From nobody Sat Sep 26 20:51:55 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788257439; cv=none; d=zohomail.com; s=zohoarc; b=IZhX2WxeH375mmeqPl99vdTWeWVtboII3ODW3Qnj+2Isyu2YrkT6oknfhclHt8CnmlrYd1ZvljzZCy1VXRTQYLdqKVhjzIoyD2zGEL/q3+PVgMMne7mmcfkHE3lLOaJ4f0UPwsyyN7U86qUbfv/vBVUp36bK6DWjfpIBJB7iWYE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788257439; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Kl+pYHx82Tu2z011P+lU27GwkRv+poRAFFh5UTR7T8c=; b=X+KwYqa0LiflLzL74vOuV+adHgyQNg6U7BKe+irY4yIPhH4vNs7MmcbifMQVC4wXUN9JoO5Us/TSxbAcT6DkKjBUsAsGaaeRoFIPBV+vmbnMlHtcCpShntjqNiwAsJJ2l/L7LUDdqmvhsZlnpMHK25dOMQeMNOf1KD5fvH63j6A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788257439367771.4377894404233; Tue, 1 Sep 2026 03:10:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x1LRA-0002c0-Nv; Tue, 01 Sep 2026 06:09:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x1LR9-0002Y4-3F for qemu-devel@nongnu.org; Tue, 01 Sep 2026 06:09:51 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x1LR6-00010g-VK for qemu-devel@nongnu.org; Tue, 01 Sep 2026 06:09:50 -0400 Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-33-H1CbWuIgN_qbqQM9Tm8Tkg-1; Tue, 01 Sept 2026 06:09:32 -0400 Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-49cced8309bso5684205e9.3 for ; Tue, 01 Sep 2026 03:09:32 -0700 (PDT) Received: from lleonard-thinkpadx1carbongen13.rmtit.csb ([151.29.41.106]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48442d7c1c0sm3941620f8f.32.2026.09.01.03.09.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 03:09:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788257388; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Kl+pYHx82Tu2z011P+lU27GwkRv+poRAFFh5UTR7T8c=; b=ZbYLHzJm+buoh5FfVPqhKYFWTsT64qt9lQ7fUFtZT3yWEfz6cdxu6PYFfidxx9KQX67ilV 647HongB6DOS8O/SjFUPZwsmVTtmZbZ/UuM4IWb0nvC+CVf3ifbbxmWM5KhpGU/pONvcC4 k2Ip2GG28gXh5cZTRxny/QZoJQjBUSA= X-MC-Unique: H1CbWuIgN_qbqQM9Tm8Tkg-1 X-Mimecast-MFC-AGG-ID: H1CbWuIgN_qbqQM9Tm8Tkg_1788257371 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1788257371; x=1788862171; darn=nongnu.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Kl+pYHx82Tu2z011P+lU27GwkRv+poRAFFh5UTR7T8c=; b=BJraqNIK4jPiOWCVpetbU0HejfplFhqpTe2+zgJNEolXTrv909a9u5ocVv+P1iwcpo O5xiBN0NaF7t1Db6B65NgtzKsUNFi1MkfaswfRLKz3XacluRN0l8e3mk+i87+JILD43r Fm6PAfbK47mzMkFxcC2813WgR9NDlBHzG2WabYkEJCjX4M4xtBY99RZE58Wo06U0yAeB 1cXlfF4248qBQaiY2VYq6gsJt1grCtzevQmoV1HEEh2r63bIHLKjjOk3gpHvfXcVA1jk r7rVnRqnHLKiQfXUTpYXOHwDSENxu3AoIHzYDPLl6B8Z4KA6RnYXx/Tm6UrYfKh0m3Vd vTXA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788257371; x=1788862171; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Kl+pYHx82Tu2z011P+lU27GwkRv+poRAFFh5UTR7T8c=; b=dJMWtqyhw+65HHbSh07vbS3XqaMl4mWveysjhwYZd/prwc3P5FSdP5UTip4Ft2vdUQ V6aYiiq3w+HWl0bwcA01QYSZQA68tG9wyJ9Kh4j6wPdCtpwOAM1nOsdP3Q0ljPcLO3Xm rJ84jLIpv5Z76EL7LE9orukclafMUIxXNVfGqZYtLF6HJ6hzo6cpZgDox6/GDOd8C7Iq lQ1HVDFHtsWMbUyoxt7aBuZmFYshbdEw49CjuQukoMUnV+V7RDBJNDPQ7t/ka9861b02 LjApbhu71/F9KUzuNzux7VQJ//q/JT9RCH65a0PjY9x/jGZ3aRhb1xm8sNyHo3NCuC9u b90g== X-Gm-Message-State: AFuF++m6uE/DbcnYLfGiuUXJ2likxKC58T9TRNSbmpY9bPLneS4Fn89J QNT8UXU1f9qXxwr0V5f4ZXYcelMBKRpBtyiV0VzqELkJpd+MrWvss/IiZFYpoq19Ft/p/+lHOLq 0ZlSmLxBBliAT2rNsMGE8a8FArDgxnBhGoJ31Ks6bclZPjX67FkUzb4eG X-Gm-Gg: AR+sD12LYqSZW1Kgd/XaJEYyxMqAuIw9J8hrYtUUMPF0xzgatUqnDFyismZOqp3SmXQ mD1N1/75ngGZ9MQahl/c0xpUgNonR3lYFKiqsrTgNt7B4zDycWGM0MkUhM0CyQPRT+VF9SyusMS oA+9Kiz9JwbHxdoky5rylke88ZLiNCldC9KYze1kRSkA/aX9NBiYBtWi600oZXW1Q2Ibh2fnCJN vj8cYtN1DEYR8y0bRCvlamPHGRVsozbls4b7iC2VgztjDywhSFxPDRZOh4+c13kqjY9OsPoVTCJ myOpbwbfHAy/nUVBtVGqjPK4K3aU5uQzJIVDjdQMfOemwfji46gwCTTqRUrJLCyIsyRCQTPI4R7 a4W1g2IKw66OGLnhLwCZhbAS9pOMf8v96MjJJ/zq0pgMLXvtpmx7hBq8VDHGDOl85TvGs X-Received: by 2002:a05:600c:1c13:b0:49c:df2b:15fc with SMTP id 5b1f17b1804b1-49cdf2b179amr72531125e9.8.1788257370777; Tue, 01 Sep 2026 03:09:30 -0700 (PDT) X-Received: by 2002:a05:600c:1c13:b0:49c:df2b:15fc with SMTP id 5b1f17b1804b1-49cdf2b179amr72529995e9.8.1788257370267; Tue, 01 Sep 2026 03:09:30 -0700 (PDT) From: Luigi Leonardi Date: Tue, 01 Sep 2026 12:09:18 +0200 Subject: [PATCH 1/4] sev: rename set_guest_policy to set_id_block and remove dead policy code MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260901-fix_igvm_policy-v1-1-e93a6cf8c5ac@redhat.com> References: <20260901-fix_igvm_policy-v1-0-e93a6cf8c5ac@redhat.com> In-Reply-To: <20260901-fix_igvm_policy-v1-0-e93a6cf8c5ac@redhat.com> To: qemu-devel@nongnu.org Cc: Gerd Hoffmann , Stefano Garzarella , Ani Sinha , Paolo Bonzini , Zhao Liu , Marcelo Tosatti , kvm@vger.kernel.org, Luigi Leonardi X-Mailer: b4 0.14.3 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=leonardi@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788257440279158500 The guest policy must be provided at guest launch start: LAUNCH_START for SEV/SEV-ES and SNP_LAUNCH_START for SEV-SNP. See the SEV API specification, chapter 3 (Guest Policy), and the SEV-SNP firmware ABI specification, section 4.3 (Guest Policy). The policy parameter in set_guest_policy was never effective: by the time this callback runs, LAUNCH_START has already been issued for both