* [PATCH v2 0/3] Extend secure IPL support to virtio-blk-pci boot devices
@ 2026-08-26 14:57 Joshua Daley
2026-08-26 14:57 ` [PATCH v2 1/3] hw/s390x/ipl: Add secure boot support to PCI dev IPLB builder Joshua Daley
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Joshua Daley @ 2026-08-26 14:57 UTC (permalink / raw)
To: qemu-s390x
Cc: qemu-devel, jrossi, zycai, borntraeger, jjherne, pasic, farman,
mjrosato, richard.henderson, iii, david, cohuck, jdaley
Changes v1 -> v2:
- Added RB tags to patches 1 & 2
- Patch 3:
The setup step is now run only once, as originally intended.
setUpClass and tearDownClass manage a shared workdir for the
subtests to use. Instance vars are now class-level vars.
v1 cover letter:
This series is based on Zhuoying Cai's series,
"[PATCH v17 00/34] Secure IPL Support for SCSI Scheme of virtio-blk/virtio-scsi Devices"
https://lore.kernel.org/qemu-devel/20260730214624.2328883-1-zycai@linux.ibm.com/
Note, the above series is based on Cornelia Huck's patch,
"[PATCH for-11.2] hw: add compat machines for 11.2"
https://lore.kernel.org/qemu-devel/20260723163806.368127-1-cohuck@redhat.com/
which requires a small fix to apply (see Eric Farman's reply).
---
To add support for secure IPL with a virtio-blk-pci boot device, we simply
write secure boot flags to the IPLB when using such a boot device.
This is achieved by calling s390_apply_secure_boot() in the PCI boot
device case of s390_build_iplb().
The secure IPL functional verification test is updated with an additional
subtest for the virtio-blk-pci boot device case. To run the FVT:
make check-functional-s390x MTESTARGS="func-s390x-secure_ipl" \
QEMU_TEST_ALLOW_LARGE_STORAGE=1
To test secure IPL yourself, view the "Secure IPL Quickstart" guide in:
docs/system/s390x/secure-ipl.rst
Joshua Daley (3):
hw/s390x/ipl: Add secure boot support to PCI dev IPLB builder
tests/functional/s390x/test_secure_ipl: Skip test if SIPL not
supported by hypervisor
tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev
case
hw/s390x/ipl.c | 8 +-
tests/functional/s390x/test_secure_ipl.py | 149 +++++++++++++++-------
2 files changed, 108 insertions(+), 49 deletions(-)
--
2.34.1
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH v2 1/3] hw/s390x/ipl: Add secure boot support to PCI dev IPLB builder
2026-08-26 14:57 [PATCH v2 0/3] Extend secure IPL support to virtio-blk-pci boot devices Joshua Daley
@ 2026-08-26 14:57 ` Joshua Daley
2026-08-26 14:57 ` [PATCH v2 2/3] tests/functional/s390x/test_secure_ipl: Skip test if SIPL not supported by hypervisor Joshua Daley
2026-08-26 14:57 ` [PATCH v2 3/3] tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev case Joshua Daley
2 siblings, 0 replies; 6+ messages in thread
From: Joshua Daley @ 2026-08-26 14:57 UTC (permalink / raw)
To: qemu-s390x
Cc: qemu-devel, jrossi, zycai, borntraeger, jjherne, pasic, farman,
mjrosato, richard.henderson, iii, david, cohuck, jdaley
In the PCI boot device case of s390_build_iplb(), call
s390_apply_secure_boot() to update the IPLB when secure boot or audit
mode are enabled.
Secure IPL is now supported for virtio-blk-pci boot devices.
