From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036673; cv=none; d=zohomail.com; s=zohoarc; b=AA5n3mngIkUgNbKqdnautERjk0PRGe966LFK5c66mklvrpGwr2y+q+af2JYotI0M1lz8V0ZLs4XOpb/Kyg/K7l04szB6oa9IQnB4WDykE28h6UlGSLekpSx2LCq+SQ2DgMT4KNjjWXJnR4HBsfVbmFrthJyaGDxgAEbvDHE90MY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036673; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=iQOI/kKi8zvtrglbxEcz2zVU/y98U5uZrr+8osdGNq4=; b=kYzJhRfiivw3R/29HBsM2Agqb1vadpZWLZ4kE1W03ZZXPfBm5YYVgk44XWijyTjavT5nkX5GqyC34wnEo1w1NvUW/xkddTuTUrYHh8/5CMVWj0/7KR7vxenjI67RDz0NfE0Kf8tjNUOR5XfqyMhV3s5M7IsxqC2k72oejlfZX6U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036673690643.2703871616405; Thu, 10 Sep 2026 03:37:53 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c98-00033T-71; Thu, 10 Sep 2026 06:36:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c96-00032q-JP for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:44 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c95-0007O9-1P for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:44 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-263-tBCwc5ktM2WrYC29F9UpQg-1; Thu, 10 Sep 2026 06:36:36 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 655A51955E96; Thu, 10 Sep 2026 10:36:35 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 3E3DA30001A2; Thu, 10 Sep 2026 10:36:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036602; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=iQOI/kKi8zvtrglbxEcz2zVU/y98U5uZrr+8osdGNq4=; b=A0Uz1b+Zy3h8x6NMmuv2c/FFRE/zew6YJL7WSapbvZPDYZhOcBQPv3PP7OcH91pUJG/Xfu EHkLEjzwBDZTrF5jp+HmRxbX48W2R+R9j3UTYivKAbMqetCg4VwP9FWnXDtcXDOwF8IaaU Pi5SCMtstK/UB1HhVU+icPAnjBfG+b0= X-MC-Unique: tBCwc5ktM2WrYC29F9UpQg-1 X-Mimecast-MFC-AGG-ID: tBCwc5ktM2WrYC29F9UpQg_1789036595 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 01/14] qom: add tracking of security state of object types Date: Thu, 10 Sep 2026 11:36:15 +0100 Message-ID: <20260910103628.2326622-2-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036673905158500 This introduces a new flag "secure" against the Type/TypeInfo structs, and helpers to check this against the ObjectClass struct. If an object is considered to provide a security boundary to protect against untrusted code, the "secure" flag must be explicitly set to true. If it is set to false, or left unset, this indicates that the object does not intend to provide a security boundary. Bugs related to this object class will be ineligible for CVE assignment. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- include/qom/object.h | 13 +++++++++++++ qom/object.c | 7 +++++++ 2 files changed, 20 insertions(+) diff --git a/include/qom/object.h b/include/qom/object.h index 7ecd0f210f..687ceb6bba 100644 --- a/include/qom/object.h +++ b/include/qom/object.h @@ -453,6 +453,10 @@ struct Object * function. * @abstract: If this field is true, then the class is considered abstract= and * cannot be directly instantiated. + * @secure: If this field is initialized to true, then the class is consid= ered + * to provide a security boundary. If initialized to false, the class do= es + * not provide a security boundary. If uninitialized (and thus implicitly + * false) its status is not yet defined. * @class_size: The size of the class object (derivative of #ObjectClass) * for this object. If @class_size is 0, then the size of the class wil= l be * assumed to be the size of the parent class. This allows a type to av= oid @@ -487,6 +491,7 @@ struct TypeInfo void (*instance_finalize)(Object *obj); =20 bool abstract; + bool secure; size_t class_size; =20 void (*class_init)(ObjectClass *klass, const void *data); @@ -1074,6 +1079,14 @@ const char *object_class_get_name(ObjectClass *klass= ); */ bool object_class_is_abstract(ObjectClass *klass); =20 +/** + * object_class_is_secure: + * @klass: The class to check security of + * + * Returns: %true if @klass is declared to be secure, %false if not declar= ed + */ +bool object_class_is_secure(ObjectClass *klass); + /** * object_class_by_name: * @typename: The QOM typename to obtain the class for. diff --git a/qom/object.c b/qom/object.c index b1834a57cc..32736a0111 100644 --- a/qom/object.c +++ b/qom/object.c @@ -67,6 +67,7 @@ struct TypeImpl void (*instance_finalize)(Object *obj); =20 bool abstract; + bool secure; =20 const char *parent; TypeImpl *parent_type; @@ -122,6 +123,7 @@ static TypeImpl *type_new(const TypeInfo *info) ti->instance_finalize =3D info->instance_finalize; =20 ti->abstract =3D info->abstract; + ti->secure =3D info->secure; =20 for (i =3D 0; info->interfaces && info->interfaces[i].type; i++) { ti->interfaces[i].typename =3D g_strdup(info->interfaces[i].type); @@ -1144,6 +1146,11 @@ bool object_class_is_abstract(ObjectClass *klass) return klass->type->abstract; } =20 +bool object_class_is_secure(ObjectClass *klass) +{ + return klass->type->secure; +} + const char *object_class_get_name(ObjectClass *klass) { return klass->type->name; --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036668; cv=none; d=zohomail.com; s=zohoarc; b=Bb5Wl5QcnYPBAX1rNSdM2/wLNjxwIFJNhGYd4Vs8AxiB9HrRRE5+lIaCXpgS0YwS+SnkPbkyVOgp16k2Lib8EfMOgOtoNZHzIP19lYhjdpn8Jm95N8VkBTpvBDRn07UvBWRuQ8jlfNrmcDTT5pI8aXbXzyB6KOcNdyXjVeywxfI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036668; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hjUZZrQAKDKJAfNmKuguZXdPFdKfOAdCOZeb4Vavte0=; b=iX2fVUurwmxudzzOAI29J9V8YPXTZixww2zf+78coLLtVaFGRvmJTvhu9zZYJ2SgBbtG7nqZ3wgTAXowv9HO4Fj4oqNOJjueqLGgkM08ubjku1sQD9CuycA4TmULVeLPuVi0+HRYGFjOoE6yauqZMnRWpMJncIYG89CvNaKqcXs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036668773461.1038049176225; Thu, 10 Sep 2026 03:37:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c98-00033U-7E; Thu, 10 Sep 2026 06:36:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c96-000334-Rf for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:44 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c95-0007OJ-AG for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:44 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-18-FDlfsomwN8W-e47v-60B2A-1; Thu, 10 Sep 2026 06:36:39 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 05D7118005BC; Thu, 10 Sep 2026 10:36:38 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D034730001A2; Thu, 10 Sep 2026 10:36:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036602; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=hjUZZrQAKDKJAfNmKuguZXdPFdKfOAdCOZeb4Vavte0=; b=aUL/Mc9zN1omOZNMCiUxF894duZ4fbdgtkvELQIVEIKBaCMezPEEHUkJYZ8eoTWIAnPWsH DRm/pJ52xPkGi69Tb3f+G3CAeD7re0lurdR/a+kEQ5Vkj5QagayaPDHw0VYvlWyS9nJE4B wmY0n1UHZrVjQJhchmLt1/zS4N+CkwA= X-MC-Unique: FDlfsomwN8W-e47v-60B2A-1 X-Mimecast-MFC-AGG-ID: FDlfsomwN8W-e47v-60B2A_1789036598 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 02/14] qapi: add 'insecure-types' option for -compat argument Date: Thu, 10 Sep 2026 11:36:16 +0100 Message-ID: <20260910103628.2326622-3-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036669878158500 This introduces a new 'insecure-types' option for the 'compat' argument that accepts three values * accept: Allow any usage * reject: Reject with an error reported * warn: Allow any usage, with a warning reported For historical compatibility it defaults to 'accept'. The 'reject' and 'warn' values will take effect for any type that has been explicitly marked insecure, or is lacking an explicit declaration of its security status. This new command line option is currently a no-op, but will become functional as following patches enable the checks. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- include/qapi/compat-policy.h | 5 +++++ qapi/compat.json | 23 ++++++++++++++++++++++- qapi/qapi-util.c | 30 ++++++++++++++++++++++++++++++ 3 files changed, 57 insertions(+), 1 deletion(-) diff --git a/include/qapi/compat-policy.h b/include/qapi/compat-policy.h index ea65e10744..f5af209069 100644 --- a/include/qapi/compat-policy.h +++ b/include/qapi/compat-policy.h @@ -24,6 +24,11 @@ bool compat_policy_input_ok(uint64_t features, const char *kind, const char *name, Error **errp); =20 +bool compat_policy_check_security(const CompatPolicy *policy, + const char *typename, + bool is_secure, + Error **errp); + /* * Create a QObject input visitor for @obj for use with QMP * diff --git a/qapi/compat.json b/qapi/compat.json index 90b8d51cf2..b54f8eb371 100644 --- a/qapi/compat.json +++ b/qapi/compat.json @@ -37,6 +37,23 @@ { 'enum': 'CompatPolicyOutput', 'data': [ 'accept', 'hide' ] } =20 +## +# @CompatPolicySecurity: +# +# Policy for handling any devices or backends which do not provide a +# security boundary to protect against untrusted environments +# +# @accept: Allow any usage +# +# @reject: Reject with an error reported +# +# @warn: Allow any usage, with a warning reported +# +# Since: 11.2 +## +{ 'enum': 'CompatPolicySecurity', + 'data': [ 'accept', 'reject', 'warn' ] } + ## # @CompatPolicy: # @@ -62,10 +79,14 @@ # @unstable-output: how to handle unstable output (default 'accept') # (since 6.2) # +# @insecure-types: how to handle types that are not declared secure +# (default 'accept') (since 11.2) +# # Since: 6.0 ## { 'struct': 'CompatPolicy', 'data': { '*deprecated-input': 'CompatPolicyInput', '*deprecated-output': 'CompatPolicyOutput', '*unstable-input': 'CompatPolicyInput', - '*unstable-output': 'CompatPolicyOutput' } } + '*unstable-output': 'CompatPolicyOutput', + '*insecure-types': 'CompatPolicySecurity' } } diff --git a/qapi/qapi-util.c b/qapi/qapi-util.c index 3d849fe034..38b1cec7a4 100644 --- a/qapi/qapi-util.c +++ b/qapi/qapi-util.c @@ -14,6 +14,7 @@ #include "qapi/compat-policy.h" #include "qapi/error.h" #include "qemu/ctype.h" +#include "qemu/error-report.h" #include "qapi/qmp/qerror.h" =20 CompatPolicy compat_policy; @@ -58,6 +59,35 @@ bool compat_policy_input_ok(uint64_t features, return true; } =20 +bool compat_policy_check_security(const CompatPolicy *policy, + const char *typename, + bool is_secure, + Error **errp) +{ + if (is_secure) { + return true; + } + + switch (policy->insecure_types) { + case COMPAT_POLICY_SECURITY_ACCEPT: + return true; + + case COMPAT_POLICY_SECURITY_REJECT: + error_setg(errp, "Type '%s' does not provide a security boundary " + "to protect against untrusted data or actions", typenam= e); + return false; + + case COMPAT_POLICY_SECURITY_WARN: + warn_report("Type '%s' does not provide a security boundary " + "to protect against untrusted data or actions", typena= me); + return true; + + default: + g_assert_not_reached(); + } +} + + const char *qapi_enum_lookup(const QEnumLookup *lookup, int val) { assert(val >=3D 0 && val < lookup->size); --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036700; cv=none; d=zohomail.com; s=zohoarc; b=g2/22iBN8xUUtHwI3VyvZotSqhRoO8d0ZY9HIwLTXxjyxeNoDZs6F3gnk6Cw+duHI+zdKySKV8RIe7pvGhIh/KblDCr/q8AOFVc9pGFzlxwCQUxdOlpcZkY2LwaiUyqf0ydahtaQkmCEpsgT1q+ydm7RyCmvRWXY8Y7wfF0UD1E= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036700; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=nT7oxGs/bBHJ2PpDTw2GfVUpTr87sAoUZynb4lEObp4=; b=Iq6d+oblzjkuVd7D8QG3Br0nfa/8GT9gNVlWjlMw8bygoZktKw8Ec7EQ1ERmstJUbAJ+pFuGXZ7a+D/W1tfC6djVz9iDc/EcJi3wGkSCr4Nn+fTFiSQUtHM9Oy6Xen8vu5yUq/1wjg2rhdQTfuj7dpKgmb+HmYnXBV99rlre8EY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036700640581.7973773979653; Thu, 10 Sep 2026 03:38:20 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9A-00033x-O3; Thu, 10 Sep 2026 06:36:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c99-00033k-7U for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:47 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c97-0007RB-Ox for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:46 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-47-FYVQd0ncMCSIfoBjJy2DlA-1; Thu, 10 Sep 2026 06:36:41 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 97CA818005AE; Thu, 10 Sep 2026 10:36:40 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 59E2830001A2; Thu, 10 Sep 2026 10:36:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036605; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=nT7oxGs/bBHJ2PpDTw2GfVUpTr87sAoUZynb4lEObp4=; b=Ft3oseGz9uAArVF0CXDxxBG/k3xu/OMKeEDvaQnI8QE1+WY5wKvK0fYgLfG2n3BsFgr1x9 8rJvPiwPtoug3bnRrgDpOUOTyw1b7ILvh71QxjgUoWXqdS35AlyJ3OoYRzyJPkbKHE3bN1 UQbHcnsuW968KnWb0rBjSnWUj30EiqE= X-MC-Unique: FYVQd0ncMCSIfoBjJy2DlA-1 X-Mimecast-MFC-AGG-ID: FYVQd0ncMCSIfoBjJy2DlA_1789036600 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 03/14] qom: add helper API for checking object class security policy compliance Date: Thu, 10 Sep 2026 11:36:17 +0100 Message-ID: <20260910103628.2326622-4-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036702117158500 This helper simply avoids a verbose code pattern being repeated for many callers. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- include/qom/object.h | 13 +++++++++++++ qom/object.c | 9 +++++++++ 2 files changed, 22 insertions(+) diff --git a/include/qom/object.h b/include/qom/object.h index 687ceb6bba..3285218664 100644 --- a/include/qom/object.h +++ b/include/qom/object.h @@ -2405,6 +2405,19 @@ Object *object_property_add_new_container(Object *ob= j, const char *name); char *object_property_help(const char *name, const char *type, QObject *defval, const char *description); =20 +/** + * object_class_check_security: + * @klass: the object class to check + * @errp: a pointer to an Error that is filled if not compliant + * + * Check whether the object class @klass complies with the + * currently requested security policy. Reports an error + * in @errp if not compliant. + * + * Returns: true if compliant, false if an error was raised + */ +bool object_class_check_security(ObjectClass *klass, Error **errp); + G_DEFINE_AUTOPTR_CLEANUP_FUNC(Object, object_unref) =20 #endif diff --git a/qom/object.c b/qom/object.c index 32736a0111..41b1ec81d4 100644 --- a/qom/object.c +++ b/qom/object.c @@ -23,6 +23,7 @@ #include "qapi/qobject-input-visitor.h" #include "qapi/forward-visitor.h" #include "qapi/qapi-builtin-visit.h" +#include "qapi/compat-policy.h" #include "qobject/qdict.h" #include "qobject/qjson.h" #include "qemu/id.h" @@ -3149,6 +3150,14 @@ void object_class_property_set_description(ObjectCla= ss *klass, op->description =3D g_strdup(description); } =20 +bool object_class_check_security(ObjectClass *klass, Error **errp) +{ + return compat_policy_check_security(&compat_policy, + object_class_get_name(klass), + object_class_is_secure(klass), + errp); +} + static void object_class_init(ObjectClass *klass, const void *data) { object_class_property_add_str(klass, "type", object_get_type, --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036632; cv=none; d=zohomail.com; s=zohoarc; b=S8IgqK91X7sv/AjPpTPmyVQ8QDGk35zg95oupVX1BLJlqaM47CzHRqTqKdYFoyuQnTH2x3a2rnrNCLtgHtNmUyg/8Z3Ztk1oU0vXaiKapWuIAGdLjGu6jwWZ1D/4vJ8paNFhghKBN5bivF6nFeypIt9NaRJYeX22OYosT9W/3UE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036632; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=p/q+QPX4I2DkD8nOzBpfzPfYXRrKvIQXPsDbpO+IXN4=; b=cqndZlY+oRcO56Ui8/mjx/eVqsgcU/2gZ5wtdA1wRx/+sRV/nAXd/W0ltR075xDNUg+wG4WDjubZFSfxD1+jkRruE05uGR0lRtIJ3Coz+u4swhivUxgpWHgd5o3MNiB1fE+JWqA7wk+HZM8pWaIcXBw3BKt4uA9lSTri/lC1TVo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036632375582.9921027271494; Thu, 10 Sep 2026 03:37:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9G-00034b-Q9; Thu, 10 Sep 2026 06:36:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9F-00034H-Oc for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:53 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9A-0007Rx-Ff for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:53 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-125-fTctdS1VOwWvrMWikPXMZA-1; Thu, 10 Sep 2026 06:36:44 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 60BC71800666; Thu, 10 Sep 2026 10:36:43 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0704530001A2; Thu, 10 Sep 2026 10:36:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036607; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=p/q+QPX4I2DkD8nOzBpfzPfYXRrKvIQXPsDbpO+IXN4=; b=LJHOdbjqgotwASKv1b/bTO7Y5CH4QxCn1EYtxE3FINnfEAy1k3eMFJi0MOiKnnNwRZ1P0g qaIbAq2QOUUgi3FJuIdYL8ZElgP3poGMnKlZYJHzep9VyrgQhPag23DYgtxJO8zo8Rpz4z vK85M2kpB3Hn9RVf0ECNj6CDZEHtXJU= X-MC-Unique: fTctdS1VOwWvrMWikPXMZA-1 X-Mimecast-MFC-AGG-ID: fTctdS1VOwWvrMWikPXMZA_1789036603 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 04/14] system: check security for accelerator types Date: Thu, 10 Sep 2026 11:36:18 +0100 Message-ID: <20260910103628.2326622-5-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036634597158500 This wires up the accelerator creation code to apply the compat policy security check. When multiple -accel options are given, normal fallback logic applies. IOW, if one is rejected by the security check, it will carry on to try the next accelerator until one passes the security check. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- system/vl.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/system/vl.c b/system/vl.c index 9bd7664b85..0c6e44f21c 100644 --- a/system/vl.c +++ b/system/vl.c @@ -2412,6 +2412,11 @@ static int do_configure_accelerator(void *opaque, Qe= muOpts *opts, Error **errp) } goto bad; } + + if (!object_class_check_security(OBJECT_CLASS(ac), errp)) { + goto bad; + } + accel =3D ACCEL(object_new_with_class(OBJECT_CLASS(ac))); object_apply_compat_props(OBJECT(accel)); qemu_opt_foreach(opts, accelerator_set_property, --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036675; cv=none; d=zohomail.com; s=zohoarc; b=moMBbZ1y4URsp0iiIyhIwPizDQMZKzslEGSeynFPPt+KwmdfRDNTPLMCE3z0UejOgQnWo9oBaCpWGJ3DXv7nOSYQk4byXboPuVTUOam2CxDHT4rDHo0UY9eY0JVoVYcPbmGQTzK3aZlC+K4DKp2s8JnKW+Q/qUpauk8DGMYGzU8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036675; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=IgbGSy2c/zJwJ6A/sMsbdO88pBHcIgP5xqTREl+UbNk=; b=NXSwogDJ4AitSk/0MEabu3roVMtUavlIHF4SGIgrgYk2BwiqyBw3pzZ9Z28Vr2cpKGF3IpM6snZ+pTUMczCU8N9yXE4CphRVS9EbJ5A5thLUnFlY/f5anYfzMVMcgaKlzkC0dTqBPPhC5L+y+7Q/MP6Z3pBKxpCJf+Min5Zzfuk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036675960717.1097702054421; Thu, 10 Sep 2026 03:37:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9I-00035C-L4; Thu, 10 Sep 2026 06:36:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9H-00034q-4D for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:55 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9D-0007TW-2V for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:54 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-145-tfJoS7cpMhSK12WPkTninw-1; Thu, 10 Sep 2026 06:36:47 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id EBD5C1800676; Thu, 10 Sep 2026 10:36:45 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id B388A30001A2; Thu, 10 Sep 2026 10:36:43 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036610; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=IgbGSy2c/zJwJ6A/sMsbdO88pBHcIgP5xqTREl+UbNk=; b=hFYqBoLcGEfgnQrJ549l6VZ7Q1ayV8eC5PKPNb9nVSamelwVPAKXJdtjH0utKWAw0+WcDW hqbBuqL7NqhHTM5L9eBg4j4hsnExIwgA47Q7Mrx7BKInBWaJCpQbfe4mjhhcCa6cSyamKe sJtPUQj0Vn0xZaits8rzyuXgVeDBDyw= X-MC-Unique: tfJoS7cpMhSK12WPkTninw-1 X-Mimecast-MFC-AGG-ID: tfJoS7cpMhSK12WPkTninw_1789036606 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 05/14] system: report acclerator security status in help output Date: Thu, 10 Sep 2026 11:36:19 +0100 Message-ID: <20260910103628.2326622-6-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036677902158500 When '-accel help' is given, report the security status of each accelerator. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- system/vl.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/system/vl.c b/system/vl.c index 0c6e44f21c..ca54da26c5 100644 --- a/system/vl.c +++ b/system/vl.c @@ -3451,7 +3451,10 @@ void qemu_init(int argc, char **argv) g_str_has_suffix(typename, ACCEL_CLASS_SUFFIX)= ) { gchar **optname =3D g_strsplit(typename, ACCEL_CLASS_SUFFI= X, 0); - printf("%s\n", optname[0]); + printf("%s%s\n", optname[0], + object_class_is_secure( + OBJECT_CLASS(el->data)) ? + " (secure)" : ""); g_strfreev(optname); } g_free(typename); --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036700; cv=none; d=zohomail.com; s=zohoarc; b=imzvz+2HnHiCqGeTKM1DzCGOGJ5clTSmBoPKdaibyiKW1ErSepLK49xYaMEVwr5XcDCXR2BD5qStUsRXbvQ5JoW4noVRapWXidILOMNZV/XgKQg0o5scbQBra4qeHGbX/3SivceDMHgNALCiDgqQwGHNu0J4h1iOyltQyQapb9s= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036700; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LgQgSKuuP4MLXuwMFUx8cwdMqy6ASae3omNjhUX9Msg=; b=OGdSl/zl9gBGvpiqNOQBRY61LkxycISIv3NZfX6eIZiWvcP1cpCIpDKO2fQYJuJh4LzxCstIxnHlHHNMw3/KgjF+o/ANW4QUI/hGAKF4Fyo95IL3JjDK59Mfs4QLPKTq0mqJ8KK+kY0mKXoKVjnKpHK6Et7BZ7ukSfLi2Xu9Xlw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036700000913.7162574415845; Thu, 10 Sep 2026 03:38:20 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9K-00035V-1M; Thu, 10 Sep 2026 06:36:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9I-00034z-7z for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:56 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9F-0007Vb-UR for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:55 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-507-PjEfXKSlOU64oJe6O4eg9A-1; Thu, 10 Sep 2026 06:36:50 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 093341954236; Thu, 10 Sep 2026 10:36:49 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 49F4530001A2; Thu, 10 Sep 2026 10:36:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036613; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=LgQgSKuuP4MLXuwMFUx8cwdMqy6ASae3omNjhUX9Msg=; b=NNXHTrCp5mnGEg5OdAXRxlo3E3Tausv21tljSswH5jb4fJO7+ZByDIkeyuE6t5tr9lhvQT 9Vxpaavw51WFbSS0hE9v+Zm7Wg3qkpY4CoqRdnshRdXzJfdmWPW6cAP+BmCVNQlmgzlSxm ieEhD95O8XIiBvnuj+qjBUr0lCx/jgI= X-MC-Unique: PjEfXKSlOU64oJe6O4eg9A-1 X-Mimecast-MFC-AGG-ID: PjEfXKSlOU64oJe6O4eg9A_1789036609 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 06/14] system: check security for machine types Date: Thu, 10 Sep 2026 11:36:20 +0100 Message-ID: <20260910103628.2326622-7-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036702079158500 This wires up the machine creation code to apply the compat policy security check. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- system/vl.c | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/system/vl.c b/system/vl.c index ca54da26c5..f54449b43e 100644 --- a/system/vl.c +++ b/system/vl.c @@ -2201,11 +2201,18 @@ static void qemu_create_machine_containers(Object *= machine) } } =20 -static void qemu_create_machine(QDict *qdict) +static bool qemu_create_machine(QDict *qdict) { + Error *local_err =3D NULL; MachineClass *machine_class =3D select_machine(qdict, &error_fatal); object_set_machine_compat_props(machine_class->compat_props); =20 + if (!object_class_check_security(OBJECT_CLASS(machine_class), + &local_err)) { + error_report_err(local_err); + return false; + } + current_machine =3D MACHINE(object_new_with_class(OBJECT_CLASS(machine= _class))); object_property_add_child(object_get_root(), "machine", OBJECT(current_machine)); @@ -2237,6 +2244,8 @@ static void qemu_create_machine(QDict *qdict) false, &error_abort); qobject_unref(default_opts); } + + return true; } =20 static int global_init_func(void *opaque, QemuOpts *opts, Error **errp) @@ -3790,7 +3799,9 @@ void qemu_init(int argc, char **argv) /* Transfer QemuOpts options into machine options */ parse_memory_options(); =20 - qemu_create_machine(machine_opts_dict); + if (!qemu_create_machine(machine_opts_dict)) { + exit(1); + } =20 /* * Load incoming CPR state before any devices are created, because it --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036668; cv=none; d=zohomail.com; s=zohoarc; b=Tu0adb0BoZhJgbkSStVop/SrqWigEd8l3t622iUeHPzPd9fhNwlPHlwrAw8kypfLS05PkjTdWz1lPQwlYJJmPzCdklfa2NYHLyVyv98HoTBk+R4nqCL3AyIAsmzxatb6U4G/CIMWePYmBTbX2O+kN2Bs1zPKO1drJESeAhL+IVA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036668; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=oSYEYbdA/Nd4faEANo5NJJBwV7v22iHg8WQxCmReiw8=; b=MPoOhwo08GOBU8/kjh+ieM9LAwkXiOQMgE4u3DMIPmo6/yur+qR9B4lb8Ipgs4p45L1Q60ciZ/03fLCGTE0g9fixwqoB7BOLA+BvKxNkL/FoGC2nUyB23iWex1653SGOboinxWyw9qJ3qevYgvnXPXPvqecUPHtHUeqIib1q0fc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036668672354.99698619939863; Thu, 10 Sep 2026 03:37:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9N-000361-7x; Thu, 10 Sep 2026 06:37:01 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9L-00035n-FM for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:59 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9K-0007Yb-4l for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:36:59 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-394-kVbGq1R4P0-xgjKjrCuEmw-1; Thu, 10 Sep 2026 06:36:52 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 889EA18005AE; Thu, 10 Sep 2026 10:36:51 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 5C91230001A2; Thu, 10 Sep 2026 10:36:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036617; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=oSYEYbdA/Nd4faEANo5NJJBwV7v22iHg8WQxCmReiw8=; b=VguoV/DZ1CzduIY6vu0EU0NSGBCUz+fGd/PIn8OqB6GkbXGgqtVOZZ6m21rL4YtFgtn4hI 7LURzrOXUtFE6rXuAY1dcIdgBMx4kSd0rlLCuxeEiycEtIejRFrpVX17DnlR1Elvo87Hsd VRLH7Qpw7az7L/B5f7177Ffox5Mp+Ps= X-MC-Unique: kVbGq1R4P0-xgjKjrCuEmw-1 X-Mimecast-MFC-AGG-ID: kVbGq1R4P0-xgjKjrCuEmw_1789036611 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 07/14] system: report machine security status in help output Date: Thu, 10 Sep 2026 11:36:21 +0100 Message-ID: <20260910103628.2326622-8-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036669832158500 When '-machine help' is given, report the security status of each machine. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- system/vl.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/system/vl.c b/system/vl.c index f54449b43e..468a9fc247 100644 --- a/system/vl.c +++ b/system/vl.c @@ -1586,9 +1586,10 @@ static void machine_help_func(const QDict *qdict) if (mc->alias) { printf("%-20s %s (alias of %s)\n", mc->alias, mc->desc, mc->na= me); } - printf("%-20s %s%s%s\n", mc->name, mc->desc, + printf("%-20s %s%s%s%s\n", mc->name, mc->desc, mc->is_default ? " (default)" : "", - mc->deprecation_reason ? " (deprecated)" : ""); + mc->deprecation_reason ? " (deprecated)" : "", + object_class_is_secure(OBJECT_CLASS(mc)) ? " (secure)" : ""= ); } } =20 --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036683; cv=none; d=zohomail.com; s=zohoarc; b=MqQxV8dqdvgQqVCnl3uPg3iOMMUUFyLn9oiv3VSIcz/gBJAfCaHc+3/3xkus1qR/7nME5iIoDlbw7rmM/Xv7d3XiLMpUafHjvBtAzLmxV0pYNIqdUJLlLhvsZvz/yCf8j7703NTsGAvJe6NK6sBmqZ3nswjmrM1NIVkIpVWzwek= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036683; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=KF8bpnyH+CNfCjnXBHhMyIxpT5SRRoUmIWg0/W6YgYM=; b=WeGRgiC2drGuC2b799gOdxaK47xG6F5swQ6Jcl2ldpf0quQcIBkA4K/edehgKBbgAT2xB0cLY9nuXm3SqrqNE+NbRxV9voMgFOviKRIRbYndEvojcWnlCyiVaOIEMg3aZr8zL7L7hbazchFwiogeWjBkEPMgef07F3C1nOxoGZk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036683232883.837824153924; Thu, 10 Sep 2026 03:38:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9a-0003GX-9F; Thu, 10 Sep 2026 06:37:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9Y-0003CX-Gd for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:12 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9T-0007fU-DI for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:12 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-91-RVeZwjHFNK2Op8UxCj_ruw-1; Thu, 10 Sep 2026 06:36:58 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 98B58180066C; Thu, 10 Sep 2026 10:36:54 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id DAA7730001A2; Thu, 10 Sep 2026 10:36:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036625; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=KF8bpnyH+CNfCjnXBHhMyIxpT5SRRoUmIWg0/W6YgYM=; b=Z2jA/Uln3YV4R+GoE0fP8LB2k8f2DbXQSA6woR7cY85HPxudlw+JMSLptzXhl0yYZ7hpvZ d9acyYYLYAaKWiNHZpJLH0s9fyT1v5ru6a9QDpigtv6AB9Zx85SZpfs0c5RSYFwvsJ7hAv GrVoxLqxt9Dj7DfElDzj9l5ir4fUdeM= X-MC-Unique: RVeZwjHFNK2Op8UxCj_ruw-1 X-Mimecast-MFC-AGG-ID: RVeZwjHFNK2Op8UxCj_ruw_1789036614 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 08/14] system: check security of device types Date: Thu, 10 Sep 2026 11:36:22 +0100 Message-ID: <20260910103628.2326622-9-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036683914158500 This wires up the DeviceClass types to have their security checked when devices are created. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- system/qdev-monitor.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/system/qdev-monitor.c b/system/qdev-monitor.c index 5c87fda509..a69dbf802f 100644 --- a/system/qdev-monitor.c +++ b/system/qdev-monitor.c @@ -672,6 +672,10 @@ DeviceState *qdev_device_add_from_qdict(const QDict *o= pts, return NULL; } =20 + if (!object_class_check_security(OBJECT_CLASS(dc), errp)) { + return NULL; + } + /* find bus */ path =3D qdict_get_try_str(opts, "bus"); if (path !