SEV/SEV-ES and SEV-SNP, so writing to kvm_start_conf.policy or sev_guest->policy has no effect. In practice the only thing this callback actually does is set the ID block and ID auth for SNP's LAUNCH_FINISH, so rename it to set_id_block to reflect its real purpose, remove the unused policy parameter, and drop the non-SNP code path which was entirely dead. This is preliminary work: actually forwarding the guest policy to the platform before LAUNCH_START is added in a later commit. Signed-off-by: Luigi Leonardi Reviewed-by: Ani Sinha --- backends/confidential-guest-support.c | 12 ++- backends/igvm.c | 6 +- include/system/confidential-guest-support.h | 28 ++++--- target/i386/sev.c | 118 +++++++++++-------------= ---- 4 files changed, 67 insertions(+), 97 deletions(-) diff --git a/backends/confidential-guest-support.c b/backends/confidential-= guest-support.c index 156dd15e66..a0b36d2da5 100644 --- a/backends/confidential-guest-support.c +++ b/backends/confidential-guest-support.c @@ -38,14 +38,12 @@ static int set_guest_state(hwaddr gpa, uint8_t *ptr, ui= nt64_t len, return -1; } =20 -static int set_guest_policy(ConfidentialGuestPolicyType policy_type, - uint64_t policy, - void *policy_data1, uint32_t policy_data1_size, - void *policy_data2, uint32_t policy_data2_size, - Error **errp) +static int set_id_block(void *id_block, uint32_t id_block_size, + void *id_auth, uint32_t id_auth_size, + Error **errp) { error_setg(errp, - "Setting confidential guest policy is not supported for thi= s platform"); + "Setting ID block is not supported for this platform"); return -1; } =20 @@ -64,7 +62,7 @@ static void confidential_guest_support_class_init(ObjectC= lass *oc, ConfidentialGuestSupportClass *cgsc =3D CONFIDENTIAL_GUEST_SUPPORT_CLA= SS(oc); cgsc->check_support =3D check_support; cgsc->set_guest_state =3D set_guest_state; - cgsc->set_guest_policy =3D set_guest_policy; + cgsc->set_id_block =3D set_id_block; cgsc->get_mem_map_entry =3D get_mem_map_entry; } =20 diff --git a/backends/igvm.c b/backends/igvm.c index 7b7bdc72b7..85de0d54ec 100644 --- a/backends/igvm.c +++ b/backends/igvm.c @@ -968,9 +968,9 @@ static int qigvm_handle_policy(QIgvm *ctx, Error **errp) id_block_len =3D sizeof(struct sev_id_block); id_auth_len =3D sizeof(struct sev_id_authentication); } - return ctx->cgsc->set_guest_policy(GUEST_POLICY_SEV, ctx->sev_poli= cy, - ctx->id_block, id_block_len, - ctx->id_auth, id_auth_len, errp); + + return ctx->cgsc->set_id_block(ctx->id_block, id_block_len, + ctx->id_auth, id_auth_len, errp); } return 0; } diff --git a/include/system/confidential-guest-support.h b/include/system/c= onfidential-guest-support.h index 5dca717308..6d35ddb97a 100644 --- a/include/system/confidential-guest-support.h +++ b/include/system/confidential-guest-support.h @@ -128,21 +128,23 @@ typedef struct ConfidentialGuestSupportClass { uint16_t cpu_index, Error **errp); =20 /* - * Set the guest policy. The policy can be used to configure the - * confidential platform, such as if debug is enabled or not and can c= ontain - * information about expected launch measurements, signed verification= of - * guest configuration and other platform data. - * - * The format of the policy data is specific to each platform. For exa= mple, - * SEV-SNP uses a policy bitfield in the 'policy' argument and provide= s an - * ID block and ID authentication in the 'policy_data' parameters. The= type - * of policy data is identified by the 'policy_type' argument. + * Set the guest policy for the confidential platform. The policy + * configures properties of the guest, such as whether debug is + * enabled. Its format is platform-specific; for SEV/SEV-ES and + * SEV-SNP it is a policy bitfield. Must be called before LAUNCH_START + * so the policy is in effect for launch. */ int (*set_guest_policy)(ConfidentialGuestPolicyType policy_type, - uint64_t policy, - void *policy_data1, uint32_t policy_data1_size, - void *policy_data2, uint32_t policy_data2_size, - Error **errp); + uint64_t policy, Error **errp); + + /* + * Set the SEV-SNP ID block and ID authentication block. These are + * passed to SNP_LAUNCH_FINISH to provide signed verification of the + * guest configuration. + */ + int (*set_id_block)(void *id_block, uint32_t id_block_size, + void *id_auth, uint32_t id_auth_size, + Error **errp); =20 /* * Iterate the system memory map, getting the entry with the given ind= ex diff --git a/target/i386/sev.c b/target/i386/sev.c index 4d875d10ff..465415c535 100644 --- a/target/i386/sev.c +++ b/target/i386/sev.c @@ -2723,10 +2723,9 @@ static int cgs_get_mem_map_entry(int index, return 0; } =20 -static int cgs_set_guest_policy(ConfidentialGuestPolicyType policy_type, - uint64_t policy, void *policy_data1, - uint32_t policy_data1_size, void *policy_d= ata2, - uint32_t policy_data2_size, Error **errp) +static int cgs_set_id_block(void *id_block, uint32_t id_block_size, + void *id_auth, uint32_t id_auth_size, + Error **errp) { SevCommonState *sev_common =3D SEV_COMMON(MACHINE(qdev_get_machine())-= >cgs); if (sev_common->state =3D=3D SEV_STATE_UNINIT) { @@ -2734,86 +2733,57 @@ static int cgs_set_guest_policy(ConfidentialGuestPo= licyType policy_type, return 0; } =20 - if (policy_type !