From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976661; cv=none; d=zohomail.com; s=zohoarc; b=CPr18M5f40sb8v1fYOdg7pb+j2nPeSG5PbSHHf4vf7fYRuly22ZbY0+Ch+7Fe8kqUdB2hqzKaEMgKRBQtnn+mWm587+lusi6CkqcOlYWDNnEqOL/Fv+9jEtt6BYn5vSUKMoRR3i3emBZHUGI2i3E7oVDjVO4SuYuHxRH4aT3iPY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976661; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=l5PmZE87TKCiubYIjrJI+9woBAy+nceE2Hd0ZDVFfZ8=; b=DggJ3kfXAZDpi+HYOR8mvMamCqc9fzG3UnPymQgKBgB4AhAx4WgmFZbiZIXZ6OLyWcjEqvG1gJ/kByD+lucj/LOyyO12YHr40u62s7NQpLGCCPdZ+gr8wXuGv8FUEiDHsK4hbjqcKwknERCy/uzwCVK6zRrKerC8HJvTDe4EIk8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976661579713.0657650096074; Wed, 9 Sep 2026 10:57:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MXq-00012x-AT; Wed, 09 Sep 2026 13:57:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXp-00012U-2H for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:13 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXm-0004c0-Uo for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:12 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-606--1XUBZtINpeXlnuur3GDSw-1; Wed, 09 Sep 2026 13:57:05 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C821A1800678; Wed, 9 Sep 2026 17:57:03 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 3B76D195608C; Wed, 9 Sep 2026 17:57:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976629; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=l5PmZE87TKCiubYIjrJI+9woBAy+nceE2Hd0ZDVFfZ8=; b=Ezw+qfHfjROrK/YKhlDJARoruwWvgLXJ07yrkHcujGrAeDhuiuzlKbzpnKlLOZsfFg/YIr jNoGtR12OtW3KqkP4pDHESblYBIydC99R2sbw/7UX9V/ewhwYE9FdB/sWkAhaY1IRFJlBq dRAzno0EPGovi7PmYBCCKMveypDVLzs= X-MC-Unique: -1XUBZtINpeXlnuur3GDSw-1 X-Mimecast-MFC-AGG-ID: -1XUBZtINpeXlnuur3GDSw_1788976624 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 01/14] qom: add tracking of security state of object types Date: Wed, 9 Sep 2026 18:56:43 +0100 Message-ID: <20260909175656.1572689-2-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976668121158500 This introduces a new flag "secure" against the Type/TypeInfo structs, and helpers to check this against the ObjectClass struct. If an object is considered to provide a security boundary to protect against untrusted code, the "secure" flag must be explicitly set to true. If it is set to false, or left unset, this indicates that the object does not intend to provide a security boundary. Bugs related to this object class will be ineligible for CVE assignment. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- include/qom/object.h | 13 +++++++++++++ qom/object.c | 7 +++++++ 2 files changed, 20 insertions(+) diff --git a/include/qom/object.h b/include/qom/object.h index 7ecd0f210f..687ceb6bba 100644 --- a/include/qom/object.h +++ b/include/qom/object.h @@ -453,6 +453,10 @@ struct Object * function. * @abstract: If this field is true, then the class is considered abstract= and * cannot be directly instantiated. + * @secure: If this field is initialized to true, then the class is consid= ered + * to provide a security boundary. If initialized to false, the class do= es + * not provide a security boundary. If uninitialized (and thus implicitly + * false) its status is not yet defined. * @class_size: The size of the class object (derivative of #ObjectClass) * for this object. If @class_size is 0, then the size of the class wil= l be * assumed to be the size of the parent class. This allows a type to av= oid @@ -487,6 +491,7 @@ struct TypeInfo void (*instance_finalize)(Object *obj); =20 bool abstract; + bool secure; size_t class_size; =20 void (*class_init)(ObjectClass *klass, const void *data); @@ -1074,6 +1079,14 @@ const char *object_class_get_name(ObjectClass *klass= ); */ bool object_class_is_abstract(ObjectClass *klass); =20 +/** + * object_class_is_secure: + * @klass: The class to check security of + * + * Returns: %true if @klass is declared to be secure, %false if not declar= ed + */ +bool object_class_is_secure(ObjectClass *klass); + /** * object_class_by_name: * @typename: The QOM typename to obtain the class for. diff --git a/qom/object.c b/qom/object.c index b1834a57cc..32736a0111 100644 --- a/qom/object.c +++ b/qom/object.c @@ -67,6 +67,7 @@ struct TypeImpl void (*instance_finalize)(Object *obj); =20 bool abstract; + bool secure; =20 const char *parent; TypeImpl *parent_type; @@ -122,6 +123,7 @@ static TypeImpl *type_new(const TypeInfo *info) ti->instance_finalize =3D info->instance_finalize; =20 ti->abstract =3D info->abstract; + ti->secure =3D info->secure; =20 for (i =3D 0; info->interfaces && info->interfaces[i].type; i++) { ti->interfaces[i].typename =3D g_strdup(info->interfaces[i].type); @@ -1144,6 +1146,11 @@ bool object_class_is_abstract(ObjectClass *klass) return klass->type->abstract; } =20 +bool object_class_is_secure(ObjectClass *klass) +{ + return klass->type->secure; +} + const char *object_class_get_name(ObjectClass *klass) { return klass->type->name; --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976707; cv=none; d=zohomail.com; s=zohoarc; b=XMghSCfMsfOqhZrvV1cG2/JT9ffDheedaGoMH+KnvpyWWeIRx14hPHsjqyHE001FEQvGI824hVPpTbcmgGlQ1Evm6FFtjCeSdGuO9zDR9LEc6HPLgq3/ImiE4r4HUN5F+ZOD+a/HkiyyNDWSnuDz/b0BdIklNHoOJcLzSyI0EcQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976707; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8dNqen7734C/KjIpTumWWEJQGLX+WmNszVyJQIS8BZw=; b=LWyP39yFXHoB/wRDe6iUJNObS3l7CgBNqRuQL3HDnXV6MD/+ghdWWkQC4CswrUhY5IIaYfU4Y8fp5vZb8604+G+7bg6iUN9L6xfLIIJD66ShwCK0tSWYm3BzyuTmEp57NBPS5NR0qIAf0aPDNxwPxs/O//c6aEHApBIrfpmjMhg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976707538411.20067034004967; Wed, 9 Sep 2026 10:58:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MXr-00013K-Un; Wed, 09 Sep 2026 13:57:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXq-000131-CJ for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:14 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXo-0004c6-QZ for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:14 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-516-0WeFGdQ2P0yfpFmyMQ3nVQ-1; Wed, 09 Sep 2026 13:57:07 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B1157180061F; Wed, 9 Sep 2026 17:57:06 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 2CE83195608E; Wed, 9 Sep 2026 17:57:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976631; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=8dNqen7734C/KjIpTumWWEJQGLX+WmNszVyJQIS8BZw=; b=bZZv4rqIdy1LudbKZm/EuZiFbr5eS4NnobHUBJ9PDTJDKbFPyVfkZ9Gj6xEKsqsP/0JSZM Wv+tJ5tvl76voG+BEBAdEfgh0+OmzXa4wTUj/UVnUCM4uA5z9Gfsmr+TBo9qtFi75UjfqP ewDTETr2UYp/h3Fm2FR7NRbnyb7pHQE= X-MC-Unique: 0WeFGdQ2P0yfpFmyMQ3nVQ-1 X-Mimecast-MFC-AGG-ID: 0WeFGdQ2P0yfpFmyMQ3nVQ_1788976626 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 02/14] qapi: add 'insecure-types' option for -compat argument Date: Wed, 9 Sep 2026 18:56:44 +0100 Message-ID: <20260909175656.1572689-3-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976708408158500 This introduces a new 'insecure-types' option for the 'compat' argument that accepts three values * accept: Allow any usage * reject: Reject with an error reported * warn: Allow any usage, with a warning reported For historical compatibility it defaults to 'accept'. The 'reject' and 'warn' values will take effect for any type that has been explicitly marked insecure, or is lacking an explicit declaration of its security status. This new command line option is currently a no-op, but will become functional as following patches enable the checks. