From nobody Sat Sep 26 20:02:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788796700; cv=none; d=zohomail.com; s=zohoarc; b=fW0unpEIXELoFPSKVppkOhuf9bs6yXKZTAHK05fCmY2hNO7ieh+RwhrDeHa5CC25GOXuzGKKnLoDDGEs22m6QoNafdukHbwdL5HGHdfU985pzYSt2vAB50ZoyesifzAzCJu7pZsyHdKwgdb49hFM8LjhIARIZO4LC68zGmmelJA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788796700; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=UtTVcX+HkxAOGfacRObZuM9p/FF3OrW8RisRppHIXLs=; b=VbsWsPNwsRx/1hxrijsvKe1MheH4jxSMAKT2JCqf8woiFZDHxIPDrhsMFcYBM/F8BbaRO19PssTJy7V6fZGDwrtvgoYpbypfogvBFhxVsn+Y16K17pmohdNshxzTEzRkIi294FxtdkUKDk1i1Errd/Kp1LI6HaBoWGWkZZ3Ldh0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788796694339318.6140783508987; Mon, 7 Sep 2026 08:58:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x3bif-0006qO-P6; Mon, 07 Sep 2026 11:57:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3bib-0006pV-Aw for qemu-devel@nongnu.org; Mon, 07 Sep 2026 11:57:13 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3biY-0000uV-Vv for qemu-devel@nongnu.org; Mon, 07 Sep 2026 11:57:13 -0400 Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-679-VvzushzmN8WP_sn-38KPsg-1; Mon, 07 Sep 2026 11:57:06 -0400 Received: by mail-wm1-f72.google.com with SMTP id 5b1f17b1804b1-49b8c651ac0so54170885e9.2 for ; Mon, 07 Sep 2026 08:57:06 -0700 (PDT) Received: from lleonard-thinkpadx1carbongen13.rmtit.csb ([151.29.41.106]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49cf755c22esm320477955e9.0.2026.09.07.08.57.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 08:57:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788796630; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UtTVcX+HkxAOGfacRObZuM9p/FF3OrW8RisRppHIXLs=; b=dq/xFhbmg1PRW2BAJyNnlRX41zpdq+PaNPj0lcwWAG/u9WL0gLk568nlApyheNHVbNodck 4l58U+f9ppT+OOB8b3yMYHjO10A9LpYjnJRVIPLJLHUDEVuMA+u6Mg0rXsJfH6zr3kvkBO 5hoGfhHdVyL5sUnIUAoNj2EYp3mQVe8= X-MC-Unique: VvzushzmN8WP_sn-38KPsg-1 X-Mimecast-MFC-AGG-ID: VvzushzmN8WP_sn-38KPsg_1788796626 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1788796626; x=1789401426; darn=nongnu.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UtTVcX+HkxAOGfacRObZuM9p/FF3OrW8RisRppHIXLs=; b=WGw9RT0blK75kDYyd76X3UoSaRT1Zf0xvcQURGIedCBrH/6rpJGTUf+OWa8i0NJ665 0Pq8lIvWKKIy4xPKJhUSjZwcgLR7R/Hx6ONurAJ5JQtPMPQjniYpfVyrNrtbvBFofxf7 nqCrk4ne9Btb8KoyVQVwQJwJfBJcUIygrUPpb9P6gL4wUwavagRAnEUxaCh8SpxFJkBz dIERUd3nBK+gmrzW4qYMcCTh6Umi+tTa3Xd3aA2FEuDAegm2IJNouD54bJg1uHuuaNn+ PEaisYCRJO9rp3//j4M2FvkR7T286tmWvxF/TybX71TU1cxq3jVOKZjWnvvvob0yXB9m BKyg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788796626; x=1789401426; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=UtTVcX+HkxAOGfacRObZuM9p/FF3OrW8RisRppHIXLs=; b=sPq+jEWgMWFXLf55d45r64mrBrKqbgyEWQzpqxzLWswkjeZtslIcPn56R/BbxX2emO RsZjqYCO4nF9zY1qEllUKOMxd6m+HsumU2owh+JLweaaTegHGOxcWIpTthLkCGW6eptu rir+CMOi5IbchubtFsWf9UxLEMsNa5oDXQMpAmIgpUjQzO7xmdn3oZMnxB1p9aRsTd0x 8HSZFklwkRg/Yy1draj/8Szl7VK35r3BUg9m5qegmcEbC0qSd0GOR7GzLFr/hWDy1b3E uHOxbcoyteJM/2rq171bLY6ouG2UuCblfT/gG5ydC10pfQCvAqL3eIhH/71uoFbFtg/0 NuOA== X-Gm-Message-State: AFuF++l+LLQsnkwMZtjts4JWRjy3XL7Mr0T3WkTfUhc3zP6Uv4eNBmZM tlWU2mwEZqRVMRWEZRlaJJ4fUkVJTJXXe4WacI0anouXsiGBsxVNaEsDIi/pInsQ9xaR09I6t3z lOHjcB+i4H9bLVnuIr+7VyFGOrdV4Tmb0rEd9KEDy9foIx9e0Y4QTDgPGTVGPiGr7kprVa4nP0W gZ5Sm9bCVaFkwXvIT/GWusyR3PIn8N079qwb033aUyl8o= X-Gm-Gg: AYBFou1Y+I9/tv83u896eD8WbooXObsEDp0e7FAkjFJ8O8bVfuPez9AHly1X+FsOwGY 0YDs1KdZSSwBFvW5U/UtocOAV5H4z6X8mZpM4LmJUHVg/61MknvW3RO4KgQiQcynom9GDgul0IO L1ZojpCAiCdoillbJaB4PZe8M3QLz4lLEwEXBtoop1YKnvs61AeO02gtvFjdY2n6tbtyI+Qn8O9 nipl8LZQmi4kUTHCZCX4JB3o4duJp6TEcn7ryOHhoPU99Cr3QPiue58rkYymhdCWX/GRvizY9H7 01CVsbUpRCzZJEdrOnfMlfdg4St4v/sljTbxwJsWIfDTyQmhfZ7klWKcEkeSsd3HIzImfAXRNNL TG1aRKk7g3YSt8RoO1nTgMiqJ6BOQ7FAui8goWlanLyOa1opvAjlXSUx3ye+nXYXuq6s5 X-Received: by 2002:a05:600c:4fc9:b0:49c:fc6e:8cb9 with SMTP id 5b1f17b1804b1-49cfc6e8e1emr206321785e9.29.1788796625666; Mon, 07 Sep 2026 08:57:05 -0700 (PDT) X-Received: by 2002:a05:600c:4fc9:b0:49c:fc6e:8cb9 with SMTP id 5b1f17b1804b1-49cfc6e8e1emr206321185e9.29.1788796625161; Mon, 07 Sep 2026 08:57:05 -0700 (PDT) From: Luigi Leonardi Date: Mon, 07 Sep 2026 17:56:57 +0200 Subject: [PATCH v2 1/5] sev: split set_guest_policy into set_guest_policy and set_id_block MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260907-fix_igvm_policy-v2-1-c8c50f1dbfda@redhat.com> References: <20260907-fix_igvm_policy-v2-0-c8c50f1dbfda@redhat.com> In-Reply-To: <20260907-fix_igvm_policy-v2-0-c8c50f1dbfda@redhat.com> To: qemu-devel@nongnu.org Cc: Gerd Hoffmann , Stefano Garzarella , Ani Sinha , Paolo Bonzini , Zhao Liu , Marcelo Tosatti , "Daniel P. Berrange" , kvm@vger.kernel.org, Luigi Leonardi X-Mailer: b4 0.14.3 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=leonardi@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788796702609154100 The set_guest_policy callback on ConfidentialGuestSupportClass mixed two unrelated jobs: writing the guest policy bits and providing the SEV-SNP ID block/ID auth for LAUNCH_FINISH. The two are only related because both come from the same 'policy' section of the SEV/SEV-SNP launch flow, but they need to be set at different times: the policy must be in effect before LAUNCH_START, while the ID block is only needed before LAUNCH_FINISH. Split the combined callback into set_guest_policy(policy_type, policy, errp) and set_id_block(id_block, id_block_size, id_auth, id_auth_size, errp), keeping both call sites exactly where the combined callback used to be called from. No functional change. Signed-off-by: Luigi Leonardi Reviewed-by: Ani Sinha --- backends/confidential-guest-support.c | 15 ++- backends/igvm.c | 14 ++- include/system/confidential-guest-support.h | 28 +++--- target/i386/sev.c | 140 +++++++++++++++---------= ---- 4 files changed, 111 insertions(+), 86 deletions(-) diff --git a/backends/confidential-guest-support.c b/backends/confidential-= guest-support.c index 156dd15e66..d60d1f6eaa 100644 --- a/backends/confidential-guest-support.c +++ b/backends/confidential-guest-support.c @@ -39,16 +39,22 @@ static int set_guest_state(hwaddr gpa, uint8_t *ptr, ui= nt64_t len, } =20 static int set_guest_policy(ConfidentialGuestPolicyType policy_type, - uint64_t policy, - void *policy_data1, uint32_t policy_data1_size, - void *policy_data2, uint32_t policy_data2_size, - Error **errp) + uint64_t policy, Error **errp) { error_setg(errp, "Setting confidential guest policy is not supported for thi= s platform"); return -1; } =20 +static int set_id_block(void *id_block, uint32_t id_block_size, + void *id_auth, uint32_t id_auth_size, + Error **errp) +{ + error_setg(errp, + "Setting ID block is not supported