=3D GUEST_POLICY_SEV) { - error_setg(errp, "SEV: Invalid guest policy type provided for SEV:= %d", - policy_type); + if (!sev_snp_enabled()) { + error_setg(errp, "SEV: ID block is only supported for SEV-SNP"); return -1; } - /* - * SEV-SNP handles policy differently. The policy flags are defined in - * kvm_start_conf.policy and an ID block and ID auth can be provided. - */ - if (sev_snp_enabled()) { - SevSnpGuestState *sev_snp_guest =3D - SEV_SNP_GUEST(MACHINE(qdev_get_machine())->cgs); - struct kvm_sev_snp_launch_finish *finish =3D - &sev_snp_guest->kvm_finish_conf; =20 - /* - * The policy consists of flags in 'policy' and optionally an ID b= lock - * and ID auth in policy_data1 and policy_data2 respectively. The = ID - * block and auth are optional so clear any previous ID block and = auth - * and set them if provided, but always set the policy flags. - */ - g_free(sev_snp_guest->id_block); - g_free((guchar *)finish->id_block_uaddr); - g_free(sev_snp_guest->id_auth); - g_free((guchar *)finish->id_auth_uaddr); - sev_snp_guest->id_block =3D NULL; - finish->id_block_uaddr =3D 0; - sev_snp_guest->id_auth =3D NULL; - finish->id_auth_uaddr =3D 0; - - if (policy_data1_size > 0) { - struct sev_snp_id_authentication *id_auth =3D - (struct sev_snp_id_authentication *)policy_data2; - - if (policy_data1_size !=3D KVM_SEV_SNP_ID_BLOCK_SIZE) { - error_setg(errp, "SEV: Invalid SEV-SNP ID block: incorrect= size"); - return -1; - } - if (policy_data2_size !=3D KVM_SEV_SNP_ID_AUTH_SIZE) { - error_setg(errp, - "SEV: Invalid SEV-SNP ID auth block: incorrect = size"); - return -1; - } - assert(policy_data1 !=3D NULL); - assert(policy_data2 !=3D NULL); + SevSnpGuestState *sev_snp_guest =3D + SEV_SNP_GUEST(MACHINE(qdev_get_machine())->cgs); + struct kvm_sev_snp_launch_finish *finish =3D + &sev_snp_guest->kvm_finish_conf; =20 - finish->id_block_uaddr =3D - (__u64)g_memdup2(policy_data1, KVM_SEV_SNP_ID_BLOCK_SIZE); - finish->id_auth_uaddr =3D - (__u64)g_memdup2(policy_data2, KVM_SEV_SNP_ID_AUTH_SIZE); + g_free(sev_snp_guest->id_block); + g_free((guchar *)finish->id_block_uaddr); + g_free(sev_snp_guest->id_auth); + g_free((guchar *)finish->id_auth_uaddr); + sev_snp_guest->id_block =3D NULL; + finish->id_block_uaddr =3D 0; + sev_snp_guest->id_auth =3D NULL; + finish->id_auth_uaddr =3D 0; =20 - /* - * Check if an author key has been provided and use that to fl= ag - * whether the author key is enabled. The first of the author = key - * must be non-zero to indicate the key type, which will curre= ntly - * always be 2. - */ - sev_snp_guest->kvm_finish_conf.auth_key_en =3D - id_auth->author_key[0] ? 1 : 0; - finish->id_block_en =3D 1; - } + if (id_block_size > 0) { + struct sev_snp_id_authentication *auth =3D + (struct sev_snp_id_authentication *)id_auth; =20 - /* do not reset existing policy if policy was not set in IGVM */ - if (policy !=3D 0) { - sev_snp_guest->kvm_start_conf.policy =3D policy; + if (id_block_size !=3D KVM_SEV_SNP_ID_BLOCK_SIZE) { + error_setg(errp, "SEV: Invalid SEV-SNP ID block: incorrect siz= e"); + return -1; } - } else { - SevGuestState *sev_guest =3D SEV_GUEST(MACHINE(qdev_get_machine())= ->cgs); - /* Only the policy flags are supported for SEV and SEV-ES */ - if ((policy_data1_size > 0) || (policy_data2_size > 0) || !sev_gue= st) { - error_setg(errp, "SEV: An ID block/ID auth block has been prov= ided " - "but SEV-SNP is not enabled"); + if (id_auth_size !=3D KVM_SEV_SNP_ID_AUTH_SIZE) { + error_setg(errp, + "SEV: Invalid SEV-SNP ID auth block: incorrect size= "); return -1; } + assert(id_block !=3D NULL); + assert(id_auth !=3D NULL); =20 - /* do not reset existing policy if policy was not set in IGVM */ - if (policy !=3D 0) { - sev_guest->policy =3D policy; - } + finish->id_block_uaddr =3D + (__u64)g_memdup2(id_block, KVM_SEV_SNP_ID_BLOCK_SIZE); + finish->id_auth_uaddr =3D + (__u64)g_memdup2(id_auth, KVM_SEV_SNP_ID_AUTH_SIZE); + + /* + * Check if an author key has been provided and use that to flag + * whether the author key is enabled. The first of the author key + * must be non-zero to indicate the key type, which will currently + * always be 2. + */ + sev_snp_guest->kvm_finish_conf.auth_key_en =3D + auth->author_key[0] ? 1 : 0; + finish->id_block_en =3D 1; } + return 0; } =20 @@ -2878,7 +2848,7 @@ sev_common_instance_init(Object *obj) cgs->check_support =3D cgs_check_support; cgs->set_guest_state =3D cgs_set_guest_state; cgs->get_mem_map_entry =3D cgs_get_mem_map_entry; - cgs->set_guest_policy =3D cgs_set_guest_policy; + cgs->set_id_block =3D cgs_set_id_block; cgs->can_rebuild_guest_state =3D true; =20 QTAILQ_INIT(&sev_common->launch_vmsa); --=20 2.55.0 From nobody Sat Sep 26 20:51:55 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788257442; cv=none; d=zohomail.com; s=zohoarc; b=NVZJC/DtAISA8IgfZWi8AojDdor1egwprw1vD50/rjOciVzoKQcnSMKvfD5U6QZ2e4vh7hOvyPQh7/yhtpVp7dFlj4qMoXeTCGFlkSK2a3lM9rgJWcSFO5kXtERyJXPmYMCrxriRcJUOjk8Z4h+qvgRQ9thyp8AhL4neVgNW4DY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788257442; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Ppz2K1vLw2zwdYGAd4h8De7d1adqi3oztEYlXl9z9H4=; b=clWNc0zWOZdPr7YABpWgPr/X+w1AccklukooLspl3fan+tIjwXDYIAXNkl6/m4bQf9sqxv5cFH+lTrXrdxf2east6cpyXHlLqSxuk6/F7cnTR9DKPhG1jGdsmB7XZz5bmYlhmyIz4sY+zEEVbTwBoXh5dlMZ8u3BQx7Z9IFCuvI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788257442718783.9552428658037; Tue, 1 Sep 2026 03:10:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x1LQy-0002Ut-AP; Tue, 01 Sep 2026 06:09:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x1LQv-0002U9-JB for qemu-devel@nongnu.org; Tue, 01 Sep 2026 06:09:37 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x1LQt-0000vE-8i for qemu-devel@nongnu.org; Tue, 01 Sep 2026 06:09:36 -0400 Received: from mail-wr1-f70.google.com (mail-wr1-f70.google.com [209.85.221.