Signed-off-by: Joshua Daley <jdaley@linux.ibm.com>
Reviewed-by: Jared Rossi <jrossi@linux.ibm.com>
Reviewed-by: Zhuoying Cai <zycai@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
---
hw/s390x/ipl.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/hw/s390x/ipl.c b/hw/s390x/ipl.c
index d59ed36c78..b0da3cbb27 100644
--- a/hw/s390x/ipl.c
+++ b/hw/s390x/ipl.c
@@ -599,11 +599,6 @@ static bool s390_build_iplb(DeviceState *dev_st, IplParameterBlock *iplb)
pbdev = s390_get_pci_device(dev_st, &devtype);
if (pbdev) {
- if (s390_secure_boot_enabled() || s390_has_certificate()) {
- error_report("Virtio pci boot device does not support secure boot!");
- exit(1);
- }
-
pci_lp = object_property_get_str(OBJECT(pbdev->pdev), "loadparm", NULL);
if (pci_lp && strlen(pci_lp) > 0) {
lp = pci_lp;
@@ -625,6 +620,9 @@ static bool s390_build_iplb(DeviceState *dev_st, IplParameterBlock *iplb)
s390_ipl_convert_loadparm((char *)lp, iplb->loadparm);
iplb->flags |= DIAG308_FLAGS_LP_VALID;
+ s390_apply_secure_boot(iplb, devtype, s390_secure_boot_enabled(),
+ s390_has_certificate());
+
return true;
}
--
2.34.1
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH v2 2/3] tests/functional/s390x/test_secure_ipl: Skip test if SIPL not supported by hypervisor
2026-08-26 14:57 [PATCH v2 0/3] Extend secure IPL support to virtio-blk-pci boot devices Joshua Daley
2026-08-26 14:57 ` [PATCH v2 1/3] hw/s390x/ipl: Add secure boot support to PCI dev IPLB builder Joshua Daley
@ 2026-08-26 14:57 ` Joshua Daley
2026-08-26 14:57 ` [PATCH v2 3/3] tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev case Joshua Daley
2 siblings, 0 replies; 6+ messages in thread
From: Joshua Daley @ 2026-08-26 14:57 UTC (permalink / raw)
To: qemu-s390x
Cc: qemu-devel, jrossi, zycai, borntraeger, jjherne, pasic, farman,
mjrosato, richard.henderson, iii, david, cohuck, jdaley
Currently, if secure IPL is not supported by the hypervisor, the test
will fail because "Verified component" never appears. One must inspect
the console log to observe the cause of the failure.
Add a check that skips the test if the host CPU model is missing the
secure IPL facilities.
Signed-off-by: Joshua Daley <jdaley@linux.ibm.com>
Reviewed-by: Jared Rossi <jrossi@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Zhuoying Cai <zycai@linux.ibm.com>
---
tests/functional/s390x/test_secure_ipl.py | 18 ++++++++++++++++++
1 file changed, 18 insertions(+)
diff --git a/tests/functional/s390x/test_secure_ipl.py b/tests/functional/s390x/test_secure_ipl.py
index 06fc93e404..5af36b91d8 100755
--- a/tests/functional/s390x/test_secure_ipl.py
+++ b/tests/functional/s390x/test_secure_ipl.py
@@ -29,6 +29,22 @@ def __init__(self, *args, **kwargs):
self.cert_path = None
self.prompt = None
+ def _require_host_secure_ipl_support(self, vm):
+ """
+ Skip the test if the host CPU model does not expose the Secure IPL
+ facilities (sipl, sclaf, cstore).
+ """
+ props = vm.cmd('query-cpu-model-expansion',
+ model={'name': 'host'},
+ type='full')['model']['props']
+ missing = [f for f in ('sipl', 'sclaf', 'cstore')
+ if not props.get(f)]
+ if missing:
+ self.skipTest(
+ f"Host CPU does not support Secure IPL: "
+ f"missing feature(s): {', '.join(missing)}. "
+ f"Secure IPL requires a z16+ host.")
