 Jul 2026 23:56:22 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwXT_1785469863 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:51:04 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470176; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=g1senpRrIBKAyuBFOowp2ZlL3plOZU6OwVUYin/8o/Q=; b=U6TV8DUNGzMY4fCtIN1BHCZsyDf8bPLDMNrxQhQIcXBTMMp2Xx35fOmIVLd5GXyUUJBe5ALQQUsDAfKpDloFkM+nmoNWBjllAevF0ZX2LYxlEOK6gbSh/oZTUmjS1NqJABQyOrxkMnH1vTHLhNpFu4PV2uHy9am1IaDLUasVA9E= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R701e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033032089153; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwXT_1785469863; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 16/17] accel/kvm: terminate on a system event of a CoVE guest Date: Fri, 31 Jul 2026 11:50:10 +0800 Message-Id: <20260731035011.4178103-17-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.110 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.110; envelope-from=blduan@linux.alibaba.com; helo=out30-110.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477633823158500 Content-Type: text/plain; charset="utf-8" The TSM does not honour a power off request for a TEE VM: the vCPU re-enters KVM_RUN and reports the same system event again, so QEMU never shuts the guest down. Terminate the process instead. This works around a missing piece of the TSM ABI rather than something QEMU should be doing. Signed-off-by: Baolong Duan --- accel/kvm/kvm-all.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/accel/kvm/kvm-all.c b/accel/kvm/kvm-all.c index 7b33a9aa3a..938bbebcd1 100644 --- a/accel/kvm/kvm-all.c +++ b/accel/kvm/kvm-all.c @@ -3613,6 +3613,17 @@ int kvm_cpu_exec(CPUState *cpu) break; case KVM_EXIT_SYSTEM_EVENT: trace_kvm_run_exit_system_event(cpu->cpu_index, run->system_ev= ent.type); + /* + * The TSM does not honour power_off for a TVM: the vCPU would + * re-enter KVM_RUN and report the same event forever, so + * terminate QEMU right away. + */ + if (riscv_cove_vm_active()) { + warn_report("CoVE VM: system event %d, terminating", + run->system_event.type); + exit(run->system_event.type =3D=3D KVM_SYSTEM_EVENT_SHUTDO= WN ? + 0 : 1); + } switch (run->system_event.type) { case KVM_SYSTEM_EVENT_SHUTDOWN: qemu_system_shutdown_request(SHUTDOWN_CAUSE_GUEST_SHUTDOWN= ); --=20 2.34.1 From nobody Mon Sep 28 02:05:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785477680; cv=none; d=zohomail.com; s=zohoarc; b=QHoh9HEta7ZrkYVmY+Dw/fO6QDcvskwgdyTMG0rG0yDvtMONQ3MjggAbNkpOr/MCHOE8J7/b0O1+pjMWk4ma1JY+iFj4NulCLx6ZjNR5QQBiZ2EUcBpZgXT8EhzgIYPMOpcPWfn1g2qdlq+FUXCMxNx8RytZ5pp1evaDz8LS+L0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785477680; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=X/93dqUZJ5vqNdc2k7leoueHxTl13Foc1+GDyPYPhhY=; b=dF4XTFsph7Ff82ED2cLijvUg3ODon+FzmPLdYJKX/rziE8VJlCTJ8EoejhqOrM95STvBuY+clmjuXMMNmIMYwhsuWTVlqJ9ZsEYHG4yFKfF3hqS+FnOrVTNv7cqJMo/sEOQCISnDiT2P6oiIGhWkmh/7MCHH0UlRZXQafCq5xuM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785477680549339.50566974222454; Thu, 30 Jul 2026 23:01:20 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFn-0002lC-QA; Fri, 31 Jul 2026 01:57:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeMA-0005vj-Ok; Thu, 30 Jul 2026 23:56:22 -0400 Received: from [115.124.30.111] (helo=out30-111.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM9-0002Jb-8n; Thu, 30 Jul 2026 23:56:22 -0400 Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwY1_1785469865 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:51:05 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470176; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=X/93dqUZJ5vqNdc2k7leoueHxTl13Foc1+GDyPYPhhY=; b=dj90vlPLGQlvgZ8Fu9ZQXSnmwh7pQknlpmE8Q6UB5cUxY71Gu1zvTrxsJ6Fl7KzxST0naWJGSl4HpPMunachBkICzqLVPtWhmFBaRzcB0hStqc0hEx0ymdrYJ7JZA43mOkr3B4nxYyE3UTMr4NC3jfEVYV+ZTp5oPG96fti+a7s= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R471e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033032089153; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwY1_1785469865; From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 17/17] hw/core/machine-qmp-cmds: shut down a CoVE guest on reset Date: Fri, 31 Jul 2026 11:50:11 +0800 Message-Id: <20260731035011.4178103-18-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.111 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.111; envelope-from=blduan@linux.alibaba.com; helo=out30-111.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785477682257158500 Content-Type: text/plain; charset="utf-8" A TEE VM cannot be reset: the TSM destroys it and the host cannot recreate it with the same measurement, so treat system_reset as a shutdown request. Changing the meaning of a QMP command like this is not acceptable as is. QEMU already has a generic mechanism for guests that cannot be rebuilt, qemu_system_reset_request() checks cpus_are_resettable() together with confidential_guest_can_rebuild_state(), and using it would require CoVE to provide a ConfidentialGuestSupport object. This patch is included to document the limitation and to ask whether that is the direction to take. Signed-off-by: Baolong Duan --- hw/core/machine-qmp-cmds.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/hw/core/machine-qmp-cmds.c b/hw/core/machine-qmp-cmds.c index e62cb4ec88..74a9274ab3 100644 --- a/hw/core/machine-qmp-cmds.c +++ b/hw/core/machine-qmp-cmds.c @@ -12,6 +12,7 @@ #include "hw/core/boards.h" #include "hw/intc/intc.h" #include "hw/mem/memory-device.h" +#include "hw/riscv/cove.h" #include "qapi/error.h" #include "qapi/qapi-builtin-visit.h" #include "qapi/qapi-commands-accelerator.h" @@ -302,6 +303,15 @@ UuidInfo *qmp_query_uuid(Error **errp) =20 void qmp_system_reset(Error **errp) { + /* + * Resetting a CoVE guest destroys the TVM, which cannot be recreated + * from the host, so shut the guest down instead. + */ + if (riscv_cove_vm_active()) { + qemu_system_shutdown_request(SHUTDOWN_CAUSE_HOST_QMP_SYSTEM_RESET); + return; + } + qemu_system_reset_request(SHUTDOWN_CAUSE_HOST_QMP_SYSTEM_RESET); } =20 --=20 2.34.1