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-163-oohbcMrUN9ejOFrdZzS7RQ-1; Tue, 01 Sept 2026 06:09:33 -0400 Received: by mail-wr1-f70.google.com with SMTP id ffacd0b85a97d-47f2de3ba47so525857f8f.1 for ; Tue, 01 Sep 2026 03:09:32 -0700 (PDT) Received: from lleonard-thinkpadx1carbongen13.rmtit.csb ([151.29.41.106]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48442d7c1c0sm3941620f8f.32.2026.09.01.03.09.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 03:09:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788257374; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Ppz2K1vLw2zwdYGAd4h8De7d1adqi3oztEYlXl9z9H4=; b=Vt7aUfWTYNva/FH06MhLRmkPbIxj1dltDT1Py/xbP6ayLMNeT2WXcJEDE8wpihjQ/mvBpw VjIbV81EcrJukDapCiJTj42/F7h2ROtM4QlaZAYhlKXybc3QKp9/H4JHFQFWKHH29UJdsC gIInxEyXXmtQJvBcEPMhXQnM/WPQdG0= X-MC-Unique: oohbcMrUN9ejOFrdZzS7RQ-1 X-Mimecast-MFC-AGG-ID: oohbcMrUN9ejOFrdZzS7RQ_1788257372 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1788257372; x=1788862172; darn=nongnu.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Ppz2K1vLw2zwdYGAd4h8De7d1adqi3oztEYlXl9z9H4=; b=ozrTvaTohAwfH+NwJkhKHI5yiHdPl1aJnO26u5GT5L15TXRgQZl4Af4o+HZ81CmB5J RQx9aH6G3N4KeUVixJQr646+QCVg/laleEtvzfaXHoVfmTeRpxQXgKBJuxCCALARsKDS vGIQATbvO3Q+j1NBJYz6zQRc0GPEVWAUbbOxZJ1ahBWn1IwNNmzH2V9J2SsYwXUw7dro RtOpnJVvWbetc1v1dq3Mgs0bt6Ar1ITDD2n9qmeBuULCzbIPo6Et35y1bbfTNbGU/2Y+ MTnZwfbIMP0zoR35Rit17/P4Sr6dwNvodcOKBIcHK+m1VbBeFT3U8L85N62omraulLNI 7yog== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788257372; x=1788862172; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Ppz2K1vLw2zwdYGAd4h8De7d1adqi3oztEYlXl9z9H4=; b=Vu4Gmede6ZILikzZBEQhqHAm1wF3vq6Qn7ArvAQEjy4uD5Mtg1jLYj3TKp54Kn6sE0 6zFRq2wAnR8UuJLiat11PLXMOLMzYIIA3WVXAfd7ohbVNpR625NoYSJ5oq1jfDXxSDiY rVyU0VlMBB9pJt10lvxztijPAutCtFKdFKVi+pcslBo/1B/9Y9guFxCC0T/333E3BW6H SU2hg9f8MxCt2kkU52S8eU/8Fw7amEOrissOxy/XatNRpJN22/fj8L0xYnu8jDc/biV8 GCy56lPUy1S8eJ+1fpI3vgragAk05YBbhtD4dvRIJqYPIE9xDXy1D3sJN6IwnseyRmEC ikhA== X-Gm-Message-State: AFuF++nIpdLDrF77cxFx2Ww1i6uIIhp+A3yiu39wpl44AzpWynkT2/R4 v8IWprqxo9O8C6a5ZFnYScc4Ig2j0MUQqH6nj7HmLzGsCyLJQjf9MwqGM7ab80eLWe2P/JLzSP1 Fs1OXPbdux5AI1N18kmcNV7Qt7QWF1lKNA8caiTXKcA1NoePUNT9rIxs7 X-Gm-Gg: AYBFou1wjL6YV+rLDXtaboTpoSSZWyrCCqaukOQeKgBoEy56uM5Eqq8IX1CwRHNYjHH XZTslNezJZyWnBZjGM6sTiGrJAM1CCF/KBHvzjkewH5TowuVNFjwmWwecilxrJWnFzCHlBjvPtd 9aOvtMwAO5jmqIAzZaUMn9LevAGmSPglvhIJdpUFgJqGFOXUeGf2ZOnyRxn2KLbck4B24PGPV3o XObacy7n4v6tf4mr3m+q8/Ps/2czK+m1tSqwCGR2WSi/hNTZozIgRj4SVWWbww6wAbf+Oqa0xiX rWWrNn/NPXsuJFnM5fU3bC2FCV7bnukmPcSvqWbg1jNU+3Ou0D9yQ7X3o6z0eSdSbUf95EN8mHH BpPsIv5eT80aEW14QR0CXXMCHC7VUyklAStiuU+8IpvKFxUfvmV1udb6ohcWuwhtRtpe8 X-Received: by 2002:a05:6000:2510:b0:483:ca4a:6b9d with SMTP id ffacd0b85a97d-483ca4a6d9cmr36047407f8f.20.1788257371810; Tue, 01 Sep 2026 03:09:31 -0700 (PDT) X-Received: by 2002:a05:6000:2510:b0:483:ca4a:6b9d with SMTP id ffacd0b85a97d-483ca4a6d9cmr36047329f8f.20.1788257371394; Tue, 01 Sep 2026 03:09:31 -0700 (PDT) From: Luigi Leonardi Date: Tue, 01 Sep 2026 12:09:19 +0200 Subject: [PATCH 2/4] igvm: move set_id_block call into the SNP ID block directive handler MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260901-fix_igvm_policy-v1-2-e93a6cf8c5ac@redhat.com> References: <20260901-fix_igvm_policy-v1-0-e93a6cf8c5ac@redhat.com> In-Reply-To: <20260901-fix_igvm_policy-v1-0-e93a6cf8c5ac@redhat.com> To: qemu-devel@nongnu.org Cc: Gerd Hoffmann , Stefano Garzarella , Ani Sinha , Paolo Bonzini , Zhao Liu , Marcelo Tosatti , kvm@vger.kernel.org, Luigi Leonardi X-Mailer: b4 0.14.3 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=leonardi@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788257443833154100 set_id_block only makes sense when the IGVM file contains an IGVM_VHT_SNP_ID_BLOCK directive. Move the call from the removed qigvm_handle_policy into qigvm_directive_snp_id_block, where the ID block and ID auth are populated. This avoids a no-op call to set_id_block when no ID block is present. The ID block embeds the guest policy, so the policy must be known by the time the directive is handled. Process the initialization section (which carries the GUEST_POLICY header) before the directive section, and copy ctx->sev_policy into the ID block in the directive handler. Signed-off-by: Luigi Leonardi --- backends/igvm.c | 81 +++++++++++++++++++++++++++--------------------------= ---- 1 file changed, 38 