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- include/qapi/compat-policy.h | 5 +++++ qapi/compat.json | 23 ++++++++++++++++++++++- qapi/qapi-util.c | 30 ++++++++++++++++++++++++++++++ 3 files changed, 57 insertions(+), 1 deletion(-) diff --git a/include/qapi/compat-policy.h b/include/qapi/compat-policy.h index ea65e10744..f5af209069 100644 --- a/include/qapi/compat-policy.h +++ b/include/qapi/compat-policy.h @@ -24,6 +24,11 @@ bool compat_policy_input_ok(uint64_t features, const char *kind, const char *name, Error **errp); =20 +bool compat_policy_check_security(const CompatPolicy *policy, + const char *typename, + bool is_secure, + Error **errp); + /* * Create a QObject input visitor for @obj for use with QMP * diff --git a/qapi/compat.json b/qapi/compat.json index 90b8d51cf2..d57f25e112 100644 --- a/qapi/compat.json +++ b/qapi/compat.json @@ -37,6 +37,23 @@ { 'enum': 'CompatPolicyOutput', 'data': [ 'accept', 'hide' ] } =20 +## +# @CompatPolicySecurity: +# +# Policy for handling any devices or backends which do not provide a +# security boundary to protect against untrusted environments +# +# @accept: Allow any usage +# +# @reject: Reject with an error reported +# +# @warn: Allow any usage, with a warning reported +# +# Since: 10.2 +## +{ 'enum': 'CompatPolicySecurity', + 'data': [ 'accept', 'reject', 'warn' ] } + ## # @CompatPolicy: # @@ -62,10 +79,14 @@ # @unstable-output: how to handle unstable output (default 'accept') # (since 6.2) # +# @insecure-types: how to handle types that are not declared secure +# (default 'accept') (since 10.2) +# # Since: 6.0 ## { 'struct': 'CompatPolicy', 'data': { '*deprecated-input': 'CompatPolicyInput', '*deprecated-output': 'CompatPolicyOutput', '*unstable-input': 'CompatPolicyInput', - '*unstable-output': 'CompatPolicyOutput' } } + '*unstable-output': 'CompatPolicyOutput', + '*insecure-types': 'CompatPolicySecurity' } } diff --git a/qapi/qapi-util.c b/qapi/qapi-util.c index 3d849fe034..38b1cec7a4 100644 --- a/qapi/qapi-util.c +++ b/qapi/qapi-util.c @@ -14,6 +14,7 @@ #include "qapi/compat-policy.h" #include "qapi/error.h" #include "qemu/ctype.h" +#include "qemu/error-report.h" #include "qapi/qmp/qerror.h" =20 CompatPolicy compat_policy; @@ -58,6 +59,35 @@ bool compat_policy_input_ok(uint64_t features, return true; } =20 +bool compat_policy_check_security(const CompatPolicy *policy, + const char *typename, + bool is_secure, + Error **errp) +{ + if (is_secure) { + return true; + } + + switch (policy->insecure_types) { + case COMPAT_POLICY_SECURITY_ACCEPT: + return true; + + case COMPAT_POLICY_SECURITY_REJECT: + error_setg(errp, "Type '%s' does not provide a security boundary " + "to protect against untrusted data or actions", typenam= e); + return false; + + case COMPAT_POLICY_SECURITY_WARN: + warn_report("Type '%s' does not provide a security boundary " + "to protect against untrusted data or actions", typena= me); + return true; + + default: + g_assert_not_reached(); + } +} + + const char *qapi_enum_lookup(const QEnumLookup *lookup, int val) { assert(val >=3D 0 && val < lookup->size); --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976736; cv=none; d=zohomail.com; s=zohoarc; b=NJS7kxK3WtfOrv3+cKUKcHnniVsUIa85h4FPHdOEnv3vb8TngCA4F/ofVoG/8HkMplS0OmEaFXArlJF7FTxt88Ccr27tjZ7NahRZ5QW2yqHi32MvDXBiFvQsCz3moxj6Jeg9jh29wyERvQ5EjGYmM/hFWSTBbVCPkNZdvBui3w8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976736; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8CclW0PON7nJCVjhG7xjOVoR0g63Bl/7rP5zKF5rGKg=; b=LVkRwf6dMDnZydIiXmDmTk8gvaupr0TodO0AVARemGKtVRgDDYFaKuso1fKrHbnZSJJD9gVPR5zn6sB4KHPUAtxxerMSvalZyoKv9CbzlMBRU4vp055w/ODcwLUhrMlnAW0uPKdWpSyJgcda3XElnRuQdzV2dEnBnSnA2duTIZI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976736894280.2856154621745; Wed, 9 Sep 2026 10:58:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MXu-00014U-8m; Wed, 09 Sep 2026 13:57:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXs-00013L-Ae for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:16 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXq-0004cK-NX for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:16 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-689-K3rIcHfQP0KqiohKtlUe6A-1; Wed, 09 Sep 2026 13:57:10 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 755931800BC8; Wed, 9 Sep 2026 17:57:09 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0D8A9195608C; Wed, 9 Sep 2026 17:57:06 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976633; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=8CclW0PON7nJCVjhG7xjOVoR0g63Bl/7rP5zKF5rGKg=; b=KI1+ga6K7dFd0RBtZicA7t1ql1eoiBkDndBDCSsRJgB9Ax9aUwnt+6ihl3ogKN4klZ5fGK jI/4IdbsRyawZ0g7PjO344c5/624FsN5ZzQ/DzoJxQnsvnGJ5e8ZelSB6obIBgmNhYEXkB RezXWJbfHtFq72c3lNfjl5CBvejwNNM= X-MC-Unique: K3rIcHfQP0KqiohKtlUe6A-1 X-Mimecast-MFC-AGG-ID: K3rIcHfQP0KqiohKtlUe6A_1788976629 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 03/14] qom: add helper APIs for checking object security policy compliance Date: Wed, 9 Sep 2026 18:56:45 +0100 Message-ID: <20260909175656.1572689-4-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976738575158500 These helpers simply avoid a verbose code pattern being repeated for many callers. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- include/qom/object.h | 26 ++++++++++++++++++++++++++ qom/object.c | 15 +++++++++++++++ 2 files changed, 41 insertions(+) diff --git a/include/qom/object.h b/include/qom/object.h index 687ceb6bba..3b83ceb7b1 100644 --- a/include/qom/object.h +++ b/include/qom/object.h @@ -2405,6 +2405,32 @@ Object *object_property_add_new_container(Object *ob= j, const char *name); char *object_property_help(const char *name, const char *type, QObject *defval, const char *description); =20 +/** + * object_class_check_security: + * @klass: the object class to check + * @errp: a pointer to an Error that is filled if not compliant + * + * Check whether the object class @klass complies with the + * currently requested security policy. Reports an error + * in @errp if not compliant. + * + * Returns: true if compliant, false if an error was raised + */ +bool object_class_check_security(ObjectClass *klass, Error **errp); + +/** + * object_check_security: + * @obj: the object instance to check + * @errp: a pointer to an Error that is filled if not compliant + * + * Check whether the object @obj complies with the + * currently requested security policy. Reports an + * error in @errp if not compliant. + * + * Returns: true if compliant, false if an error was raised + */ +bool object_check_security(Object *obj, Error **errp); + G_DEFINE_AUTOPTR_CLEANUP_FUNC(Object, object_unref) =20 #endif diff --git a/qom/object.c b/qom/object.c index 32736a0111..2c93c17802 100644 --- a/qom/object.c +++ b/qom/object.c @@ -23,6 +23,7 @@ #include "qapi/qobject-input-visitor.h" #include "qapi/forward-visitor.h" #include "qapi/qapi-builtin-visit.h" +#include "qapi/compat-policy.h" #include "qobject/qdict.h" #include "qobject/qjson.h" #include "qemu/id.h" @@ -3149,6 +3150,20 @@ void object_class_property_set_description(ObjectCla= ss *klass, op->description =3D