for this platform"); + return -1; +} + static int get_mem_map_entry(int index, ConfidentialGuestMemoryMapEntry *e= ntry, Error **errp) { @@ -65,6 +71,7 @@ static void confidential_guest_support_class_init(ObjectC= lass *oc, cgsc->check_support =3D check_support; cgsc->set_guest_state =3D set_guest_state; cgsc->set_guest_policy =3D set_guest_policy; + cgsc->set_id_block =3D set_id_block; cgsc->get_mem_map_entry =3D get_mem_map_entry; } =20 diff --git a/backends/igvm.c b/backends/igvm.c index 7b7bdc72b7..99304d6467 100644 --- a/backends/igvm.c +++ b/backends/igvm.c @@ -963,14 +963,22 @@ static int qigvm_handle_policy(QIgvm *ctx, Error **er= rp) if (ctx->platform_type =3D=3D IGVM_PLATFORM_TYPE_SEV_SNP) { int id_block_len =3D 0; int id_auth_len =3D 0; + int retval; + if (ctx->id_block) { ctx->id_block->policy =3D ctx->sev_policy; id_block_len =3D sizeof(struct sev_id_block); id_auth_len =3D sizeof(struct sev_id_authentication); } - return ctx->cgsc->set_guest_policy(GUEST_POLICY_SEV, ctx->sev_poli= cy, - ctx->id_block, id_block_len, - ctx->id_auth, id_auth_len, errp); + + retval =3D ctx->cgsc->set_guest_policy(GUEST_POLICY_SEV, ctx->sev_= policy, + errp); + if (retval < 0) { + return retval; + } + + return ctx->cgsc->set_id_block(ctx->id_block, id_block_len, + ctx->id_auth, id_auth_len, errp); } return 0; } diff --git a/include/system/confidential-guest-support.h b/include/system/c= onfidential-guest-support.h index 5dca717308..6d35ddb97a 100644 --- a/include/system/confidential-guest-support.h +++ b/include/system/confidential-guest-support.h @@ -128,21 +128,23 @@ typedef struct ConfidentialGuestSupportClass { uint16_t cpu_index, Error **errp); =20 /* - * Set the guest policy. The policy can be used to configure the - * confidential platform, such as if debug is enabled or not and can c= ontain - * information about expected launch measurements, signed verification= of - * guest configuration and other platform data. - * - * The format of the policy data is specific to each platform. For exa= mple, - * SEV-SNP uses a policy bitfield in the 'policy' argument and provide= s an - * ID block and ID authentication in the 'policy_data' parameters. The= type - * of policy data is identified by the 'policy_type' argument. + * Set the guest policy for the confidential platform. The policy + * configures properties of the guest, such as whether debug is + * enabled. Its format is platform-specific; for SEV/SEV-ES and + * SEV-SNP it is a policy bitfield. Must be called before LAUNCH_START + * so the policy is in effect for launch. */ int (*set_guest_policy)(ConfidentialGuestPolicyType policy_type, - uint64_t policy, - void *policy_data1, uint32_t policy_data1_size, - void *policy_data2, uint32_t policy_data2_size, - Error **errp); + uint64_t policy, Error **errp); + + /* + * Set the SEV-SNP ID block and ID authentication block. These are + * passed to SNP_LAUNCH_FINISH to provide signed verification of the + * guest configuration. + */ + int (*set_id_block)(void *id_block, uint32_t id_block_size, + void *id_auth, uint32_t id_auth_size, + Error **errp); =20 /* * Iterate the system memory map, getting the entry with the given ind= ex diff --git a/target/i386/sev.c b/target/i386/sev.c index cc16c6b071..b53d13e2fa 100644 --- a/target/i386/sev.c +++ b/target/i386/sev.c @@ -2726,9 +2726,7 @@ static int cgs_get_mem_map_entry(int index, } =20 static int cgs_set_guest_policy(ConfidentialGuestPolicyType policy_type, - uint64_t policy, void *policy_data1, - uint32_t policy_data1_size, void *policy_d= ata2, - uint32_t policy_data2_size, Error **errp) + uint64_t policy, Error **errp) { SevCommonState *sev_common =3D SEV_COMMON(MACHINE(qdev_get_machine())-= >cgs); if (sev_common->state =3D=3D SEV_STATE_UNINIT) { @@ -2741,81 +2739,90 @@ static int cgs_set_guest_policy(ConfidentialGuestPo= licyType policy_type, policy_type); return -1; } - /* - * SEV-SNP handles policy differently. The policy flags are defined in - * kvm_start_conf.policy and an ID block and ID auth can be provided. - */ + + /* do not reset existing policy if policy was not set in IGVM */ + if (policy =3D=3D 0) { + return 0; + } + if (sev_snp_enabled()) { SevSnpGuestState *sev_snp_guest =3D SEV_SNP_GUEST(MACHINE(qdev_get_machine())->cgs); - struct kvm_sev_snp_launch_finish *finish =3D - &sev_snp_guest->kvm_finish_conf; =20 - /* - * The policy consists of flags in 'policy' and optionally an ID b= lock - * and ID auth in policy_data1 and policy_data2 respectively. The = ID - * block and auth are optional so clear any previous ID block and = auth - * and set them if provided, but always set the policy flags. - */ - g_free(sev_snp_guest->id_block); - g_free((guchar *)finish->id_block_uaddr); - g_free(sev_snp_guest->id_auth); - g_free((guchar *)finish->id_auth_uaddr); - sev_snp_guest->id_block =3D NULL; - finish->id_block_uaddr =3D 0; - sev_snp_guest->id_auth =3D NULL; - finish->id_auth_uaddr =3D 0; - - if (policy_data1_size > 0) { - struct sev_snp_id_authentication *id_auth =3D - (struct sev_snp_id_authentication *)policy_data2; - - if (policy_data1_size !=3D KVM_SEV_SNP_ID_BLOCK_SIZE) { - error_setg(errp, "SEV: Invalid SEV-SNP ID block: incorrect= size"); - return -1; - } - if (policy_data2_size !=3D KVM_SEV_SNP_ID_AUTH_SIZE) { - error_setg(errp, - "SEV: Invalid SEV-SNP ID auth block: incorrect = size"); - return -1; - } - assert(policy_data1 !=3D NULL); - assert(policy_data2 !=3D NULL); + sev_snp_guest->kvm_start_conf.policy =3D policy; + } else { + SevGuestState *sev_guest =3D SEV_GUEST(MACHINE(qdev_get_machine())= ->cgs); =20 - finish->id_block_uaddr =3D - (__u64)g_memdup2(policy_data1, KVM_SEV_SNP_ID_BLOCK_SIZE); - finish->id_auth_uaddr =3D - (__u64)g_memdup2(policy_data2, KVM_SEV_SNP_ID_AUTH_SIZE); + sev_guest->policy =3D policy; + } + return 0; +} =20 - /* - * Check if an author key has been provided and use that to fl= ag - * whether the author key is enabled. The first of the author = key - * must be non-zero to indicate the key type, which will curre= ntly - * always be 2. - */ - sev_snp_guest->kvm_finish_conf.auth_key_en =3D - id_auth->author_key[0] ? 1 : 0; - finish->id_block_en =3D 1; - } +static int cgs_set_id_block(void *id_block, uint32_t id_block_size, + void *id_auth, uint32_t id_auth_size, + Error **errp) +{ + SevCommonState *sev_common =3D SEV_COMMON(MACHINE(qdev_get_machine())-= >cgs); + if (sev_common->state =3D=3D SEV_STATE_UNINIT) { + /* Pre-processing of IGVM file called from sev_common_kvm_init() */ + return 0; + } + + if (!sev_snp_enabled()) { + error_setg(errp, "SEV: ID block is only supported for SEV-SNP"); + return -1; + } =20 - /* do not reset existing policy if policy was not set in IGVM */ - if (policy !