[RFC v3 00/24] Add Realm support to QEMU-VMM

Mathieu Poirier posted 24 patches 1 month ago
Failed in applying to current master (apply log)
There is a newer version of this series
docs/interop/firmware.json                 |   5 +-
docs/system/arm/virt.rst                   |   9 +-
docs/system/confidential-guest-support.rst |   1 +
hw/arm/boot.c                              |  70 ++++-
hw/arm/virt.c                              | 142 +++++++--
hw/core/loader.c                           |  15 +
include/hw/arm/boot.h                      |   9 +
include/hw/arm/virt.h                      |   2 +-
include/hw/core/loader.h                   |  17 ++
linux-headers/asm-arm64/kvm.h              |   9 +
linux-headers/linux/kvm.h                  |  12 +-
qapi/qom.json                              |  13 +
target/arm/arm-qmp-cmds.c                  |   1 +
target/arm/cpu.c                           |   5 +
target/arm/cpu.h                           |  10 +
target/arm/cpu64.c                         | 122 ++++++++
target/arm/kvm-rme.c                       | 336 +++++++++++++++++++++
target/arm/kvm-stub.c                      |   9 +
target/arm/kvm.c                           | 202 ++++++++++++-
target/arm/kvm_arm.h                       |  20 ++
target/arm/meson.build                     |   5 +-
21 files changed, 963 insertions(+), 51 deletions(-)
create mode 100644 target/arm/kvm-rme.c
[RFC v3 00/24] Add Realm support to QEMU-VMM
Posted by Mathieu Poirier 1 month ago
This patchset provides minimal functionality to start a Realm VM
from an Arm RME capable host using the following command line:

qemu-system-aarch64 \
 -M confidential-guest-support=rme0,memory-backend=ram0 \
 -object rme-guest,id=rme0,convert-in-place=on \
 -object memory-backend-guest-memfd,id=ram0,size=1G,share=on \
 -cpu host -M virt -enable-kvm -M gic-version=3,its=on -nodefaults ..

It is a refactoring of Jean-Philippe Brucker's initial work dating from a while
back.  It is compatible with Steven Price's v16 revision [1] of his work adding
CCA support to KVM.

This revision is based on Michael Roth's work on guest memfd in-place memory
conversion [2] and as such, the QEMU baseline is different from 'master'.  Other
than modifications to use in-place memory conversion from Lorenzo Pieralisi that
were integrated to patches 04, 08-11, it is identical to V2.   

It was tested on the QEMU SBSA machine.  For convenience, a repository is hosted
here [3], along with the TF-A [4] and RMM [5] for the SBSA machine (compatible
with Steven's v16 patchset).  The Repository for the kernel [6] is available
from Arm.

Instructions to compile and run the entire stack can be found here [7].

Device Assignment is not included.

Thanks,
Mathieu

[1]. https://lore.kernel.org/kvm/20260803134403.80630-1-steven.price@arm.com/
[2]. https://lore.kernel.org/kvm/20260528000416.8161-1-michael.roth@amd.com/
[3]. https://gitlab.com/Linaro/cca-public/qemu/-/tree/upstream-v3?ref_type=heads
[4]. https://gitlab.com/Linaro/cca-public/tf-a/trusted-firmware-a/-/tree/cca/v13?ref_type=heads
[5]. https://gitlab.com/Linaro/cca-public/rmm/-/tree/cca/v16?ref_type=heads
[6]. https://gitlab.arm.com/linux-arm/linux-cca/-/tree/cca-host/v16?ref_type=heads
[7]. https://gitlab.com/Linaro/cca-public/build-instructions

RFC v2: https://lore.kernel.org/kvm/20260728192630.240375-1-mathieu.poirier@linaro.org/
RFC v1: https://lists.gnu.org/archive/html/qemu-devel/2026-07/msg02307.html