+
def _create_certificate(self, vm):
"""Generate x509 certificate"""
exec_command_and_wait_for_pattern(self,
@@ -107,6 +123,8 @@ def setup_s390x_secure_ipl(self):
'-device', 'virtio-blk-ccw,drive=drive0,bootindex=1')
temp_vm.launch()
+ self._require_host_secure_ipl_support(temp_vm)
+
# Initial root account setup (Fedora first boot screen)
self.root_password = 'fedora40password'
wait_for_console_pattern(self, 'Please make a selection from the above',
--
2.34.1
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH v2 3/3] tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev case
2026-08-26 14:57 [PATCH v2 0/3] Extend secure IPL support to virtio-blk-pci boot devices Joshua Daley
2026-08-26 14:57 ` [PATCH v2 1/3] hw/s390x/ipl: Add secure boot support to PCI dev IPLB builder Joshua Daley
2026-08-26 14:57 ` [PATCH v2 2/3] tests/functional/s390x/test_secure_ipl: Skip test if SIPL not supported by hypervisor Joshua Daley
@ 2026-08-26 14:57 ` Joshua Daley
2026-09-01 20:36 ` Matthew Rosato
2 siblings, 1 reply; 6+ messages in thread
From: Joshua Daley @ 2026-08-26 14:57 UTC (permalink / raw)
To: qemu-s390x
Cc: qemu-devel, jrossi, zycai, borntraeger, jjherne, pasic, farman,
mjrosato, richard.henderson, iii, david, cohuck, jdaley
Split test_s390x_secure_ipl() into two subtests. Each tests with a
different boot device: virtio-blk-ccw or virtio-blk-pci. Use class-level
variables and a temporary shared workdir such that the time-consuming
setup is not run multiple times.
Signed-off-by: Joshua Daley <jdaley@linux.ibm.com>
---
tests/functional/s390x/test_secure_ipl.py | 131 ++++++++++++++--------
1 file changed, 87 insertions(+), 44 deletions(-)
diff --git a/tests/functional/s390x/test_secure_ipl.py b/tests/functional/s390x/test_secure_ipl.py
index 5af36b91d8..cc9bff5737 100755
--- a/tests/functional/s390x/test_secure_ipl.py
+++ b/tests/functional/s390x/test_secure_ipl.py
@@ -8,6 +8,9 @@
secure-boot enabled, and verifying cryptographic validation results.
"""
+import os
+import shutil
+import tempfile
from subprocess import check_call, DEVNULL
from qemu_test import QemuSystemTest, Asset, get_qemu_img
@@ -22,12 +25,24 @@ class S390xSecureIpl(QemuSystemTest):
'Fedora-Server-KVM-40-1.14.s390x.qcow2'),
'091c232a7301be14e19c76ce9a0c1cbd2be2c4157884a731e1fc4f89e7455a5f')
- def __init__(self, *args, **kwargs):
- super().__init__(*args, **kwargs)
- self.root_password = None
- self.qcow2_path = None
- self.cert_path = None
- self.prompt = None
+ _shared_workdir = None
+ _root_password = None
+ _qcow2_path = None
+ _cert_path = None
+ _prompt = None
+ _setup_done = None
+
+ @classmethod
+ def setUpClass(cls):
+ super().setUpClass()
+ cls._shared_workdir = tempfile.mkdtemp(prefix='qemu_sipl_')
+
+ @classmethod
+ def tearDownClass(cls):
+ if cls._shared_workdir is not None:
+ shutil.rmtree(cls._shared_workdir, ignore_errors=True)
+ cls._shared_workdir = None
+ super().tearDownClass()
def _require_host_secure_ipl_support(self, vm):
"""
@@ -62,7 +77,7 @@ def _sign_binaries(self, vm):
exec_command_and_wait_for_pattern(self,
'sudo dnf install kernel-devel-$(uname -r) -y',
'Complete!', vm=vm)
- wait_for_console_pattern(self, self.prompt, vm=vm)
+ wait_for_console_pattern(self, S390xSecureIpl._prompt, vm=vm)
exec_command_and_wait_for_pattern(self,
'ls /usr/src/kernels/$(uname -r)/scripts/',
'sign-file', vm=vm)
@@ -71,11 +86,11 @@ def _sign_binaries(self, vm):
exec_command(self, '/usr/src/kernels/$(uname -r)/scripts/sign-file '