=3D 0) { - sev_snp_guest->kvm_start_conf.policy =3D policy; + SevSnpGuestState *sev_snp_guest =3D + SEV_SNP_GUEST(MACHINE(qdev_get_machine())->cgs); + struct kvm_sev_snp_launch_finish *finish =3D + &sev_snp_guest->kvm_finish_conf; + + /* + * Drop any ID block and ID auth from a previous pass before repopulat= ing + * them, then set them only if an ID block was provided. + */ + g_free(sev_snp_guest->id_block); + g_free((guchar *)finish->id_block_uaddr); + g_free(sev_snp_guest->id_auth); + g_free((guchar *)finish->id_auth_uaddr); + sev_snp_guest->id_block =3D NULL; + finish->id_block_uaddr =3D 0; + sev_snp_guest->id_auth =3D NULL; + finish->id_auth_uaddr =3D 0; + + if (id_block_size > 0) { + struct sev_snp_id_authentication *auth =3D + (struct sev_snp_id_authentication *)id_auth; + + if (id_block_size !=3D KVM_SEV_SNP_ID_BLOCK_SIZE) { + error_setg(errp, "SEV: Invalid SEV-SNP ID block: incorrect siz= e"); + return -1; } - } else { - SevGuestState *sev_guest =3D SEV_GUEST(MACHINE(qdev_get_machine())= ->cgs); - /* Only the policy flags are supported for SEV and SEV-ES */ - if ((policy_data1_size > 0) || (policy_data2_size > 0) || !sev_gue= st) { - error_setg(errp, "SEV: An ID block/ID auth block has been prov= ided " - "but SEV-SNP is not enabled"); + if (id_auth_size !=3D KVM_SEV_SNP_ID_AUTH_SIZE) { + error_setg(errp, + "SEV: Invalid SEV-SNP ID auth block: incorrect size= "); return -1; } + assert(id_block !=3D NULL); + assert(id_auth !=3D NULL); =20 - /* do not reset existing policy if policy was not set in IGVM */ - if (policy !=3D 0) { - sev_guest->policy =3D policy; - } + finish->id_block_uaddr =3D + (__u64)g_memdup2(id_block, KVM_SEV_SNP_ID_BLOCK_SIZE); + finish->id_auth_uaddr =3D + (__u64)g_memdup2(id_auth, KVM_SEV_SNP_ID_AUTH_SIZE); + + /* + * Check if an author key has been provided and use that to flag + * whether the author key is enabled. The first of the author key + * must be non-zero to indicate the key type, which will currently + * always be 2. + */ + sev_snp_guest->kvm_finish_conf.auth_key_en =3D + auth->author_key[0] ? 1 : 0; + finish->id_block_en =3D 1; } + return 0; } =20 @@ -2881,6 +2888,7 @@ sev_common_instance_init(Object *obj) cgs->set_guest_state =3D cgs_set_guest_state; cgs->get_mem_map_entry =3D cgs_get_mem_map_entry; cgs->set_guest_policy =3D cgs_set_guest_policy; + cgs->set_id_block =3D cgs_set_id_block; cgs->can_rebuild_guest_state =3D true; =20 QTAILQ_INIT(&sev_common->launch_vmsa); --=20 2.55.0 From nobody Sat Sep 26 20:02:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788796677; cv=none; d=zohomail.com; s=zohoarc; b=TQ4Ff29NOtNFIvxEVDM6FNVWX1XRq34+qu9qhcNFIUe9ceczL6XLD+QgR4jvhEOSvYHK3TYF5ba9mDUAhnuwGCzRCDEdmVO3U05+fdk4Z95Hv48RrNT7FFpf1Ixm3LDYfhA7kkC3bdygTQ5lk4bKf5hbYrBsZ/u4WBlJFMezjLU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788796677; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8EQ1Hp/5/EcMqD759ADXm85y9O+auBS8uFJpNUQOG/o=; b=O8QyVjEoXmE0F4k7SInqMSsdJCnnnUKuZMnbUBQPOuC9x4IUxGs5nSX9jbsaoZ3/C8vFkhrXh8L0uimTHFKWNUxSnxDNGkzd81Ydk0pmQwutrB8zMbzeVYX5/i4prb5qIAVsLVfaX8kwSO0/uRwKyCeC2tVEpGyzHFXO5aFIwp0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788796677113413.86139976149593; Mon, 7 Sep 2026 08:57:57 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x3bic-0006pd-5U; Mon, 07 Sep 2026 11:57:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3bia-0006pH-2f for qemu-devel@nongnu.org; Mon, 07 Sep 2026 11:57:12 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3biX-0000uK-Th for qemu-devel@nongnu.org; Mon, 07 Sep 2026 11:57:11 -0400 Received: from mail-wr1-f72.google.com (mail-wr1-f72.google.com [209.85.221.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-685-q9j_E5JDPzOXGrIHelw2oQ-1; Mon, 07 Sep 2026 11:57:07 -0400 Received: by mail-wr1-f72.google.com with SMTP id ffacd0b85a97d-485866e0066so2036940f8f.2 for ; Mon, 07 Sep 2026 08:57:07 -0700 (PDT) Received: from lleonard-thinkpadx1carbongen13.rmtit.csb ([151.29.41.106]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49cf755c22esm320477955e9.0.2026.09.07.08.57.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 08:57:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788796629; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=8EQ1Hp/5/EcMqD759ADXm85y9O+auBS8uFJpNUQOG/o=; b=VLIFJenqj0WSljKs8QlCauDeOeY/wALOsF1ILJktvPChoWzo8W7Qiw4WyqvrE0Fe1O4ciM jeu0xnhk3Tqv4BSh+3/aVXSfeNjIdhcTp06z/XJxgwqDQJIJ2Yo4uOLHAb1odOeNUQF/7y cgjZMdjMOkQcG4pGAT/dLLZKoPyB7To= X-MC-Unique: q9j_E5JDPzOXGrIHelw2oQ-1 X-Mimecast-MFC-AGG-ID: q9j_E5JDPzOXGrIHelw2oQ_1788796627 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1788796626; x=1789401426; darn=nongnu.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8EQ1Hp/5/EcMqD759ADXm85y9O+auBS8uFJpNUQOG/o=; b=tAph4QU2nXAmp9gRMm5D36kp3t8xC+v/jXdR26ITXOAqXqmC3kBqjxW/PFxxH2/2O4 LF4/a+f1l3wwdhpeLxGZJSOIMMvcDdXWv/mfI1OBYtNoHxjEn32wcNf8AL1ZwpKLHqup r758Mdybz4qd2fMhO0UTLHda0QCWemN9bO9kEbfTr4MDmq89vt9e967AhypFBMH08rqv O5G4UQI0iYOONhE+JwzQM2xQmharygc+N1m2nu/BO5kU7sYPPXhy7OZ4kU8vOMaTng2m c2UKMP/CirsAJjer2SrH5+AvkPxz6i1G5V5KoJVfGA/g/sO8pvGvupBTUcZ4Z9R8Eb1Z PYPA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788796626; x=1789401426; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=8EQ1Hp/5/EcMqD759ADXm85y9O+auBS8uFJpNUQOG/o=; b=qIpATHq3y75QP3CkbUFQYmOsXjxabEakFIwGTzeK4iKV8aOjZfVHCOU1ji8Jjvo9EI nKSmLDFyJM36HPk/5PGkxVVp4KuoE6PJZ5y3U9l6Q2x1tSZNuZoSRM7sek/ahvP8axwa J5wYgZDn7pdiVcw5DzK6YCakOjvTwdofeduJXCLrPWK/5ptIOVKJSdTVumHv+LH0ETkR luCRdmqszM8WRaEnHXETQKWIM8CqbI+xJvFgQoRY+CoBC1GcTDlE2N/C97BZYwN9sbTo pyUoI9WHOZ7wQp0Q4bhWxcJyylM7/cUkuJszerY2XL+zmxAlzomc3pCYzEYlglnjcTPr WvVA== X-Gm-Message-State: AFuF++nMgIkMyCI4RN+AMXVyPtQW6CQauvZ/6ufsAAcAmYg62qxIanND ZdYp9ZNaqjEvcewfODL0yZJwMGcodpTistox3jiBm+WZ7dxsfmjIou2FtfvaIj5sfpK+fEA4nCo lpfjh8gMmvTpegDoS9Fpcrk13GidFPbFXmLMB8JyZ87sHLIqWYQzcXnrr/k8qIUFom7qfFcYOjb wpK1M5vgmm4jKhKS1OdfQhVdQ2JtWn+HWvfR4/W1Y2XH0= X-Gm-Gg: AYBFou289QusdApWnwQS5TN8lrYs1JBsUijcgA53e0mMNh1LIHQaRj8KjBsOXBYBB5W Lte13/60B6ryzOnEVeG9YtmqZJWiyMbYz5gTPWKpwB/abWeiWakdTHgmZ8we1IQoEp3k4dTw0Ez QueOi8HfWH3KGGZSb0zHV6u5FpGrsB8GmfSHZMGXN5mGHjvsjx+LpTPqP7H5Z2y37GjmOj52cw3 uphqcrNHiQAcVfkLvy38a/Q8+hmI0TqmwoGIKUvJYiS3fkUCu6ATMqYq8/NfskTdwPytGUL4bW7 tslQfbh5ocZxK2QronyfzrqIhaKo8JqkskmMMuwTY9VapnBUBQtyWDhp/rrMH+Yfa/AN42WzzzV wBZgIBNuR3Hc9gPSLEK4GPpRqbfoYubBrxq9uQuKk/3R032HmHnw5fSDVjOj5iBrMW498 X-Received: by 2002:a05:600c:c162:b0:49d:16dc:e721 with SMTP id 5b1f17b1804b1-49d16dce7aamr27511855e9.24.1788796626641; Mon, 07 Sep 2026 08:57:06 -0700 (PDT) X-Received: by 2002:a05:600c:c162:b0:49d:16dc:e721 with SMTP id 5b1f17b1804b1-49d16dce7aamr27511415e9.24.1788796626179; Mon, 07 