From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 54CDFC5516D for ; Thu, 30 Jul 2026 21:48:08 +0000 (UTC) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpYbN-00043k-BM; Thu, 30 Jul 2026 17:47:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpYbJ-0003V6-9P; Thu, 30 Jul 2026 17:47:37 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpYbG-0002SS-SI; Thu, 30 Jul 2026 17:47:36 -0400 Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66UJls8V4001339; Thu, 30 Jul 2026 21:47:31 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=h6blUfV6AQdKi6j1+ OsJXmOWdDVB+ZLKxBiwg7cKYgk=; b=LySkVV2sNznVGqRdMKKMcCKqgGPYHwXh5 7gjx1uXdusT1HWAYyDqvcHHUh584PKFHiMaYISz6guDZ8bLwd6UtbwYZU7Hy7iO2 Dc+7D58/tlfeKFqO1ATBm8NyNPsCC5gmmJU/P91crAB94F2jI/fanjuSKKIOtThD M0EZQmtEr2AJAfOhlRaZiL625OAYErrivaH4Xi9/R9DJZQ/pQIYvgAmSYehqORV/ jZXwWDP1YnZjEce6JeHgqdT2AHzFQG56aP2LUQmN7aEsKP5/GlBfLUh4o8KHJs3i 1kkvWT5cGntA5aolQbG8D6zlF/oi5sdFiKZVD0EJ8jfWM6pvVmbrA== Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fmuwd94xq-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 30 Jul 2026 21:47:31 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 66ULfGrx003305; Thu, 30 Jul 2026 21:47:30 GMT Received: from smtprelay03.wdc07v.mail.ibm.com ([172.16.1.70]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fna5yd1h3-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 30 Jul 2026 21:47:30 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (smtpav05.wdc07v.mail.ibm.com [10.39.53.232]) by smtprelay03.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 66ULkqUs16384612 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 30 Jul 2026 21:46:52 GMT Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 1735E58053; Thu, 30 Jul 2026 21:47:29 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 2CC0258059; Thu, 30 Jul 2026 21:47:27 +0000 (GMT) Received: from fedora-workstation.ibmuc.com (unknown [9.61.77.192]) by smtpav05.wdc07v.mail.ibm.com (Postfix) with ESMTP; Thu, 30 Jul 2026 21:47:27 +0000 (GMT) From: Zhuoying Cai To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com, richard.henderson@linaro.org, david@kernel.org, walling@linux.ibm.com, jjherne@linux.ibm.com, pasic@linux.ibm.com, borntraeger@linux.ibm.com, farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com, eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com, alifm@linux.ibm.com, brueckner@linux.ibm.com, pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com Subject: [PATCH v17 29/34] pc-bios/s390-ccw: Handle true secure IPL mode Date: Thu, 30 Jul 2026 17:46:18 -0400 Message-ID: <20260730214624.2328883-30-zycai@linux.ibm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260730214624.2328883-1-zycai@linux.ibm.com> References: <20260730214624.2328883-1-zycai@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-TM-AS-GCONF: 00 X-Proofpoint-ORIG-GUID: UcY7HIqXhc2YT2hyeK4Q-ZL8-ZDjNjHj X-Proofpoint-Spam-Info: AW1haW4tMjYwNzMwMDE1NCBTYWx0ZWRfX7fbzpY7aZ3mh hFv2UiYcPLtg551dNNCU9uiscF0JrtLa6RwlltSShCsA/xDV8BdSvZraQsxr6ywfsafoIdbmds4 