Jean-Philippe Brucker (23):
  linux-headers: Add RME related definitions
  target/arm/kvm: Return immediately on error in kvm_arch_init()
  target/arm: Add confidential guest support
  target/arm/kvm: Split kvm_arch_get/put_registers
  target/arm/kvm-rme: Initialize vCPU
  target/arm/kvm: Create scratch Realm VM when requested
  target/arm/kvm: Use kvm_vm_check_extension() where necessary
  hw/core/loader: Add a ROM loader notifier
  target/arm/kvm-rme: Keep track of images loaded in Realm memory
  target/arm/kvm-rme: Populate Realm with runtime images
  target/arm/cpu: Set number of breakpoints and watchpoints in KVM
  target/arm/cpu: Set number of PMU counters in KVM
  target/arm/cpu: Don't read Realm registers
  hw/arm/virt: Set proper conduit method for Realms
  hw/arm/virt: Embed Realm VM type with IPA address space
  hw/arm/virt: Reserve one bit of guest physical address for RME
  hw/arm/virt: Disable DTB randomness for confidential VMs
  hw/arm/virt: Move virt_flash_create() to machvirt_init()
  hw/arm/virt: Use RAM instead of flash for confidential guest firmware
  target/arm/kvm-rme: Add DMA remapping for the shared memory region
  docs/interop/firmware.json: Add arm-rme firmware feature
  hw/arm/boot: Load DTB as is for confidential VMs
  hw/arm/boot: Skip bootloader for confidential guests

Mathieu Poirier (1):
  target/arm/kvm-rme: Add mechanic to initialize realms

 docs/interop/firmware.json                 |   5 +-
 docs/system/arm/virt.rst                   |   9 +-
 docs/system/confidential-guest-support.rst |   1 +
 hw/arm/boot.c                              |  70 ++++-
 hw/arm/virt.c                              | 142 +++++++--
 hw/core/loader.c                           |  15 +
 include/hw/arm/boot.h                      |   9 +
 include/hw/arm/virt.h                      |   2 +-
 include/hw/core/loader.h                   |  17 ++
 linux-headers/asm-arm64/kvm.h              |   9 +
 linux-headers/linux/kvm.h                  |  12 +-
 qapi/qom.json                              |  13 +
 target/arm/arm-qmp-cmds.c                  |   1 +
 target/arm/cpu.c                           |   5 +
 target/arm/cpu.h                           |  10 +
 target/arm/cpu64.c                         | 122 ++++++++
 target/arm/kvm-rme.c                       | 336 +++++++++++++++++++++
 target/arm/kvm-stub.c                      |   9 +
 target/arm/kvm.c                           | 202 ++++++++++++-
 target/arm/kvm_arm.h                       |  20 ++
 target/arm/meson.build                     |   5 +-
 21 files changed, 963 insertions(+), 51 deletions(-)
 create mode 100644 target/arm/kvm-rme.c

-- 
2.43.0
Re: [RFC v3 00/24] Add Realm support to QEMU-VMM
Posted by Daniel P. Berrangé 1 month ago
On Tue, Aug 25, 2026 at 04:00:37PM -0600, Mathieu Poirier wrote:
> This patchset provides minimal functionality to start a Realm VM
> from an Arm RME capable host using the following command line:
> 
> qemu-system-aarch64 \
>  -M confidential-guest-support=rme0,memory-backend=ram0 \
>  -object rme-guest,id=rme0,convert-in-place=on \
>  -object memory-backend-guest-memfd,id=ram0,size=1G,share=on \
>  -cpu host -M virt -enable-kvm -M gic-version=3,its=on -nodefaults ..

This example mentions 'convert-in-place=on', but I don't see that property
implemented in this series. Is the example a mistake or is this from a
further follow-on series yet to come ?


Also as a more general conceptual question, in there going to be any
equiv to SNP's  "hostdata" or TDX's  "mr-config-id", that will let the
guest owner pass in some bytes of data that get included in the
measurement ?  Trustee has mention of "CCA_REALM_PERSONALIZATION_VALUE"
for Arm.  Would that become a property of 'rme-guest' in future work ?