insertions(+), 43 deletions(-) diff --git a/backends/igvm.c b/backends/igvm.c index 85de0d54ec..6545382546 100644 --- a/backends/igvm.c +++ b/backends/igvm.c @@ -778,6 +778,8 @@ static int qigvm_directive_snp_id_block(QIgvm *ctx, con= st uint8_t *header_data, ctx->id_block->version =3D IGVM_SEV_ID_BLOCK_VERSION; memcpy(ctx->id_block->ld, igvm_id->ld, sizeof(ctx->id_block->ld)); =20 + ctx->id_block->policy =3D ctx->sev_policy; + ctx->id_auth->id_key_alg =3D igvm_id->id_key_algorithm; assert(sizeof(igvm_id->id_key_signature) <=3D sizeof(ctx->id_auth->id_block_sig)); @@ -805,6 +807,14 @@ static int qigvm_directive_snp_id_block(QIgvm *ctx, co= nst uint8_t *header_data, memcpy(&ctx->id_auth->author_key[76], &igvm_id->author_public_key.qy, 72); =20 + if (ctx->cgsc) { + return ctx->cgsc->set_id_block(ctx->id_block, + sizeof(struct sev_id_block), + ctx->id_auth, + sizeof(struct sev_id_authentication= ), + errp); + } + return 0; } =20 @@ -958,23 +968,6 @@ static int qigvm_supported_platform_compat_mask(QIgvm = *ctx, Error **errp) return 0; } =20 -static int qigvm_handle_policy(QIgvm *ctx, Error **errp) -{ - if (ctx->platform_type =3D=3D IGVM_PLATFORM_TYPE_SEV_SNP) { - int id_block_len =3D 0; - int id_auth_len =3D 0; - if (ctx->id_block) { - ctx->id_block->policy =3D ctx->sev_policy; - id_block_len =3D sizeof(struct sev_id_block); - id_auth_len =3D sizeof(struct sev_id_authentication); - } - - return ctx->cgsc->set_id_block(ctx->id_block, id_block_len, - ctx->id_auth, id_auth_len, errp); - } - return 0; -} - IgvmHandle qigvm_file_init(char *filename, Error **errp) { IgvmHandle igvm; @@ -1032,6 +1025,34 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *m= achine_state, goto cleanup; } =20 + /* + * Process the initialization section first so that the guest policy is + * known before the directive section is handled. The SNP ID block + * directive embeds the guest policy into the ID block, so the policy = from + * the guest policy initialization header must be available by then. + */ + header_count =3D + igvm_header_count(ctx.cfg->file, IGVM_HEADER_SECTION_INITIALIZATIO= N); + if (header_count < 0) { + error_setg( + errp, + "Invalid initialization header count in IGVM file. Error code:= %X", + header_count); + goto cleanup; + } + + for (ctx.current_header_index =3D 0; + ctx.current_header_index < (unsigned)header_count; + ctx.current_header_index++) { + IgvmVariableHeaderType type =3D + igvm_get_header_type(ctx.cfg->file, + IGVM_HEADER_SECTION_INITIALIZATION, + ctx.current_header_index); + if (qigvm_handler(&ctx, type, errp) < 0) { + goto cleanup; + } + } + header_count =3D igvm_header_count(ctx.cfg->file, IGVM_HEADER_SECTION_DIRECTIVE); if (header_count <=3D 0) { @@ -1065,28 +1086,6 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *m= achine_state, goto cleanup_parameters; } =20 - header_count =3D - igvm_header_count(ctx.cfg->file, IGVM_HEADER_SECTION_INITIALIZATIO= N); - if (header_count < 0) { - error_setg( - errp, - "Invalid initialization header count in IGVM file. Error code:= %X", - header_count); - goto cleanup_parameters; - } - - for (ctx.current_header_index =3D 0; - ctx.current_header_index < (unsigned)header_count; - ctx.current_header_index++) { - IgvmVariableHeaderType type =3D - igvm_get_header_type(ctx.cfg->file, - IGVM_HEADER_SECTION_INITIALIZATION, - ctx.current_header_index); - if (qigvm_handler(&ctx, type, errp) < 0) { - goto cleanup_parameters; - } - } - /* * Contiguous pages of data with compatible flags are grouped together= in * order to reduce the number of memory regions we create. Make sure t= he @@ -1094,10 +1093,6 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *m= achine_state, */ retval =3D qigvm_process_mem_page(&ctx, NULL, errp); =20 - if (retval =3D=3D 0) { - retval =3D qigvm_handle_policy(&ctx, errp); - } - cleanup_parameters: QTAILQ_FOREACH(parameter, &ctx.parameter_data, next) { --=20 2.55.0 From nobody Sat Sep 26 20:51:55 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788257402; cv=none; d=zohomail.com; s=zohoarc; b=ggLcMLfEEuiNnl0Hw9Tvm1pg3Bt1BHFx+BsXnMcNPVEDOfIbRnPTDMGh54QBxNj406ipOJ9ujIu8s/nZoPcK7cLeaJPX1SjKGxQa1FEPJlNZuTHduSZ1+nLG6yUpi4CltAhCJkoeRx5afed164prRnf71zIckE6Gul+dJgFvJSU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788257402; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=QIEprrdH7LZapW8zVSYHVi8VsanTJW2FyNSSrivNz7A=; b=WY0VFa0VEfGdVLJaKgQ++LpsMMJgh/66zRLWBlM8yjzhdEwHq1qzATmtiIKUFq5ethCHZqPujhiVVlkR5V+sH3NQuSj4o0kDKsUmD4R91dxbb//nEO12l09K6Sio3zb+WWfcWzIH12q0cVMKjFTGDGYVtoPk4YaLelGCQRezFsI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788257402776306.13796987338753; Tue, 1 Sep 2026 03:10:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x1LR2-0002WA-DI; Tue, 01 Sep 2026 06:09:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x1LR0-0002Vm-V6 for qemu-devel@nongnu.org; Tue, 01 Sep 2026 06:09:42 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x1LQz-0000xh-AA for qemu-devel@nongnu.org; Tue, 01 Sep 2026 06:09:42 -0400 Received: from mail-wr1-f71.google.com (mail-wr1-f71.google.com [209.85.221.71]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-267-vBmRl-fZO6SVu56GXhhTcw-1; Tue, 01 Sept 2026 06:09:34 -0400 Received: by mail-wr1-f71.google.com with SMTP id ffacd0b85a97d-4843313047eso1735819f8f.1 for ; Tue, 01 Sep 2026 03:09:33 -0700 (PDT) Received: from lleonard-thinkpadx1carbongen13.rmtit.csb ([151.29.41.106]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48442d7c1c0sm3941620f8f.32.2026.09.01.03.09.