wlDa9Evm0PldIGr+w9dWTRjG7biDdRk= X-Authority-Analysis: v=2.4 cv=E/z9Y6dl c=1 sm=1 tr=0 ts=6a6bc673 cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=f2vt_NpQTvy9KJbTYrsA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzMwMDE1NCBTYWx0ZWRfX351+XlF7In5V SRKrvxdtmf1vTGGbN+GQmi3M4kXyxGrc0s6NeZuNn4Sowln86HKaJ/WmUKW6XHlShSkD3yTxSpw 8GsZybjNYRtuZ3QJrWAmSBG/XNoiB4BBvNnxKSniGTPlqvisMjw6f6LIx7x4De4x/xd5Kajvys9 htpug1gqgglH8lIWCpaqsHkcB8YPAsPStOYOBudrRKLhGUzqh+kcRiBbn5sgG3CiEhafEarM9bS YLhrpRSHMYbJN2NdBbV8h5T4UM6aCYFfHedHjxyU2LCeDSk+oRWG7rCaua2ndkOuGUnjiENtkjD XRtEro3Tt5f8epLpxDJPdsMJ3gm5cceHiAQ+FnAjiwKV42oQhsEjM5ikRDuhXdvc8Cjos1uv6Zt KGwdis6NtiKw+LgEh+QoAktlpmK0igMVT9aEgY+5jN7G4MwLNRydYcU6mEKXaOrRLuHAkxqGKMF YMFC/Km5DPguweQuSvQ== X-Proofpoint-GUID: UcY7HIqXhc2YT2hyeK4Q-ZL8-ZDjNjHj X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-30_06,2026-07-30_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 priorityscore=1501 spamscore=0 clxscore=1015 phishscore=0 lowpriorityscore=0 bulkscore=0 malwarescore=0 impostorscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607300154 Received-SPF: pass client-ip=148.163.158.5; envelope-from=zycai@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+qemu-devel=archiver.kernel.org@nongnu.org Sender: qemu-devel-bounces+qemu-devel=archiver.kernel.org@nongnu.org When secure boot is enabled (-secure-boot on) and certificate(s) are provided, the boot operates in True Secure IPL mode. Any verification error during True Secure IPL mode will cause the entire boot process to terminate. Secure IPL in audit mode requires at least one certificate provided in the key store along with necessary facilities. If secure boot is enabled but no certificate is provided, the boot process will also terminate, as this is not a valid secure boot configuration. Note: True Secure IPL mode is implemented for the SCSI scheme of virtio-blk/virtio-scsi devices. Signed-off-by: Zhuoying Cai Reviewed-by: Collin Walling Reviewed-by: Matthew Rosato --- docs/system/s390x/secure-ipl.rst | 13 +++++++++++++ hw/s390x/ipl.c | 3 ++- pc-bios/s390-ccw/bootmap.c | 6 +++++- pc-bios/s390-ccw/main.c | 7 ++++++- pc-bios/s390-ccw/s390-ccw.h | 1 + pc-bios/s390-ccw/secure-ipl.h | 3 +++ 6 files changed, 30 insertions(+), 3 deletions(-) diff --git a/docs/system/s390x/secure-ipl.rst b/docs/system/s390x/secure-ipl.rst index 9e3955f8fc..c8fb887ac0 100644 --- a/docs/system/s390x/secure-ipl.rst +++ b/docs/system/s390x/secure-ipl.rst @@ -66,3 +66,16 @@ Configuration: .. code-block:: shell qemu-system-s390x -machine s390-ccw-virtio,boot-certs.0.path=/.../qemu/certs,boot-certs.1.path=/another/path/cert.pem ... + +Secure Mode +^^^^^^^^^^^ + +When the ``secure-boot=on`` option is set and certificates are provided, +a secure boot is performed with error reporting enabled. The boot process aborts +if any error occurs. + +Configuration: + +.. code-block:: shell + + qemu-system-s390x -machine s390-ccw-virtio,secure-boot=on,boot-certs.0.path=/.../qemu/certs,boot-certs.1.path=/another/path/cert.pem ... diff --git a/hw/s390x/ipl.c