From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661309; cv=none; d=zohomail.com; s=zohoarc; b=PDCmIZp+82AFZK2PliVuevLBC/ccV742UbwoHGTDaet8h89PQ3/Ux5U3GXBjpfgJzAjmTXm+FoKDRynH0aHGQ/Fhu5feY8DPkYsgRVCyO4f4/+2I5Ow5gqT5Zzi8G2idNBdnP0x/Ky5v6XHR1Qkq0EWUTM8e/RY7qBg6FR4YJww= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661309; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=dMa85vmFyQ5UuLbzWOL7PoyW7GKfUTR//SukCVfnsuI=; b=k7vC8OrC/s53zA2fHqs8edOtOrQizcsFd4OUqF/ZdjoRrreTqHO5DaJtPM0lEtQ7vw0taAE3d14n+9AK4XpdpGwDMoOCAn7TN0FGxbXC/WVXUfpczXgU75YXpF0fQPOixtUKGFfEqVeSfkb4VsMWy9EvqMd9d/81m35opFKgpt8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661309548121.73214971718926; Thu, 17 Sep 2026 09:08:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Ece-00060F-4R; Thu, 17 Sep 2026 12:06:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcH-0005pV-SJ for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:44 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcA-0006qq-Q2 for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:39 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-675-qo3qBJ41MaCldSXq4tb64w-1; Thu, 17 Sep 2026 12:05:31 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 5F95918015CC; Thu, 17 Sep 2026 16:05:30 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0E76F300022B; Thu, 17 Sep 2026 16:05:28 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661133; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=dMa85vmFyQ5UuLbzWOL7PoyW7GKfUTR//SukCVfnsuI=; b=iDh7ZMsjcI9c5p2og8WmZmzW+io7E94RylJQNOX689teZh93y8O43IDRTtPF8rSOc+EKfW EbYfYKhRmqAh9PXMuVlmOKDPix3WtcAYqMWE1SMHy/3RMj7VfGTqHrvu7DiGC9+aDcumwK 4HV2kqxLlkRCxTqXZNVERYfl+AXnRmY= X-MC-Unique: qo3qBJ41MaCldSXq4tb64w-1 X-Mimecast-MFC-AGG-ID: qo3qBJ41MaCldSXq4tb64w_1789661130 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 01/14] qom: add tracking of security state of object types Date: Thu, 17 Sep 2026 17:05:12 +0100 Message-ID: <20260917160525.1275388-2-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661311001158500 This introduces a new flag "secure" against the Type/TypeInfo structs, and helpers to check this against the ObjectClass struct. If an object is considered to provide a security boundary to protect against untrusted code, the "secure" flag must be explicitly set to true. If it is set to false, or left unset, this indicates that the object does not intend to provide a security boundary. Bugs related to this object class will be ineligible for CVE assignment. Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- include/qom/object.h | 13 +++++++++++++ qom/object.c | 7 +++++++ rust/qom/src/qom.rs | 4 ++++ 3 files changed, 24 insertions(+) diff --git a/include/qom/object.h b/include/qom/object.h index 7ecd0f210fb..687ceb6bba0 100644 --- a/include/qom/object.h +++ b/include/qom/object.h @@ -453,6 +453,10 @@ struct Object * function. * @abstract: If this field is true, then the class is considered abstract= and * cannot be directly instantiated. + * @secure: If this field is initialized to true, then the class is consid= ered + * to provide a security boundary. If initialized to false, the class do= es + * not provide a security boundary. If uninitialized (and thus implicitly + * false) its status is not yet defined. * @class_size: The size of the class object (derivative of #ObjectClass) * for this object. If @class_size is 0, then the size of the class wil= l be * assumed to be the size of the parent class. This allows a type to av= oid @@ -487,6 +491,7 @@ struct TypeInfo void (*instance_finalize)(Object *obj); =20 bool abstract; + bool secure; size_t class_size; =20 void (*class_init)(ObjectClass *klass, const void *data); @@ -1074,6 +1079,14 @@ const char *object_class_get_name(ObjectClass *klass= ); */ bool object_class_is_abstract(ObjectClass *klass); =20 +/** + * object_class_is_secure: + * @klass: The class to check security of + * + * Returns: %true if @klass is declared to be secure, %false if not declar= ed + */ +bool object_class_is_secure(ObjectClass *klass); + /** * object_class_by_name: * @typename: The QOM typename to obtain the class for. diff --git a/qom/object.c b/qom/object.c index b1834a57cc9..32736a01114 100644 --- a/qom/object.c +++ b/qom/object.c @@ -67,6 +67,7 @@ struct TypeImpl void (*instance_finalize)(Object *obj); =20 bool abstract; + bool secure; =20 const char *parent; TypeImpl *parent_type; @@ -122,6 +123,7 @@ static TypeImpl *type_new(const TypeInfo *info) ti->instance_finalize =3D info->instance_finalize; =20 ti->abstract =3D info->abstract; + ti->secure =3D info->secure; =20 for (i =3D 0; info->interfaces && info->interfaces[i].type; i++) { ti->interfaces[i].typename =3D g_strdup(info->interfaces[i].type); @@ -1144,6 +1146,11 @@ bool object_class_is_abstract(ObjectClass *klass) return klass->type->abstract; } =20 +bool object_class_is_secure(ObjectClass *klass) +{ + return klass->type->secure; +} + const char *object_class_get_name(ObjectClass *klass) { return klass->type->name; diff --git a/rust/qom/src/qom.rs b/rust/qom/src/qom.rs index bbb485e2cfd..81449eeefad 100644 --- a/rust/qom/src/qom.rs +++ b/rust/qom/src/qom.rs @@ -651,6 +651,9 @@ pub trait ObjectImpl: ObjectType + IsA { /// Whether the object can be instantiated const ABSTRACT: bool =3D false; =20 + /// Whether the object provides a security boundary for untrusted acce= ss + const SECURE: bool =3D false; + /// Function that is called to initialize an object. The parent class= will /// have already been initialized so the type is only responsible for /// initializing its own members. @@ -687,6 +690,7 @@ pub trait ObjectImpl: ObjectType + IsA { }, instance_finalize: Some(drop_object::), abstract_: Self::ABSTRACT, + secure: Self::SECURE, class_size: core::mem::size_of::(), class_init: Some(rust_class_init::), class_base_init: Self::CLASS_BASE_INIT, --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661174; cv=none; d=zohomail.com; s=zohoarc; b=PCcesOoso6Ck6tXAhdvPursacK5psn1f7jEBMXzRF1s20vZ//7ImY8Z6Vl3JWywFQKt8nAwYmPz7V4oCXOIApKAeqoUHnv5eBGIG5AzXTipYJFpiKuoikgt7fd8sjdh+GdSqqAx0c1gtt5fFYzypdY3chWHyqr6WY4oi8RkBNBo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661174; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Tp4k2TnLWm2690QQrf2eUErZJWedHgYyEX3pnFdeeD0=; b=fvJtfwNLcpfSuxaPcS4uqCvTcZgjjcgVfWhE7UEekdvSh9Gw0rtrJv19E7XUqMapXKMFnSxrPjNeGJd5/AAEoTtal7VMa4zyyHVMLhR54qK1EHb1GoiKr/xvrlDV8tgQkNaBzsX/mwu5wIj9YXnzYBOtgMnjJBCw0uwP+k1nV98= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661174909153.54935371928752; Thu, 17 Sep 2026 09:06:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Ech-00067e-Mg; Thu, 17 Sep 2026 12:06:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcH-0005pW-VM for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:44 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcE-0006rR-9i for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:40 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-32-2cvvQTDKPjOsm0e9XJNkMg-1; Thu, 17 Sep 2026 12:05:33 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 1BDCD1828B22; Thu, 17 Sep 2026 16:05:32 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id DD83A300022B; Thu, 17 Sep 2026 16:05:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661136; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Tp4k2TnLWm2690QQrf2eUErZJWedHgYyEX3pnFdeeD0=; b=M8GN7A+cq2fm3B/3Mgh93WKuPjHIp8Esb2WruUAH1ltaxGDPlYRau0c2rgy5o7KtZkhB/O eTROvi3biBMg2SoqBcUN5l5FKOes3MfM0zZba6V/TYS9j7VzPQ936zijTHrXghLYhp8m/U l1kZqjHrhFFbuWuwksb2OBluctjrHB8= X-MC-Unique: 2cvvQTDKPjOsm0e9XJNkMg-1 X-Mimecast-MFC-AGG-ID: 2cvvQTDKPjOsm0e9XJNkMg_1789661132 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 02/14] qapi: add 'insecure-types' option for -compat argument Date: Thu, 17 Sep 2026 17:05:13 +0100 Message-ID: <20260917160525.1275388-3-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661182641158500 This introduces a new 'insecure-types' option for the 'compat' argument that accepts three values * accept: Allow any usage * reject: Reject with an error reported * warn: Allow any usage, with a warning reported For historical compatibility it defaults to 'accept'. The 'reject' and 'warn' values will take effect for any type that has been explicitly marked insecure, or is lacking an explicit declaration of its security status. This new command line option is currently a no-op, but will become functional as following patches enable the checks. Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- include/qapi/compat-policy.h | 5 +++++ qapi/compat.json | 23 ++++++++++++++++++++++- qapi/qapi-util.c | 30 ++++++++++++++++++++++++++++++ 3 files changed, 57 insertions(+), 1 deletion(-) diff --git a/include/qapi/compat-policy.h b/include/qapi/compat-policy.h index ea65e10744a..f5af2090692 100644 --- a/include/qapi/compat-policy.h +++ b/include/qapi/compat-policy.h @@ -24,6 +24,11 @@ bool compat_policy_input_ok(uint64_t features, const char *kind, const char *name, Error **errp); =20 +bool compat_policy_check_security(const CompatPolicy *policy, + const char *typename, + bool is_secure, + Error **errp); + /* * Create a QObject input visitor for @obj for use with QMP * diff --git a/qapi/compat.json b/qapi/compat.json index 90b8d51cf27..b54f8eb3713 100644 --- a/qapi/compat.json +++ b/qapi/compat.json @@ -37,6 +37,23 @@ { 'enum': 'CompatPolicyOutput', 'data': [ 'accept', 'hide' ] } =20 +## +# @CompatPolicySecurity: +# +# Policy for handling any devices or backends which do not provide a +# security boundary to protect against untrusted environments +# +# @accept: Allow any usage +# +# @reject: Reject with an error reported +# +# @warn: Allow any usage, with a warning reported +# +# Since: 11.2 +## +{ 'enum': 'CompatPolicySecurity', + 'data': [ 'accept', 'reject', 'warn' ] } + ## # @CompatPolicy: # @@ -62,10 +79,14 @@ # @unstable-output: how to handle unstable output (default 'accept') # (since 6.2) # +# @insecure-types: how to handle types that are not declared secure +# (default 'accept') (since 11.2) +# # Since: 6.0 ## { 'struct': 'CompatPolicy', 'data': { '*deprecated-input': 'CompatPolicyInput', '*deprecated-output': 'CompatPolicyOutput', '*unstable-input': 'CompatPolicyInput', - '*unstable-output': 'CompatPolicyOutput' } } + '*unstable-output': 'CompatPolicyOutput', + '*insecure-types': 'CompatPolicySecurity' } } diff --git a/qapi/qapi-util.c b/qapi/qapi-util.c index 3d849fe0347..38b1cec7a41 100644 --- a/qapi/qapi-util.c +++ b/qapi/qapi-util.c @@ -14,6 +14,7 @@ #include "qapi/compat-policy.h" #include "qapi/error.h" #include "qemu/ctype.h" +#include "qemu/error-report.h" #include "qapi/qmp/qerror.h" =20 CompatPolicy compat_policy; @@ -58,6 +59,35 @@ bool compat_policy_input_ok(uint64_t features, return true; } =20 +bool compat_policy_check_security(const CompatPolicy *policy, + const char *typename, + bool is_secure, + Error **errp) +{ + if (is_secure) { + return true; + } + + switch (policy->insecure_types) { + case COMPAT_POLICY_SECURITY_ACCEPT: + return true; + + case COMPAT_POLICY_SECURITY_REJECT: + error_setg(errp, "Type '%s' does not provide a security boundary " + "to protect against untrusted data or actions", typenam= e); + return false; + + case COMPAT_POLICY_SECURITY_WARN: + warn_report("Type '%s' does not provide a security boundary " + "to protect against untrusted data or actions", typena= me); + return true; + + default: + g_assert_not_reached(); + } +} + + const char *qapi_enum_lookup(const QEnumLookup *lookup, int val) { assert(val >=3D 0 && val < lookup->size); --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661216; cv=none; d=zohomail.com; s=zohoarc; b=TQf7n2Tcr0MCsxjmll/pP4MMceV204iBZIbVVnM8UBwWhKWUqz8QaPCAOkk2oD9uNQQlERxbXodLA2Uj5jOTpQ6862G/VWspwVOj/49uHOfR98fsrVrTfDUI7HWoa1HtNGZWEYqSde46D7SonSv6ouE74esI9nfVcYp/apS/L1g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661216; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yFy03EcNo/zN+LXjPdSvqXANo3cII39jdhmCAaK+hoc=; b=USBm/XSDhiVnPFdnZX7lwFhhXgo6qOOOXhnLfo+GhJW3QyRa1CvBI0CTS0RBSg0jsjO6yWBGJEi7jlMvxdB7KaoedEn+5wsWGluXEVMyieJlxuNqRsxLcSO6TTO9V04C7Ro+cJ9DdN7cu/H/V9XdkHT+dLA+dm36Yx+s3UwDJa4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661216122835.3772884014653; Thu, 17 Sep 2026 09:06:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Ecg-00067H-MU; Thu, 17 Sep 2026 12:06:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcH-0005pX-Vg for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:44 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcE-0006rP-AO for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:40 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-62-0WXWCDLCNLqHvaCGU91Tcg-1; Thu, 17 Sep 2026 12:05:34 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id AB123195DE3A; Thu, 17 Sep 2026 16:05:33 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 82D96300022B; Thu, 17 Sep 2026 16:05:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661136; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=yFy03EcNo/zN+LXjPdSvqXANo3cII39jdhmCAaK+hoc=; b=Q2G9Tmzo3tJnCvp/gJ00oIkTdZl8gw3olFArOZ2pYiid1xQSKrzyQHdlaTWZnVqxJe6u9G NiuYdWrMiMibrfIgCPCBDU2MuL6kkwYQmuh5OKH76mFB65GNub+kiWgGoPzZgZKGwEdezP TJoeBHgGGDHpKlAuqxET0eOF0FBiTG4= X-MC-Unique: 0WXWCDLCNLqHvaCGU91Tcg-1 X-Mimecast-MFC-AGG-ID: 0WXWCDLCNLqHvaCGU91Tcg_1789661133 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 03/14] qom: add helper API for checking object class security policy compliance Date: Thu, 17 Sep 2026 17:05:14 +0100 Message-ID: <20260917160525.1275388-4-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661218888158500 This helper simply avoids a verbose code pattern being repeated for many callers. Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- include/qom/object.h | 13 +++++++++++++ qom/object.c | 9 +++++++++ 2 files changed, 22 insertions(+) diff --git a/include/qom/object.h b/include/qom/object.h index 687ceb6bba0..32852186646 100644 --- a/include/qom/object.h +++ b/include/qom/object.h @@ -2405,6 +2405,19 @@ Object *object_property_add_new_container(Object *ob= j, const char *name); char *object_property_help(const char *name, const char *type, QObject *defval, const char *description); =20 +/** + * object_class_check_security: + * @klass: the object class to check + * @errp: a pointer to an Error that is filled if not compliant + * + * Check whether the object class @klass complies with the + * currently requested security policy. Reports an error + * in @errp if not compliant. + * + * Returns: true if compliant, false if an error was raised + */ +bool object_class_check_security(ObjectClass *klass, Error **errp); + G_DEFINE_AUTOPTR_CLEANUP_FUNC(Object, object_unref) =20 #endif diff --git a/qom/object.c b/qom/object.c index 32736a01114..41b1ec81d4e 100644 --- a/qom/object.c +++ b/qom/object.c @@ -23,6 +23,7 @@ #include "qapi/qobject-input-visitor.h" #include "qapi/forward-visitor.h" #include "qapi/qapi-builtin-visit.h" +#include "qapi/compat-policy.h" #include "qobject/qdict.h" #include "qobject/qjson.h" #include "qemu/id.h" @@ -3149,6 +3150,14 @@ void object_class_property_set_description(ObjectCla= ss *klass, op->description =3D g_strdup(description); } =20 +bool object_class_check_security(ObjectClass *klass, Error **errp) +{ + return compat_policy_check_security(&compat_policy, + object_class_get_name(klass), + object_class_is_secure(klass), + errp); +} + static void object_class_init(ObjectClass *klass, const void *data) { object_class_property_add_str(klass, "type", object_get_type, --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661305; cv=none; d=zohomail.com; s=zohoarc; b=KjcY9pdFMT/Es2p3BL2sut8yQzQ9MvygDdcAlHXfCcdpDA71HSftqSir7rH3XkqcUerbuc88MKtniU5GFJZ0qCc0xeu8FVGX+ERNorZklJJJ/MHzhX10dtUh1omQNPdWC0hDgYE5TGYyFILxt56eFq65erX8WkoFUxcj/ICEAbQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661305; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wR7t6Boq5Krc0f3t8KsJTcIEdLNSXWXN1MubH9P3R1U=; b=ku+QdCJfuM8Ds8mH8JA5ScPvtIsrQe7RwgNpQZyiIErOQ+jZFw9TsdHjtdT06j/lrrMYyAzK03xzeJvusWsSsRM1/3bwE9hs6IdLd4ix3PBP9iL9PVjYs9ikPyddKuhLvnOMU2QzGx5MniCP/yy/bnMmM1GaGKWr73864ywXS4U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661305926393.3523941886227; Thu, 17 Sep 2026 09:08:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Ece-00060M-4G; Thu, 17 Sep 2026 12:06:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcM-0005po-3z for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:50 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcH-0006s6-LM for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:42 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-628-YBh17tlYOYiqM9XDMPkeUg-1; Thu, 17 Sep 2026 12:05:36 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 6D2B618301AD; Thu, 17 Sep 2026 16:05:35 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0822930002C2; Thu, 17 Sep 2026 16:05:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661140; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=wR7t6Boq5Krc0f3t8KsJTcIEdLNSXWXN1MubH9P3R1U=; b=EcjzCVsN60xhvVxk0Xct09p6ZK9kUVowJ4NnifhzqcnV6RYbC7znFdOl327sj71IzSb9+o 8csoIva7wB9PpqQat5mQmDxUZI+hDxF37yufWWs3DcOP87zBR9u6h9yal18hphdxXqV5Qm feOr7pEr5YHS3hIZYjOx0ou/IlGepYI= X-MC-Unique: YBh17tlYOYiqM9XDMPkeUg-1 X-Mimecast-MFC-AGG-ID: YBh17tlYOYiqM9XDMPkeUg_1789661135 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 04/14] system: check security for accelerator types Date: Thu, 17 Sep 2026 17:05:15 +0100 Message-ID: <20260917160525.1275388-5-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661307139158501 This wires up the accelerator creation code to apply the compat policy security check. When multiple -accel options are given, normal fallback logic applies. IOW, if one is rejected by the security check, it will carry on to try the next accelerator until one passes the security check. Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- system/vl.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/system/vl.c b/system/vl.c index 9bd7664b85c..0c6e44f21cc 100644 --- a/system/vl.c +++ b/system/vl.c @@ -2412,6 +2412,11 @@ static int do_configure_accelerator(void *opaque, Qe= muOpts *opts, Error **errp) } goto bad; } + + if (!object_class_check_security(OBJECT_CLASS(ac), errp)) { + goto bad; + } + accel =3D ACCEL(object_new_with_class(OBJECT_CLASS(ac))); object_apply_compat_props(OBJECT(accel)); qemu_opt_foreach(opts, accelerator_set_property, --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661212; cv=none; d=zohomail.com; s=zohoarc; b=ZQceKFSrFuXGe3kBltZCuMoa8tO631jzSIreobaQesVwc5YtEfO3KvIbhM2pe+0+jIRhXyvceHsxq9WrbCN+RWMvNxiy+WT44/Ja7AldUlC7NF7ohd1hB0L34FlJnwSH2Ywvafc9nF2cZu49Ovlrg/s9Q2Und5lRxpyzpq9C9K0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661212; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=v6tZoiLc8RcWQgEwCTF/+HbzvmlO1jmoCuKsSJrbcAY=; b=SEAx1/GEOn2eZaVhTrQzNJ73fzcYutkRgbJgKVr1R6mTClTw6kcNxKnwQ/4p8RtE9020HkkcrMjnwimCVMhZlwUyw8UjiBz8N1cxcNL3N0oQQyQSnQ66h7Nxupdlb+BM8hQAIwoMncUwG3lgKrnl0eI4IFBHUQM8l26AFuSGOgI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661212518868.6692292373879; Thu, 17 Sep 2026 09:06:52 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Ed6-0006QF-MZ; Thu, 17 Sep 2026 12:06:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcI-0005pY-0Z for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:44 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcG-0006ry-DA for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:41 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-570-_OV55Q5YO7CrfG3vvrn0HQ-1; Thu, 17 Sep 2026 12:05:37 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id E43E91802658; Thu, 17 Sep 2026 16:05:36 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id BEDB3300022B; Thu, 17 Sep 2026 16:05:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661139; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=v6tZoiLc8RcWQgEwCTF/+HbzvmlO1jmoCuKsSJrbcAY=; b=fikAJLXBxI0kJnljmmu3IWFoKoelQJrhb/GpZI+SXPSfHFY/3Mli17+xHNXm5Mjx5TWorG OVy4yh7mUDjdyzSR4lTdARcdQ20pN58Znq/GvrwcOTBDavd79QcieHV++64Sp8FTZpN7BR DSqQpoFBLOhL0YFk4Hd5Vo2qYKcwfu4= X-MC-Unique: _OV55Q5YO7CrfG3vvrn0HQ-1 X-Mimecast-MFC-AGG-ID: _OV55Q5YO7CrfG3vvrn0HQ_1789661137 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 05/14] system: report acclerator security status in help output Date: Thu, 17 Sep 2026 17:05:16 +0100 Message-ID: <20260917160525.1275388-6-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661214817158500 When '-accel help' is given, report the security status of each accelerator. Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- system/vl.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/system/vl.c b/system/vl.c index 0c6e44f21cc..ca54da26c54 100644 --- a/system/vl.c +++ b/system/vl.c @@ -3451,7 +3451,10 @@ void qemu_init(int argc, char **argv) g_str_has_suffix(typename, ACCEL_CLASS_SUFFIX)= ) { gchar **optname =3D g_strsplit(typename, ACCEL_CLASS_SUFFI= X, 0); - printf("%s\n", optname[0]); + printf("%s%s\n", optname[0], + object_class_is_secure( + OBJECT_CLASS(el->data)) ? + " (secure)" : ""); g_strfreev(optname); } g_free(typename); --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661316; cv=none; d=zohomail.com; s=zohoarc; b=JMIcAl8Mr+nU/011oFRO+FbE8y1RRozaPGV3EQzW8bF9N1/7NrvQdyxYAyxBwvmvaNntgASH+0Bz+u9FNUziqgBunM8H6jR5ujABmtA/+6H4Ub2Bde7/YlAPF/UX6gDXC8hYpelEAEV08lUo7ClQcQ6WieIOUngUOxQ/8Ns/yLE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661316; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=iSZY2PhwDM9Fxaivu9DK/zZyur+tKhVl6Df8R3YZRwc=; b=XnQQWLppMK9YfezggFtlPPMJMOx+LeBx7WrjWkRRJcEXISDB+2195pCu5mesOC/CN6XrcNxeuzyL33quWd1kmPfdsEcu9im0LRK9xocmcS246uc5A2UUB/D7JIRFZQzz9Fb6Wn5avndiJJuN1XOataHn3p2m8xBx3T5vbbs+oYU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661316008856.1251713829139; Thu, 17 Sep 2026 09:08:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Eci-00068y-QG; Thu, 17 Sep 2026 12:06:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcU-0005rQ-RZ for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:55 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcL-0006sj-AS for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:49 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-30-MkMX_e8CMTWzm7bRPAlvYg-1; Thu, 17 Sep 2026 12:05:39 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 62803182E6BE; Thu, 17 Sep 2026 16:05:38 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 4EB7F300022B; Thu, 17 Sep 2026 16:05:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661142; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=iSZY2PhwDM9Fxaivu9DK/zZyur+tKhVl6Df8R3YZRwc=; b=GBjqa4UQYC65H3oSgUL2JIFtc9BaejXw+WPGyFI2GcvLVritHuXRiRyQ9mBBtMeSt4rygz lSDOt3wDHogSDImeLbN7qAd4yP9VcNcNWm7UpawkEiXS4H3FEsjn2O9dkXmQtj/xjZI/ON kv65IX4dshRUnXZBkNg3pLenY6soVWg= X-MC-Unique: MkMX_e8CMTWzm7bRPAlvYg-1 X-Mimecast-MFC-AGG-ID: MkMX_e8CMTWzm7bRPAlvYg_1789661138 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 06/14] system: check security for machine types Date: Thu, 17 Sep 2026 17:05:17 +0100 Message-ID: <20260917160525.1275388-7-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661316974158500 This wires up the machine creation code to apply the compat policy security check. Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- system/vl.c | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/system/vl.c b/system/vl.c index ca54da26c54..f54449b43e7 100644 --- a/system/vl.c +++ b/system/vl.c @@ -2201,11 +2201,18 @@ static void qemu_create_machine_containers(Object *= machine) } } =20 -static void qemu_create_machine(QDict *qdict) +static bool qemu_create_machine(QDict *qdict) { + Error *local_err =3D NULL; MachineClass *machine_class =3D select_machine(qdict, &error_fatal); object_set_machine_compat_props(machine_class->compat_props); =20 + if (!object_class_check_security(OBJECT_CLASS(machine_class), + &local_err)) { + error_report_err(local_err); + return false; + } + current_machine =3D MACHINE(object_new_with_class(OBJECT_CLASS(machine= _class))); object_property_add_child(object_get_root(), "machine", OBJECT(current_machine)); @@ -2237,6 +2244,8 @@ static void qemu_create_machine(QDict *qdict) false, &error_abort); qobject_unref(default_opts); } + + return true; } =20 static int global_init_func(void *opaque, QemuOpts *opts, Error **errp) @@ -3790,7 +3799,9 @@ void qemu_init(int argc, char **argv) /* Transfer QemuOpts options into machine options */ parse_memory_options(); =20 - qemu_create_machine(machine_opts_dict); + if (!qemu_create_machine(machine_opts_dict)) { + exit(1); + } =20 /* * Load incoming CPR state before any devices are created, because it --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661210; cv=none; d=zohomail.com; s=zohoarc; b=TDLDasoivw6SKc4445q/++JvOhGvjej2DznBQQxou4/jXlKeDSg56XxCbej+Owcn4dOYVfyYlT7cxDeNYXGpZTtT+B33jX1U7cWc2BfbiHRZpTAUzbth9JZq5RhG9gRQCob9+uvNQuiy8p0hf/Qvcn5rR1wAo9xySE8dBL2cZjo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661210; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=h6C5xmlCR2JXcQHyl0SNQ/EzI6XVx+RnguXt9cvj1ZM=; b=G+uchbS6xFKUjRyR+cK/pzIxVbZSMfIWkrGNe84eqezfH7P3h9PchKblKl3ECcuv+4g32eMrpDuZBevk1u+K3jWHpztRMULArL8e8wqn00jvsiLI/mdDx1rCc8uy3eW5hPJSUpkfT3nscVOLyRb48u7/qoBXaEHuf+8EGTovIwU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661210540490.8704948286854; Thu, 17 Sep 2026 09:06:50 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Eci-00067s-3b; Thu, 17 Sep 2026 12:06:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcU-0005rR-Rt for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:55 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcJ-0006sh-Jj for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:49 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-687-uxSSBZydNZqqiUW_05yySw-1; Thu, 17 Sep 2026 12:05:40 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id E4A831977004; Thu, 17 Sep 2026 16:05:39 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id B45CB30002C7; Thu, 17 Sep 2026 16:05:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661142; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=h6C5xmlCR2JXcQHyl0SNQ/EzI6XVx+RnguXt9cvj1ZM=; b=ayoLsYwLOCy0108Cq7CJxl4VUe+nRyKDlNdUSqsaLnpW8Canc514o911f7MHqJanEA3EGR kE9vxTm4xcB9l/eLjzefqsJ5iGmqDl2BYsD5pBILt0bsx0JER5WVnazaGCG3pNtZbHfIWq 2srXbUta0uUj5hDK1m8T6UynlNaXPSo= X-MC-Unique: uxSSBZydNZqqiUW_05yySw-1 X-Mimecast-MFC-AGG-ID: uxSSBZydNZqqiUW_05yySw_1789661140 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 07/14] system: report machine security status in help output Date: Thu, 17 Sep 2026 17:05:18 +0100 Message-ID: <20260917160525.1275388-8-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661212926158500 When '-machine help' is given, report the security status of each machine. Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- system/vl.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/system/vl.c b/system/vl.c index f54449b43e7..468a9fc247a 100644 --- a/system/vl.c +++ b/system/vl.c @@ -1586,9 +1586,10 @@ static void machine_help_func(const QDict *qdict) if (mc->alias) { printf("%-20s %s (alias of %s)\n", mc->alias, mc->desc, mc->na= me); } - printf("%-20s %s%s%s\n", mc->name, mc->desc, + printf("%-20s %s%s%s%s\n", mc->name, mc->desc, mc->is_default ? " (default)" : "", - mc->deprecation_reason ? " (deprecated)" : ""); + mc->deprecation_reason ? " (deprecated)" : "", + object_class_is_secure(OBJECT_CLASS(mc)) ? " (secure)" : ""= ); } } =20 --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661251; cv=none; d=zohomail.com; s=zohoarc; b=HXaUu8p9Upww4uDk3W1cev8mx3HPI5oEtcb/7GTGtT6f2HqeQX2Z2M7PH94dOhIAuqPjSy9KwjRYGASZbvLXLglYzPbxgYcSorxKFJHWWFNmkFHoVXsNJyZcdP7gzatlcaFY92RCBxCyfdfWedtrjyzAwjuqTPIPrJY+YlVRJOk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661251; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=FQe8sJGvYAqaJiDb0N7zRD2FwNjep9c+ZrKN/xn3FGU=; b=iGi4p6oQoJZrQRx5rvr5XoqYr3XhGEb2gFEoOZhSafXNc/9hG9rBlZW5saDZEla9OeLBObgEiGgH5UVPYJIR+81iaTnoG18qSRo8tauURJ8aM6c1Xi79jF14NEMtNyWWB6SnqIOCouiTT0Y1C2ORKiu79nGResAh+K0tgSfKevo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661251508810.4509753741677; Thu, 17 Sep 2026 09:07:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Ece-00062y-Pt; Thu, 17 Sep 2026 12:06:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcU-0005rP-RV for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:55 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcN-0006sp-Un for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:50 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-264-mPwo_cI7MNqDUXh15vdCDw-1; Thu, 17 Sep 2026 12:05:42 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 6324618C1065; Thu, 17 Sep 2026 16:05:41 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 42128300022B; Thu, 17 Sep 2026 16:05:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661144; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=FQe8sJGvYAqaJiDb0N7zRD2FwNjep9c+ZrKN/xn3FGU=; b=AjJa+Gag9nAND4tQjpSFAhmJEvj3QjetYbh+G9xjfO0FDu6c+pc1KOAYkIx31aE4V769CF R7zLLmJOwGiHBzLIVqcuGAcM6hMR43TWT4Z6n/ud1OzG4g+YpnMrwYUe4XSHtBTVmM+PGw 400ZXN+DmI0pyytIAqqrGaJDKBcqb4s= X-MC-Unique: mPwo_cI7MNqDUXh15vdCDw-1 X-Mimecast-MFC-AGG-ID: mPwo_cI7MNqDUXh15vdCDw_1789661141 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 08/14] system: check security of device types Date: Thu, 17 Sep 2026 17:05:19 +0100 Message-ID: <20260917160525.1275388-9-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661252940158500 This wires up the DeviceClass types to have their security checked when devices are created. Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- system/qdev-monitor.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/system/qdev-monitor.c b/system/qdev-monitor.c index a62ad23ecf0..c483b4e6281 100644 --- a/system/qdev-monitor.c +++ b/system/qdev-monitor.c @@ -672,6 +672,10 @@ DeviceState *qdev_device_add_from_qdict(const QDict *o= pts, return NULL; } =20 + if (!object_class_check_security(OBJECT_CLASS(dc), errp)) { + return NULL; + } + /* find bus */ path =3D qdict_get_try_str(opts, "bus"); if (path !