g_strdup(description); } =20 +bool object_class_check_security(ObjectClass *klass, Error **errp) +{ + return compat_policy_check_security(&compat_policy, + object_class_get_name(klass), + object_class_is_secure(klass), + errp); +} + +bool object_check_security(Object *obj, Error **errp) +{ + ObjectClass *klass =3D OBJECT_CLASS(obj); + return object_class_check_security(klass, errp); +} + static void object_class_init(ObjectClass *klass, const void *data) { object_class_property_add_str(klass, "type", object_get_type, --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976701; cv=none; d=zohomail.com; s=zohoarc; b=PyK0f2JtyHdoYKDXdszWq6abHQyTw5xNPGbZP7HN2D3uDPPOyOYfdbCHjlBRlaMgwQt9mmx6IclpfxbvgiTttFDZmHOEgAxu0ff0DSCbEgQTz66LWye8Skvdk5TWVIa2QqQa/fu0YabQ1WgfGG1Sya7G89DFZrnbbWfW/X3u5y4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976701; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yHRcM+f+qh3837ppHP4zrC+XzjGtSY5yOhH9gpZDcdU=; b=UokwBTUGKpLueYkj8kJXBgV2DEkqYZuAsnFRTzRfGabghKrKKgIjZjjrByWQMC1cJgVGpyEkTw4Vi9KuDvuqO5R6IE4Qf33w11kBO2M6Mjz2GihA8FK+hyd7XNfHu+xPt4pXBbstiTRFeukuoanigWFx2OdctehnBlAx1k3KPeQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976701796372.5276482589726; Wed, 9 Sep 2026 10:58:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MXy-00016s-L8; Wed, 09 Sep 2026 13:57:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXw-00016a-1E for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:20 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXu-0004cZ-Lw for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:19 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-67-0urfthlEMaKYGvHa_4Pfcg-1; Wed, 09 Sep 2026 13:57:13 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7064F1800632; Wed, 9 Sep 2026 17:57:12 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 28489195608E; Wed, 9 Sep 2026 17:57:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976636; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=yHRcM+f+qh3837ppHP4zrC+XzjGtSY5yOhH9gpZDcdU=; b=SDd5HNMOH3thjAz4UNM6P485jkIcc4IemZL9YKRaSiAXSEZQxGMDv3y9x5/3bVo0bcx1n5 DLmyx4jutUAbaAssz8xJveWjIbc60o+ZY4djvLHy5+TfqR0MGNr2JfQFlRLbyhDutfKx9u 8gbgWUt8AJXThbLZkvhH8YIjFacGnQM= X-MC-Unique: 0urfthlEMaKYGvHa_4Pfcg-1 X-Mimecast-MFC-AGG-ID: 0urfthlEMaKYGvHa_4Pfcg_1788976632 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 04/14] system: check security for accelerator types Date: Wed, 9 Sep 2026 18:56:46 +0100 Message-ID: <20260909175656.1572689-5-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976702403158500 This wires up the accelerator creation code to apply the compat policy security check. When multiple -accel options are given, normal fallback logic applies. IOW, if one is rejected by the security check, it will carry on to try the next accelerator until one passes the security check. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- system/vl.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/system/vl.c b/system/vl.c index 9bd7664b85..0c6e44f21c 100644 --- a/system/vl.c +++ b/system/vl.c @@ -2412,6 +2412,11 @@ static int do_configure_accelerator(void *opaque, Qe= muOpts *opts, Error **errp) } goto bad; } + + if (!object_class_check_security(OBJECT_CLASS(ac), errp)) { + goto bad; + } + accel =3D ACCEL(object_new_with_class(OBJECT_CLASS(ac))); object_apply_compat_props(OBJECT(accel)); qemu_opt_foreach(opts, accelerator_set_property, --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976707; cv=none; d=zohomail.com; s=zohoarc; b=eu1NKdvYfSwG2L1Ufb/RdWhelrZHprJCUQjf+bSQno0+YuiChC+nIouyS13JcFO1yhtcc/Tn0hTk5oV4utimC6zPdhReXpgjUDt5OdPOnGSKq7JmZ36I+ScVJz4ACBmMq7r/jmQvzRwZlFhve0WBMHo08xDjYeQCHeUKhlpjfFU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976707; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=c0jrRY8hYU69CSl6yV6zH5g6wWqnIG9J42LG3y7YnKk=; b=OMi1QuAKAbmedMzVc+0oiUEDPPM6oC95kspApTsNDuAzIuvBhOgKo3K09qUGgv7eHPC2PQ7+0pKPnLLaHsYlhh78+8MtkykyhV24s7s0ocEFPdMMpyp8PB2kswvnTe+6FHNS3wW5twcxjQm2I8Ifu/4UuPVQg2GCKQ1GuQSEf4o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976707621478.20948461785974; Wed, 9 Sep 2026 10:58:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MXz-00017T-Nr; Wed, 09 Sep 2026 13:57:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXx-00016v-Ur for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:22 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXw-0004dh-Lq for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:21 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-411-nWrLd16oML-hI2p7XvU_6Q-1; Wed, 09 Sep 2026 13:57:16 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 14E2E19540C8; Wed, 9 Sep 2026 17:57:15 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id BB077195608C; Wed, 9 Sep 2026 17:57:12 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976639; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=c0jrRY8hYU69CSl6yV6zH5g6wWqnIG9J42LG3y7YnKk=; b=gQnJijFtZtTzD0YVjsTqt0qLNi6iFHzSaTDOUVcdkpF9ISbqCGZAmdEL57tpcSyXkOMIG2 /meowqXVZQJgZm7yDNZasjAFRzCcb/NABmuF2UueRSX6WnCpbR0KMH4Rw/x7kBnaEoRKpC qlSPRsHdXaSbTaa/Jjamkn90KvkPQ8g= X-MC-Unique: nWrLd16oML-hI2p7XvU_6Q-1 X-Mimecast-MFC-AGG-ID: nWrLd16oML-hI2p7XvU_6Q_1788976635 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 05/14] system: report acclerator security status in help output Date: Wed, 9 Sep 2026 18:56:47 +0100 Message-ID: <20260909175656.1572689-6-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976708341158500 When '-accel help' is given, report the security status of each accelerator. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- system/vl.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/system/vl.c b/system/vl.c index 0c6e44f21c..ca54da26c5 100644 --- a/system/vl.c +++ b/system/vl.c @@ -3451,7 +3451,10 @@ void qemu_init(int argc, char **argv) g_str_has_suffix(typename, ACCEL_CLASS_SUFFIX)= ) { gchar **optname =3D g_strsplit(typename, ACCEL_CLASS_SUFFI= X, 0); - printf("%s\n", optname[0]); + printf("%s%s\n", optname[0], + object_class_is_secure( + OBJECT_CLASS(el->data)) ? + " (secure)" : ""); g_strfreev(optname); } g_free(typename); --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976695; cv=none; d=zohomail.com; s=zohoarc; b=iICIMNdv4plRv9XZBDqZEaYpR8Rte+nWEUrSrrWMxq+oDTgsr20vgbkNDLubv40cw0GU1SgzBeQbCJTaD7TNnakNydOJDpbZwtcyZAM/KZcn8C2BK9d3IosEb9aeWjzAaCKKnQ5YfAAoLBZUlBhAA0nI6FCr0o0+SFM7ipb/Hq0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976695; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4v3mW10Ipprj3R5TPPbrP6YSI8nMwCr8UrUntQ//omc=; b=acIZCvbxyWS4YEU/DkwU/rAvL/66sxRKnpdqdbC7JHO++B2pQj0Vq2tS3heo5afQAxfCsBV9bTCI8fqW6+l9yaHK5u3/OJITW3zoY4GTRRdljm9KWsWKKKylPJ/OXnPRsjl7qA1DRj8/vll/nkWWFzEc8lwVAd3pMp7p/QynAwQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976695169989.8201499163139; Wed, 9 Sep 2026 10:58:15 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MY1-00017k-3S; Wed, 09 Sep 2026 13:57:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MY0-00017U-2J for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:24 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXy-0004eB-IL for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:23 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-486-m5p7TfRPNRSQQwa2za5taQ-1; Wed, 09 Sep 2026 13:57:19 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 3E8701955F3D; Wed, 9 Sep 2026 17:57:18 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 67C5C195608C; Wed, 9 Sep 2026 17:57:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976641; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=4v3mW10Ipprj3R5TPPbrP6YSI8nMwCr8UrUntQ//omc=; b=QA3p3vqsxyv4TEhxJzaC6EkHElvS3n+xfs0WSSH+OcyHhWdodNv7lBuTtDsvW3PqM52HUZ B+bxbK2SOggeCmkVHFcbh4yc+fUP5qDQm9utOhGrHaARXwCI7GvrnWRQOwvLMrfkmnY+mR wVle5F2pWBG8gFDEmn1oUh6/lXXov8c= X-MC-Unique: m5p7TfRPNRSQQwa2za5taQ-1 X-Mimecast-MFC-AGG-ID: m5p7TfRPNRSQQwa2za5taQ_1788976638 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 06/14] system: check security for machine types Date: Wed, 9 Sep 2026 18:56:48 +0100 Message-ID: <20260909175656.1572689-7-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976696261158500 This wires up the machine creation code to apply the compat policy security check. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- system/vl.c | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/system/vl.c b/system/vl.c index ca54da26c5..f54449b43e 100644 --- a/system/vl.c +++ b/system/vl.c @@ -2201,11 +2201,18 @@ static void qemu_create_machine_containers(Object *= machine) } } =20 -static void qemu_create_machine(QDict *qdict) +static bool qemu_create_machine(QDict *qdict) { + Error *local_err =3D NULL; MachineClass *machine_class =3D select_machine(qdict, &error_fatal); object_set_machine_compat_props(machine_class->compat_props); =20 + if (!object_class_check_security(OBJECT_CLASS(machine_class), + &local_err)) { + error_report_err(local_err); + return false; + } + current_machine =3D MACHINE(object_new_with_class(OBJECT_CLASS(machine= _class))); object_property_add_child(object_get_root(), "machine", OBJECT(current_machine)); @@ -2237,6 +2244,8 @@ static void qemu_create_machine(QDict *qdict) false, &error_abort); qobject_unref(default_opts); } + + return true; } =20 static int global_init_func(void *opaque, QemuOpts *opts, Error **errp) @@ -3790,7 +3799,9 @@ void qemu_init(int argc, char **argv) /* Transfer QemuOpts options into machine options */ parse_memory_options(); =20 - qemu_create_machine(machine_opts_dict); + if (!qemu_create_machine(machine_opts_dict)) { + exit(1); + } =20 /* * Load incoming CPR state before any devices are created, because it --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976689; cv=none; d=zohomail.com; s=zohoarc; b=BtseeamNLNITYSQZjnGCzdVxPOvbPoLkANFAPQfieeNNhf6Nd4fH/HhwfqhQ6M1/6oOLMaFwdlDFitUhOx/vI5R6Hdt+VIy1+MPzi6UUp1pzlnFocfojXbv4/DadLBS3foqz/MA71AxMiJEa1NBb2GyB7VN/rw2EVfRJnqj4n6c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976689; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hMTl/SX9gFM63yifEKPck5QKtEk2WlR7xHGwQ5+8qpM=; b=ZVOj5k1bD5+RND0OIFynhul6luMwTXFLDVg7NgJLGo7oau0pka3FPIK0P+gquJPD4ILRdGBxiT5LOhh3EUuHcpJZJfLLGFN4UwyALtA7bhKbxDqej+3HTJbiVva3MyWQLdp80Bp0G9CvFRsRGZNAVDwUTQ9R0BKNmNa5CZ1i+ZI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976689712471.36415793193714; Wed, 9 Sep 2026 10:58:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MY5-00018v-Vf; Wed, 09 Sep 2026 13:57:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MY3-00018M-Mt for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:27 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MY2-0004eV-1O for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:27 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-306-pY0QCtZUN8qLUqrc6Q84hg-1; Wed, 09 Sep 2026 13:57:22 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 0CB3A1800EFE; Wed, 9 Sep 2026 17:57:21 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id C22A4195608C; Wed, 9 Sep 2026 17:57:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976645; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=hMTl/SX9gFM63yifEKPck5QKtEk2WlR7xHGwQ5+8qpM=; b=YHEuo0TO63tu5vlnAA7hwMxL9xQuhbDh/QCKZr4z/2IBR8ZwMlHkHAO4wCgj8ZyycmtZ+y ATq+sjeGoPuoZTbGGIPj/v+pv3RDvknCyrcqQ1OM4IBH/hSoHZ8P+GpUeVzg/fFH2VKRTj +TaN1QgzJ1jem6W5IxdVtaW11NCrbEo= X-MC-Unique: pY0QCtZUN8qLUqrc6Q84hg-1 X-Mimecast-MFC-AGG-ID: pY0QCtZUN8qLUqrc6Q84hg_1788976641 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 07/14] system: report machine security status in help output Date: Wed, 9 Sep 2026 18:56:49 +0100 Message-ID: <20260909175656.1572689-8-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976690197158500 When '-machine help' is given, report the security status of each machine. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- system/vl.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/system/vl.c b/system/vl.c index f54449b43e..468a9fc247 100644 --- a/system/vl.c +++ b/system/vl.c @@ -1586,9 +1586,10 @@ static void machine_help_func(const QDict *qdict) if (mc->alias) { printf("%-20s %s (alias of %s)\n", mc->alias, mc->desc, mc->na= me); } - printf("%-20s %s%s%s\n", mc->name, mc->desc, + printf("%-20s %s%s%s%s\n", mc->name, mc->desc, mc->is_default ? " (default)" : "", - mc->deprecation_reason ? " (deprecated)" : ""); + mc->deprecation_reason ? " (deprecated)" : "", + object_class_is_secure(OBJECT_CLASS(mc)) ? " (secure)" : ""= ); } } =20 --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976685; cv=none; d=zohomail.com; s=zohoarc; b=SUniiQcKP81+xKIMN//qPlLlL9Tundv4SSyXAGtwe4s43/zVYTPEeZgZ5MMi6R0bRI+O70Dg/Vf3zveC97urttqPB1t1nD5SIzPRfNXxos1GhQXuhakDQcj8we4mxnqJsfhDmB/PDSGirAHvKGQ2DWqNs4Gya7zQjcYAXpMp04c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976685; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yyugIe4QkYlJ3sXHCa1ll3cA7L2XvQ9gexEgkD1qec0=; b=GrVZPsYTUBunp0RvKH6Cvv9wgb7mpOp06lx+Io4GEPDTAxTJL+2g+UP1MYONNnnooB/2ZBZfAxciWZREiGHGGibO+JZ4lXb2V17ujsKGZsd83TFYH1mnBUaXxC7JosqS3ih/1Qh8XezRFLFcBioSKFFS9tybwaRcwGvCgrYvzRI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976685793568.9560547546114; Wed, 9 Sep 2026 10:58:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MY5-00018u-V6; Wed, 09 Sep 2026 13:57:29 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MY4-00018Z-8X for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:28 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MY2-0004eb-RA for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:28 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-655-QBR6_CZwOh6Obocr3Xm78A-1; Wed, 09 Sep 2026 13:57:24 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 9DBD31956095; Wed, 9 Sep 2026 17:57:23 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 5ED9A195608C; Wed, 9 Sep 2026 17:57:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976646; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=yyugIe4QkYlJ3sXHCa1ll3cA7L2XvQ9gexEgkD1qec0=; b=PAGYV2To6Ahh6fUSmj14QkGgEMn1VYVFb+5TbmKWmZv+3VW3VAvBjvclUh2v+9HLap4dRj Z/VGOCdFo/TgQ0UeY+ZHUFEfSQKfSmCKgjjCmMDS1bokDJ/EjqAVUsiBQymGoXHLxk3vEn +lmGnjI0562sN5Ji6d8ZMaQaneHKucY= X-MC-Unique: QBR6_CZwOh6Obocr3Xm78A-1 X-Mimecast-MFC-AGG-ID: QBR6_CZwOh6Obocr3Xm78A_1788976643 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 08/14] system: check security of device types Date: Wed, 9 Sep 2026 18:56:50 +0100 Message-ID: <20260909175656.1572689-9-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976692297158500 This wires up the DeviceClass types to have their security checked when devices are created. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- system/qdev-monitor.