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 03:09:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788257380; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=QIEprrdH7LZapW8zVSYHVi8VsanTJW2FyNSSrivNz7A=; b=OmsDzJy1DRXBh0da4+OfwS9MaY8JK/CGvuqX5cXxgj/TuKbR6D68lWf5ltzlZ38FQV94aI fp4MVHvAe3NEPxcHypLq4gXniCPl9yIpgOrsWRCnX8MM6w/pn4h+8Q5VeC+8TH2GhgiTTE VQXolCWpoigknpTtTnUa0rxrNbtqN48= X-MC-Unique: vBmRl-fZO6SVu56GXhhTcw-1 X-Mimecast-MFC-AGG-ID: vBmRl-fZO6SVu56GXhhTcw_1788257373 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1788257373; x=1788862173; darn=nongnu.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=QIEprrdH7LZapW8zVSYHVi8VsanTJW2FyNSSrivNz7A=; b=VXGdwe6ST/bUNVtPyUCwkLGSs9fqWjZ6+n70Ce8AjldfhTeHUhXxk76ziiWU+9SvY3 zmRbK+OLfcgFFwp1JechPYIOBEwTnYFI+1ipoWA0vGgpWgBnN9c3DKbFe83y+PEq+x1Q 9jkn/0lGQefxZYcATkDAS2JK/VmN2CKrNOBIQdu2tOZuZrcrsZzYQH6/nVKFzT8CPj2a unJX1Ag+6LKmWg68wTFDXLosRa4DGSRP+epmDRfjImskBeZWKej3EK7YxsYyMEXfKaBt jwS5JxuSXEJlU87R5BrRI+0akEccs2861wCaRzIENOd6w2pXxATGzH3rVI3XmIL8UtkT 2HZg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788257373; x=1788862173; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=QIEprrdH7LZapW8zVSYHVi8VsanTJW2FyNSSrivNz7A=; b=jquc61IUgfZCKcKdt9cVluKVVdQ5YMISZ9Ym+Z9ambmG4ADEsM8JTd9iHF9jsf+6be AwGOxDrbLZpaHxFwbPaKtYMASc4kCEoSHNGK4h4PSmBPvIvhbRz4GtkCdZ6Ki0ukUbAr sZKmK4MuXxxD7xOIb6m8Ds1K1YRlnJLUu5QzwPO2yAhTVasxH+rAW0Ty59wjUzrBPGtH ytlRH71YUAP47Q9lR63+7r+E33OlH89PSPepGEQeOlEhFojQQrMGez85JBkKW4vbSdb5 paCfw3zJRhedwzEah3kBYhXWTfSagDIGBso/bY/mtTvoQ42U4O2zBflinEF6UX96vQc/ aoMA== X-Gm-Message-State: AFuF++mpSb/u9xoi41nbKyQGHdhhpM/DzxJiV4ZfYkUsHQzYsyF9cpBD kaCRmKhmF29K7cHiWFy39b/xnW+rYN/q0ylw6plADNklwvuZGXDzdlxTD3qDYhQhDt8M8GflPcm ROFlw1FHWE9Suj5Vejx4BFzq9nE98nmkleWRQCfdQX2Heb89OjrSVdsQP X-Gm-Gg: AR+sD11B2x+cU7wpgE2e9Lq9Lul4HHhuOl6+Woq0SXklW7Lh2EItyFeKERjTat2nDNQ 8M/b4h/hck2GMLJqA6HKYobGHXAi3LEMpyTuhTV3RWRRiRRDnjSsKltFpmyiArL0Lt4Y2BwiBN2 J4dQ1aP4h69IFNLJTrP3rsQEahwwffeSwXD3AwFPLVZu744Wx4ADWMR7HaQq/qKS8Vk0lct00C4 fJQbusF08MfzTkf31kDzyzNW4/g23NSzV3qCTPcCR5EfFBvhJxVmZkUz9Ur+sgHzCN7McUkHL4t kM09VEXesCQA2jjSVrW9Nv2BgE40SC2r0G0Nzp+moWb5ewekp+p8UQHE52sysVkBGkC22yYkE1q sHOz6d0uobbi5qKcanJzcEPc1OOP8ypDv3nhP5sOrNwTtu8P+7a1C5qGw3MpG+/456njf X-Received: by 2002:a05:600c:8411:b0:499:bf0e:95c8 with SMTP id 5b1f17b1804b1-49cdc405494mr133905095e9.1.1788257372974; Tue, 01 Sep 2026 03:09:32 -0700 (PDT) X-Received: by 2002:a05:600c:8411:b0:499:bf0e:95c8 with SMTP id 5b1f17b1804b1-49cdc405494mr133904365e9.1.1788257372560; Tue, 01 Sep 2026 03:09:32 -0700 (PDT) From: Luigi Leonardi Date: Tue, 01 Sep 2026 12:09:20 +0200 Subject: [PATCH 3/4] i386/sev: convert the guest policy properties to custom accessors MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260901-fix_igvm_policy-v1-3-e93a6cf8c5ac@redhat.com> References: <20260901-fix_igvm_policy-v1-0-e93a6cf8c5ac@redhat.com> In-Reply-To: <20260901-fix_igvm_policy-v1-0-e93a6cf8c5ac@redhat.com> To: qemu-devel@nongnu.org Cc: Gerd Hoffmann , Stefano Garzarella , Ani Sinha , Paolo Bonzini , Zhao Liu , Marcelo Tosatti , kvm@vger.kernel.org, Luigi Leonardi X-Mailer: b4 0.14.3 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=leonardi@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788257404427158500 Both SEV/SEV-ES and SEV-SNP expose a "policy" object property. The SEV/SEV-ES one was registered as a plain uint32 pointer property, and the SEV-SNP setter ignored the result of the visit. Give both properties explicit getter/setter functions and check the return value of the visit in the setters. This is preparation for tracking whether the guest policy was set on the command line. No functional change intended. Signed-off-by: Luigi Leonardi Reviewed-by: Ani Sinha --- target/i386/sev.c | 30 +++++++++++++++++++++++++----- 1 file changed, 25 insertions(+), 5 deletions(-) diff --git a/target/i386/sev.c b/target/i386/sev.c index 465415c535..c76cdba8d2 100644 --- a/target/i386/sev.c +++ b/target/i386/sev.c @@ -2956,6 +2956,22 @@ sev_guest_class_init(ObjectClass *oc, const void *da= ta) "use legacy VM type to maintain measurement compatibility with= older QEMU or kernel versions."); } =20 +static void +sev_guest_get_policy(Object *obj, Visitor *v, const char *name, + void *opaque, Error **errp) +{ + visit_type_uint32(v, name, &SEV_GUEST(obj)->policy, errp); +} + +static void +sev_guest_set_policy(Object *obj, Visitor *v, const char *name, + void *opaque, Error **errp) +{ + if (!visit_type_uint32(v, name, &SEV_GUEST(obj)->policy, errp)) { + return; + } +} + static void sev_guest_instance_init(Object *obj) { @@ -2964,8 +2980,8 @@ sev_guest_instance_init(Object *obj) sev_guest->policy =3D