=3D NULL) { --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661308; cv=none; d=zohomail.com; s=zohoarc; b=ngU7JBpSB2k0wmTzTY7Frc3g55nWLlAgfJFZ49YLy/0yQqLFOTan0+DN3bGs7fKtQmQMuBN4gSLGQBjNzR7fBJy+B9MrEI9OxYUvahKc7xDr4j1WQJedh2+oStIrNufhck8j7o9wuu+Di3CZ3+ALRL6FLhMvrrpl28XNrkFa+/o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661308; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=G0VQkouzoYhlR59Hu3kB1kc6y7dRoIOBKf1xRTNGllw=; b=AlEMrcgBGfrTAd8ENjSMhX1lGGYPqb1MGw6tiNP5VIxmPfZ8B5KzlbGYe7FsgL2N6IykQC2s16SJtKiZtQmwbmNev3BJsrW1BC5rey2otuW7/Hv4AbMGYqmKviiVVWjyWmJPZtYPCGedjU8BD2l9BvJFWUrn7PPQN1Pyel8sT7s= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661308929445.01719554828844; Thu, 17 Sep 2026 09:08:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Eci-00068M-ET; Thu, 17 Sep 2026 12:06:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcU-0005rS-S4 for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:55 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcO-0006t2-O9 for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:50 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-694-gEUdhq2-OQaThdjVHK6QAA-1; Thu, 17 Sep 2026 12:05:43 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id D2A3C1953976; Thu, 17 Sep 2026 16:05:42 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id B5085300022B; Thu, 17 Sep 2026 16:05:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661146; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=G0VQkouzoYhlR59Hu3kB1kc6y7dRoIOBKf1xRTNGllw=; b=LRAJsiJVB8nrHeQyktriSHXhjfqnthjUaZY9ACdNzuRydcxQ+NYx7i5n/rlAxOv1FJC07V CUUTarTXYmxp7Cp6nA/kjjz+kjounHF3U4vg0RLbtIs8ji26dgoZw0pWWvvhu6SFW/vTJQ 4nyUxfnhqXu3NAlGqMK7J1GZGRPg6Ow= X-MC-Unique: gEUdhq2-OQaThdjVHK6QAA-1 X-Mimecast-MFC-AGG-ID: gEUdhq2-OQaThdjVHK6QAA_1789661142 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 09/14] system: report device security status in help output Date: Thu, 17 Sep 2026 17:05:20 +0100 Message-ID: <20260917160525.1275388-10-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661310916158500 When '-device help', 'device_add help' and 'info qdm' are used, report the security status of each device. Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- system/qdev-monitor.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/system/qdev-monitor.c b/system/qdev-monitor.c index c483b4e6281..8185822daa7 100644 --- a/system/qdev-monitor.c +++ b/system/qdev-monitor.c @@ -166,6 +166,9 @@ static void qdev_print_devinfo(DeviceClass *dc) if (!dc->user_creatable) { qemu_printf(", no-user"); } + if (object_class_is_secure(OBJECT_CLASS(dc))) { + qemu_printf(", secure"); + } qemu_printf("\n"); } =20 --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661227; cv=none; d=zohomail.com; s=zohoarc; b=gQbPOk0tV3GJk4IlDHbi1Ve2+uELKFMwvk00Mg+9WNFEfpFw0AXLpZu1rRaZ3nzsufIufPu91Ede5L0HzmwO8mihDxgoRh0DYsfZOite7bp2tO/OAy2Btd9lbMpSWj/RADUaa6vXI7Xc8Bx2AysafAJMZQSJbuBLCUCtyGhVO/w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661227; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=p9dUM6y2y45ld8Hjcvnahtyp0OKrQAiASStuY4/L9HU=; b=LsuqcSVlZusqROoaChbBRXqpzzObiKLz0FYjT7EDwg1K/U1yQy/Xr/E5+eDsP4pxnEZd6jnWLI7qQTxYohSSJMqfP2annG5rNKG2iKGcCvFREGVpiTlrq0MnWiPvf9+6llfw+gGnBVOw5kC8lCXpbcWjBS4x8pJQLY0yaddatBM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661227981157.21824958100171; Thu, 17 Sep 2026 09:07:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7EdJ-0006ig-Gf; Thu, 17 Sep 2026 12:06:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcW-0005sc-9h for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:56 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcT-0006tO-IK for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:56 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-498-MF5AuqvHPcSXoAovrCid-Q-1; Thu, 17 Sep 2026 12:05:45 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 5AB3C19772E6; Thu, 17 Sep 2026 16:05:44 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 302C3300022B; Thu, 17 Sep 2026 16:05:43 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661148; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=p9dUM6y2y45ld8Hjcvnahtyp0OKrQAiASStuY4/L9HU=; b=hkfsoaZraKcqwTxJOP0I0lubESA9bBTozewyLIQDLS9Wyxw5BPoKYd06rIYWplrjkwPRIT /Pia0ocuiXZybQoSL1WicWPtVcIA8ARHcV6rKGlrPYD3k0AUD0VEgBm4EqX4towoGYYc76 D4iFvSWMBz4ju7NATHYzNYPsNXtg0jQ= X-MC-Unique: MF5AuqvHPcSXoAovrCid-Q-1 X-Mimecast-MFC-AGG-ID: MF5AuqvHPcSXoAovrCid-Q_1789661144 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 10/14] hw/core: report security status in query-machines Date: Thu, 17 Sep 2026 17:05:21 +0100 Message-ID: <20260917160525.1275388-11-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661230695158501 Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- hw/core/machine-qmp-cmds.c | 1 + qapi/machine.json | 8 +++++++- 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/hw/core/machine-qmp-cmds.c b/hw/core/machine-qmp-cmds.c index 543dd3201b5..9c08b17510a 100644 --- a/hw/core/machine-qmp-cmds.c +++ b/hw/core/machine-qmp-cmds.c @@ -127,6 +127,7 @@ MachineInfoList *qmp_query_machines(bool has_compat_pro= ps, bool compat_props, if (mc->default_ram_id) { info->default_ram_id =3D g_strdup(mc->default_ram_id); } + info->secure =3D object_class_is_secure(OBJECT_CLASS(mc)); =20 if (compat_props && mc->compat_props) { int i; diff --git a/qapi/machine.json b/qapi/machine.json index de6460f091c..b1be5608b61 100644 --- a/qapi/machine.json +++ b/qapi/machine.json @@ -196,6 +196,11 @@ # present when `query-machines` argument @compat-props is true. # (since 9.1) # +# @secure: If true, the machine is declared to provide a security +# boundary from the guest; if false the machine is either +# not providing a security boundary, or its status is undefined. +# (since 11.2) +# # Features: # # @unstable: Member @compat-props is experimental. @@ -209,7 +214,8 @@ 'deprecated': 'bool', '*default-cpu-type': 'str', '*default-ram-id': 'str', 'acpi': 'bool', '*compat-props': { 'type': ['CompatProperty'], - 'features': ['unstable'] } } } + 'features': ['unstable'] }, + 'secure': 'bool' } } =20 ## # @query-machines: --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661208; cv=none; d=zohomail.com; s=zohoarc; b=BUJ+RSgLU+jgztlhM4i5ePtjsFhog9ApcimIXebZhGTdX6Af96IQeRo7ufXsATs99GDwg4fhn+oNJbc+W06GJjyTQXUb8KC7jObnKDTYh1myzE2lkv0bbLf8ADc2/bSdLNjznUQpx7mswsPEP7Q3e6HRWFxiXaZdkejyG85FLpY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661208; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=mWjtgRPnsKG/TTE0wUI5Zo3PVF5E2wPwy4wEYJhNQHQ=; b=hD+uVvgqk4j7hpJQZV2PLtL2DhOhDJXeLYHYcGWoOubBE8OAZgnoVCJCc86STC2tmbKmSbQZih8Y4fQVB9KtKan4pUcChOuqP+RaFhAzsf07mxxDG/70mjacoMX3uEJw6nd5dXWrmM6mAykAiT4wQJzjKIRgxXB+gEqS5d4wb0Q= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661208854422.146213005165; Thu, 17 Sep 2026 09:06:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Ece-00063O-Tt; Thu, 17 Sep 2026 12:06:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcV-0005sH-2T for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:56 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcP-0006t7-7Z for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:52 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-304-4pbjSA6WOZOvyMNvzD1B2w-1; Thu, 17 Sep 2026 12:05:46 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 95A5B18301BF for ; Thu, 17 Sep 2026 16:05:45 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 95F98300022B; Thu, 17 Sep 2026 16:05:44 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661148; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=mWjtgRPnsKG/TTE0wUI5Zo3PVF5E2wPwy4wEYJhNQHQ=; b=Gn1KelfFiViCvwPzDkVMMPLIE/VNLG8yrETR0K0/B1AcBzpiH1dgUfcyvJRM7xL8qkyn1W eJPofPU9hdMvyTHwvoBsiWkQXJSoBCuRyGW+nGrCzUBUTZhMt5ifnnbzXn1+IuRq4jBtnc ZHLvKVU7b3Werhn5ESVgu6Albsqerkk= X-MC-Unique: 4pbjSA6WOZOvyMNvzD1B2w-1 X-Mimecast-MFC-AGG-ID: 4pbjSA6WOZOvyMNvzD1B2w_1789661145 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= Subject: [PULL 11/14] qom: refactor data passing for QOM list filtering Date: Thu, 17 Sep 2026 17:05:22 +0100 Message-ID: <20260917160525.1275388-12-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661210766158500 Currently the QOM list method can filter on the abstract flag, but extending the filtering to more variables requires a way to pass in extra data items. This requires a refactoring of the iterator to take a full struct as its opaque data item. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 --- qom/qom-qmp-cmds.c | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/qom/qom-qmp-cmds.c b/qom/qom-qmp-cmds.c index 330895361d4..b999e9f7238 100644 --- a/qom/qom-qmp-cmds.c +++ b/qom/qom-qmp-cmds.c @@ -151,9 +151,13 @@ QObject *qmp_qom_get(const char *path, const char *pro= perty, Error **errp) return object_property_get_qobject(obj, property, errp); } =20 -static void qom_list_types_tramp(ObjectClass *klass, void *data) +typedef struct { + ObjectTypeInfoList *list; +} ObjectTypeInfoData; + +static void qom_list_types_tramp(ObjectClass *klass, void *opaque) { - ObjectTypeInfoList **pret =3D data; + ObjectTypeInfoData *data =3D opaque; ObjectTypeInfo *info; ObjectClass *parent =3D object_class_get_parent(klass); =20 @@ -164,7 +168,7 @@ static void qom_list_types_tramp(ObjectClass *klass, vo= id *data) info->parent =3D g_strdup(object_class_get_name(parent)); } =20 - QAPI_LIST_PREPEND(*pret, info); + QAPI_LIST_PREPEND(data->list, info); } =20 ObjectTypeInfoList *qmp_qom_list_types(const char *implements, @@ -172,12 +176,14 @@ ObjectTypeInfoList *qmp_qom_list_types(const char *im= plements, bool abstract, Error **errp) { - ObjectTypeInfoList *ret =3D NULL; + ObjectTypeInfoData data =3D { + .list =3D NULL, + }; =20 module_load_qom_all(); - object_class_foreach(qom_list_types_tramp, implements, abstract, &ret); + object_class_foreach(qom_list_types_tramp, implements, abstract, &data= ); =20 - return ret; + return data.list; } =20 ObjectPropertyInfoList *qmp_device_list_properties(const char *typename, --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661218; cv=none; d=zohomail.com; s=zohoarc; b=hbZtXbxujvT44qBCHupW+NGyc2l9OzXE9VFgs6JTIAOiH81J32HmpX40G+Gg/bKtM8yHEYTTlW/PGO5xAfQC/o7Smqs6NsOzPJgmW8MgEyhNYHwtDs/Oy7CLrxE5oKt7A6CMuBlCXkk5yIi12DJQK8BAcv6FfNuU8AvCZkQ9Tj8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661218; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=czMxHq/PLqDyc6efSQ090RtkFqrVb3VLHhpMylOmSaM=; b=myyDUZy93+GAT+bqohBdPXJrja1xG+IbKAa1Kw3oSMfj6dN069DkEXQ56bI9qqL6+afSseIWUpPKE+5N4FRi28YQx62OfwvJi2wjY6qVlNJdnCu/oNJ8sUVABNebSUjBgMIlo0UkhBcjuyFvf3gr2UX+d/GXBR6ZBPm4RzCI93A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661218181986.0508457780512; Thu, 17 Sep 2026 09:06:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7EdB-0006TW-DJ; Thu, 17 Sep 2026 12:06:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcW-0005sk-GY for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:56 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcU-0006tM-Ko for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:56 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-495-CIK2rO_MM9-8r9l73Q7NKA-1; Thu, 17 Sep 2026 12:05:48 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 2575A1977036; Thu, 17 Sep 2026 16:05:47 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id E73F5300022B; Thu, 17 Sep 2026 16:05:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661149; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=czMxHq/PLqDyc6efSQ090RtkFqrVb3VLHhpMylOmSaM=; b=GBEdgxzp2aQ8MPXlIhtA/oLZropXSGksKoRvdE6yC9b9F65yVFrDVL9xCtMs6jQ0d0yGGc dv5AGmSDiWzvIO8VWdaegk7dfgO5QsAqpTPeI2Ti9MtMJROJ6rMBJH8l8xa/IbA2sOh6aI OQKGD4KwWEGayOYHdmYeVJauTAyeb5Q= X-MC-Unique: CIK2rO_MM9-8r9l73Q7NKA-1 X-Mimecast-MFC-AGG-ID: CIK2rO_MM9-8r9l73Q7NKA_1789661147 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 12/14] qom: report & filter on security status in qom-list-types Date: Thu, 17 Sep 2026 17:05:23 +0100 Message-ID: <20260917160525.1275388-13-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661220674158500 This adds: * a new boolean 'secure' field to the type info returned by qom-list-types, which will be set if the type provides a security boundary * a new boolean 'secure' parameter to the arguments of qom-list-types, which can be used to filter types based on their security status Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- qapi/qom.json | 13 +++++++++++-- qom/qom-qmp-cmds.c | 17 +++++++++++++++++ tests/qtest/fuzz/qos_fuzz.c | 3 ++- 3 files changed, 30 insertions(+), 3 deletions(-) diff --git a/qapi/qom.json b/qapi/qom.json index 4a9b7f90884..5895c977503 100644 --- a/qapi/qom.json +++ b/qapi/qom.json @@ -210,12 +210,18 @@ # @abstract: the type is abstract and can't be directly instantiated. # Omitted if false. (since 2.10) # +# @secure: the type provides a security boundary. Omitted if false. +# (since 11.2) +# # @parent: Name of parent type, if any (since 2.10) # # Since: 1.1 ## { 'struct': 'ObjectTypeInfo', - 'data': { 'name': 'str', '*abstract': 'bool', '*parent': 'str' } } + 'data': { 'name': 'str', + '*abstract': 'bool', + '*parent': 'str', + '*secure': 'bool' } } =20 ## # @qom-list-types: @@ -227,12 +233,15 @@ # # @abstract: if true, include abstract types in the results # +# @secure: if set, filter to only include types with matching security +# status (since 11.2) +# # Returns: a list of types, or an empty list if no results are found # # Since: 1.1 ## { 'command': 'qom-list-types', - 'data': { '*implements': 'str', '*abstract': 'bool' }, + 'data': { '*implements': 'str', '*abstract': 'bool', '*secure': 'bool' }, 'returns': [ 'ObjectTypeInfo' ], 'allow-preconfig': true } =20 diff --git a/qom/qom-qmp-cmds.c b/qom/qom-qmp-cmds.c index b999e9f7238..f17389c7305 100644 --- a/qom/qom-qmp-cmds.c +++ b/qom/qom-qmp-cmds.c @@ -153,6 +153,8 @@ QObject *qmp_qom_get(const char *path, const char *prop= erty, Error **errp) =20 typedef struct { ObjectTypeInfoList *list; + bool has_secure; + bool secure; } ObjectTypeInfoData; =20 static void qom_list_types_tramp(ObjectClass *klass, void *opaque) @@ -160,10 +162,21 @@ static void qom_list_types_tramp(ObjectClass *klass, = void *opaque) ObjectTypeInfoData *data =3D opaque; ObjectTypeInfo *info; ObjectClass *parent =3D object_class_get_parent(klass); + bool secure =3D object_class_is_secure(klass); + + if (data->has_secure && + data->secure !