'sha256 mykey.pem mycert.pem /lib/s390-tools/stage3.bin',
vm=vm)
- wait_for_console_pattern(self, self.prompt, vm=vm)
+ wait_for_console_pattern(self, S390xSecureIpl._prompt, vm=vm)
exec_command(self, '/usr/src/kernels/$(uname -r)/scripts/sign-file '
'sha256 mykey.pem mycert.pem /boot/vmlinuz-$(uname -r)',
vm=vm)
- wait_for_console_pattern(self, self.prompt, vm=vm)
+ wait_for_console_pattern(self, S390xSecureIpl._prompt, vm=vm)
def _run_zipl_secure(self, vm):
"""Run zipl to prepare for secure boot"""
@@ -91,10 +106,11 @@ def _extract_certificate(self, vm):
cert = "\n".join(out.decode("utf-8").splitlines()[1:])
self.log.info("%s", cert)
- self.cert_path = self.scratch_file("mycert.pem")
+ cert_path = os.path.join(S390xSecureIpl._shared_workdir, "mycert.pem")
- with open(self.cert_path, 'w', encoding="utf-8") as file_object:
+ with open(cert_path, 'w', encoding="utf-8") as file_object:
file_object.write(cert)
+ S390xSecureIpl._cert_path = cert_path
def setup_s390x_secure_ipl(self):
"""
@@ -109,39 +125,42 @@ def setup_s390x_secure_ipl(self):
temp_vm.set_machine('s390-ccw-virtio')
asset_path = self.ASSET_F40_QCOW2.fetch()
- self.qcow2_path = self.scratch_file('f40.qcow2')
+ qcow2_path = os.path.join(S390xSecureIpl._shared_workdir, 'f40.qcow2')
qemu_img = get_qemu_img(self)
check_call([qemu_img, 'create', '-f', 'qcow2', '-b', asset_path,
- '-F', 'qcow2', self.qcow2_path], stdout=DEVNULL, stderr=DEVNULL)
+ '-F', 'qcow2', qcow2_path], stdout=DEVNULL, stderr=DEVNULL)
+ S390xSecureIpl._qcow2_path = qcow2_path
temp_vm.set_console()
temp_vm.add_args('-nographic',
'-accel', 'kvm',
'-m', '1024',
'-drive',
- f'id=drive0,if=none,format=qcow2,file={self.qcow2_path}',
+ f'id=drive0,if=none,format=qcow2,file={qcow2_path}',
'-device', 'virtio-blk-ccw,drive=drive0,bootindex=1')
temp_vm.launch()
self._require_host_secure_ipl_support(temp_vm)
# Initial root account setup (Fedora first boot screen)
- self.root_password = 'fedora40password'
+ S390xSecureIpl._root_password = 'fedora40password'
wait_for_console_pattern(self, 'Please make a selection from the above',
vm=temp_vm)
exec_command_and_wait_for_pattern(self, '4', 'Password:', vm=temp_vm)
- exec_command_and_wait_for_pattern(self, self.root_password,
+ exec_command_and_wait_for_pattern(self, S390xSecureIpl._root_password,
'Password (confirm):', vm=temp_vm)
- exec_command_and_wait_for_pattern(self, self.root_password,
+ exec_command_and_wait_for_pattern(self, S390xSecureIpl._root_password,
'Please make a selection from the above',
vm=temp_vm)
# Login as root
- self.prompt = '[root@localhost ~]#'
- exec_command_and_wait_for_pattern(self, 'c', 'localhost login:', vm=temp_vm)
- exec_command_and_wait_for_pattern(self, 'root', 'Password:', vm=temp_vm)
- exec_command_and_wait_for_pattern(self, self.root_password, self.prompt,
+ S390xSecureIpl._prompt = '[root@localhost ~]#'
+ exec_command_and_wait_for_pattern(self, 'c', 'localhost login:',
vm=temp_vm)
+ exec_command_and_wait_for_pattern(self, 'root', 'Password:',
+ vm=temp_vm)
+ exec_command_and_wait_for_pattern(self, S390xSecureIpl._root_password,
+ S390xSecureIpl._prompt, vm=temp_vm)
self._create_certificate(temp_vm)
self._sign_binaries(temp_vm)
@@ -150,41 +169,65 @@ def setup_s390x_secure_ipl(self):
# Shutdown temp vm
temp_vm.shutdown()
+ S390xSecureIpl._setup_done = True
- @skipBigDataTest()
- def test_s390x_secure_ipl(self):
+ def verify_s390x_secure_ipl(self, boot_dev_bus: str):
"""
Verify secure boot validation during s390x guest boot.