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/system/qdev-monitor.c b/system/qdev-monitor.c index 5c87fda509..a69dbf802f 100644 --- a/system/qdev-monitor.c +++ b/system/qdev-monitor.c @@ -672,6 +672,10 @@ DeviceState *qdev_device_add_from_qdict(const QDict *o= pts, return NULL; } =20 + if (!object_class_check_security(OBJECT_CLASS(dc), errp)) { + return NULL; + } + /* find bus */ path =3D qdict_get_try_str(opts, "bus"); if (path !=3D NULL) { --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976728; cv=none; d=zohomail.com; s=zohoarc; b=gssjG3CVUtq8rp6lG1huYG+4c5fktwLwe3TP/pf5saHhBIqr3OvoYToe7O39SVUQS3nC3UBX+7VRuqzAAIOI6W11llzT2mtpvgDqjqy+k9NUo/V2m6a9qwVwgWeBGkNWmxjEPgYgX8Xth0jgebuUmCMcq+owxfWS6rvy56QbX/Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976728; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=+FDTGVYGQDSXOee1XoAMtsBsUXccfmzu4JIuTZxV03U=; b=i3EgptUO75vtxdu80fdRkCNuTmKJL5o7jGTZd22ICIzqBeRxRDhoSap19cnaSJ8+o4R5RXXw2jXlX7i2ot9kmdN2RURPEOaDgQPGbIzUffiwjy/mL6NnG3teNuuEXx54qFYSxa2yWexpeynI/qY+C3kysKzgMNoAioQyisj0yDQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976728451313.07353511126917; Wed, 9 Sep 2026 10:58:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MY7-0001BE-DV; Wed, 09 Sep 2026 13:57:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MY6-00019Y-Om for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:30 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MY5-0004eu-Cm for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:30 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-651-iZ1wPXiiOO-rwBCSM0gr-g-1; Wed, 09 Sep 2026 13:57:27 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 2D9E818001E1; Wed, 9 Sep 2026 17:57:26 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0080E195608C; Wed, 9 Sep 2026 17:57:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976648; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=+FDTGVYGQDSXOee1XoAMtsBsUXccfmzu4JIuTZxV03U=; b=EegfvZRdpvhl69qeT6r8+LQ43awKUcEwcOghDzFWAJPDnGgBLK3iPnb2rspMMNO8s8GZwN YGtqln+HXUdGZk6BZdAK6X+dsyFrz8hLipShgX8OM4yQh+SV4lYWoNWU3rkozcj2Je8+2a hKWp1+sETNq10KrCb7m0krgUnBKA60E= X-MC-Unique: iZ1wPXiiOO-rwBCSM0gr-g-1 X-Mimecast-MFC-AGG-ID: iZ1wPXiiOO-rwBCSM0gr-g_1788976646 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 09/14] system: report device security status in help output Date: Wed, 9 Sep 2026 18:56:51 +0100 Message-ID: <20260909175656.1572689-10-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976730504158500 When '-device help', 'device_add help' and 'info qdm' are used, report the security status of each device. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- system/qdev-monitor.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/system/qdev-monitor.c b/system/qdev-monitor.c index a69dbf802f..2120292fd5 100644 --- a/system/qdev-monitor.c +++ b/system/qdev-monitor.c @@ -166,6 +166,9 @@ static void qdev_print_devinfo(DeviceClass *dc) if (!dc->user_creatable) { qemu_printf(", no-user"); } + if (object_class_is_secure(OBJECT_CLASS(dc))) { + qemu_printf(", secure"); + } qemu_printf("\n"); } =20 --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976677; cv=none; d=zohomail.com; s=zohoarc; b=nxr5zjrKzsJ8aXzshfct+Gcz6Vq5mwMs5SVLraq7VhdNGjtXxm+Jx8kljI51IqoY4itzEJG2OxRa1lx3jHvwlpN3r3QeblAw2HHPUUe+qyW+cQ5KNK01lhJWX45Db17u8BAU+Oy4zSjbvVdzgs23o7N8nkCF2oKnWOTMlhNAopw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976677; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=NfFoqhkVGFU+6bnehh5K+UVdsmypJJUyRfJ+s8P0ttE=; b=L3B5Ku4gJJJkNTPogqxGXldCSb1dsruFzf5h1hL7feuvh7Db8KK7zdTg/9JzOgLdPm1/nWY1gZa/dl4SjDtk19ZMUuiWbkB6qbq3B9+C6piUhf5BLLwrVS2Wl41OFxKy+bAG/Al2UPM2y3c/WYOGQLDyKZY/vXfAkWVqZUCnYw4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976677468107.13413057964283; Wed, 9 Sep 2026 10:57:57 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MYD-0001LC-4e; Wed, 09 Sep 2026 13:57:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MYB-0001Dp-Cc for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:35 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MY9-0004fK-Tr for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:35 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-605-7M50VGy7MVuSBEGDJsRpsQ-1; Wed, 09 Sep 2026 13:57:29 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id A27D91800666; Wed, 9 Sep 2026 17:57:28 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 7F5C1195608C; Wed, 9 Sep 2026 17:57:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976653; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=NfFoqhkVGFU+6bnehh5K+UVdsmypJJUyRfJ+s8P0ttE=; b=Cnef7ZmwpNaWwY2MFneBmuT7TmnuPIPKdmSz4sAq4d1lZ65/gv6s4yp+2MK9fgfOvgfpo9 tQOl2rGRb3UAAQBhGgacGWHj7X8XMmiF6fQC5LxKBYeJxkCVwI8BTrv2Y6G81yTRBOyPFu kiz8IAeRQv5xFpHe4it0PedJcfmTXIk= X-MC-Unique: 7M50VGy7MVuSBEGDJsRpsQ-1 X-Mimecast-MFC-AGG-ID: 7M50VGy7MVuSBEGDJsRpsQ_1788976648 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 10/14] hw/core: report security status in query-machines Date: Wed, 9 Sep 2026 18:56:52 +0100 Message-ID: <20260909175656.1572689-11-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976678261158500 Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- hw/core/machine-qmp-cmds.c | 1 + qapi/machine.json | 8 +++++++- 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/hw/core/machine-qmp-cmds.c b/hw/core/machine-qmp-cmds.c index 543dd3201b..9c08b17510 100644 --- a/hw/core/machine-qmp-cmds.c +++ b/hw/core/machine-qmp-cmds.c @@ -127,6 +127,7 @@ MachineInfoList *qmp_query_machines(bool has_compat_pro= ps, bool compat_props, if (mc->default_ram_id) { info->default_ram_id =3D g_strdup(mc->default_ram_id); } + info->secure =3D object_class_is_secure(OBJECT_CLASS(mc)); =20 if (compat_props && mc->compat_props) { int i; diff --git a/qapi/machine.json b/qapi/machine.json index 2d63c1bac3..942db9a52b 100644 --- a/qapi/machine.json +++ b/qapi/machine.json @@ -196,6 +196,11 @@ # present when `query-machines` argument @compat-props is true. # (since 9.1) # +# @secure: If true, the machine is declared to provide a security +# boundary from the guest; if false the machine is either +# not providing a security boundary, or its status is undefined. +# (since 11.1) +# # Features: # # @unstable: Member @compat-props is experimental. @@ -209,7 +214,8 @@ 'deprecated': 'bool', '*default-cpu-type': 'str', '*default-ram-id': 'str', 'acpi': 'bool', '*compat-props': { 'type': ['CompatProperty'], - 'features': ['unstable'] } } } + 'features': ['unstable'] }, + 'secure': 'bool' } } =20 ## # @query-machines: --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976672; cv=none; d=zohomail.com; s=zohoarc; b=KVSFJLcB+g/95c22IDqpx3qnSTweHOHsmguyciqMwoGlMYiEcZ85vFSKAMnHhJafjGyU9muPZT3bZxDLrNPfXJThgAyWb4jhr3t1x1ezeeuI2qrm0A2tUrZE6k5epHz0Ps4hLKBYKTgKfrZEcFFXOhD2sAQ0f+DcOKgXinj1fD4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976672; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=flh/980jnVpAPZkwsbO31P26l76jqDtGML7jbwkAhzg=; b=m5TwwMG8CXp21OpyaUNyL+dQIZg8ZWXvdIp1xjZH06uiormQOZ2AXxmFRtSBTembSqY5qd/Lf3F7megA+LLKyDPtjEx4a/CevzPSozKyVIZGNw2Bi7or/3x0XOln57CLjrU3KokY9II3ZoObu5yAbaYFOFI0sJTemd4GQvZz0s0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976672042238.20244881199426; Wed, 9 Sep 2026 10:57:52 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MYF-0001Tc-Em; Wed, 09 Sep 2026 13:57:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MYD-0001Ol-NI