Sep 2026 08:57:06 -0700 (PDT) From: Luigi Leonardi Date: Mon, 07 Sep 2026 17:56:58 +0200 Subject: [PATCH v2 2/5] igvm: move set_id_block call into the SNP ID block directive handler MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260907-fix_igvm_policy-v2-2-c8c50f1dbfda@redhat.com> References: <20260907-fix_igvm_policy-v2-0-c8c50f1dbfda@redhat.com> In-Reply-To: <20260907-fix_igvm_policy-v2-0-c8c50f1dbfda@redhat.com> To: qemu-devel@nongnu.org Cc: Gerd Hoffmann , Stefano Garzarella , Ani Sinha , Paolo Bonzini , Zhao Liu , Marcelo Tosatti , "Daniel P. Berrange" , kvm@vger.kernel.org, Luigi Leonardi X-Mailer: b4 0.14.3 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=leonardi@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788796681026154100 set_id_block only makes sense when the IGVM file contains an IGVM_VHT_SNP_ID_BLOCK directive. Move the call from qigvm_handle_policy (which continues to handle the set_guest_policy call) into qigvm_directive_snp_id_block, where the ID block and ID auth are populated. This avoids a no-op call to set_id_block when no ID block is present. The ID block embeds the guest policy, so the policy must be known by the time the directive is handled. Process the initialization section (which carries the GUEST_POLICY header) before the directive section, and copy ctx->sev_policy into the ID block in the directive handler. Signed-off-by: Luigi Leonardi --- backends/igvm.c | 80 ++++++++++++++++++++++++++++-------------------------= ---- 1 file changed, 40 insertions(+), 40 deletions(-) diff --git a/backends/igvm.c b/backends/igvm.c index 99304d6467..521560822a 100644 --- a/backends/igvm.c +++ b/backends/igvm.c @@ -778,6 +778,8 @@ static int qigvm_directive_snp_id_block(QIgvm *ctx, con= st uint8_t *header_data, ctx->id_block->version =3D IGVM_SEV_ID_BLOCK_VERSION; memcpy(ctx->id_block->ld, igvm_id->ld, sizeof(ctx->id_block->ld)); =20 + ctx->id_block->policy =3D ctx->sev_policy; + ctx->id_auth->id_key_alg =3D igvm_id->id_key_algorithm; assert(sizeof(igvm_id->id_key_signature) <=3D sizeof(ctx->id_auth->id_block_sig)); @@ -805,6 +807,14 @@ static int qigvm_directive_snp_id_block(QIgvm *ctx, co= nst uint8_t *header_data, memcpy(&ctx->id_auth->author_key[76], &igvm_id->author_public_key.qy, 72); =20 + if (ctx->cgsc) { + return ctx->cgsc->set_id_block(ctx->id_block, + sizeof(struct sev_id_block), + ctx->id_auth, + sizeof(struct sev_id_authentication= ), + errp); + } + return 0; } =20 @@ -961,24 +971,8 @@ static int qigvm_supported_platform_compat_mask(QIgvm = *ctx, Error **errp) static int qigvm_handle_policy(QIgvm *ctx, Error **errp) { if (ctx->platform_type =3D=3D IGVM_PLATFORM_TYPE_SEV_SNP) { - int id_block_len =3D 0; - int id_auth_len =3D 0; - int retval; - - if (ctx->id_block) { - ctx->id_block->policy =3D ctx->sev_policy; - id_block_len =3D sizeof(struct sev_id_block); - id_auth_len =3D sizeof(struct sev_id_authentication); - } - - retval =3D ctx->cgsc->set_guest_policy(GUEST_POLICY_SEV, ctx->sev_= policy, - errp); - if (retval < 0) { - return retval; - } - - return ctx->cgsc->set_id_block(ctx->id_block, id_block_len, - ctx->id_auth, id_auth_len, errp); + return ctx->cgsc->set_guest_policy(GUEST_POLICY_SEV, ctx->sev_poli= cy, + errp); } return 0; } @@ -1040,6 +1034,34 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *m= achine_state, goto cleanup; } =20 + /* + * Process the initialization section first so that the guest policy is + * known before the directive section is handled. The SNP ID block + * directive embeds the guest policy into the ID block, so the policy = from + * the guest policy initialization header must be available by then. + */ + header_count =3D + igvm_header_count(ctx.cfg->file, IGVM_HEADER_SECTION_INITIALIZATIO= N); + if (header_count < 0) { + error_setg( + errp, + "Invalid initialization header count in IGVM file. Error code:= %X", + header_count); + goto cleanup; + } + + for (ctx.current_header_index =3D 0; + ctx.current_header_index < (unsigned)header_count; + ctx.current_header_index++) { + IgvmVariableHeaderType type =3D + igvm_get_header_type(ctx.cfg->file, + IGVM_HEADER_SECTION_INITIALIZATION, + ctx.current_header_index); + if (qigvm_handler(&ctx, type, errp) < 0) { + goto cleanup; + } + } + header_count =3D igvm_header_count(ctx.cfg->file, IGVM_HEADER_SECTION_DIRECTIVE); if (header_count <=3D 0) { @@ -1073,28 +1095,6 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *m= achine_state, goto cleanup_parameters; } =20 - header_count =3D - igvm_header_count(ctx.cfg->file, IGVM_HEADER_SECTION_INITIALIZATIO= N); - if (header_count < 0) { - error_setg( - errp, - "Invalid initialization header count in IGVM file. Error code:= %X", - header_count); - goto cleanup_parameters; - } - - for (ctx.current_header_index =3D 0; - ctx.current_header_index < (unsigned)header_count; - ctx.current_header_index++) { - IgvmVariableHeaderType type =3D - igvm_get_header_type(ctx.cfg->file, - IGVM_HEADER_SECTION_INITIALIZATION, - ctx.current_header_index); - if (qigvm_handler(&ctx, type, errp) < 0) { - goto cleanup_parameters; - } - } - /* * Contiguous pages of data with compatible flags are grouped together= in * order to reduce the number of memory regions we create. Make sure t= he --=20 2.55.0 From nobody Sat Sep 26 20:02:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788796699; cv=none; d=zohomail.com; s=zohoarc; b=JTUVQbpkp7QheIIOnShmP4qprX0i9OO4RB99A2uh2ABxzK8hskwa3k9phRljnOKwjnbv1DaWwBPzFs58qyCojYsYeuL/l63VW8SrUMK5a2dJpFW9N6Oc9T1lfkmw2kKo1chgoCbB5nHlqDLc3VeHfmJrwsNsVmg7eNZ7kzF8588= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788796699; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LNEHRJDHdcdZeT0Nz44zT2pq9EwMvgRWKA64S1eEvDM=; b=eUc9CIu8mpBoHToE1sB9j3Si8nJzzFafRognbIjvS4dVAPN8lQ3Zism4x1CzSpVvmZMpd70hxBv6RGrMFLIhCod5VaKPS+3915TRyp0sheNgY4iFAw/P+oVIHQBb0kJ0TIS4uXrZZtBs8CkgwqDYZKQY4nS6n384cMnc1KAhoB8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788796699773106.85178223217599; Mon, 7 Sep 2026 08:58:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x3bii-0006qS-8o; Mon, 07 Sep 2026 11:57:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3bib-0006pW-CH for qemu-devel@nongnu.org; Mon, 07 Sep 2026 11:57:13 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3biZ-0000uX-Ao for qemu-devel@nongnu.org; Mon, 07 Sep 2026 11:57:13 -0400 Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-41-Q462VYAuO6CRT1FFCWpwUw-1; Mon, 07 Sep 2026 11:57:09 -0400 Received: by mail-wm1-f72.google.com with SMTP id 5b1f17b1804b1-49ccfad90f1so22775715e9.0 for ; Mon, 07 Sep 2026 08:57:08 -0700 (PDT) Received: from lleonard-thinkpadx1carbongen13.rmtit.csb ([151.29.41.106]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49cf755c22esm320477955e9.0.2026.09.07.08.57.