Expects two "Verified component" messages and confirms
/sys/firmware/ipl/secure reports secure boot is active.
"""
- self.require_accelerator('kvm')
- self.setup_s390x_secure_ipl()
-
- self.set_machine('s390-ccw-virtio')
-
- self.vm.set_console()
- self.vm.add_args('-nographic',
- '-machine', 's390-ccw-virtio,secure-boot=on,'
- f'boot-certs.0.path={self.cert_path}',
- '-accel', 'kvm',
- '-m', '1024',
- '-drive',
- f'id=drive1,if=none,format=qcow2,file={self.qcow2_path}',
- '-device', 'virtio-blk-ccw,drive=drive1,bootindex=1')
- self.vm.launch()
+ if boot_dev_bus not in ['ccw', 'pci']:
+ raise ValueError(
+ f"boot_dev_bus must be 'ccw' or 'pci', got {boot_dev_bus}")
+
+ vm = self.get_vm(name=f'sipl_test_vblk_{boot_dev_bus}')
+ vm.set_machine('s390-ccw-virtio')
+
+ vm.set_console()
+ vm.add_args('-nographic',
+ '-machine', 's390-ccw-virtio,secure-boot=on,'
+ f'boot-certs.0.path={S390xSecureIpl._cert_path}',
+ '-accel', 'kvm',
+ '-m', '1024',
+ '-drive',
+ f'id=drive1,if=none,format=qcow2,'
+ f'file={S390xSecureIpl._qcow2_path}',
+ '-device',
+ f'virtio-blk-{boot_dev_bus},drive=drive1,bootindex=1')
+ vm.launch()
# Expect two verified components
verified_output = "Verified component"
- wait_for_console_pattern(self, verified_output)
- wait_for_console_pattern(self, verified_output)
+ wait_for_console_pattern(self, verified_output, vm=vm)
+ wait_for_console_pattern(self, verified_output, vm=vm)
# Login and verify the vm is booted using secure boot
- wait_for_console_pattern(self, 'localhost login:')
- exec_command_and_wait_for_pattern(self, 'root', 'Password:')
- exec_command_and_wait_for_pattern(self, self.root_password, self.prompt)
- exec_command_and_wait_for_pattern(self, 'cat /sys/firmware/ipl/secure', '1')
+ wait_for_console_pattern(self, 'localhost login:', vm=vm)
+ exec_command_and_wait_for_pattern(self, 'root', 'Password:', vm=vm)
+ exec_command_and_wait_for_pattern(
+ self, S390xSecureIpl._root_password, S390xSecureIpl._prompt, vm=vm)
+ exec_command_and_wait_for_pattern(
+ self, 'cat /sys/firmware/ipl/secure', '1', vm=vm)
+
+ vm.shutdown()
+
+ @skipBigDataTest()
+ def test_s390x_secure_ipl_ccw(self):
+ """Test secure IPL with a virtio-blk-ccw boot device."""
