From: "Dr. David Alan Gilbert" <dgilbert@redhat.com>
To: James Bottomley <jejb@linux.ibm.com>, pbonzini@redhat.com
Cc: thomas.lendacky@amd.com, brijesh.singh@amd.com, tobin@ibm.com,
qemu-devel@nongnu.org,
Tobin Feldman-Fitzthum <tobin@linux.ibm.com>
Subject: Re: [PATCH v3] SEV: QMP support for Inject-Launch-Secret
Date: Mon, 12 Oct 2020 17:38:21 +0100 [thread overview]
Message-ID: <20201012163821.GJ6677@work-vm> (raw)
In-Reply-To: <b6137b4997b0729e576bc6c0c5476960d1992115.camel@linux.ibm.com>
* James Bottomley (jejb@linux.ibm.com) wrote:
> On Mon, 2020-10-12 at 16:57 +0100, Dr. David Alan Gilbert wrote:
> > * Tobin Feldman-Fitzthum (tobin@linux.ibm.com) wrote:
> > > On 2020-09-21 15:16, Dr. David Alan Gilbert wrote:
> > > > * Tobin Feldman-Fitzthum (tobin@linux.vnet.ibm.com) wrote:
> > > > > AMD SEV allows a guest owner to inject a secret blob
> > > > > into the memory of a virtual machine. The secret is
> > > > > encrypted with the SEV Transport Encryption Key and
> > > > > integrity is guaranteed with the Transport Integrity
> > > > > Key. Although QEMU faciliates the injection of the
> > > > > launch secret, it cannot access the secret.
> > > > >
> > > > > Signed-off-by: Tobin Feldman-Fitzthum <tobin@linux.vnet.ibm.com
> > > > > >
> > > >
> > > > Hi Tobin,
> > > > Did the ovmf stuff for agreeing the GUID for automating this
> > > > ever happen?
> > > >
> > > OVMF patches have not been upstreamed yet. I think we are planning
> > > to do that relatively soon.
> >
> > So as we're getting to the end of another qemu dev cycle; do we aim
> > to get this one in by itself, or to wait for the GUID?
>
> Since they're independent of each other, I'd say get this one in now if
> it's acceptable. The GUID will come as a discoverable way of setting
> the GPA, but this patch at least gives people a way to play with SEV
> secret injection. I'm also reworking the OVMF GUID patch to tack on to
> the reset vector GUID that just went upstream, so it will be a few more
> weeks yet before we have it all integrated with the -ES patch set.
OK, so I've just replied with a minor error leak that needs fixing, but
other than that it looks OK to me.
I've not quite figured out who would pull it, Paolo?
Dave
> James
>
>
--
Dr. David Alan Gilbert / dgilbert@redhat.com / Manchester, UK
next prev parent reply other threads:[~2020-10-12 16:40 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-07-06 21:54 [PATCH v3] SEV: QMP support for Inject-Launch-Secret Tobin Feldman-Fitzthum
2020-07-06 22:00 ` tobin
2020-09-21 19:16 ` Dr. David Alan Gilbert
2020-09-21 20:33 ` Tobin Feldman-Fitzthum
2020-09-21 22:14 ` Tom Lendacky
2020-10-12 15:57 ` Dr. David Alan Gilbert
2020-10-12 16:00 ` James Bottomley
2020-10-12 16:38 ` Dr. David Alan Gilbert [this message]
2020-10-12 16:21 ` Dr. David Alan Gilbert
2020-10-12 16:49 ` Daniel P. Berrangé
2020-10-13 21:56 ` tobin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20201012163821.GJ6677@work-vm \
--to=dgilbert@redhat.com \
--cc=brijesh.singh@amd.com \
--cc=jejb@linux.ibm.com \
--cc=pbonzini@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=thomas.lendacky@amd.com \
--cc=tobin@ibm.com \
--cc=tobin@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.