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 08:57:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788796630; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=LNEHRJDHdcdZeT0Nz44zT2pq9EwMvgRWKA64S1eEvDM=; b=DC0qxUvQBdA8ny5wqkJA77TiePQ+V8C/U1jcOnN9ow80cLcjznF9ZGkVbdOnlV9FzIm0dP qlfOzSZb+HqQqXp+k6sOY8CMlWA2uBa9LK7Ompz7RNcyuTSGaDyGbJ83JUPDlT06MyVUcz Ahi2rxUTRYlfs7B72E4dzePV5t7mSns= X-MC-Unique: Q462VYAuO6CRT1FFCWpwUw-1 X-Mimecast-MFC-AGG-ID: Q462VYAuO6CRT1FFCWpwUw_1788796628 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1788796628; x=1789401428; darn=nongnu.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=LNEHRJDHdcdZeT0Nz44zT2pq9EwMvgRWKA64S1eEvDM=; b=p3nt4Iytrh3vaIOQ3Ny7mNMuor4cobLDS2+lqRrWlRC73sKrQHbrnD0V/JYfHSM849 FDyGS2hkVIsATQQl0iHKP+xCElfpdwbsc/txawzassY1imGOxI1Abs9/ZX0Q/elWp3KR iHeQ3obervjTqPspJW7yfmQKd/yABqpYJuhHQbRTxuNUTWFkFmjbFDxJZEC4AmJHpYxr xGHM5Nw+Ay7SeYA/JmkjnTNsQU//8n2nmfUt+9dBQaKkbeuckWIOFUr7+4ad1+OFppvA X9zFeT0sErvlRLcBqgdcBr+AQoN2HP26BfQr+bF2p9FYA9lO/wW99J6Fp52JI2ASqj90 H0aA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788796628; x=1789401428; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=LNEHRJDHdcdZeT0Nz44zT2pq9EwMvgRWKA64S1eEvDM=; b=KONBBPMN8r/VpFkHu88l6jWJkcevtwhg2WaZW3ckB8D96Nk49XPnvRotFZmmBhf7Ft Of87pWCj8PqK3YxMdz1l1JXlQcKw5Y43/1SEAf5ljxVdUix0Pi1JNXI2Jt4y6qOS2VvB BTXkBSKy/vMuZyW+vauHzkO721iyx5noiS04wRDOmmRIpYzT9Nb9gJVSEmJwkET5AvVm iffSh/+mRUs7K+irmZYPJhDF8zO64kWGR+dkTEUnXDjDZzooReeGY8j6007r8/sXB2Y3 8MzbRoE3Cko4/S+i9bUdLuOVzF/UDqLnDrMIsuxx5QDTy3MqcSLTdJKjXD5xti/iaKxV DuOw== X-Gm-Message-State: AFuF++n2dLtvYVUN7d1wYh/y+erNaAaljhXQBRyg7ZNaHj3hF76q6KOk WVdUwN9gv6qDevJ+uFzaSLA625bUxsLp2vblym7LeJfbRUbMZDNp0qs4o9PAEWX8ydZb7RCa3WZ gF+AQsxT/q+x+B/BiqDzGM1+zHdHZ5sxIMj/DWjE/DOFgY+K51EGCM+8SZseYfJdSkrTGpYAe+4 qrholPibY903LlbqC9kpMg3Aa9mWF0I5d19BjlAVXc8lY= X-Gm-Gg: AYBFou2pBvoHbK51RPB42saQB5d/CwTp8WEQx2AEMD1TrHcAq9nhNDZi0RAdLgnOWU/ XYnmZcQ4n8OutisJ8b9Ou3dVFx21vM5e/nQHrfDZ4U2oNnDxLHGQVgeeIJJTgffNDQWuKFbc8jU mkHmzHDs+9yniLOSmlhL2sMQf7wYQwptXP53MOaGPnnhDp28SkPZdnCuyxDNrrg1WVrln/5RX2a Rt++Nk6IRk0XC8b8UnrELnj7W0T5FxE/70uirUuuo0IQ3GC16dsoAjXgStRzkI2tFespsC7UKtR mva1Rh/DS3amvAykzGqFWXS3js2Vr7bx/Z/LibwROS0FkrxcTacfaIp4lnWWLi44DTn3IWoPxjz Q57pIM5gZnBXdfi8Vqs81YYYtTYhoI6ctgMPioCNTGQBHblK1L4ZUFK4aWJB/rWkPxF3q X-Received: by 2002:a05:600d:4449:20b0:49d:3a:e576 with SMTP id 5b1f17b1804b1-49d003ae639mr122997665e9.5.1788796627847; Mon, 07 Sep 2026 08:57:07 -0700 (PDT) X-Received: by 2002:a05:600d:4449:20b0:49d:3a:e576 with SMTP id 5b1f17b1804b1-49d003ae639mr122997145e9.5.1788796627429; Mon, 07 Sep 2026 08:57:07 -0700 (PDT) From: Luigi Leonardi Date: Mon, 07 Sep 2026 17:56:59 +0200 Subject: [PATCH v2 3/5] i386/sev: convert the guest policy properties to custom accessors MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260907-fix_igvm_policy-v2-3-c8c50f1dbfda@redhat.com> References: <20260907-fix_igvm_policy-v2-0-c8c50f1dbfda@redhat.com> In-Reply-To: <20260907-fix_igvm_policy-v2-0-c8c50f1dbfda@redhat.com> To: qemu-devel@nongnu.org Cc: Gerd Hoffmann , Stefano Garzarella , Ani Sinha , Paolo Bonzini , Zhao Liu , Marcelo Tosatti , "Daniel P. Berrange" , kvm@vger.kernel.org, Luigi Leonardi X-Mailer: b4 0.14.3 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=leonardi@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788796702656158500 Both SEV/SEV-ES and SEV-SNP expose a "policy" object property. The SEV/SEV-ES one was registered as a plain uint32 pointer property, and the SEV-SNP setter ignored the result of the visit. Give both properties explicit getter/setter functions and check the return value of the visit in the setters. This is preparation for tracking whether the guest policy was set on the command line. No functional change intended. Reviewed-by: Ani Sinha Signed-off-by: Luigi Leonardi --- target/i386/sev.c | 30 +++++++++++++++++++++++++----- 1 file changed, 25 insertions(+), 5 deletions(-) diff --git a/target/i386/sev.c b/target/i386/sev.c index b53d13e2fa..38f97fd9b2 100644 --- a/target/i386/sev.c +++ b/target/i386/sev.c @@ -2996,6 +2996,22 @@ sev_guest_class_init(ObjectClass *oc, const void *da= ta) "use legacy VM type to maintain measurement compatibility with= older QEMU or kernel versions."); } =20 +static void +sev_guest_get_policy(Object *obj, Visitor *v, const char *name, + void *opaque, Error **errp) +{ + visit_type_uint32(v, name, &SEV_GUEST(obj)->policy, errp); +} + +static void +sev_guest_set_policy(Object *obj, Visitor *v, const char *name, + void *opaque, Error **errp) +{ + if (!visit_type_uint32(v, name, &SEV_GUEST(obj)->policy, errp)) { + return; + } +} + static void sev_guest_instance_init(Object *obj) { @@ -3004,8 +3020,8 @@ sev_guest_instance_init(Object *obj) sev_guest->policy =3D DEFAULT_GUEST_POLICY; object_property_add_uint32_ptr(obj, "handle", &sev_guest->handle, OBJ_PROP_FLAG_READWRITE); - object_property_add_uint32_ptr(obj, "policy", &sev_guest->policy, - OBJ_PROP_FLAG_READWRITE); + object_property_add(obj, "policy", "uint32", sev_guest_get_policy, + sev_guest_set_policy, NULL, NULL); object_apply_compat_props(obj); =20 sev_guest->legacy_vm_type =3D ON_OFF_AUTO_AUTO; @@ -3044,9 +3060,13 @@ static void sev_snp_guest_set_policy(Object *obj, Visitor *v, const char *name, void *opaque, Error **errp) { - visit_type_uint64(v, name, - (uint64_t *)&SEV_SNP_GUEST(obj)->kvm_start_conf.poli= cy, - errp); + SevSnpGuestState *sev_snp_guest =3D SEV_SNP_GUEST(obj); + + if (!visit_type_uint64(v, name, + (uint64_t *)&sev_snp_guest->kvm_start_conf.poli= cy, + errp)) { + return; + } } =20 static char * --=20 2.55.0 From nobody Sat Sep 26 20:02:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788796694; cv=none; d=zohomail.com; s=zohoarc; b=B8f1gGLEvYPqloIAnN5L4smq32a1f/RFiEn0gzwUn0vfcNuX+ovj0gQ7MncxCk1nTztFXCaxcmQHoqoNymrBkkYSJDl/Q6z+Bn9lujI/6KaYMstYz9HvV+zVCvHGboiHx4ligfO4IhOtXbHAsBE8WypYaPVai5LwSME3o314uNA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788796694; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Z5hdb76LHaeRDjiMZ4Xz5jIByuQ8SJeJucbeRZQQXsU=; b=jf5s8xcqHjE37oodxlaHUPxU6ePSXWZ0Uq6Mk6Almhnt5YLrXWkz4aJniCSrQXu1ME7lmV2MvkIZIXZRmeFyRwvHZ8o0O0R7eDkYd6CwQhU3fUQyZ5UISCkg7sLnk8ASXKLS0MKhZGA8jECdggTD6V3dpei29Mh+71XKhbGvWok= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788796694923973.231470517279; Mon, 7 Sep 2026 08:58:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x3bii-0006qU-AY; Mon, 07 Sep 2026 11:57:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3bic-0006pf-3d for qemu-devel@nongnu.org; Mon, 07 Sep 2026 11:57:14 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3bia-0000uo-BT for qemu-devel@nongnu.org; Mon, 07 Sep 2026 11:57:13 -0400 Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-194-z0vVQkpqPfmWvXxsjXdSYA-1; Mon, 07 Sep 2026 11:57:10 -0400 Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-4957287363bso30313075e9.0 for ; Mon, 07 Sep 2026 08:57:10 -0700 (PDT) Received: from lleonard-thinkpadx1carbongen13.rmtit.csb ([151.29.41.106]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49cf755c22esm320477955e9.0.2026.09.07.08.57.