From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 64049C55167 for ; Fri, 31 Jul 2026 06:00:30 +0000 (UTC) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpgFo-0002lY-9C; Fri, 31 Jul 2026 01:57:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM9-0005uy-US; Thu, 30 Jul 2026 23:56:22 -0400 Received: from [115.124.30.119] (helo=out30-119.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpeM7-0002Jc-I0; Thu, 30 Jul 2026 23:56:21 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785470176; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=RAtJ32hEdTI4Y88GDT5CEtSyJ9YBee4mz+bhPMzq8kI=; b=moM1uPHFhELmS8dLk31r1wpX0mFDisxajJ4JoW3eLkO/vRnBEy7gxEgwEEaoN608xPyOFdq+G0zRw8nx3G5drdZb9A9leZfTSTcJrqSwh9UXP2W8Nq33gQJADMgpqmUWwbZLO+whfgtAg38nrlH9aT7HXnxIErj1HsN1GCCWCmk= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R181e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033032089153; MF=blduan@linux.alibaba.com; NM=1; PH=DS; RN=7; SR=0; TI=SMTPD_---0X86jwVc_1785469860; Received: from ea134-sw16.eng.xrvm.cn(mailfrom:blduan@linux.alibaba.com fp:SMTPD_---0X86jwVc_1785469860 cluster:ay36) by smtp.aliyun-inc.com; Fri, 31 Jul 2026 11:51:01 +0800 From: Baolong Duan To: qemu-devel@nongnu.org Cc: qemu-riscv@nongnu.org, alistair23@gmail.com, dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com, zengxiangyi.zxy@alibaba-inc.com, Baolong Duan Subject: [RFC PATCH v1 13/17] accel/kvm: only register the DRAM slot of a CoVE guest Date: Fri, 31 Jul 2026 11:50:07 +0800 Message-Id: <20260731035011.4178103-14-blduan@linux.alibaba.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com> References: <20260731035011.4178103-1-blduan@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.119 (deferred) Received-SPF: pass client-ip=115.124.30.119; envelope-from=blduan@linux.alibaba.com; helo=out30-119.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 31 Jul 2026 01:57:33 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+qemu-devel=archiver.kernel.org@nongnu.org Sender: qemu-devel-bounces+qemu-devel=archiver.kernel.org@nongnu.org The TSM tracks the confidential region of a TEE VM itself. Registering the remaining memory slots of the machine, such as the mask ROM or the flash, overwrites that region and the guest fails to start. Filtering them by slot number is a workaround rather than a solution: the machine should describe which regions belong to the confidential guest instead. Suggestions on how to express that are very welcome. Signed-off-by: Baolong Duan --- accel/kvm/kvm-all.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/accel/kvm/kvm-all.c b/accel/kvm/kvm-all.c index 005abb1c54..2753bf8b8b 100644 --- a/accel/kvm/kvm-all.c +++ b/accel/kvm/kvm-all.c @@ -26,6 +26,7 @@ #include "qapi/error.h" #include "hw/pci/msi.h" #include "hw/pci/msix.h" +#include "hw/riscv/cove.h" #include "hw/s390x/adapter.h" #include "gdbstub/enums.h" #include "system/kvm_int.h" @@ -393,6 +394,16 @@ static int kvm_set_user_memory_region(KVMMemoryListener *kml, KVMSlot *slot, boo struct kvm_userspace_memory_region2 mem = {}; int ret; + /* + * Only the DRAM slot is registered with KVM for a CoVE guest: the TSM + * tracks the confidential region of the TVM itself and registering the + * other slots (MROM, flash, ...) would overwrite it. + */ + if (riscv_cove_vm_active() && (slot->slot & 0xffff) != 0 && + slot->memory_size > 0) { + return 0; + } + mem.slot = slot->slot | (kml->as_id << 16); mem.guest_phys_addr = slot->start_addr; mem.userspace_addr = (unsigned long)slot->ram; -- 2.34.1