=3D NULL) { --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036699; cv=none; d=zohomail.com; s=zohoarc; b=ARFQb4xpTStmM82w80H4DAwD9tExlGB0grMf341qrQaj8WS9JVl0oiRZKJnOnTKdpky6Sgxthu4ScQXirIcHsmYXNUmI2000Um2r8fKVvlqSt08dXcV/dtWWlLiHJAJZVTcUut7X4ZdeiF9wWJxsfszw+2Ju8NmKwY+BLhjQO8A= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036699; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6PcY7nNld8xGJkPQk6x+YwNirw64B9PuSRP2JAPrHzk=; b=PR6+Ngs0vtPTQg7fYnR01NhKvYWBrG0PKVXeyWLkci9DWVXktV/AipDnmRPaukTmIOSpUf9/KHPU9qvn5Rkib0rGYLLY/mcyi6sSk5gguFJmiB0lUhyms8Dh52/3gTQfm6GpKndEVwbJqOJeEbU7PvzJrI3hTOejbddDTsaOv5Q= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036699004725.1733408654992; Thu, 10 Sep 2026 03:38:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9Q-00036i-LG; Thu, 10 Sep 2026 06:37:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9P-00036O-PM for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:03 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9O-0007cG-0m for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:03 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-515-jnSFMS-zMRG_S1a3MlvysA-1; Thu, 10 Sep 2026 06:36:58 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 3BDB91800676; Thu, 10 Sep 2026 10:36:57 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id EA97130001A2; Thu, 10 Sep 2026 10:36:54 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036621; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=6PcY7nNld8xGJkPQk6x+YwNirw64B9PuSRP2JAPrHzk=; b=CBKzfEfvQMg6a/v/hzTkhOfVIwg+baUSoa8MvFY/IUIZobqUSUfPqujGKZEz092D3ZQgES khK61mdag7aikiBlpooxUuITCQJXLUkUvq3HQwoRL6KsX7W6L9L2CeRoIK0ZcEFVwNtiud ozGal8BhFWbZPuZ47gzgr4Hqb0Kd6FQ= X-MC-Unique: jnSFMS-zMRG_S1a3MlvysA-1 X-Mimecast-MFC-AGG-ID: jnSFMS-zMRG_S1a3MlvysA_1789036617 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 09/14] system: report device security status in help output Date: Thu, 10 Sep 2026 11:36:23 +0100 Message-ID: <20260910103628.2326622-10-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036702172158500 When '-device help', 'device_add help' and 'info qdm' are used, report the security status of each device. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- system/qdev-monitor.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/system/qdev-monitor.c b/system/qdev-monitor.c index a69dbf802f..2120292fd5 100644 --- a/system/qdev-monitor.c +++ b/system/qdev-monitor.c @@ -166,6 +166,9 @@ static void qdev_print_devinfo(DeviceClass *dc) if (!dc->user_creatable) { qemu_printf(", no-user"); } + if (object_class_is_secure(OBJECT_CLASS(dc))) { + qemu_printf(", secure"); + } qemu_printf("\n"); } =20 --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036679; cv=none; d=zohomail.com; s=zohoarc; b=fTnjo46LZALYzdQZ6EnvhSMIZBmtSQ/SqIjIRka2rb7l/kspRd7wsoTyXMOl1+7BVie+EgVMI19uuHnagijOj/A3KXmhSRf9bTFqwdudgUJWrRbmXt7P3vsfigJgV/KVVHtS0pndhHOLLi8q66jTqa2zGXZEKlijr3Hi3IlD6IA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036679; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EQFzUPspqHyHlCvnAwb+Cvbijhz3gcVYsKf/pjNmb4g=; b=fOJwcT8HtCq1xtWHqkrOF+mw8zEc2DSRqB8TcARkASIpWVLrnP3MlhBuhNVV8Geq6CZOOg5BSdcFy35OPN73o4D9FEZe8FWAaz4mSwhLZIo8fd7P8aBTJepgTrTXezE+i0fjSAMn/9vrg1Y1f3KOQYgAHeIoMjp4RMS3sepvQmY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036679980623.0426571436976; Thu, 10 Sep 2026 03:37:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9R-00036x-E9; Thu, 10 Sep 2026 06:37:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9Q-00036X-6b for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:04 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9O-0007da-Py for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:03 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-176-8WB9PSO2M9K1lzAEygXX7A-1; Thu, 10 Sep 2026 06:37:00 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C5B65180066C; Thu, 10 Sep 2026 10:36:59 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 8DAEB30001A2; Thu, 10 Sep 2026 10:36:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036622; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=EQFzUPspqHyHlCvnAwb+Cvbijhz3gcVYsKf/pjNmb4g=; b=UpYVHdiTymOpZP+X5c/MpE2Puq+z2+ZGDuvsF1wFX3vcDk9sJrdnhDSKX9uNdec7JDz7tX aT3sqFiKwCg44ODdTsydOR/YwDwn4U5e9X1HnwfocpYnU0vk+5/KcOreWaN2igP7zPLtoD XpeA95MKB1OdWP4uGeN1YGe7x3WSXr8= X-MC-Unique: 8WB9PSO2M9K1lzAEygXX7A-1 X-Mimecast-MFC-AGG-ID: 8WB9PSO2M9K1lzAEygXX7A_1789036619 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 10/14] hw/core: report security status in query-machines Date: Thu, 10 Sep 2026 11:36:24 +0100 Message-ID: <20260910103628.2326622-11-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036681902158500 Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- hw/core/machine-qmp-cmds.c | 1 + qapi/machine.json | 8 +++++++- 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/hw/core/machine-qmp-cmds.c b/hw/core/machine-qmp-cmds.c index 543dd3201b..9c08b17510 100644 --- a/hw/core/machine-qmp-cmds.c +++ b/hw/core/machine-qmp-cmds.c @@ -127,6 +127,7 @@ MachineInfoList *qmp_query_machines(bool has_compat_pro= ps, bool compat_props, if (mc->default_ram_id) { info->default_ram_id =3D g_strdup(mc->default_ram_id); } + info->secure =3D object_class_is_secure(OBJECT_CLASS(mc)); =20 if (compat_props && mc->compat_props) { int i; diff --git a/qapi/machine.json b/qapi/machine.json index 2d63c1bac3..fb9382471f 100644 --- a/qapi/machine.json +++ b/qapi/machine.json @@ -196,6 +196,11 @@ # present when `query-machines` argument @compat-props is true. # (since 9.1) # +# @secure: If true, the machine is declared to provide a security +# boundary from the guest; if false the machine is either +# not providing a security boundary, or its status is undefined. +# (since 11.2) +# # Features: # # @unstable: Member @compat-props is experimental. @@ -209,7 +214,8 @@ 'deprecated': 'bool', '*default-cpu-type': 'str', '*default-ram-id': 'str', 'acpi': 'bool', '*compat-props': { 'type': ['CompatProperty'], - 'features': ['unstable'] } } } + 'features': ['unstable'] }, + 'secure': 'bool' } } =20 ## # @query-machines: --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036644; cv=none; d=zohomail.com; s=zohoarc; b=bD0D+to3zhROOvXieYh9/MQ32r9h+0YrLQAKk4hsWSExo9ZZgk7PQHH4/0NZlbZc3UsiDiJYu5GD7sfnWSJDbxvVbenwE6ZkpVNSY0CK00pkJpWBtfejywmRzohlacvS5iloBvxvmhk73WO7Owp12sbd69vrAGu8NlfElxLJs8U= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036644; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ayhgKrurP9uKIIxZOSsOToWEUcaVKB8ROFt2LR3a45Q=; b=RPPa89405rGsLsuBG6YC3+L+WVWLPwXN/fhUdTBNibn0InwUZOVlZrtvbZDfRx8LAFzEMiS14ygLZVsraDh6SAWtpjQfQUmcOznbj6r/mTAhacui46hnGiiqspxfdP+qsdS9gQcSfbd7laWYFcexkPJVOePkTxCXa8RlWoYl3CY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036644104402.89714415858464; Thu, 10 Sep 2026 03:37:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9X-0003Be-TN; Thu, 10 Sep 2026 06:37:11 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9X-000395-3Z for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:11 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9U-0007iE-Dw for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:10 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-655-jdVlAD5eOva2XXGu3dV_fA-1; Thu, 10 Sep 2026 06:37:03 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 5941D18005A6; Thu, 10 Sep 2026 10:37:02 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 18DD030001A2; Thu, 10 Sep 2026 10:36:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036627; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ayhgKrurP9uKIIxZOSsOToWEUcaVKB8ROFt2LR3a45Q=; b=Q36jG73elu7ZCdspjf+/Z5JWsKw/NUh6bidX+WXYou3+3BQmHu5mqWP4fLAWO5HQ1Pbo4A yU5I7TKy6YD0EmyLkAGnzkymj9dYIxvHz4lzR2C182fUPgfS5rB2VUCuAbc1jZSZmsxJeW i1XD3lBnCZvCVpIJeEH0V3DQzzpLX/4= X-MC-Unique: jdVlAD5eOva2XXGu3dV_fA-1 X-Mimecast-MFC-AGG-ID: jdVlAD5eOva2XXGu3dV_fA_1789036622 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 11/14] qom: refactor data passing for QOM list filtering Date: Thu, 10 Sep 2026 11:36:25 +0100 Message-ID: <20260910103628.2326622-12-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036645836158500 Currently the QOM list method can filter on the abstract flag, but extending the filtering to more variables requires a way to pass in extra data items. This requires a refactoring of the iterator to take a full struct as its opaque data item. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 --- qom/qom-qmp-cmds.c | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/qom/qom-qmp-cmds.c b/qom/qom-qmp-cmds.c index 330895361d..b999e9f723 100644 --- a/qom/qom-qmp-cmds.c +++ b/qom/qom-qmp-cmds.c @@ -151,9 +151,13 @@ QObject *qmp_qom_get(const char *path, const char *pro= perty, Error **errp) return object_property_get_qobject(obj, property, errp); } =20 -static void qom_list_types_tramp(ObjectClass *klass, void *data) +typedef struct { + ObjectTypeInfoList *list; +} ObjectTypeInfoData; + +static void qom_list_types_tramp(ObjectClass *klass, void *opaque) { - ObjectTypeInfoList **pret =3D data; + ObjectTypeInfoData *data =3D opaque; ObjectTypeInfo *info; ObjectClass *parent =3D object_class_get_parent(klass); =20 @@ -164,7 +168,7 @@ static void qom_list_types_tramp(ObjectClass *klass, vo= id *data) info->parent =3D g_strdup(object_class_get_name(parent)); } =20 - QAPI_LIST_PREPEND(*pret, info); + QAPI_LIST_PREPEND(data->list, info); } =20 ObjectTypeInfoList *qmp_qom_list_types(const char *implements, @@ -172,12 +176,14 @@ ObjectTypeInfoList *qmp_qom_list_types(const char *im= plements, bool abstract, Error **errp) { - ObjectTypeInfoList *ret =3D NULL; + ObjectTypeInfoData data =3D { + .list =3D NULL, + }; =20 module_load_qom_all(); - object_class_foreach(qom_list_types_tramp, implements, abstract, &ret); + object_class_foreach(qom_list_types_tramp, implements, abstract, &data= ); =20 - return ret; + return data.list; } =20 ObjectPropertyInfoList *qmp_device_list_properties(const char *typename, --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036653; cv=none; d=zohomail.com; s=zohoarc; b=VbXSj+iulp9ugOldDub2ayVIUxoQaOUbiCPBjozsly51hLeCetKUKU/vVUevJGP8PO57TGeiNXFxm2RMoVOFaL02pMM3l9cxxVEj2tFAH1zG6E9OgUdGb6RuyyMbRBOsoYGn4sAA5xxxkeF3HdCQQPZ/KDesBpLNuH+rCpbmEGc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036653; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9zjeL7Bi7S8pfI44ZpjgUyiYQRHPvAE+LawV2R0Z6t4=; b=AJG7/cMfU0X579DLE8x7LMo/bUcibbOOPyLntal+f/W639RtEei8BgYOkpjj/IUW8sJnNXNlPRINtjUEndsyVjO60iUJbWGBLvDWZjiPuhVf01dlyQZQNaZmnCGynwu65T3j/z/b+QlOeB9zL4klPCJua2exoUXPwrVMS64+cd8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036653232740.431506954466; Thu, 10 Sep 2026 03:37:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9b-0003LX-5s; Thu, 10 Sep 2026 06:37:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9Z-0003DF-1h for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:13 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9W-0007lU-Se for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:12 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-607-1QNP8SEnPr2wCb0X2DCclQ-1; Thu, 10 Sep 2026 06:37:07 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id E12031954223; Thu, 10 Sep 2026 10:37:05 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id BABF530001A2; Thu, 10 Sep 2026 10:37:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036630; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=9zjeL7Bi7S8pfI44ZpjgUyiYQRHPvAE+LawV2R0Z6t4=; b=QLCP80KYV9WfgL02uV429pDD4RRltQEckQH1r0kuPB9h9dr/JSw1ACl5qA1i5AFceNUDwk Ca9J1F50JovSMnnewNHN1exU7si1Dj2Y3aHo2VNyETZ113mbpmktDExYpqjWgbo5mc0e6a UqUeCHab75oPJBWoTCkRqk0zUbdCCkI= X-MC-Unique: 1QNP8SEnPr2wCb0X2DCclQ-1 X-Mimecast-MFC-AGG-ID: 1QNP8SEnPr2wCb0X2DCclQ_1789036626 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 12/14] qom: report & filter on security status in qom-list-types Date: Thu, 10 Sep 2026 11:36:26 +0100 Message-ID: <20260910103628.2326622-13-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036653813158500 This adds: * a new boolean 'secure' field to the type info returned by qom-list-types, which will be set if the type provides a security boundary * a new boolean 'secure' parameter to the arguments of qom-list-types, which can be used to filter types based on their security status Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- qapi/qom.json | 13 +++++++++++-- qom/qom-qmp-cmds.c | 12 ++++++++++++ 2 files changed, 23 insertions(+), 2 deletions(-) diff --git a/qapi/qom.json b/qapi/qom.json index 4a9b7f9088..5895c97750 100644 --- a/qapi/qom.json +++ b/qapi/qom.json @@ -210,12 +210,18 @@ # @abstract: the type is abstract and can't be directly instantiated. # Omitted if false. (since 2.10) # +# @secure: the type provides a security boundary. Omitted if false. +# (since 11.2) +# # @parent: Name of parent type, if any (since 2.10) # # Since: 1.1 ## { 'struct': 'ObjectTypeInfo', - 'data': { 'name': 'str', '*abstract': 'bool', '*parent': 'str' } } + 'data': { 'name': 'str', + '*abstract': 'bool', + '*parent': 'str', + '*secure': 'bool' } } =20 ## # @qom-list-types: @@ -227,12 +233,15 @@ # # @abstract: if true, include abstract types in the results # +# @secure: if set, filter to only include types with matching security +# status (since 11.2) +# # Returns: a list of types, or an empty list if no results are found # # Since: 1.1 ## { 'command': 'qom-list-types', - 'data': { '*implements': 'str', '*abstract': 'bool' }, + 'data': { '*implements': 'str', '*abstract': 'bool', '*secure': 'bool' }, 'returns': [ 'ObjectTypeInfo' ], 'allow-preconfig': true } =20 diff --git a/qom/qom-qmp-cmds.c b/qom/qom-qmp-cmds.c index b999e9f723..9474a1b04b 100644 --- a/qom/qom-qmp-cmds.c +++ b/qom/qom-qmp-cmds.c @@ -153,6 +153,8 @@ QObject *qmp_qom_get(const char *path, const char *prop= erty, Error **errp) =20 typedef struct { ObjectTypeInfoList *list; + bool has_secure; + bool secure; } ObjectTypeInfoData; =20 static void qom_list_types_tramp(ObjectClass *klass, void *opaque) @@ -161,9 +163,15 @@ static void qom_list_types_tramp(ObjectClass *klass, v= oid *opaque) ObjectTypeInfo *info; ObjectClass *parent =3D object_class_get_parent(klass); =20 + if (data->has_secure && + data->secure !