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 08:57:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788796631; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Z5hdb76LHaeRDjiMZ4Xz5jIByuQ8SJeJucbeRZQQXsU=; b=YNgiTlnb+NgBHYZRFzUbmQR8CLa7uGE/gV1aOq+rgHa3yQsF7CPOKORDFM83AVayj8a1UL xTrLaOv6nJYaMIFg9vUCOQBhT/5KmMP16yr7bpfkUYg98ZdW0e+mVzMvyTkKtDjsTdywoE DEmUOghl7ur2aIuND1qQS4/nDgJ+ywc= X-MC-Unique: z0vVQkpqPfmWvXxsjXdSYA-1 X-Mimecast-MFC-AGG-ID: z0vVQkpqPfmWvXxsjXdSYA_1788796629 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1788796629; x=1789401429; darn=nongnu.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Z5hdb76LHaeRDjiMZ4Xz5jIByuQ8SJeJucbeRZQQXsU=; b=tbRpi6VpaMtMTrzivIwgxR+7cJEM5XtlGSv/7dJokpqSsT8B3VtDIUQj7rnat3ts/5 SilXlB5oW2O4X7NP7X8RMZOppPXzzNbV2FgPNtPIbWuBUomoYxgf2Bb8mZnSW+e2G/JL s2TPhGy8w/jWMqXMn0E7QvemaP64wYN61j1bR7ycTxeA81i7iVxgqBm8I6uB127DHIeg zDPm1CS1j051X0HWKV67QW9NhnyZaICpMZlZXpBPok28cF2iW1shTMTmN4LUVTRCg+50 l2tGvbCe5GrkKrbW8WJal67WyFXUsM92CtBNx3Axr6+wVuLiyHai/0lzopjOIoDj08hU qs/Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788796629; x=1789401429; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Z5hdb76LHaeRDjiMZ4Xz5jIByuQ8SJeJucbeRZQQXsU=; b=NK9AQgw30SCqcQCJN/iSVl/AWLRAVRjdBPb1xLlldHLU3/lhonyy4LvKBMHP3eFWlO DHfmbjy1ySrXo7RUFEs7LzDO7VbupujQIc8l+WmazxCbR/uksryrApDNyzWbTLFZ7JjB AkV7lRlmQN7KYZ6Pw+0G5G7Nor9nx5brWxjsVrrJ7vAMkFKBs09tFL7z//TFYHKpgLUB Pb48A4ZAmodwDWZOFbcoRzdn7wbnKOI7z89IDNp01f2oH7+52MIyXpP+DQFl4nyJD5cF A3nJmzlfovkGl/n1R87ZMnLAK5RkpCcsVFu5pWLFfeUsNr/ttDnoHI5OB+9Vgm1eepEa yJbQ== X-Gm-Message-State: AFuF++kLpXX3aSNDcfthJc1I/ADPUHxoSKLyqybh+iHKtw1B64DUw1+1 t8KAbcTvO/AE8LTcX889JGSpNdFKWEffOYn96p5pEr/szxpYszlV+kIBvqzS15QGN+iXoGJoECU hnXc13HqUlNiQsr8jF1qaJmndWssMXx5I/mwQwseOhjGGg5baJirESKEZeda9h2tEH5ALXpG+Ij pOR3PbmcmwAxCg3G17ukey6O0FdM0PAD7mZEe99LOG69E= X-Gm-Gg: AYBFou1VUv0jhSfS4S1k25YKVYtKJgZrXBDQ2scmmJtKFUuShV+cnknd7/cu/Q34Rrz p5Lz/H8EXP606zgqf44Ne2UhvxgSwfPnW8eCIrvUNQBngn3CmsxbwiOZ01sun4LvC9gCk80u2qQ MEQ2oyk6pOkTuZG4IKmS5S8t60or8hpM33JokoWEQtab6hL1sNuKp7u4Ouk2aITlVVUnM4nI5jx VaX+t9/d7o4uDUqrTelo6vs+UlVcj6XRDWK3LBMjvctbSPxQ6eF7ThDz4wXCTZBDhrD/d4Q8o8V nZy865G5mtQsWksAHJcAKXbZFuWelG4nfPmPnlRTGCFY9sFWeA6TmQ768mHqDS5aBu7v2BecDjw DMbXLBa0JfeEdRq2QmnY+GQ7ALiqczgNvDuJh9efhKMXws8rpkd/qFIf4Ir8mb8XLXj2b X-Received: by 2002:a05:600c:1d1c:b0:49d:91d:d192 with SMTP id 5b1f17b1804b1-49d091dd358mr118096925e9.5.1788796629313; Mon, 07 Sep 2026 08:57:09 -0700 (PDT) X-Received: by 2002:a05:600c:1d1c:b0:49d:91d:d192 with SMTP id 5b1f17b1804b1-49d091dd358mr118096055e9.5.1788796628557; Mon, 07 Sep 2026 08:57:08 -0700 (PDT) From: Luigi Leonardi Date: Mon, 07 Sep 2026 17:57:00 +0200 Subject: [PATCH v2 4/5] i386/sev: add a get_guest_policy callback MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260907-fix_igvm_policy-v2-4-c8c50f1dbfda@redhat.com> References: <20260907-fix_igvm_policy-v2-0-c8c50f1dbfda@redhat.com> In-Reply-To: <20260907-fix_igvm_policy-v2-0-c8c50f1dbfda@redhat.com> To: qemu-devel@nongnu.org Cc: Gerd Hoffmann , Stefano Garzarella , Ani Sinha , Paolo Bonzini , Zhao Liu , Marcelo Tosatti , "Daniel P. Berrange" , kvm@vger.kernel.org, Luigi Leonardi X-Mailer: b4 0.14.3 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=leonardi@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788796698531154101 The next patch populates the SEV-SNP ID block's policy field. That value must be whatever policy is currently in effect on the platform but there is no way to read it back: the policy can come either from an IGVM GUEST_POLICY header or from the command line, and the command line sets it directly into the SEV/SNP guest struct without going through IGVM. Reading it back from the platform is the only source that always reflects the value in effect, regardless of where it came from. Add a get_guest_policy callback to ConfidentialGuestSupportClass for this purpose. It is not yet used; the following patch wires it into the SNP ID block population. Signed-off-by: Luigi Leonardi --- backends/confidential-guest-support.c | 9 +++++++++ include/system/confidential-guest-support.h | 8 ++++++++ target/i386/sev.c | 24 ++++++++++++++++++++++++ 3 files changed, 41 insertions(+) diff --git a/backends/confidential-guest-support.c b/backends/confidential-= guest-support.c index d60d1f6eaa..91701f1a5f 100644 --- a/backends/confidential-guest-support.c +++ b/backends/confidential-guest-support.c @@ -46,6 +46,14 @@ static int set_guest_policy(ConfidentialGuestPolicyType = policy_type, return -1; } =20 +static int get_guest_policy(ConfidentialGuestPolicyType policy_type, + uint64_t *policy, Error **errp) +{ + error_setg(errp, + "Getting guest policy is not supported for this platform"); + return -1; +} + static int set_id_block(void *id_block, uint32_t id_block_size, void *id_auth, uint32_t id_auth_size, Error **errp) @@ -71,6 +79,7 @@ static void confidential_guest_support_class_init(ObjectC= lass *oc, cgsc->check_support =3D check_support; cgsc->set_guest_state =3D set_guest_state; cgsc->set_guest_policy =3D set_guest_policy; + cgsc->get_guest_policy =3D get_guest_policy; cgsc->set_id_block =3D set_id_block; cgsc->get_mem_map_entry =3D get_mem_map_entry; } diff --git a/include/system/confidential-guest-support.h b/include/system/c= onfidential-guest-support.h index 6d35ddb97a..27ae0a21b6 100644 --- a/include/system/confidential-guest-support.h +++ b/include/system/confidential-guest-support.h @@ -137,6 +137,14 @@ typedef struct ConfidentialGuestSupportClass { int (*set_guest_policy)(ConfidentialGuestPolicyType policy_type, uint64_t policy, Error **errp); =20 + /* + * Get the guest policy currently configured for the confidential + * platform, be it from the command line or from a previous call to + * set_guest_policy. Its format is the same as for set_guest_policy. + */ + int (*get_guest_policy)(ConfidentialGuestPolicyType policy_type, + uint64_t *policy, Error **errp); + /* * Set the SEV-SNP ID block and ID authentication block. These are * passed to SNP_LAUNCH_FINISH to provide signed verification of the diff --git a/target/i386/sev.c b/target/i386/sev.c index 38f97fd9b2..f11fdb6590 100644 --- a/target/i386/sev.c +++ b/target/i386/sev.c @@ -2758,6 +2758,29 @@ static int cgs_set_guest_policy(ConfidentialGuestPol= icyType policy_type, return 0; } =20 +static int cgs_get_guest_policy(ConfidentialGuestPolicyType policy_type, + uint64_t *policy, Error **errp) +{ + SevCommonState *sev_common =3D SEV_COMMON(MACHINE(qdev_get_machine())-= >cgs); + + if (policy_type !