DEFAULT_GUEST_POLICY; object_property_add_uint32_ptr(obj, "handle", &sev_guest->handle, OBJ_PROP_FLAG_READWRITE); - object_property_add_uint32_ptr(obj, "policy", &sev_guest->policy, - OBJ_PROP_FLAG_READWRITE); + object_property_add(obj, "policy", "uint32", sev_guest_get_policy, + sev_guest_set_policy, NULL, NULL); object_apply_compat_props(obj); =20 sev_guest->legacy_vm_type =3D ON_OFF_AUTO_AUTO; @@ -3004,9 +3020,13 @@ static void sev_snp_guest_set_policy(Object *obj, Visitor *v, const char *name, void *opaque, Error **errp) { - visit_type_uint64(v, name, - (uint64_t *)&SEV_SNP_GUEST(obj)->kvm_start_conf.poli= cy, - errp); + SevSnpGuestState *sev_snp_guest =3D SEV_SNP_GUEST(obj); + + if (!visit_type_uint64(v, name, + (uint64_t *)&sev_snp_guest->kvm_start_conf.poli= cy, + errp)) { + return; + } } =20 static char * --=20 2.55.0 From nobody Sat Sep 26 20:51:55 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788257411; cv=none; d=zohomail.com; s=zohoarc; b=Vod/MAFTArqMmv8VNOtkVnsc269jeivmOaxTAQdhrO/PXCPpDfBaGWSo9YLF+U99FafsvZafg4OwvMXPl3FAK61dcvBRvVyDVmyRWpMh0ReddHTWz7QrrCdidUEfKU5AwQdnTRXzl/dPVhjystPcH38leq8K7Odi0+ef9Ey64PY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788257411; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=1q8tTUm5QcHyiu9DXLZbI88hsaICvNBYvi0zuGJw3GM=; b=WP32yln9ilK8Pbvlmv1RRKMwfE40PbRWd7+/8yEJ7YfKPe754JVU3hpnDKEmfeCAoA8E1QhhWur9icPpv8TcIAXv48ogiTPcXM1i194px2Ii2UBkE7LcfCDSoAeA1eHcRXboVSZOetQNKiFZb7tcT4+FSWAEtVDEDehcFiyK/9k= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788257411386937.3570369446547; Tue, 1 Sep 2026 03:10:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x1LQz-0002VW-Uz; Tue, 01 Sep 2026 06:09:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x1LQx-0002UY-Hr for qemu-devel@nongnu.org; Tue, 01 Sep 2026 06:09:39 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x1LQv-0000vs-CV for qemu-devel@nongnu.org; Tue, 01 Sep 2026 06:09:38 -0400 Received: from mail-wr1-f69.google.com (mail-wr1-f69.google.com [209.85.221.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-441-GAilDrsMOvG3YfmX6Vp1pA-1; Tue, 01 Sept 2026 06:09:35 -0400 Received: by mail-wr1-f69.google.com with SMTP id ffacd0b85a97d-482e575596aso2033151f8f.3 for ; Tue, 01 Sep 2026 03:09:35 -0700 (PDT) Received: from lleonard-thinkpadx1carbongen13.rmtit.csb ([151.29.41.106]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48442d7c1c0sm3941620f8f.32.2026.09.01.03.09.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 03:09:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788257376; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=1q8tTUm5QcHyiu9DXLZbI88hsaICvNBYvi0zuGJw3GM=; b=LY9heBj/bAPfvvozIOYG0u4gZEnF0X39/fa6r1Ss/+8B8kNhE75iSm4kyDX+l4W90yQwZq pT7A3njjjN8HFC9AsKr4RZUY3+co+CRFv/6Y5qpR8xPLEt/KDToMgO7pDgNQ5d/WFygxo1 uAozYAL/yICBvT1qVGwowiWM3Qlo/Ik= X-MC-Unique: GAilDrsMOvG3YfmX6Vp1pA-1 X-Mimecast-MFC-AGG-ID: GAilDrsMOvG3YfmX6Vp1pA_1788257374 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1788257374; x=1788862174; darn=nongnu.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=1q8tTUm5QcHyiu9DXLZbI88hsaICvNBYvi0zuGJw3GM=; b=Am34jGkwlds3RiHu2yYRHCoCijtpdf9gniq3Pq1RIkT0DkTi5EVWEQIcH0PdUpX0uX SvnzmB7NCuBnb4OOxCKfLTjzgOVv4EUSVAiYa5+e06dFYkJKEZG88uT+OF52ji+WceVK ennUaSf0TukB3kSJkQTAO4OHmj8DMrZWl8kqMHgpunNlUkHCUG1kol3YF0gkfPRiFZSH R2ljbbmolmuiRU4xaQEhd1tyXE1pvwRXO57+HBhz+Vig7orsk+sgELtVjSvj/geg430N pOC3gW1s6nQjY6c8SNJn6rSKchxsSh3G8t2vnor7SdT/MDVmwrrhMpM27xATMdiyncM/ cipQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788257374; x=1788862174; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=1q8tTUm5QcHyiu9DXLZbI88hsaICvNBYvi0zuGJw3GM=; b=Zz6ffDpBzRcU0Ap2h9QusQq7H/IVdzaYIFtN+ttilQOt8wjajVSo8CFWW9ZkW+f31Y KTzhmzrGds5zTH923vFPHtP1DGX9MxizUbAjkOOgmaBoKNLvzPV/EyyaCYTboExS/KfX fQ9m+jlpPu5Zetk7g/i6iZsgIV9I22MOm5bNxLDTzMcQuyf9YEKQhHKeefosOPnJj+zW vCfZWJgYkS1EkhG1LfaP8pbTcp1Ydy8OXmywJ7yhflRNXBP7vFFdG8JQWQ1NuXGzWd/7 d7FETh6pqcTaP2CpfSBIWgQAIKC2GJP0AjaL1M6Gjq52XBlEF3z7o/sByp/ewdfoLTVh sXcw== X-Gm-Message-State: AFuF++nrBZWDQ07y4jMjmVmzzYeqRz2UcgryuMvT4ohLLL2KVKlfkbUz +sr3L0IoWn72hxQ4YUNf9KkxhFLEPmSv6cp+JX2wbWPW0n/BbakmNZ7899iXSpmHD2DYRNi2Wlz igRzw/Miv4LB0Nrclhh7aPUlWKDchouu9IWS/dj0O3PFxP7LsKdEcytRw X-Gm-Gg: AYBFou0roQ8aJIdZsjUdP4gbX4c5buw5r6zIuCuDAPO46J16KrH/IDsKhYY4DXkens5 AKIB8HeD+CE+sNleud5JQ+fDKz+wqUpGrpdO3AFnQvKxCiiCkmTYlx6U/DKwSAOJuwZ+qkYPVwb nL0oBp4f1CD7vItHETSzcxdV/JU7vdyuwT8HEW6G9OYQlGNMfMkB8g2Iqx054/oEj+HSdRjze3N jJCDD4n3WS9OMfNYctwcn33otybrg5H/9k0+SnJ4Hgo8okJo8krfSfzwr9YQAaCQ1auNnm6cZ/M Nqrsiik3on5HT+hk6CT139RR7/3XNCJoSryIzbPNmKd/vjv5zKxCG/hi6KqTa1shUFaPYjYjTu9 DTXxF2FQ8fXgceFotbGjrpyCis9ZHiBWnh46uBTZ2DCTFNIftb8ZcopEK86AMj8Lr458T X-Received: by 2002:a05:6000:991:b0:484:3311:3703 with SMTP id ffacd0b85a97d-484331138a0mr42340510f8f.26.1788257374236; Tue, 01 Sep 2026 03:09:34 -0700 (PDT) X-Received: by 2002:a05:6000:991:b0:484:3311:3703 with SMTP id ffacd0b85a97d-484331138a0mr42340369f8f.26.1788257373745; Tue, 01 Sep 2026 03:09:33 -0700 (PDT) From: Luigi Leonardi Date: Tue, 01 Sep 2026 12:09:21 +0200 Subject: [PATCH 4/4] igvm/sev: forward the IGVM guest policy to the platform before launch MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260901-fix_igvm_policy-v1-4-e93a6cf8c5ac@redhat.com> References: <20260901-fix_igvm_policy-v1-0-e93a6cf8c5ac@redhat.com> In-Reply-To: <20260901-fix_igvm_policy-v1-0-e93a6cf8c5ac@redhat.com> To: qemu-devel@nongnu.org Cc: Gerd Hoffmann , Stefano Garzarella , Ani Sinha , Paolo Bonzini , Zhao Liu , Marcelo Tosatti , kvm@vger.kernel.org, Luigi Leonardi X-Mailer: b4 0.14.3 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=leonardi@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788257413476154100 The guest policy carried in the IGVM guest-policy initialization header was parsed into QIgvm but never forwarded to the confidential guest platform: the previous callback ran at the end of qigvm_process_file, after LAUNCH_START had already been issued, so writing the policy had no effect. Add a set_guest_policy callback and invoke it from the guest-policy initialization handler, so the policy reaches the platform before LAUNCH_START. The guest policy can also be set on the command line. As it is part of the attestation report, silently overriding it would cause attestation to fail, so return an error if the command-line value differs from the one supplied by the IGVM file. Link: https://gitlab.com/qemu-project/qemu/-/work_items/4189 Fixes: 915b47078d ("backends/igvm: Handle policy for SEV guests") Signed-off-by: Luigi Leonardi --- backends/confidential-guest-support.c | 9 ++++++++ backends/igvm.c | 4 ++++ target/i386/sev.c | 39 +++++++++++++++++++++++++++++++= ++++ 3 files changed, 52 insertions(+) diff --git a/backends/confidential-guest-support.c b/backends/confidential-= guest-support.c index a0b36d2da5..c0d15b4a76 100644 --- a/backends/confidential-guest-support.c +++ b/backends/confidential-guest-support.c @@ -38,6 +38,14 @@ static int set_guest_state(hwaddr gpa, uint8_t *ptr, uin= t64_t len, return -1; } =20 +static int set_guest_policy(ConfidentialGuestPolicyType policy_type, + uint64_t policy, Error **errp) +{ + error_setg(errp, + "Setting guest policy is not supported for this platform"); + return -1; +} + static int set_id_block(void *id_block, uint32_t id_block_size, void *id_auth, uint32_t id_auth_size, Error **errp) @@ -62,6 +70,7 @@ static void confidential_guest_support_class_init(ObjectC= lass *oc, ConfidentialGuestSupportClass *cgsc =3D CONFIDENTIAL_GUEST_SUPPORT_CLA= SS(oc); cgsc->check_support =3D check_support; cgsc->set_guest_state =3D set_guest_state; + cgsc->set_guest_policy =3D set_guest_policy; cgsc->set_id_block =3D set_id_block; cgsc->get_mem_map_entry =3D get_mem_map_entry; } diff --git a/backends/igvm.c b/backends/igvm.c index 6545382546..5131ee7829 100644 --- a/backends/igvm.c +++ b/backends/igvm.c @@ -868,6 +868,10 @@ static int qigvm_initialization_guest_policy(QIgvm *ct= x, =20 if (guest->compatibility_mask & ctx->compatibility_mask) { ctx->sev_policy =3D guest->policy; + if (ctx->cgsc) { + return ctx->cgsc->set_guest_policy(GUEST_POLICY_SEV, + guest->policy, errp); + } } return 0; } diff --git a/target/i386/sev.c b/target/i386/sev.c index c76cdba8d2..533ea4b54e 100644 --- a/target/i386/sev.c +++ b/target/i386/sev.c @@ -128,6 +128,8 @@ struct SevCommonState { bool kernel_hashes; uint64_t sev_features; uint64_t supported_sev_features; + /* whether the guest policy was explicitly set on the command line */ + bool policy_set; =20 /* runtime state */ uint8_t api_major; @@ -2723,6 +2725,40 @@ static int cgs_get_mem_map_entry(int index, return 0; } =20 +static int cgs_set_guest_policy(ConfidentialGuestPolicyType policy_type, + uint64_t policy, Error **errp) +{ + SevCommonState *sev_common =3D SEV_COMMON(MACHINE(qdev_get_machine())-= >cgs); + + if (policy_type !=3D GUEST_POLICY_SEV) { + error_setg(errp, "SEV: Invalid guest policy type provided for SEV:= %d", + policy_type); + return -1; + } + + if (sev_snp_enabled()) { + SevSnpGuestState *sev_snp_guest =3D SEV_SNP_GUEST(sev_common); + + if (sev_common->policy_set && + sev_snp_guest->kvm_start_conf.policy !=3D policy) { + error_setg(errp, "SNP: policy mismatch between IGVM and CLI"); + return -1; + } + + sev_snp_guest->kvm_start_conf.policy =3D policy; + } else { + SevGuestState *sev_guest =3D SEV_GUEST(sev_common); + + if (sev_common->policy_set && sev_guest->policy !=3D policy) { + error_setg(errp, "SEV: policy mismatch between IGVM and CLI"); + return -1; + } + + sev_guest->policy =3D policy; + } + return 0; +} + static int cgs_set_id_block(void *id_block, uint32_t id_block_size, void *id_auth, uint32_t id_auth_size, Error **errp) @@ -2848,6 +2884,7 @@ sev_common_instance_init(Object *obj) cgs->check_support =3D cgs_check_support; cgs->set_guest_state =3D cgs_set_guest_state; cgs->get_mem_map_entry =3D cgs_get_mem_map_entry; + cgs->set_guest_policy =3D cgs_set_guest_policy; cgs->set_id_block =3D cgs_set_id_block; cgs->can_rebuild_guest_state =3D true; =20 @@ -2970,6 +3007,7 @@ sev_guest_set_policy(Object *obj, Visitor *v, const c= har *name, if (!visit_type_uint32(v, name, &SEV_GUEST(obj)->policy, errp)) { return; } + SEV_COMMON(obj)->policy_set =3D true; } =20 static void @@ -3027,6 +3065,7 @@ sev_snp_guest_set_policy(Object *obj, Visitor *v, con= st char *name, errp)) { return; } + SEV_COMMON(obj)->policy_set =3D true; } =20 static char * --=20 2.55.0