+ self.require_accelerator('kvm')
+ if not S390xSecureIpl._setup_done:
+ self.setup_s390x_secure_ipl()
+ self.verify_s390x_secure_ipl('ccw')
+
+ @skipBigDataTest()
+ def test_s390x_secure_ipl_pci(self):
+ """Test secure IPL with a virtio-blk-pci boot device."""
+ self.require_accelerator('kvm')
+ if not S390xSecureIpl._setup_done:
+ self.setup_s390x_secure_ipl()
+ self.verify_s390x_secure_ipl('pci')
if __name__ == '__main__':
QemuSystemTest.main()
--
2.34.1
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH v2 3/3] tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev case
2026-08-26 14:57 ` [PATCH v2 3/3] tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev case Joshua Daley
@ 2026-09-01 20:36 ` Matthew Rosato
2026-09-02 14:27 ` Joshua Daley
0 siblings, 1 reply; 6+ messages in thread
From: Matthew Rosato @ 2026-09-01 20:36 UTC (permalink / raw)
To: Joshua Daley, qemu-s390x
Cc: qemu-devel, jrossi, zycai, borntraeger, jjherne, pasic, farman,
richard.henderson, iii, david, cohuck
On 8/26/26 10:57 AM, Joshua Daley wrote:
> Split test_s390x_secure_ipl() into two subtests. Each tests with a
> different boot device: virtio-blk-ccw or virtio-blk-pci. Use class-level
> variables and a temporary shared workdir such that the time-consuming
> setup is not run multiple times.
>
> Signed-off-by: Joshua Daley <jdaley@linux.ibm.com>
Thanks, I verified that the setup is not run twice (and indeed, you can
tell that while the first test takes quite a while, the second test
finishes much faster)
One other thought below...
[...]
> @@ -109,39 +125,42 @@ def setup_s390x_secure_ipl(self):
> temp_vm.set_machine('s390-ccw-virtio')
>
> asset_path = self.ASSET_F40_QCOW2.fetch()
> - self.qcow2_path = self.scratch_file('f40.qcow2')
> + qcow2_path = os.path.join(S390xSecureIpl._shared_workdir, 'f40.qcow2')
> qemu_img = get_qemu_img(self)
> check_call([qemu_img, 'create', '-f', 'qcow2', '-b', asset_path,
> - '-F', 'qcow2', self.qcow2_path], stdout=DEVNULL, stderr=DEVNULL)
> + '-F', 'qcow2', qcow2_path], stdout=DEVNULL, stderr=DEVNULL)
> + S390xSecureIpl._qcow2_path = qcow2_path
>
> temp_vm.set_console()
> temp_vm.add_args('-nographic',
> '-accel', 'kvm',
> '-m', '1024',
> '-drive',
> - f'id=drive0,if=none,format=qcow2,file={self.qcow2_path}',
> + f'id=drive0,if=none,format=qcow2,file={qcow2_path}',
> '-device', 'virtio-blk-ccw,drive=drive0,bootindex=1')
> temp_vm.launch()
>
> self._require_host_secure_ipl_support(temp_vm)
If we find this fails the first time, then we are going to fail setup
and therefore the 2nd test will also enter here, create the qcow2 again,
and then fail again for the same reason.
Couldn't we also save the time spent creating the qcow2 and launching a
VM the second time if we know it didn't work the first time? It's
checking the same host facilities.
Basically I'm wondering if we should just create another flag in
S390xSecureIpl that defaults to false and gets set to true in
_require_host_secure_ipl_support() if the support is missing. And check
that flag in each test before checking _setup_done and skip right away
if it's true (with the same message as the one in
_require_host_secure_ipl_support().