=3D GUEST_POLICY_SEV) { + error_setg(errp, "SEV: Invalid guest policy type provided for SEV:= %d", + policy_type); + return -1; + } + + if (sev_snp_enabled()) { + SevSnpGuestState *sev_snp_guest =3D SEV_SNP_GUEST(sev_common); + + *policy =3D sev_snp_guest->kvm_start_conf.policy; + } else { + SevGuestState *sev_guest =3D SEV_GUEST(sev_common); + + *policy =3D sev_guest->policy; + } + return 0; +} + static int cgs_set_id_block(void *id_block, uint32_t id_block_size, void *id_auth, uint32_t id_auth_size, Error **errp) @@ -2888,6 +2911,7 @@ sev_common_instance_init(Object *obj) cgs->set_guest_state =3D cgs_set_guest_state; cgs->get_mem_map_entry =3D cgs_get_mem_map_entry; cgs->set_guest_policy =3D cgs_set_guest_policy; + cgs->get_guest_policy =3D cgs_get_guest_policy; cgs->set_id_block =3D cgs_set_id_block; cgs->can_rebuild_guest_state =3D true; =20 --=20 2.55.0 From nobody Sat Sep 26 20:02:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788796704; cv=none; d=zohomail.com; s=zohoarc; b=cp/0Kq8uYwYKNEuLTtXXX/dcUW4z4lyNoQH2B9mG0ZvneaMArLn7EhDs75JnfHIdaAvJ6EP2ndS+E6sW5kAhovXLYUA2lW1s8d8cxiXsxU+QFnkbjQIq0y1dhWMfVC7sqYqrUGEEChxZmmlrXY1sKzFN2Ese5qkpPmNVQwBt8zE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788796704; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fQaiA+qhLoVzKtGnL0lSxJUvzGHQNtKK5icFkRaD4Dg=; b=hNGy7/PmpKl1Y0LrCI6+TTmWLFpvEmGoA+1AIMtzCc24CYwk6p47sauzK1Km2vN99ECuOjkbS1btZvkTVN40rvm49/dmUIW1oJYjIAaMH8813OhxhSs/iC5Rb36B1j0TwETFercBik78+3nUmjQxvE/0Z7iLMNS09Ah3P+7NTsQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788796704198752.9140055472014; Mon, 7 Sep 2026 08:58:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x3bii-0006qt-SO; Mon, 07 Sep 2026 11:57:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3bid-0006qE-GV for qemu-devel@nongnu.org; Mon, 07 Sep 2026 11:57:16 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3bib-0000v6-Dy for qemu-devel@nongnu.org; Mon, 07 Sep 2026 11:57:15 -0400 Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-155-aTis1ks3OAC2Jf-ni7VoiQ-1; Mon, 07 Sep 2026 11:57:11 -0400 Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-490a767c7dcso27378245e9.2 for ; Mon, 07 Sep 2026 08:57:11 -0700 (PDT) Received: from lleonard-thinkpadx1carbongen13.rmtit.csb ([151.29.41.106]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49cf755c22esm320477955e9.0.2026.09.07.08.57.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 08:57:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788796632; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=fQaiA+qhLoVzKtGnL0lSxJUvzGHQNtKK5icFkRaD4Dg=; b=Hq7OvWiqusThkDC+G1yOuDZOXWPx5kMio3YDiFctc3LZUpIMxaxBcVv3BrFo7cZzahcOk/ c3bxK2qvPiYUxUbw0f9vXyKtEfAY5O5IUUlK9g6wJ+oPnUBRjFsR2fg8NjO5ZxLVQKk9HJ BzjpLizgi8ZtdsBe575WtBB6WE4rbIA= X-MC-Unique: aTis1ks3OAC2Jf-ni7VoiQ-1 X-Mimecast-MFC-AGG-ID: aTis1ks3OAC2Jf-ni7VoiQ_1788796630 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1788796630; x=1789401430; darn=nongnu.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=fQaiA+qhLoVzKtGnL0lSxJUvzGHQNtKK5icFkRaD4Dg=; b=iY7YFGyiecXgoU1eFfx4gtZQLTc7FjPA60/YBk1jy9w6AERUOm97Rq/eNVKITuPAtY yMPA+3KBsCgUF5VWgfUPI/4QMkPUW7f33suxTreYFwhNWPHSMwWTuxIpsb6CcEJi5NZf heVF45tza89pHG9jb/0EZwPPvkPpWN8KpM0HkOBij6invoqsMlx1Cu/n0KYMJTmav+lF CKiVD28oTEV4FOcRM5RnQPxfi3rPkuJoNcM3INW2f9cknI4lCBj724fivo/YxqiFuv3N SrsxLO7xM/V9ji5qIQYb7uYqLekaPpuUfF4330qy190X5beCi7FUyfyVO4aveDWYNVFI W9kQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788796630; x=1789401430; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=fQaiA+qhLoVzKtGnL0lSxJUvzGHQNtKK5icFkRaD4Dg=; b=GDnr/KB964e5ndDrZPJ15NO1r/vxixp/6Q50HIO79Kn7st6xt25RovkK3D1/mGDJSm Zqb67CX46cZ9cFTBN40pUNOgZdG9Vwti03UTTXmGZieciEp0/2XzEpyf0x64kqW8VnJG r++OLTcFAZsuTWFDbePHrTasg6CehK2n8YWMhxAu1NoJH4fuRLtrdOZs0z1H0xhGAWa/ tRtsLr9ePU87/sAIQgmVeHyEX1a/OMsR1Z27a78eE1z4SJRgPnayZKnmdD+eg5cZQL4f 6m1qB39/utAR1bAu5uKRmWQKepwesvAgnP3K36wIyvD0QMQZB08isVS9WzAZQ5P6tZzD fkNA== X-Gm-Message-State: AFuF++nEtsqRXmHpGIKD5D8yr3XjNoYRvfvNoc6nDwLMdfUFVn/ru4KY c76+GS9lITN10Z3pWNHPy/oegB4Goc0Eljhs0Alhq3+teYHWy6JAFwu19DXFXLdMQ1w6nDmUFFr CDas52f7ExYWBO9JjUOpbjsGH3FNLckvSabL6IKbWsRnIns93rjVJo81X6oT8ZOFsQbYfzjy1Tj 4naB3xYh78UxyD/VzKsQHOrhgz1wb7mIXwTPQ8ZZJG3Dw= X-Gm-Gg: AYBFou3tJiV4uG0s/f3dQBfJT6CPYFApLjR26EQxx+21nJNChfu0Bm/cpoa4uYi2WvF mBtmifedrX+sg8NFrSDS/7gP44364JNdkxIzfXFFaCjc/p1Fe61+XNnThyTjV7EiXUsz5bryjd7 K5tLQjV7nP6XqVNUqNaW4R/CL0WYyGa6V2WMRNnOsFZ0JeFvozosfExC1tccYpxAkaEugAnq1O/ 1j3ML5YaSyR+2gfvpfD4hvbt4yokRg7h84SwnsD9dSgywajGpfiwBhjUeYGxFbF2Kgi5+xdLKTp vQ2TVayeeADAcSYljN9e3Rs1Axv5Pe7Qwv2DhJwAf0jwiUB5a1b6mHv+Dme8u66JdYDDM8jl1ig iVbITO5IAbJ2CrNw5YRmocabzHxynYSnhU4qpfnMnG1Zyg4Fc6husB+IYMPP+uzUXu21z X-Received: by 2002:a05:600c:46d5:b0:49c:fc6c:be04 with SMTP id 5b1f17b1804b1-49cfc6cc091mr196552065e9.27.1788796630337; Mon, 07 Sep 2026 08:57:10 -0700 (PDT) X-Received: by 2002:a05:600c:46d5:b0:49c:fc6c:be04 with SMTP id 5b1f17b1804b1-49cfc6cc091mr196551635e9.27.1788796629803; Mon, 07 Sep 2026 08:57:09 -0700 (PDT) From: Luigi Leonardi Date: Mon, 07 Sep 2026 17:57:01 +0200 Subject: [PATCH v2 5/5] igvm/sev: forward the IGVM guest policy to the platform before launch MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260907-fix_igvm_policy-v2-5-c8c50f1dbfda@redhat.com> References: <20260907-fix_igvm_policy-v2-0-c8c50f1dbfda@redhat.com> In-Reply-To: <20260907-fix_igvm_policy-v2-0-c8c50f1dbfda@redhat.com> To: qemu-devel@nongnu.org Cc: Gerd Hoffmann , Stefano Garzarella , Ani Sinha , Paolo Bonzini , Zhao Liu , Marcelo Tosatti , "Daniel P. Berrange" , kvm@vger.kernel.org, Luigi Leonardi X-Mailer: b4 0.14.3 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=leonardi@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788796706055158500 set_guest_policy was called from qigvm_handle_policy at the end of qigvm_process_file, after LAUNCH_START had already been issued for both SEV/SEV-ES and SEV-SNP. The guest was therefore launched with whatever policy was already configured (the command-line value, or the platform default if none was given) instead of the one requested by the IGVM file, quietly breaking attestation since the policy is part of the attestation report. Move the call into qigvm_initialization_guest_policy, which runs while the initialization section is processed. Because that section is now handled during the pre-launch pass (see previous