for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:37 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MYC-0004fa-6J for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:37 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-528-igZlxwm4OJGCgzoE2Q1aZg-1; Wed, 09 Sep 2026 13:57:32 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 22A2B1956042; Wed, 9 Sep 2026 17:57:31 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id F33A0195608C; Wed, 9 Sep 2026 17:57:28 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976655; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=flh/980jnVpAPZkwsbO31P26l76jqDtGML7jbwkAhzg=; b=heO+1EWV664QUrHaSX3tVRSise0a552UUIOkP6UJ/vlppNTZU9EeyeoRsPtT1GNo1dFYyK 1RBd7NCd4BJBPe1geGTc4J+s852zGg2w6HOnN5szIt7IBrWwAYmHb5NP6rUHjXQ3B/6+bJ tS+lUOB/hy1TXATIxd8dXcpqnndYbZE= X-MC-Unique: igZlxwm4OJGCgzoE2Q1aZg-1 X-Mimecast-MFC-AGG-ID: igZlxwm4OJGCgzoE2Q1aZg_1788976651 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 11/14] qom: refactor data passing for QOM list filtering Date: Wed, 9 Sep 2026 18:56:53 +0100 Message-ID: <20260909175656.1572689-12-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976674114158500 Currently the QOM list method can filter on the abstract flag, but extending the filtering to more variables requires a way to pass in extra data items. This requires a refactoring of the iterator to take a full struct as its opaque data item. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- qom/qom-qmp-cmds.c | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/qom/qom-qmp-cmds.c b/qom/qom-qmp-cmds.c index 330895361d..b999e9f723 100644 --- a/qom/qom-qmp-cmds.c +++ b/qom/qom-qmp-cmds.c @@ -151,9 +151,13 @@ QObject *qmp_qom_get(const char *path, const char *pro= perty, Error **errp) return object_property_get_qobject(obj, property, errp); } =20 -static void qom_list_types_tramp(ObjectClass *klass, void *data) +typedef struct { + ObjectTypeInfoList *list; +} ObjectTypeInfoData; + +static void qom_list_types_tramp(ObjectClass *klass, void *opaque) { - ObjectTypeInfoList **pret =3D data; + ObjectTypeInfoData *data =3D opaque; ObjectTypeInfo *info; ObjectClass *parent =3D object_class_get_parent(klass); =20 @@ -164,7 +168,7 @@ static void qom_list_types_tramp(ObjectClass *klass, vo= id *data) info->parent =3D g_strdup(object_class_get_name(parent)); } =20 - QAPI_LIST_PREPEND(*pret, info); + QAPI_LIST_PREPEND(data->list, info); } =20 ObjectTypeInfoList *qmp_qom_list_types(const char *implements, @@ -172,12 +176,14 @@ ObjectTypeInfoList *qmp_qom_list_types(const char *im= plements, bool abstract, Error **errp) { - ObjectTypeInfoList *ret =3D NULL; + ObjectTypeInfoData data =3D { + .list =3D NULL, + }; =20 module_load_qom_all(); - object_class_foreach(qom_list_types_tramp, implements, abstract, &ret); + object_class_foreach(qom_list_types_tramp, implements, abstract, &data= ); =20 - return ret; + return data.list; } =20 ObjectPropertyInfoList *qmp_device_list_properties(const char *typename, --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976682; cv=none; d=zohomail.com; s=zohoarc; b=nNrdPEuOMvoqhfZtiIVVWOf4nLzBer74LuSSBUDNtFF611v2r70yIKPe25QsYrc8mFV295zbNdeQQkztE93ImXjI6+FIY09Yvia+7FUdU8OVgQR3ryoSP79N4fE2L6DjcQFHEukrOkw3UxJnhtDwas1WdFTEFU6eDei5b8+KcuA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976682; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GsNUUYqdAiPllVlkaaPa7kwn8XDQOV08WDQ69+ppcqk=; b=JcA6PbVdVAZP2H68cX1AvG687Ei6sOHET/XSBu0Y2OR1f7M4oinLP5ZONNnPyXqPrK116aPR06rXde/4ASV8TKTHynPtnQt+TJAimRq8lLteEFVoO7YWX21R0ijoabgf+9IO4VjkOEa7fgysFEHT8WvDbhGx8fedYE0wtIGuo9o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178897668292385.55833094282514; Wed, 9 Sep 2026 10:58:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MYG-0001WT-RH; Wed, 09 Sep 2026 13:57:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MYE-0001T3-VI for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:38 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MYD-0004g2-By for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:38 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-520-geUk3rm7N5atcQfDoaUGLQ-1; Wed, 09 Sep 2026 13:57:35 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 4F85D1956050; Wed, 9 Sep 2026 17:57:34 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 76256195608C; Wed, 9 Sep 2026 17:57:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976656; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=GsNUUYqdAiPllVlkaaPa7kwn8XDQOV08WDQ69+ppcqk=; b=dYvQfNekxliXBs+rL5WvweNiJAEkE/c7ZgNgzgWyt5MGrm0ycvqA9DGPE3TmpLmpnuDBfX wWpC/5OedPyPZTzcxxa/VQwJfTN8UgLzIQxyM0Z9k1SJvhLlTkQjm+NCTr1qR8KQEzhBl7 00rKCDY/GW3YHcHd0pPjsNfrUVb+Go8= X-MC-Unique: geUk3rm7N5atcQfDoaUGLQ-1 X-Mimecast-MFC-AGG-ID: geUk3rm7N5atcQfDoaUGLQ_1788976654 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 12/14] qom: report & filter on security status in qom-list-types Date: Wed, 9 Sep 2026 18:56:54 +0100 Message-ID: <20260909175656.1572689-13-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976684286158500 This adds: * a new boolean 'secure' field to the type info returned by qom-list-types, which will be set if the type provides a security boundary * a new boolean 'secure' parameter to the arguments of qom-list-types, which can be used to filter types based on their security status Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- qapi/qom.json | 13 +++++++++++-- qom/qom-qmp-cmds.c | 12 ++++++++++++ 2 files changed, 23 insertions(+), 2 deletions(-) diff --git a/qapi/qom.json b/qapi/qom.json index 4a9b7f9088..b14f063144 100644 --- a/qapi/qom.json +++ b/qapi/qom.json @@ -210,12 +210,18 @@ # @abstract: the type is abstract and can't be directly instantiated. # Omitted if false. (since 2.10) # +# @secure: the type provides a security boundary. Omitted if false. +# (since 11.2) +# # @parent: Name of parent type, if any (since 2.10) # # Since: 1.1 ## { 'struct': 'ObjectTypeInfo', - 'data': { 'name': 'str', '*abstract': 'bool', '*parent': 'str' } } + 'data': { 'name': 'str', + '*abstract': 'bool', + '*parent': 'str', + '*secure': 'bool' } } =20 ## # @qom-list-types: @@ -227,12 +233,15 @@ # # @abstract: if true, include abstract types in the results # +# @secure: if set, filter to only include types with matching security +# status (since 11.1) +# # Returns: a list of types, or an empty list if no results are found # # Since: 1.1 ## { 'command': 'qom-list-types', - 'data': { '*implements': 'str', '*abstract': 'bool' }, + 'data': { '*implements': 'str', '*abstract': 'bool', '*secure': 'bool' }, 'returns': [ 'ObjectTypeInfo' ], 'allow-preconfig': true } =20 diff --git a/qom/qom-qmp-cmds.c b/qom/qom-qmp-cmds.c index b999e9f723..9474a1b04b 100644 --- a/qom/qom-qmp-cmds.c +++ b/qom/qom-qmp-cmds.c @@ -153,6 +153,8 @@ QObject *qmp_qom_get(const char *path, const char *prop= erty, Error **errp) =20 typedef struct { ObjectTypeInfoList *list; + bool has_secure; + bool secure; } ObjectTypeInfoData; =20 static void qom_list_types_tramp(ObjectClass *klass, void *opaque) @@ -161,9 +163,15 @@ static void qom_list_types_tramp(ObjectClass *klass, v= oid *opaque) ObjectTypeInfo *info; ObjectClass *parent =3D object_class_get_parent(klass); =20 + if (data->has_secure && + data->secure !