=3D secure) { + return; + } =20 info =3D g_malloc0(sizeof(*info)); info->name =3D g_strdup(object_class_get_name(klass)); info->has_abstract =3D info->abstract =3D object_class_is_abstract(kla= ss); + /* + * Set has_secure such that we omit the 'secure' attribute + * from the QMP response for insecure types + */ + info->has_secure =3D info->secure =3D secure; if (parent) { info->parent =3D g_strdup(object_class_get_name(parent)); } @@ -174,10 +187,14 @@ static void qom_list_types_tramp(ObjectClass *klass, = void *opaque) ObjectTypeInfoList *qmp_qom_list_types(const char *implements, bool has_abstract, bool abstract, + bool has_secure, + bool secure, Error **errp) { ObjectTypeInfoData data =3D { .list =3D NULL, + .has_secure =3D has_secure, + .secure =3D secure, }; =20 module_load_qom_all(); diff --git a/tests/qtest/fuzz/qos_fuzz.c b/tests/qtest/fuzz/qos_fuzz.c index 9afe8bf6d8b..9ea6b1aef09 100644 --- a/tests/qtest/fuzz/qos_fuzz.c +++ b/tests/qtest/fuzz/qos_fuzz.c @@ -50,7 +50,8 @@ static void qos_set_machines_devices_available(void) machines_apply_to_node(mach_info); qapi_free_MachineInfoList(mach_info); =20 - type_info =3D qmp_qom_list_types("device", true, true, &error_abort); + type_info =3D qmp_qom_list_types("device", true, true, + false, false, &error_abort); types_apply_to_node(type_info); qapi_free_ObjectTypeInfoList(type_info); } --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661177; cv=none; d=zohomail.com; s=zohoarc; b=E79uis5r8KiNgiYTr4a4WnOIMwEtRXA5zy7cRWpGM2bj0eapF9vb3LaNG9F4EaJyu3W8JE+mHuyrO3VBPdGc2+/RKfbDJTa0xXhfukEwOahidl031uF9L3BjUPW4cy5tfnniMsc8waZ4u4Qd7kVpztoZq4smIts7ROjZJSNmCCE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661177; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=pHxv3zL5OXmdAPFMAHj7uNNc/Awb/QxXo9x+pbmadRQ=; b=Wg3Y/rhfyZWbDhlZYjqqrQNW+okk/i+lZd9CGEO1p/AsbaM7rEbMQ2f6AVEsc8Ql6wsgKr8mITy5CX83mZm73Kb398loomnfqDuzOiXBTF6VV7iNkRATB46sGH/h/TfGplenUhgJlgvIh6EkAs+WYBPh3uYwrNIp5RKjy93wHrI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661177806859.6064810966622; Thu, 17 Sep 2026 09:06:17 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Ecm-0006AG-0c; Thu, 17 Sep 2026 12:06:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcX-0005uc-H1 for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:59 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcU-0006u7-QC for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:57 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-428-5m_5v15CO1G9tHI5V_TUwQ-1; Thu, 17 Sep 2026 12:05:49 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 8A8E1193E8AF; Thu, 17 Sep 2026 16:05:48 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 75CC0300022B; Thu, 17 Sep 2026 16:05:47 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661152; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=pHxv3zL5OXmdAPFMAHj7uNNc/Awb/QxXo9x+pbmadRQ=; b=N22MDNz+B0rbHQSNmV81nDX5WEIAprTWYc1RhQzaN9NydDUEIS7Xulm/1ulpZ9YutZkdgo L9WIT2HpTCG4EiFKN2hNYXah6GETEz4Chf4iAlEVfMFzcfla/r9ZTtSBiY9Ai10dBd3QNV vgftYTeLfNRlzXKNScwgIPIEQBswKxY= X-MC-Unique: 5m_5v15CO1G9tHI5V_TUwQ-1 X-Mimecast-MFC-AGG-ID: 5m_5v15CO1G9tHI5V_TUwQ_1789661148 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Richard Henderson Subject: [PULL 13/14] docs: expand security docs with info about security status Date: Thu, 17 Sep 2026 17:05:24 +0100 Message-ID: <20260917160525.1275388-14-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661180486158500 The description of virtualization vs non-virtualization use cases is a crude approximation of the security characteristics of QEMU devices. Document how QEMU can be probed to obtain information on the security status of type classes, and how policies can be set to inform or control their usage. Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Richard Henderson Signed-off-by: Daniel P. Berrang=C3=A9 --- docs/system/security.rst | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) diff --git a/docs/system/security.rst b/docs/system/security.rst index 8c42d1a6d83..75e39caedea 100644 --- a/docs/system/security.rst +++ b/docs/system/security.rst @@ -158,6 +158,42 @@ an issue as a normal bug. usually not justify handling as security bugs, nor assignment of CVEs. They will be fixed as routine bugs when time allows. =20 +Security status reporting +''''''''''''''''''''''''' + +The QEMU project annotates types to explicitly state whether they are +considered to provide a security boundary or not. For machine, accelerator +and device types, only those annotated with the "secure" flag will be +eligible for CVE assignment. Annotations will be extended to other backend +and object types over time, to make their security status explicit. + +It is possible to control or identify the usage of types that do not offer +an explicit security boundary using the ``insecure-types`` parameter to the +``-compat`` argument, which accepts three values: + + * accept: usage of any type will be permitted. This is the current + and historical default behaviour + * warn: usage of types not explicitly declared secure will result + in a warning message, but still be permitted. + * reject: usage of types not explicitly declared secure will result + in an error message, and will not be permitted. + +The compatibility policy will be honoured both at initial startup of +QEMU and during any runtime alterations made with monitor commands. + +The status of any type class can be queried at runtime using the +``qom-list-types`` command, whose returned information will flag any +types declared as secure. The ``query-machines`` command will also +reflect this same information for machine types. + +Machine type, accelerator and device security status can be queried +using ``-machine help``, ``-accel help`` and ``-device help`` command +line options respectively. + +Setting the ``.secure`` field to ``true`` in the ``TypeInfo`` +instance for an Object class, declares that the type aims to provide +a security boundary. + Architecture ------------ =20 --=20 2.55.0 From nobody Sun Sep 27 23:08:06 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789661264; cv=none; d=zohomail.com; s=zohoarc; b=dXadouoeD+sY6Gz2YyjBRY0HSEJjGNLYGTrcxx0eiM8ExYe/hfE6JSHNLNda3HcRGJ+dpfwu5ecbizdz8j86lqfHwpWqBXMgiVjYRWFD09BcIPyG/LgwHZrCKFMmyEZQJ+/bVlnWCY9e2ezLU4PhVksURSpNnutxlbiC3JSXw8M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789661264; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4fYsuiuQ5aFVUk7Zo7NwjKQO4rNj68Q6fb48JsuCOHU=; b=Hy6AEFeWKtNMpUMXJ1bKSzfdC/d9XBKIk+9unYLc08rmtyKdv83RAUy+0V0fVBU9mDNAwmZjiu50QtFnPfJvadnKllsek16ltKXGiORAZLjPDoAjZsmif65AC5UjbrijWaeGckWth9dgJMI1QCT5l5Nlp/9eb2aFbOQi2LBer78= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789661264767392.24583262611554; Thu, 17 Sep 2026 09:07:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7Ece-00062N-PL; Thu, 17 Sep 2026 12:06:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcY-0005uf-1L for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:06:00 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7EcU-0006ts-QZ for qemu-devel@nongnu.org; Thu, 17 Sep 2026 12:05:57 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-231-q4Q7OAu7MKOQg_fS1q9m7g-1; Thu, 17 Sep 2026 12:05:50 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C6ABE1977012 for ; Thu, 17 Sep 2026 16:05:49 +0000 (UTC) Received: from berrange.csb (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id DC40930002C2; Thu, 17 Sep 2026 16:05:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789661152; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=4fYsuiuQ5aFVUk7Zo7NwjKQO4rNj68Q6fb48JsuCOHU=; b=OXiKwZ40nqE9gBBw3vjtvtYgLJYEmZxnlHc0iFRH+m94p5fKpo/20Lt22m84y33V6EkSqp pGXSm6Vq3MkG4+/uP3tAuQdtJDpU/eAZEU32t3KcusOr/me0n+b9C8Sfun38DB0oZQTkrO mcYWE+AsATLSDV2fn2B1jyPUzQykouk= X-MC-Unique: q4Q7OAu7MKOQg_fS1q9m7g-1 X-Mimecast-MFC-AGG-ID: q4Q7OAu7MKOQg_fS1q9m7g_1789661149 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= Subject: [PULL 14/14] machine: add helpers for declaring secure/insecure machine types Date: Thu, 17 Sep 2026 17:05:25 +0100 Message-ID: <20260917160525.1275388-15-berrange@redhat.com> In-Reply-To: <20260917160525.1275388-1-berrange@redhat.com> References: <20260917160525.1275388-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789661267103158500 The current DEFINE_MACHINE macro will declare machine type without any explicit statement about the security status. As such the machine type will be treated as implicitly insecure at runtime. Introduce a new DEFINE_SECURE_MACHINE macro (with variants) that allow code to make an explicit statement that the machine is treated as secure. This should primarily be used for versioned machine types that are intended to be used with KVM, though some others may warrant a security declaration. Use of the existing macros marks a machine as insecure, which is the desired default for most machines servicing emulation use cases. The same is done for the specialized i386 PC related macros. Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 --- hw/arm/bananapi_m2u.c | 2 +- hw/arm/cubieboard.c | 2 +- hw/arm/imx8mm-evk.c | 2 +- hw/arm/integratorcp.c | 2 +- hw/arm/mcimx7d-sabre.c | 2 +- hw/arm/orangepi.c | 2 +- hw/ppc/pegasos.c | 3 ++- include/hw/core/boards.h | 25 ++++++++++++++++++++----- include/hw/i386/pc.h | 11 ++++++++++- 9 files changed, 38 insertions(+), 13 deletions(-) diff --git a/hw/arm/bananapi_m2u.c b/hw/arm/bananapi_m2u.c index 8f59111fd4e..ccf60ba2955 100644 --- a/hw/arm/bananapi_m2u.c +++ b/hw/arm/bananapi_m2u.c @@ -153,4 +153,4 @@ static void bpim2u_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("bpim2u", MACHINE, Bpim2uMachineState, - bpim2u_machine_init, false, NULL) + bpim2u_machine_init, false, false, NULL) diff --git a/hw/arm/cubieboard.c b/hw/arm/cubieboard.c index ae27056938f..e4fef9cd76b 100644 --- a/hw/arm/cubieboard.c +++ b/hw/arm/cubieboard.c @@ -133,5 +133,5 @@ static void cubieboard_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("cubieboard", MACHINE, CubieboardMachineState, - cubieboard_machine_init, false, + cubieboard_machine_init, false, false, NULL) diff --git a/hw/arm/imx8mm-evk.c b/hw/arm/imx8mm-evk.c index 8a5737502fd..c3215b11cb9 100644 --- a/hw/arm/imx8mm-evk.c +++ b/hw/arm/imx8mm-evk.c @@ -134,5 +134,5 @@ static void imx8mm_evk_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("imx8mm-evk", MACHINE, Imx8mmEvkMachineState, - imx8mm_evk_machine_init, false, + imx8mm_evk_machine_init, false, false, NULL) diff --git a/hw/arm/integratorcp.c b/hw/arm/integratorcp.c index 382ea7850d8..b766edeeee1 100644 --- a/hw/arm/integratorcp.c +++ b/hw/arm/integratorcp.c @@ -704,7 +704,7 @@ static void integratorcp_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("integratorcp", MACHINE, IntegratorcpMachineState, - integratorcp_machine_init, false, + integratorcp_machine_init, false, false, NULL) =20 static const Property core_properties[] =3D { diff --git a/hw/arm/mcimx7d-sabre.c b/hw/arm/mcimx7d-sabre.c index db8a62e5f6c..65fdb19c06f 100644 --- a/hw/arm/mcimx7d-sabre.c +++ b/hw/arm/mcimx7d-sabre.c @@ -86,5 +86,5 @@ static void mcimx7d_sabre_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("mcimx7d-sabre", MACHINE, Mcimx7dSabreMachineState, - mcimx7d_sabre_machine_init, false, + mcimx7d_sabre_machine_init, false, false, NULL) diff --git a/hw/arm/orangepi.c b/hw/arm/orangepi.c index 7a19732f5df..18ed174032b 100644 --- a/hw/arm/orangepi.c +++ b/hw/arm/orangepi.c @@ -133,5 +133,5 @@ static void orangepi_machine_init(MachineClass *mc) } =20 DEFINE_MACHINE_EXTENDED("orangepi-pc", MACHINE, OrangePiMachineState, - orangepi_machine_init, false, + orangepi_machine_init, false, false, NULL) diff --git a/hw/ppc/pegasos.c b/hw/ppc/pegasos.c index 9d7e279123b..fba2a558905 100644 --- a/hw/ppc/pegasos.c +++ b/hw/ppc/pegasos.c @@ -788,7 +788,8 @@ static void pegasos2_machine_class_init(ObjectClass *oc= , const void *data) } =20 DEFINE_MACHINE_EXTENDED("pegasos", MACHINE, PegasosMachineState, - pegasos_machine_init, true, (const InterfaceInfo[]= ) { + pegasos_machine_init, true, false, + (const InterfaceInfo[]) { { TYPE_PPC_VIRTUAL_HYPERVISOR }, { TYPE_VOF_MACHINE_IF }, { } }) =20 diff --git a/include/hw/core/boards.h b/include/hw/core/boards.h index dba465efc2c..3b86724cf00 100644 --- a/include/hw/core/boards.h +++ b/include/hw/core/boards.h @@ -514,7 +514,7 @@ struct MachineState { */ =20 #define DEFINE_MACHINE_EXTENDED(namestr, PARENT_NAME, InstanceName, \ - machine_initfn, ABSTRACT, ifaces...) \ + machine_initfn, ABSTRACT, SECURE, ifaces..= .) \ static void machine_initfn##_class_init(ObjectClass *oc, const void *d= ata) \ { \ MachineClass *mc =3D MACHINE_CLASS(oc); \ @@ -526,6 +526,7 @@ struct MachineState { .class_init =3D machine_initfn##_class_init, \ .instance_size =3D sizeof(InstanceName), \ .abstract =3D ABSTRACT, \ + .secure =3D SECURE, \ .interfaces =3D ifaces, \ }; \ static void machine_initfn##_register_types(void) \ @@ -534,18 +535,32 @@ struct MachineState { } \ type_init(machine_initfn##_register_types) =20 +/* Implicitly insecure */ #define DEFINE_MACHINE(namestr, machine_initfn) \ DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ - false, NULL) + false, false, NULL) =20 -#define DEFINE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, iface= s...)\ +#define DEFINE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, iface= s...) \ DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ - false, ifaces) + false, false, ifaces) =20 -#define DEFINE_MACHINE_WITH_INTERFACES(namestr, machine_initfn, ...) \ +#define DEFINE_MACHINE_WITH_INTERFACES(namestr, machine_initfn, ...) \ DEFINE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, \ (const InterfaceInfo[]) { __VA_ARG= S__ }) =20 + +#define DEFINE_SECURE_MACHINE(namestr, machine_initfn) \ + DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ + false, true, NULL) + +#define DEFINE_SECURE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn= , ifaces...) \ + DEFINE_MACHINE_EXTENDED(namestr, MACHINE, MachineState, machine_initfn= , \ + false, true, ifaces) + +#define DEFINE_SECURE_MACHINE_WITH_INTERFACES(namestr, machine_initfn, ...= ) \ + DEFINE_SECURE_MACHINE_WITH_INTERFACE_ARRAY(namestr, machine_initfn, \ + (const InterfaceInfo[]) { _= _VA_ARGS__ }) + /* * Helper for dispatching different macros based on how * many __VA_ARGS__ are passed. Supports 1 to 5 variadic diff --git a/include/hw/i386/pc.h b/include/hw/i386/pc.h index ac03da97b64..d5dc79df178 100644 --- a/include/hw/i386/pc.h +++ b/include/hw/i386/pc.h @@ -275,7 +275,7 @@ extern const size_t pc_compat_4_2_len; extern GlobalProperty pc_compat_4_1[]; extern const size_t pc_compat_4_1_len; =20 -#define DEFINE_PC_MACHINE(suffix, namestr, initfn, optsfn) \ +#define DEFINE_PC_MACHINE_EXTENDED(suffix, namestr, initfn, optsfn, issecu= re) \ static void pc_machine_##suffix##_class_init(ObjectClass *oc, \ const void *data) \ { \ @@ -287,6 +287,7 @@ extern const size_t pc_compat_4_1_len; .name =3D namestr TYPE_MACHINE_SUFFIX, \ .parent =3D TYPE_PC_MACHINE, \ .class_init =3D pc_machine_##suffix##_class_init, \ + .secure =3D issecure, \ }; \ static void pc_machine_init_##suffix(void) \ { \ @@ -294,6 +295,14 @@ extern const size_t pc_compat_4_1_len; } \ type_init(pc_machine_init_##suffix) =20 +/* Implicitly insecure */ +#define DEFINE_PC_MACHINE(suffix, namestr, initfn, optsfn) \ + DEFINE_PC_MACHINE_EXTENDED(suffix, namestr, initfn, optsfn, false) + +#define DEFINE_SECURE_PC_MACHINE(suffix, namestr, initfn, optsfn) \ + DEFINE_PC_MACHINE_EXTENDED(suffix, namestr, initfn, optsfn, true) + + #define DEFINE_PC_VER_MACHINE(namesym, namestr, initfn, isdefault, malias,= ...) \ static void MACHINE_VER_SYM(init, namesym, __VA_ARGS__)( \ MachineState *machine) \ --=20 2.55.0