=3D object_class_is_secure(klass)) { + return; + } + info =3D g_malloc0(sizeof(*info)); info->name =3D g_strdup(object_class_get_name(klass)); info->has_abstract =3D info->abstract =3D object_class_is_abstract(kla= ss); + info->has_secure =3D info->secure =3D object_class_is_secure(klass); if (parent) { info->parent =3D g_strdup(object_class_get_name(parent)); } @@ -174,10 +182,14 @@ static void qom_list_types_tramp(ObjectClass *klass, = void *opaque) ObjectTypeInfoList *qmp_qom_list_types(const char *implements, bool has_abstract, bool abstract, + bool has_secure, + bool secure, Error **errp) { ObjectTypeInfoData data =3D { .list =3D NULL, + .has_secure =3D has_secure, + .secure =3D secure, }; =20 module_load_qom_all(); --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036687; cv=none; d=zohomail.com; s=zohoarc; b=hhYg5d9w3e3cqwX39dI9/OgyIusZqfHx4OcltwqRvD6EqSV/oo4f9kho9XljfGbMYvp15SUooet2atn1bngeiXcHSoUNf1LVnCT7idzY8UYlZnoB10xqaBxPshcd4A6IONqLVyZ4yNsXAq7S/QIijuu2Rmqy74TE/JTpfzt7t+s= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036687; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gvF28c3ohGlr655lD6IdQeYNke8O1NdNaHR8fRDT/PA=; b=e26E2nQZnMd9/CqoKhmLw2DdCEI268f8FTu5xP0jZ2msIqEXsz/XwQPlsxpYVnHgmhfXBXLXrhIFsLpVGJxCDgzz3tLSQEhZ8Qj+NVYLpVC47Y9BmaMOqh2So/hIe72gvkne0QH3x8dH6g2si+dAbxECFlxQztRclC6nlZuWrsQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036687793218.14241278931968; Thu, 10 Sep 2026 03:38:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9d-0003SS-2x; Thu, 10 Sep 2026 06:37:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9b-0003MK-AM for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:15 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9Z-0007ov-Gv for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:14 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-639-94_gH7Q_M_CwPs6zcrDLjw-1; Thu, 10 Sep 2026 06:37:09 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 78D6319541A7; Thu, 10 Sep 2026 10:37:08 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 3F6FA30001A2; Thu, 10 Sep 2026 10:37:06 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036632; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=gvF28c3ohGlr655lD6IdQeYNke8O1NdNaHR8fRDT/PA=; b=ZuwQLgEvsvKgAHKMIdXHj9ZCvoPmcz1FpiXOjNnbAyUk/jmdxNcwEwc+Wj4XOkzPxnVTHN Hm63kWFzEktczaf8pIvvgSdQaxFmLNEossPgelhqoAH1q5tf5GnjV0XVhgMUzYyGyvKS+B 67QwP4r5HxSNAXCrukPecmlI47Cnodg= X-MC-Unique: 94_gH7Q_M_CwPs6zcrDLjw-1 X-Mimecast-MFC-AGG-ID: 94_gH7Q_M_CwPs6zcrDLjw_1789036628 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 13/14] docs: expand security docs with info about security status Date: Thu, 10 Sep 2026 11:36:27 +0100 Message-ID: <20260910103628.2326622-14-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036689973158500 The description of virtualization vs non-virtualization use cases is a crude approximation of the security characteristics of QEMU devices. Document how QEMU can be probed to obtain information on the security status of type classes, and how policies can be set to inform or control their usage. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson --- docs/system/security.rst | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) diff --git a/docs/system/security.rst b/docs/system/security.rst index 8c42d1a6d8..75e39caede 100644 --- a/docs/system/security.rst +++ b/docs/system/security.rst @@ -158,6 +158,42 @@ an issue as a normal bug. usually not justify handling as security bugs, nor assignment of CVEs. They will be fixed as routine bugs when time allows. =20 +Security status reporting +''''''''''''''''''''''''' + +The QEMU project annotates types to explicitly state whether they are +considered to provide a security boundary or not. For machine, accelerator +and device types, only those annotated with the "secure" flag will be +eligible for CVE assignment. Annotations will be extended to other backend +and object types over time, to make their security status explicit. + +It is possible to control or identify the usage of types that do not offer +an explicit security boundary using the ``insecure-types`` parameter to the +``-compat`` argument, which accepts three values: + + * accept: usage of any type will be permitted. This is the current + and historical default behaviour + * warn: usage of types not explicitly declared secure will result + in a warning message, but still be permitted. + * reject: usage of types not explicitly declared secure will result + in an error message, and will not be permitted. + +The compatibility policy will be honoured both at initial startup of +QEMU and during any runtime alterations made with monitor commands. + +The status of any type class can be queried at runtime using the +``qom-list-types`` command, whose returned information will flag any +types declared as secure. The ``query-machines`` command will also +reflect this same information for machine types. + +Machine type, accelerator and device security status can be queried +using ``-machine help``, ``-accel help`` and ``-device help`` command +line options respectively. + +Setting the ``.secure`` field to ``true`` in the ``TypeInfo`` +instance for an Object class, declares that the type aims to provide +a security boundary. + Architecture ------------ =20 --=20 2.55.0 From nobody Sat Sep 26 20:00:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789036687; cv=none; d=zohomail.com; s=zohoarc; b=hjxszz65Z9Ok3mS2xO8QW41rAyr9FGku5x3nxq/z3DwTH25jdFuoqiEOehE3UHVVryDEeDSnYhyRSAMQ5PHmho/YjItUdOn9DzFa97cb9VtCifWAfU+mRtkfxXe70TkGOvT1zNJ1DkotAu7ZrquCzkGNhdHkj3es+wE8wGUdBPE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789036687; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=CXJgVC4XLVtkKGj5Y8kcJarPECLGk2rTDsJbaQXsZnE=; b=AT0FB+GxeuR5mf6sr02LbAhPCaYdfcMixSYjYhHYBi0TlAs3kGWDwwqVoIRJqIZUkoQXBdRNNYVaC+qwsgg6ZTIFUWIR85jmBLeKzCMyMnDUamiDDvakHfLIqVAWV60Wt3DJ6lkDQ2sc99Z/x3K9s9k31rjBhBpdkpSG3UwQNi4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789036687865211.86377914471632; Thu, 10 Sep 2026 03:38:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4c9g-0003eO-62; Thu, 10 Sep 2026 06:37:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9e-0003Yu-Gq for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:18 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4c9c-0007ry-8X for qemu-devel@nongnu.org; Thu, 10 Sep 2026 06:37:18 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-39-ccMqCgAlM9WOZf6IUpwHlw-1; Thu, 10 Sep 2026 06:37:12 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 0E1E71800665; Thu, 10 Sep 2026 10:37:11 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id CB99D30001A2; Thu, 10 Sep 2026 10:37:08 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789036635; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=CXJgVC4XLVtkKGj5Y8kcJarPECLGk2rTDsJbaQXsZnE=; b=CuV56TuwpkIqtcoGnWEJURovyRIXJyijoFnzS3k8JzsmezMjLs0etiqJMu6Pvm/VdsYBeS 61njhBe+jIh8CZUDVGJIr7SElURa7Bgipe5DCVzHD00gpiCrfpDTgCTY3JR10SJHIyxKfS +6HK/IGayBv9/6sjtaUQY5QiAxanD0w= X-MC-Unique: ccMqCgAlM9WOZf6IUpwHlw-1 X-Mimecast-MFC-AGG-ID: ccMqCgAlM9WOZf6IUpwHlw_1789036631 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Markus Armbruster , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Stefan Hajnoczi , Paolo Bonzini , "Michael S. Tsirkin" , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v4 14/14] machine: add helpers for declaring secure/insecure machine types Date: Thu, 10 Sep 2026 11:36:28 +0100 Message-ID: <20260910103628.2326622-15-berrange@redhat.com> In-Reply-To: <20260910103628.2326622-1-berrange@redhat.com> References: <20260910103628.2326622-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789036690035158500 The current DEFINE_MACHINE macro will declare machine type without any explicit statement about the security status. As such the machine type will be treated as implicitly insecure at runtime. Introduce a new DEFINE_SECURE_MACHINE macro (with variants) that allow code to make an explicit statement that the machine is treated as secure. This should primarily be used for versioned machine types that are intended to be used with KVM, though some others may warrant a security declaration. Use of the existing macros marks a machine as insecure, which is the desired default for most machines servicing emulation use cases. The same is done for the specialized i386 PC related macros. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 --- hw/arm/bananapi_m2u.c | 2 +- hw/arm/cubieboard.c | 2 +- hw/arm/imx8mm-evk.c | 2 +- hw/arm/integratorcp.c | 2 +- hw/arm/mcimx7d-sabre.c | 2 +- hw/arm/orangepi.c | 2 +- hw/ppc/pegasos.c | 3 ++- include/hw/core/boards.h | 25 ++++++++++++++++++++----- include/hw/i386/pc.h | 11 ++++++++++- 9 files changed, 38 insertions(+), 13 deletions(-) diff --git a/hw/arm/bananapi_m2u.c b/hw/arm/bananapi_m2u.c index 8f59111fd4..ccf60ba295 100644 --- a/hw/arm/bananapi_m2u.c +++ b/hw/arm/bananapi_m2u.c @@ -153,4 +153,4 @@ static void bpim2u_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("bpim2u", MACHINE, Bpim2uMachineState, - bpim2u_machine_init, false, NULL) + bpim2u_machine_init, false, false, NULL) diff --git a/hw/arm/cubieboard.c b/hw/arm/cubieboard.c index ae27056938..e4fef9cd76 100644 --- a/hw/arm/cubieboard.c +++ b/hw/arm/cubieboard.c @@ -133,5 +133,5 @@ static void cubieboard_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("cubieboard", MACHINE, CubieboardMachineState, - cubieboard_machine_init, false, + cubieboard_machine_init, false, false, NULL) diff --git a/hw/arm/imx8mm-evk.c b/hw/arm/imx8mm-evk.c index 8a5737502f..c3215b11cb 100644 --- a/hw/arm/imx8mm-evk.c +++ b/hw/arm/imx8mm-evk.c @@ -134,5 +134,5 @@ static void imx8mm_evk_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("imx8mm-evk", MACHINE, Imx8mmEvkMachineState, - imx8mm_evk_machine_init, false, + imx8mm_evk_machine_init, false, false, NULL) diff --git a/hw/arm/integratorcp.c b/hw/arm/integratorcp.c index 382ea7850d..b766edeeee 100644 --- a/hw/arm/integratorcp.c +++ b/hw/arm/integratorcp.c @@ -704,7 +704,7 @@ static void integratorcp_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("integratorcp", MACHINE, IntegratorcpMachineState, - integratorcp_machine_init, false, + integratorcp_machine_init, false, false, NULL) =20 static const Property core_properties[] =3D { diff --git a/hw/arm/mcimx7d-sabre.c b/hw/arm/mcimx7d-sabre.c index db8a62e5f6..65fdb19c06 100644 --- a/hw/arm/mcimx7d-sabre.c +++ b/hw/arm/mcimx7d-sabre.c @@ -86,5 +86,5 @@ static void mcimx7d_sabre_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("mcimx7d-sabre", MACHINE, Mcimx7dSabreMachineState, - mcimx7d_sabre_machine_init, false, + mcimx7d_sabre_machine_init, false, false, NULL) diff --git a/hw/arm/orangepi.c b/hw/arm/orangepi.c index 7a19732f5d..18ed174032 100644 --- a/hw/arm/orangepi.c +++ b/hw/arm/orangepi.c @@ -133,5 +133,5 @@ static void orangepi_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("orangepi-pc", MACHINE, OrangePiMachineState, - orangepi_machine_init, false, + orangepi_machine_init, false, false, NULL) diff --git a/hw/ppc/pegasos.c b/hw/ppc/pegasos.c index 9d7e279123..fba2a55890 100644 --- a/hw/ppc/pegasos.c +++ b/hw/ppc/pegasos.c @@ -788,7 +788,8 @@ static void pegasos2_machine_class_init(ObjectClass *oc= , const void *data) } =20 DEFINE_MACHINE_EXTENDED("pegasos", MACHINE, PegasosMachineState, - pegasos_machine_init, true, (const InterfaceInfo[]= ) { + pegasos_machine_init, true, false, + (const InterfaceInfo[]) { { TYPE_PPC_VIRTUAL_HYPERVISOR }, { TYPE_VOF_MACHINE_IF }, { } }) =20 diff --git a/include/hw/core/boards.h b/include/hw/core/boards.h index a436d48c8e..c2e0327a39 100644 --- a/include/hw/core/boards.h +++ b/include/hw/core/boards.h @@ -514,7 +514,7 @@ struct MachineState { */ =20 #define DEFINE_MACHINE_EXTENDED(namestr, PARENT_NAME, InstanceName, \ - machine_initfn, ABSTRACT, ifaces...) \ + machine_initfn, ABSTRACT, SECURE, ifaces..= .) \ static void machine_initfn##_class_init(ObjectClass *oc, const void *d= ata) \ { \ MachineClass *mc =3D MACHINE_CLASS(oc); \ @@ -526,6 +526,7 @@ struct MachineState { .class_init =3D machine_initfn##_class_init, \ .instance_size =3D sizeof(InstanceName), \ .abstract =3D ABSTRACT, \ + .secure =3D SECURE, \ .interfaces =3D ifaces, \ }; \ static void machine_initfn##_register_types(void) \ @@ -534,18 +535,32 @@ struct MachineState { } \ type_init(machine_initfn##_register_types) =20 +/* Implicitly insecure */ #define DEFINE_MACHINE(namestr, machine_initfn) \ DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ - false, NULL) + false, false, NULL) =20 -#define DEFINE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, iface= s...)\ +#define DEFINE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, iface= s...) \ DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ - false, ifaces) + false, false, ifaces) =20 -#define DEFINE_MACHINE_WITH_INTERFACES(namestr, machine_initfn, ...) \ +#define DEFINE_MACHINE_WITH_INTERFACES(namestr, machine_initfn, ...) \ DEFINE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, \ (const InterfaceInfo[]) { __VA_ARG= S__ }) =20 + +#define DEFINE_SECURE_MACHINE(namestr, machine_initfn) \ + DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ + false, true, NULL) + +#define DEFINE_SECURE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn= , ifaces...) \ + DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ + false, true, ifaces) + +#define DEFINE_SECURE_MACHINE_WITH_INTERFACES(namestr, machine_initfn, ...= ) \ + DEFINE_SECURE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, \ + (const InterfaceInfo[]) { _= _VA_ARGS__ }) + /* * Helper for dispatching different macros based on how * many __VA_ARGS__ are passed. Supports 1 to 5 variadic diff --git a/include/hw/i386/pc.h b/include/hw/i386/pc.h index ac03da97b6..d5dc79df17 100644 --- a/include/hw/i386/pc.h +++ b/include/hw/i386/pc.h @@ -275,7 +275,7 @@ extern const size_t pc_compat_4_2_len; extern GlobalProperty pc_compat_4_1[]; extern const size_t pc_compat_4_1_len; =20 -#define DEFINE_PC_MACHINE(suffix, namestr, initfn, optsfn) \ +#define DEFINE_PC_MACHINE_EXTENDED(suffix, namestr, initfn, optsfn, issecu= re) \ static void pc_machine_##suffix##_class_init(ObjectClass *oc, \ const void *data) \ { \ @@ -287,6 +287,7 @@ extern const size_t pc_compat_4_1_len; .name =3D namestr TYPE_MACHINE_SUFFIX, \ .parent =3D TYPE_PC_MACHINE, \ .class_init =3D pc_machine_##suffix##_class_init, \ + .secure =3D issecure, \ }; \ static void pc_machine_init_##suffix(void) \ { \ @@ -294,6 +295,14 @@ extern const size_t pc_compat_4_1_len; } \ type_init(pc_machine_init_##suffix) =20 +/* Implicitly insecure */ +#define DEFINE_PC_MACHINE(suffix, namestr, initfn, optsfn) \ + DEFINE_PC_MACHINE_EXTENDED(suffix, namestr, initfn, optsfn, false) + +#define DEFINE_SECURE_PC_MACHINE(suffix, namestr, initfn, optsfn) \ + DEFINE_PC_MACHINE_EXTENDED(suffix, namestr, initfn, optsfn, true) + + #define DEFINE_PC_VER_MACHINE(namesym, namestr, initfn, isdefault, malias,= ...) \ static void MACHINE_VER_SYM(init, namesym, __VA_ARGS__)( \ MachineState *machine) \ --=20 2.55.0