With regards,
Daniel

[1] https://github.com/confidential-containers/trustee/blob/main/kbs/docs/initdata.md
-- 
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|
Re: [RFC v3 00/24] Add Realm support to QEMU-VMM
Posted by Lorenzo Pieralisi 1 month ago
On Thu, Aug 27, 2026 at 02:06:49PM +0100, Daniel P. Berrangé wrote:
> On Tue, Aug 25, 2026 at 04:00:37PM -0600, Mathieu Poirier wrote:
> > This patchset provides minimal functionality to start a Realm VM
> > from an Arm RME capable host using the following command line:
> > 
> > qemu-system-aarch64 \
> >  -M confidential-guest-support=rme0,memory-backend=ram0 \
> >  -object rme-guest,id=rme0,convert-in-place=on \
> >  -object memory-backend-guest-memfd,id=ram0,size=1G,share=on \
> >  -cpu host -M virt -enable-kvm -M gic-version=3,its=on -nodefaults ..
> 
> This example mentions 'convert-in-place=on', but I don't see that property
> implemented in this series. Is the example a mistake or is this from a
> further follow-on series yet to come ?

This series depends on Michael's patchset [0] as Mathieu mentioned in
this cover letter (+ a fixlet that was added in the QEmu repo reported
in this cover letter too that Michael should hopefully squash in in
his series to make it work for CCA and possible other arches).

[1] contains all of the above.

[0] https://lore.kernel.org/kvm/20260528000416.8161-1-michael.roth@amd.com/
[1] https://gitlab.com/Linaro/cca-public/qemu/-/tree/upstream-v3

Thanks,
Lorenzo
Re: [RFC v3 00/24] Add Realm support to QEMU-VMM
Posted by Markus Armbruster 3 weeks, 4 days ago
Mathieu Poirier <mathieu.poirier@linaro.org> writes:

> This patchset provides minimal functionality to start a Realm VM
> from an Arm RME capable host using the following command line:
>
> qemu-system-aarch64 \
>  -M confidential-guest-support=rme0,memory-backend=ram0 \
>  -object rme-guest,id=rme0,convert-in-place=on \
>  -object memory-backend-guest-memfd,id=ram0,size=1G,share=on \
>  -cpu host -M virt -enable-kvm -M gic-version=3,its=on -nodefaults ..
>
> It is a refactoring of Jean-Philippe Brucker's initial work dating from a while
> back.  It is compatible with Steven Price's v16 revision [1] of his work adding
> CCA support to KVM.
>
> This revision is based on Michael Roth's work on guest memfd in-place memory
> conversion [2] and as such, the QEMU baseline is different from 'master'.  Other

Use

    Based-on: <20260528000416.8161-1-michael.roth@amd.com>

to document your base.  This stands out to humans, and is readable by
machines.  Next time :)

> than modifications to use in-place memory conversion from Lorenzo Pieralisi that
> were integrated to patches 04, 08-11, it is identical to V2.   
>
> It was tested on the QEMU SBSA machine.  For convenience, a repository is hosted
> here [3],

Michael's series doesn't apply on master anymore, so I fetched this
branch.  It's based on master as of *May*.  This won't do.  Please rebase.