patch), the call happens before LAUNCH_START, so the policy is in effect for launch. Drop qigvm_handle_policy, whose only remaining job was that misplaced call. cgs_set_guest_policy no longer special-cases SEV_STATE_UNINIT: that guard used to skip the pre-processing pass so the policy was applied later, but forwarding it during pre-processing, before LAUNCH_START, is now precisely the point. The 'policy =3D=3D 0 means unset' guard is dropped too, since the call site now only fires when the IGVM file actually provides a GUEST_POLICY header. The command line can also set a policy. It now takes precedence: if it differs from the IGVM one, print a warning and keep the command-line value instead of silently overriding it. Also reject a policy that doesn't fit in the 32-bit SEV/SEV-ES policy field instead of truncating it. Finally, use the get_guest_policy callback added by the previous patch to populate the SNP ID block's policy field. The command line sets its policy directly into the SEV/SNP guest's own struct, bypassing IGVM entirely, so ctx->sev_policy only ever reflects a GUEST_POLICY header and is 0 otherwise, causing SNP_LAUNCH_FINISH to reject the ID block whenever the file relies on a command-line policy. Reading the policy back from the platform instead always gets the value actually in effect, regardless of its source. ctx->sev_policy is now unused and removed. Link: https://gitlab.com/qemu-project/qemu/-/work_items/4189 Fixes: 915b47078d ("backends/igvm: Handle policy for SEV guests") Signed-off-by: Luigi Leonardi --- backends/igvm.c | 27 +++++++++++---------------- include/system/igvm-internal.h | 3 --- target/i386/sev.c | 37 +++++++++++++++++++++++++------------ 3 files changed, 36 insertions(+), 31 deletions(-) diff --git a/backends/igvm.c b/backends/igvm.c index 521560822a..5360a2575b 100644 --- a/backends/igvm.c +++ b/backends/igvm.c @@ -778,8 +778,6 @@ static int qigvm_directive_snp_id_block(QIgvm *ctx, con= st uint8_t *header_data, ctx->id_block->version =3D IGVM_SEV_ID_BLOCK_VERSION; memcpy(ctx->id_block->ld, igvm_id->ld, sizeof(ctx->id_block->ld)); =20 - ctx->id_block->policy =3D ctx->sev_policy; - ctx->id_auth->id_key_alg =3D igvm_id->id_key_algorithm; assert(sizeof(igvm_id->id_key_signature) <=3D sizeof(ctx->id_auth->id_block_sig)); @@ -808,6 +806,13 @@ static int qigvm_directive_snp_id_block(QIgvm *ctx, co= nst uint8_t *header_data, 72); =20 if (ctx->cgsc) { + uint64_t policy; + + if (ctx->cgsc->get_guest_policy(GUEST_POLICY_SEV, &policy, errp) <= 0) { + return -1; + } + ctx->id_block->policy =3D policy; + return ctx->cgsc->set_id_block(ctx->id_block, sizeof(struct sev_id_block), ctx->id_auth, @@ -867,7 +872,10 @@ static int qigvm_initialization_guest_policy(QIgvm *ct= x, (const IGVM_VHS_GUEST_POLICY *)header_data; =20 if (guest->compatibility_mask & ctx->compatibility_mask) { - ctx->sev_policy =3D guest->policy; + if (ctx->cgsc) { + return ctx->cgsc->set_guest_policy(GUEST_POLICY_SEV, + guest->policy, errp); + } } return 0; } @@ -968,15 +976,6 @@ static int qigvm_supported_platform_compat_mask(QIgvm = *ctx, Error **errp) return 0; } =20 -static int qigvm_handle_policy(QIgvm *ctx, Error **errp) -{ - if (ctx->platform_type =3D=3D IGVM_PLATFORM_TYPE_SEV_SNP) { - return ctx->cgsc->set_guest_policy(GUEST_POLICY_SEV, ctx->sev_poli= cy, - errp); - } - return 0; -} - IgvmHandle qigvm_file_init(char *filename, Error **errp) { IgvmHandle igvm; @@ -1102,10 +1101,6 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *m= achine_state, */ retval =3D qigvm_process_mem_page(&ctx, NULL, errp); =20 - if (retval =3D=3D 0) { - retval =3D qigvm_handle_policy(&ctx, errp); - } - cleanup_parameters: QTAILQ_FOREACH(parameter, &ctx.parameter_data, next) { diff --git a/include/system/igvm-internal.h b/include/system/igvm-internal.h index 9e9fa1d9af..041f77586a 100644 --- a/include/system/igvm-internal.h +++ b/include/system/igvm-internal.h @@ -64,9 +64,6 @@ struct QIgvm { struct sev_id_block *id_block; struct sev_id_authentication *id_auth; =20 - /* Define the guest policy for SEV guests */ - uint64_t sev_policy; - /* These variables keep track of contiguous page regions */ IGVM_VHS_PAGE_DATA region_prev_page_data; uint64_t region_start; diff --git a/target/i386/sev.c b/target/i386/sev.c index f11fdb6590..11072b00dc 100644 --- a/target/i386/sev.c +++ b/target/i386/sev.c @@ -128,6 +128,8 @@ struct SevCommonState { bool kernel_hashes; uint64_t sev_features; uint64_t supported_sev_features; + /* whether the guest policy was explicitly set on the command line */ + bool policy_set; =20 /* runtime state */ uint8_t api_major; @@ -2729,10 +2731,6 @@ static int cgs_set_guest_policy(ConfidentialGuestPol= icyType policy_type, uint64_t policy, Error **errp) { SevCommonState *sev_common =3D SEV_COMMON(MACHINE(qdev_get_machine())-= >cgs); - if (sev_common->state =3D=3D SEV_STATE_UNINIT) { - /* Pre-processing of IGVM file called from sev_common_kvm_init() */ - return 0; - } =20 if (policy_type !=3D GUEST_POLICY_SEV) { error_setg(errp, "SEV: Invalid guest policy type provided for SEV:= %d", @@ -2740,18 +2738,31 @@ static int cgs_set_guest_policy(ConfidentialGuestPo= licyType policy_type, return -1; } =20 - /* do not reset existing policy if policy was not set in IGVM */ - if (policy =3D=3D 0) { - return 0; - } - if (sev_snp_enabled()) { - SevSnpGuestState *sev_snp_guest =3D - SEV_SNP_GUEST(MACHINE(qdev_get_machine())->cgs); + SevSnpGuestState *sev_snp_guest =3D SEV_SNP_GUEST(sev_common); + + if (sev_common->policy_set && + sev_snp_guest->kvm_start_conf.policy !=3D policy) { + warn_report_once("SNP: policy mismatch between IGVM and CLI, " + "keeping the command-line policy"); + return 0; + } =20 sev_snp_guest->kvm_start_conf.policy =3D policy; } else { - SevGuestState *sev_guest =3D SEV_GUEST(MACHINE(qdev_get_machine())= ->cgs); + SevGuestState *sev_guest =3D SEV_GUEST(sev_common); + + if (sev_common->policy_set && sev_guest->policy !=3D policy) { + warn_report_once("SEV: policy mismatch between IGVM and CLI, " + "keeping the command-line policy"); + return 0; + } + + if (policy > UINT32_MAX) { + error_setg(errp, "SEV: policy 0x%" PRIx64 " does not fit in th= e " + "32-bit SEV/SEV-ES guest policy field", policy); + return -1; + } =20 sev_guest->policy =3D policy; } @@ -3034,6 +3045,7 @@ sev_guest_set_policy(Object *obj, Visitor *v, const c= har *name, if (!visit_type_uint32(v, name, &SEV_GUEST(obj)->policy, errp)) { return; } + SEV_COMMON(obj)->policy_set =3D true; } =20 static void @@ -3091,6 +3103,7 @@ sev_snp_guest_set_policy(Object *obj, Visitor *v, con= st char *name, errp)) { return; } + SEV_COMMON(obj)->policy_set =3D true; } =20 static char * --=20 2.55.0