=3D object_class_is_secure(klass)) { + return; + } + info =3D g_malloc0(sizeof(*info)); info->name =3D g_strdup(object_class_get_name(klass)); info->has_abstract =3D info->abstract =3D object_class_is_abstract(kla= ss); + info->has_secure =3D info->secure =3D object_class_is_secure(klass); if (parent) { info->parent =3D g_strdup(object_class_get_name(parent)); } @@ -174,10 +182,14 @@ static void qom_list_types_tramp(ObjectClass *klass, = void *opaque) ObjectTypeInfoList *qmp_qom_list_types(const char *implements, bool has_abstract, bool abstract, + bool has_secure, + bool secure, Error **errp) { ObjectTypeInfoData data =3D { .list =3D NULL, + .has_secure =3D has_secure, + .secure =3D secure, }; =20 module_load_qom_all(); --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976711; cv=none; d=zohomail.com; s=zohoarc; b=dvakD7TcV3SDU3LvEOklO02DS1j7xe7yzqK7k3BAEV2u4XnqNl+PxGth/Y2lFOYeHrlf89a9hgLqLWwYhfUffoJcB6sxWBnVqWDnaijsoWD6eshizY/9MqtbtbrT6SsKe5ZwQvEc0Wftm86B5mbyGx3jxtQXYHwYzazI1XjLuDk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976711; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3m1BmB7PtZ2wtk+yN1uo6hLU4XrJC8ervwBC9Yx/mJ8=; b=f84mJCdHsdKGNhJh4oyVF/BWN+4iLDHnR2gohY+XQGh4g7CWtkJSEIYfNbWJGA470JsWy8rJPYYwcrV7evMpAhUhOIdm25bcbQhnFwKWrpLef5sspjmx8bogIkhQlAR1Tj10C1FqGVj8nd03HJlzE7lI7/C1F/cfLRKoDPpwdS0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976711504189.122362625331; Wed, 9 Sep 2026 10:58:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MYL-0001dv-9G; Wed, 09 Sep 2026 13:57:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MYJ-0001bZ-Gu for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:43 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MYI-0004gW-0p for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:43 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-690-aWPYew8tOXaZyvvRXnitIg-1; Wed, 09 Sep 2026 13:57:37 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C59C219541A4; Wed, 9 Sep 2026 17:57:36 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id A26EF195608C; Wed, 9 Sep 2026 17:57:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976661; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=3m1BmB7PtZ2wtk+yN1uo6hLU4XrJC8ervwBC9Yx/mJ8=; b=NfEW4jSfcKnepKbiIzuTEi9YFF4zdNX736Okd9iOOlVHa0RKNgE/UHZgoMsz5XzCT0qbOP /xHy+ZZ1zQ7vVDHtXmrhOqwwJdgJCU7fFNBitGCIT3hMKlgSvzvcMUw74U9ycqM7UvdFKm OceGT7aiHSe/UQn3Js44W/bZVLZsh2g= X-MC-Unique: aWPYew8tOXaZyvvRXnitIg-1 X-Mimecast-MFC-AGG-ID: aWPYew8tOXaZyvvRXnitIg_1788976656 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 13/14] docs: expand security docs with info about security status Date: Wed, 9 Sep 2026 18:56:55 +0100 Message-ID: <20260909175656.1572689-14-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976712618158501 The description of virtualization vs non-virtualization use cases is a crude approximation of the security characteristics of QEMU devices. Document how QEMU can be probed to obtain information on the security status of type classes, and how policies can be set to inform or control their usage. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- docs/system/security.rst | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) diff --git a/docs/system/security.rst b/docs/system/security.rst index 8c42d1a6d8..75e39caede 100644 --- a/docs/system/security.rst +++ b/docs/system/security.rst @@ -158,6 +158,42 @@ an issue as a normal bug. usually not justify handling as security bugs, nor assignment of CVEs. They will be fixed as routine bugs when time allows. =20 +Security status reporting +''''''''''''''''''''''''' + +The QEMU project annotates types to explicitly state whether they are +considered to provide a security boundary or not. For machine, accelerator +and device types, only those annotated with the "secure" flag will be +eligible for CVE assignment. Annotations will be extended to other backend +and object types over time, to make their security status explicit. + +It is possible to control or identify the usage of types that do not offer +an explicit security boundary using the ``insecure-types`` parameter to the +``-compat`` argument, which accepts three values: + + * accept: usage of any type will be permitted. This is the current + and historical default behaviour + * warn: usage of types not explicitly declared secure will result + in a warning message, but still be permitted. + * reject: usage of types not explicitly declared secure will result + in an error message, and will not be permitted. + +The compatibility policy will be honoured both at initial startup of +QEMU and during any runtime alterations made with monitor commands. + +The status of any type class can be queried at runtime using the +``qom-list-types`` command, whose returned information will flag any +types declared as secure. The ``query-machines`` command will also +reflect this same information for machine types. + +Machine type, accelerator and device security status can be queried +using ``-machine help``, ``-accel help`` and ``-device help`` command +line options respectively. + +Setting the ``.secure`` field to ``true`` in the ``TypeInfo`` +instance for an Object class, declares that the type aims to provide +a security boundary. + Architecture ------------ =20 --=20 2.55.0 From nobody Sat Sep 26 19:59:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788976725; cv=none; d=zohomail.com; s=zohoarc; b=dzgGDr0kpuvq8gQkPIJ38eAP251cblK7+JR1qqRCjt9bsO6M4npLo5Jfk+n7tFgjdpO2MgW1D8jp94QHlOea3ESVT086PMwz6UHJe9rNDrZa9KNkUZEGc60qkQa/X/7agXxZ//qqvQSQ03R/DXXbXKPfgrLID1a/K56luSSS7TY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788976725; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EQEVhPzGHbhDNWasuYnPt706NkETsiDZwTzdL1TciMA=; b=XLIJRVweyyYmopY/v3iYLEUqWiHe5xvId1s+uLJqavzAqwG5hcCRwcg847ykUjgU8zgve49Zgr365NokAm9yA/obTdmwaLbe7EBeJPiYzCL2BSMnj3MAXkSNo+7UMzEV4Dbg7rYpZsKDKTEZvx2eWfPKwBEKUGIftk1y9ociiA0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788976725334867.6064025618227; Wed, 9 Sep 2026 10:58:45 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MYN-0001rN-Kd; Wed, 09 Sep 2026 13:57:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MYL-0001eT-HJ for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:45 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MYJ-0004hC-OI for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:45 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-658-_ZKvjm4RM4yr2D6VNy8cSw-1; Wed, 09 Sep 2026 13:57:40 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 5CB051964CFE; Wed, 9 Sep 2026 17:57:39 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 214B3195608C; Wed, 9 Sep 2026 17:57:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976662; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=EQEVhPzGHbhDNWasuYnPt706NkETsiDZwTzdL1TciMA=; b=GpOYwKYlXZsS4j6q7N4wsBPUjWrYGFhOVYo3vL4jK4A2KLhSn8GF6bGLt9x/+WntZiCFsu 7tn7Vep+zBKU47tWLzorFc07kN/Tr6JFbkLUiCZ41PXcYBXCZwWWckdE+eOxaAZce6WTR8 QIjSFtyj4yNuczDHvTjYsyaGuWy/uLA= X-MC-Unique: _ZKvjm4RM4yr2D6VNy8cSw-1 X-Mimecast-MFC-AGG-ID: _ZKvjm4RM4yr2D6VNy8cSw_1788976659 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 14/14] machine: add helpers for declaring secure/insecure machine types Date: Wed, 9 Sep 2026 18:56:56 +0100 Message-ID: <20260909175656.1572689-15-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788976726596158500 The current DEFINE_MACHINE macro will declare machine type without any explicit statement about the security status. As such the machine type will be treated as implicitly insecure at runtime. Introduce a new DEFINE_SECURE_MACHINE macro (with variants) that allow code to make an explicit statement that the machine is treated as secure. This should primarily be used for versioned machine types that are intended to be used with KVM, though some others may warrant a security declaration. Use of the existing macros marks a machine as insecure, which is the desired default for most machines servicing emulation use cases. The same is done for the specialized i386 PC related macros. Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau --- hw/arm/bananapi_m2u.c | 2 +- hw/arm/cubieboard.c | 2 +- hw/arm/imx8mm-evk.c | 2 +- hw/arm/integratorcp.c | 2 +- hw/arm/mcimx7d-sabre.c | 2 +- hw/arm/orangepi.c | 2 +- hw/ppc/pegasos.c | 3 ++- include/hw/core/boards.h | 25 ++++++++++++++++++++----- include/hw/i386/pc.h | 11 ++++++++++- 9 files changed, 38 insertions(+), 13 deletions(-) diff --git a/hw/arm/bananapi_m2u.c b/hw/arm/bananapi_m2u.c index 8f59111fd4..ccf60ba295 100644 --- a/hw/arm/bananapi_m2u.c +++ b/hw/arm/bananapi_m2u.c @@ -153,4 +153,4 @@ static void bpim2u_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("bpim2u", MACHINE, Bpim2uMachineState, - bpim2u_machine_init, false, NULL) + bpim2u_machine_init, false, false, NULL) diff --git a/hw/arm/cubieboard.c b/hw/arm/cubieboard.c index ae27056938..e4fef9cd76 100644 --- a/hw/arm/cubieboard.c +++ b/hw/arm/cubieboard.c @@ -133,5 +133,5 @@ static void cubieboard_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("cubieboard", MACHINE, CubieboardMachineState, - cubieboard_machine_init, false, + cubieboard_machine_init, false, false, NULL) diff --git a/hw/arm/imx8mm-evk.c b/hw/arm/imx8mm-evk.c index 8a5737502f..c3215b11cb 100644 --- a/hw/arm/imx8mm-evk.c +++ b/hw/arm/imx8mm-evk.c @@ -134,5 +134,5 @@ static void imx8mm_evk_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("imx8mm-evk", MACHINE, Imx8mmEvkMachineState, - imx8mm_evk_machine_init, false, + imx8mm_evk_machine_init, false, false, NULL) diff --git a/hw/arm/integratorcp.c b/hw/arm/integratorcp.c index 382ea7850d..b766edeeee 100644 --- a/hw/arm/integratorcp.c +++ b/hw/arm/integratorcp.c @@ -704,7 +704,7 @@ static void integratorcp_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("integratorcp", MACHINE, IntegratorcpMachineState, - integratorcp_machine_init, false, + integratorcp_machine_init, false, false, NULL) =20 static const Property core_properties[] =3D { diff --git a/hw/arm/mcimx7d-sabre.c b/hw/arm/mcimx7d-sabre.c index db8a62e5f6..65fdb19c06 100644 --- a/hw/arm/mcimx7d-sabre.c +++ b/hw/arm/mcimx7d-sabre.c @@ -86,5 +86,5 @@ static void mcimx7d_sabre_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("mcimx7d-sabre", MACHINE, Mcimx7dSabreMachineState, - mcimx7d_sabre_machine_init, false, + mcimx7d_sabre_machine_init, false, false, NULL) diff --git a/hw/arm/orangepi.c b/hw/arm/orangepi.c index 7a19732f5d..18ed174032 100644 --- a/hw/arm/orangepi.c +++ b/hw/arm/orangepi.c @@ -133,5 +133,5 @@ static void orangepi_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("orangepi-pc", MACHINE, OrangePiMachineState, - orangepi_machine_init, false, + orangepi_machine_init, false, false, NULL) diff --git a/hw/ppc/pegasos.c b/hw/ppc/pegasos.c index 9d7e279123..fba2a55890 100644 --- a/hw/ppc/pegasos.c +++ b/hw/ppc/pegasos.c @@ -788,7 +788,8 @@ static void pegasos2_machine_class_init(ObjectClass *oc= , const void *data) } =20 DEFINE_MACHINE_EXTENDED("pegasos", MACHINE, PegasosMachineState, - pegasos_machine_init, true, (const InterfaceInfo[]= ) { + pegasos_machine_init, true, false, + (const InterfaceInfo[]) { { TYPE_PPC_VIRTUAL_HYPERVISOR }, { TYPE_VOF_MACHINE_IF }, { } }) =20 diff --git a/include/hw/core/boards.h b/include/hw/core/boards.h index a436d48c8e..c2e0327a39 100644 --- a/include/hw/core/boards.h +++ b/include/hw/core/boards.h @@ -514,7 +514,7 @@ struct MachineState { */ =20 #define DEFINE_MACHINE_EXTENDED(namestr, PARENT_NAME, InstanceName, \ - machine_initfn, ABSTRACT, ifaces...) \ + machine_initfn, ABSTRACT, SECURE, ifaces..= .) \ static void machine_initfn##_class_init(ObjectClass *oc, const void *d= ata) \ { \ MachineClass *mc =3D MACHINE_CLASS(oc); \ @@ -526,6 +526,7 @@ struct MachineState { .class_init =3D machine_initfn##_class_init, \ .instance_size =3D sizeof(InstanceName), \ .abstract =3D ABSTRACT, \ + .secure =3D SECURE, \ .interfaces =3D ifaces, \ }; \ static void machine_initfn##_register_types(void) \ @@ -534,18 +535,32 @@ struct MachineState { } \ type_init(machine_initfn##_register_types) =20 +/* Implicitly insecure */ #define DEFINE_MACHINE(namestr, machine_initfn) \ DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ - false, NULL) + false, false, NULL) =20 -#define DEFINE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, iface= s...)\ +#define DEFINE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, iface= s...) \ DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ - false, ifaces) + false, false, ifaces) =20 -#define DEFINE_MACHINE_WITH_INTERFACES(namestr, machine_initfn, ...) \ +#define DEFINE_MACHINE_WITH_INTERFACES(namestr, machine_initfn, ...) \ DEFINE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, \ (const InterfaceInfo[]) { __VA_ARG= S__ }) =20 + +#define DEFINE_SECURE_MACHINE(namestr, machine_initfn) \ + DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ + false, true, NULL) + +#define DEFINE_SECURE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn= , ifaces...) \ + DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ + false, true, ifaces) + +#define DEFINE_SECURE_MACHINE_WITH_INTERFACES(namestr, machine_initfn, ...= ) \ + DEFINE_SECURE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, \ + (const InterfaceInfo[]) { _= _VA_ARGS__ }) + /* * Helper for dispatching different macros based on how * many __VA_ARGS__ are passed. Supports 1 to 5 variadic diff --git a/include/hw/i386/pc.h b/include/hw/i386/pc.h index ac03da97b6..d5dc79df17 100644 --- a/include/hw/i386/pc.h +++ b/include/hw/i386/pc.h @@ -275,7 +275,7 @@ extern const size_t pc_compat_4_2_len; extern GlobalProperty pc_compat_4_1[]; extern const size_t pc_compat_4_1_len; =20 -#define DEFINE_PC_MACHINE(suffix, namestr, initfn, optsfn) \ +#define DEFINE_PC_MACHINE_EXTENDED(suffix, namestr, initfn, optsfn, issecu= re) \ static void pc_machine_##suffix##_class_init(ObjectClass *oc, \ const void *data) \ { \ @@ -287,6 +287,7 @@ extern const size_t pc_compat_4_1_len; .name =3D namestr TYPE_MACHINE_SUFFIX, \ .parent =3D TYPE_PC_MACHINE, \ .class_init =3D pc_machine_##suffix##_class_init, \ + .secure =3D issecure, \ }; \ static void pc_machine_init_##suffix(void) \ { \ @@ -294,6 +295,14 @@ extern const size_t pc_compat_4_1_len; } \ type_init(pc_machine_init_##suffix) =20 +/* Implicitly insecure */ +#define DEFINE_PC_MACHINE(suffix, namestr, initfn, optsfn) \ + DEFINE_PC_MACHINE_EXTENDED(suffix, namestr, initfn, optsfn, false) + +#define DEFINE_SECURE_PC_MACHINE(suffix, namestr, initfn, optsfn) \ + DEFINE_PC_MACHINE_EXTENDED(suffix, namestr, initfn, optsfn, true) + + #define DEFINE_PC_VER_MACHINE(namesym, namestr, initfn, isdefault, malias,= ...) \ static void MACHINE_VER_SYM(init, namesym, __VA_ARGS__)( \ MachineState *machine) \ --=20 2.55.0