>           along with the TF-A [4] and RMM [5] for the SBSA machine (compatible
> with Steven's v16 patchset).  The Repository for the kernel [6] is available
> from Arm.
>
> Instructions to compile and run the entire stack can be found here [7].
>
> Device Assignment is not included.
>
> Thanks,
> Mathieu
>
> [1]. https://lore.kernel.org/kvm/20260803134403.80630-1-steven.price@arm.com/
> [2]. https://lore.kernel.org/kvm/20260528000416.8161-1-michael.roth@amd.com/
> [3]. https://gitlab.com/Linaro/cca-public/qemu/-/tree/upstream-v3?ref_type=heads
> [4]. https://gitlab.com/Linaro/cca-public/tf-a/trusted-firmware-a/-/tree/cca/v13?ref_type=heads
> [5]. https://gitlab.com/Linaro/cca-public/rmm/-/tree/cca/v16?ref_type=heads
> [6]. https://gitlab.arm.com/linux-arm/linux-cca/-/tree/cca-host/v16?ref_type=heads
> [7]. https://gitlab.com/Linaro/cca-public/build-instructions
>
> RFC v2: https://lore.kernel.org/kvm/20260728192630.240375-1-mathieu.poirier@linaro.org/
> RFC v1: https://lists.gnu.org/archive/html/qemu-devel/2026-07/msg02307.html
Re: [RFC v3 00/24] Add Realm support to QEMU-VMM
Posted by Mathieu Poirier 3 weeks, 3 days ago
On Tue, Sep 01, 2026 at 03:20:13PM +0200, Markus Armbruster wrote:
> Mathieu Poirier <mathieu.poirier@linaro.org> writes:
> 
> > This patchset provides minimal functionality to start a Realm VM
> > from an Arm RME capable host using the following command line:
> >
> > qemu-system-aarch64 \
> >  -M confidential-guest-support=rme0,memory-backend=ram0 \
> >  -object rme-guest,id=rme0,convert-in-place=on \
> >  -object memory-backend-guest-memfd,id=ram0,size=1G,share=on \
> >  -cpu host -M virt -enable-kvm -M gic-version=3,its=on -nodefaults ..
> >
> > It is a refactoring of Jean-Philippe Brucker's initial work dating from a while
> > back.  It is compatible with Steven Price's v16 revision [1] of his work adding
> > CCA support to KVM.
> >
> > This revision is based on Michael Roth's work on guest memfd in-place memory
> > conversion [2] and as such, the QEMU baseline is different from 'master'.  Other
> 
> Use
> 
>     Based-on: <20260528000416.8161-1-michael.roth@amd.com>
> 
> to document your base.  This stands out to humans, and is readable by
> machines.  Next time :)
> 
> > than modifications to use in-place memory conversion from Lorenzo Pieralisi that
> > were integrated to patches 04, 08-11, it is identical to V2.   
> >
> > It was tested on the QEMU SBSA machine.  For convenience, a repository is hosted
> > here [3],
> 
> Michael's series doesn't apply on master anymore, so I fetched this
> branch.  It's based on master as of *May*.  This won't do.  Please rebase.

This was clearly explained above.  The goal was to provide a patchset that can
be used for testing. I can attempt a rebase but can't guarantee a timeline or
success.

> 
> >           along with the TF-A [4] and RMM [5] for the SBSA machine (compatible
> > with Steven's v16 patchset).  The Repository for the kernel [6] is available
> > from Arm.
> >
> > Instructions to compile and run the entire stack can be found here [7].
> >
> > Device Assignment is not included.
> >
> > Thanks,
> > Mathieu
> >
> > [1]. https://lore.kernel.org/kvm/20260803134403.80630-1-steven.price@arm.com/
> > [2]. https://lore.kernel.org/kvm/20260528000416.8161-1-michael.roth@amd.com/
> > [3]. https://gitlab.com/Linaro/cca-public/qemu/-/tree/upstream-v3?ref_type=heads
> > [4]. https://gitlab.com/Linaro/cca-public/tf-a/trusted-firmware-a/-/tree/cca/v13?ref_type=heads
> > [5]. https://gitlab.com/Linaro/cca-public/rmm/-/tree/cca/v16?ref_type=heads
> > [6]. https://gitlab.arm.com/linux-arm/linux-cca/-/tree/cca-host/v16?ref_type=heads
> > [7]. https://gitlab.com/Linaro/cca-public/build-instructions
> >
> > RFC v2: https://lore.kernel.org/kvm/20260728192630.240375-1-mathieu.poirier@linaro.org/
> > RFC v1: https://lists.gnu.org/archive/html/qemu-devel/2026-07/msg02307.html
> 
>