b/hw/s390x/ipl.c index 08294af4d0..35bdfe03d8 100644 --- a/hw/s390x/ipl.c +++ b/hw/s390x/ipl.c @@ -851,7 +851,8 @@ void s390_ipl_prepare_cpu(S390CPU *cpu) * Secure IPL without specifying a boot device. * IPLB is not generated if no boot device is defined. */ - if (s390_has_certificate() && !ipl->iplb_valid) { + if ((s390_has_certificate() || s390_secure_boot_enabled()) && + !ipl->iplb_valid) { error_report("No boot device defined for Secure IPL"); exit(1); } diff --git a/pc-bios/s390-ccw/bootmap.c b/pc-bios/s390-ccw/bootmap.c index 3d681bcacb..a41820de2e 100644 --- a/pc-bios/s390-ccw/bootmap.c +++ b/pc-bios/s390-ccw/bootmap.c @@ -741,6 +741,7 @@ static int zipl_run(ScsiBlockPtr *pte) case ZIPL_BOOT_MODE_NORMAL: rc = zipl_run_normal(&entry, tmp_sec); break; + case ZIPL_BOOT_MODE_SECURE: case ZIPL_BOOT_MODE_SECURE_AUDIT: rc = zipl_run_secure(&entry, tmp_sec, &comp_list, &cert_list, &tmp_cert_buf); break; @@ -760,7 +761,8 @@ static int zipl_run(ScsiBlockPtr *pte) write_reset_psw(entry->compdat.load_psw); - if (boot_mode == ZIPL_BOOT_MODE_SECURE_AUDIT) { + if (boot_mode == ZIPL_BOOT_MODE_SECURE || + boot_mode == ZIPL_BOOT_MODE_SECURE_AUDIT) { update_cert_list(&cert_list); update_iirb(&comp_list, &cert_list); free(tmp_cert_buf); @@ -1128,6 +1130,8 @@ ZiplBootMode get_boot_mode(uint8_t hdr_flags) if (!sipl_set && iplir_set) { return ZIPL_BOOT_MODE_SECURE_AUDIT; + } else if (sipl_set && iplir_set) { + return ZIPL_BOOT_MODE_SECURE; } return ZIPL_BOOT_MODE_NORMAL; diff --git a/pc-bios/s390-ccw/main.c b/pc-bios/s390-ccw/main.c index 520c448c2c..c5c093534c 100644 --- a/pc-bios/s390-ccw/main.c +++ b/pc-bios/s390-ccw/main.c @@ -402,15 +402,20 @@ void main(void) boot_mode = get_boot_mode(iplb->hdr_flags); switch (boot_mode) { + case ZIPL_BOOT_MODE_SECURE: case ZIPL_BOOT_MODE_SECURE_AUDIT: if (!secure_ipl_supported()) { - panic("Unable to boot in audit mode"); + panic("Unable to boot in secure/audit mode"); } vcssb_len = zipl_secure_get_vcssb(); if (vcssb_len == 0) { panic("Failed to query certificate storage information!"); } + + if (vcssb_len == VCSSB_NO_VC) { + panic("Need at least one certificate for secure boot!"); + } break; default: break; diff --git a/pc-bios/s390-ccw/s390-ccw.h b/pc-bios/s390-ccw/s390-ccw.h index ca2737054d..0ea4810f1f 100644 --- a/pc-bios/s390-ccw/s390-ccw.h +++ b/pc-bios/s390-ccw/s390-ccw.h @@ -90,6 +90,7 @@ void zipl_load(void); typedef enum ZiplBootMode { ZIPL_BOOT_MODE_NORMAL = 0, ZIPL_BOOT_MODE_SECURE_AUDIT = 1, + ZIPL_BOOT_MODE_SECURE = 2, } ZiplBootMode; extern ZiplBootMode boot_mode; diff --git a/pc-bios/s390-ccw/secure-ipl.h b/pc-bios/s390-ccw/secure-ipl.h index ce354b4d6a..4908245b9b 100644 --- a/pc-bios/s390-ccw/secure-ipl.h +++ b/pc-bios/s390-ccw/secure-ipl.h @@ -59,6 +59,9 @@ static inline void zipl_secure_error(const char *message) case ZIPL_BOOT_MODE_SECURE_AUDIT: printf("AUDIT MODE WARNING: %s\n", message); break; + case ZIPL_BOOT_MODE_SECURE: + panic(message); + break; default: /* * Errors are intentionally ignored in non-secure boot modes. -- 2.55.0