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v2 3/3] tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev case
2026-09-01 20:36 ` Matthew Rosato
@ 2026-09-02 14:27 ` Joshua Daley
0 siblings, 0 replies; 6+ messages in thread
From: Joshua Daley @ 2026-09-02 14:27 UTC (permalink / raw)
To: Matthew Rosato, qemu-s390x
Cc: qemu-devel, jrossi, zycai, borntraeger, jjherne, pasic, farman,
richard.henderson, iii, david, cohuck
On 9/1/2026 4:36 PM, Matthew Rosato wrote:
> On 8/26/26 10:57 AM, Joshua Daley wrote:
>> Split test_s390x_secure_ipl() into two subtests. Each tests with a
>> different boot device: virtio-blk-ccw or virtio-blk-pci. Use class-level
>> variables and a temporary shared workdir such that the time-consuming
>> setup is not run multiple times.
>>
>> Signed-off-by: Joshua Daley <jdaley@linux.ibm.com>
>
> Thanks, I verified that the setup is not run twice (and indeed, you can
> tell that while the first test takes quite a while, the second test
> finishes much faster)
>
> One other thought below...
>
> [...]
>
>> @@ -109,39 +125,42 @@ def setup_s390x_secure_ipl(self):
>> temp_vm.set_machine('s390-ccw-virtio')
>>
>> asset_path = self.ASSET_F40_QCOW2.fetch()
>> - self.qcow2_path = self.scratch_file('f40.qcow2')
>> + qcow2_path = os.path.join(S390xSecureIpl._shared_workdir, 'f40.qcow2')
>> qemu_img = get_qemu_img(self)
>> check_call([qemu_img, 'create', '-f', 'qcow2', '-b', asset_path,
>> - '-F', 'qcow2', self.qcow2_path], stdout=DEVNULL, stderr=DEVNULL)
>> + '-F', 'qcow2', qcow2_path], stdout=DEVNULL, stderr=DEVNULL)
>> + S390xSecureIpl._qcow2_path = qcow2_path
>>
>> temp_vm.set_console()
>> temp_vm.add_args('-nographic',
>> '-accel', 'kvm',
>> '-m', '1024',
>> '-drive',
>> - f'id=drive0,if=none,format=qcow2,file={self.qcow2_path}',
>> + f'id=drive0,if=none,format=qcow2,file={qcow2_path}',
>> '-device', 'virtio-blk-ccw,drive=drive0,bootindex=1')
>> temp_vm.launch()
>>
>> self._require_host_secure_ipl_support(temp_vm)
>
> If we find this fails the first time, then we are going to fail setup
> and therefore the 2nd test will also enter here, create the qcow2 again,
> and then fail again for the same reason.
> Couldn't we also save the time spent creating the qcow2 and launching a
> VM the second time if we know it didn't work the first time? It's
> checking the same host facilities.
>
> Basically I'm wondering if we should just create another flag in
> S390xSecureIpl that defaults to false and gets set to true in
> _require_host_secure_ipl_support() if the support is missing. And check
> that flag in each test before checking _setup_done and skip right away
> if it's true (with the same message as the one in
> _require_host_secure_ipl_support().
>
>
I think that's a good idea. I'll add it. Thanks for reviewing.
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-09-02 14:27 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-26 14:57 [PATCH v2 0/3] Extend secure IPL support to virtio-blk-pci boot devices Joshua Daley
2026-08-26 14:57 ` [PATCH v2 1/3] hw/s390x/ipl: Add secure boot support to PCI dev IPLB builder Joshua Daley
2026-08-26 14:57 ` [PATCH v2 2/3] tests/functional/s390x/test_secure_ipl: Skip test if SIPL not supported by hypervisor Joshua Daley
2026-08-26 14:57 ` [PATCH v2 3/3] tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev case Joshua Daley
2026-09-01 20:36 ` Matthew Rosato
2026-09-02 14:27 ` Joshua Daley
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.