From: Baolong Duan <blduan@linux.alibaba.com>
To: qemu-devel@nongnu.org
Cc: qemu-riscv@nongnu.org, alistair23@gmail.com,
dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com,
zengxiangyi.zxy@alibaba-inc.com,
Baolong Duan <blduan@linux.alibaba.com>
Subject: [RFC PATCH v1 03/17] target/riscv/kvm: create and measure a CoVE TEE VM
Date: Fri, 31 Jul 2026 11:49:57 +0800 [thread overview]
Message-ID: <20260731035011.4178103-4-blduan@linux.alibaba.com> (raw)
In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com>
Ask KVM for a TEE VM (TVM) instead of a regular guest when the machine
runs in CoVE mode, and add kvm_riscv_cove_measure_region() to add a
memory region to the initial measurement of that TVM.
The measurement is what allows a CoVE guest to be attested later on, so
failing to add a region to it is fatal.
The KVM ABI this relies on is not part of an upstream Linux release yet, so
KVM_VM_TYPE_RISCV_COVE and KVM_RISCV_COVE_MEASURE_REGION are defined here
rather than imported into linux-headers/. They have to be replaced by a
regular scripts/update-linux-headers.sh run once the kernel side has been
merged.
Signed-off-by: Baolong Duan <blduan@linux.alibaba.com>
---
target/riscv/kvm/kvm-cpu.c | 46 ++++++++++++++++++++++++++++++++++++
target/riscv/kvm/kvm_riscv.h | 10 ++++++++
2 files changed, 56 insertions(+)
diff --git a/target/riscv/kvm/kvm-cpu.c b/target/riscv/kvm/kvm-cpu.c
index 495cb42dc8..67c99d68ce 100644
--- a/target/riscv/kvm/kvm-cpu.c
+++ b/target/riscv/kvm/kvm-cpu.c
@@ -48,10 +48,27 @@
#include "migration/misc.h"
#include "system/runstate.h"
#include "hw/riscv/numa.h"
+#include "hw/riscv/cove.h"
#define PR_RISCV_V_SET_CONTROL 69
#define PR_RISCV_V_VSTATE_CTRL_ON 2
+/*
+ * CoVE KVM ABI. These definitions are not part of an upstream Linux release
+ * yet, so they cannot be imported into linux-headers/ and are kept here until
+ * the kernel side has been merged.
+ */
+#define KVM_VM_TYPE_RISCV_COVE (1UL << 9)
+
+struct kvm_riscv_cove_measure_region {
+ uint64_t user_addr;
+ uint64_t gpa;
+ uint64_t size;
+};
+
+#define KVM_RISCV_COVE_MEASURE_REGION \
+ _IOR(KVMIO, 0xb5, struct kvm_riscv_cove_measure_region)
+
void riscv_kvm_aplic_request(void *opaque, int irq, int level)
{
kvm_set_irq(kvm_state, irq, !!level);
@@ -1549,6 +1566,9 @@ int kvm_arch_add_msi_route_post(struct kvm_irq_routing_entry *route,
int kvm_arch_get_default_type(MachineState *ms)
{
+ if (riscv_cove_vm_active()) {
+ return KVM_VM_TYPE_RISCV_COVE;
+ }
return 0;
}
@@ -1829,6 +1849,32 @@ void kvm_arch_accel_class_init(ObjectClass *oc)
"auto");
}
+/*
+ * Add the contents of a memory region to the initial measurement of the TVM.
+ * Nothing is measured for a guest that is not confidential.
+ */
+void kvm_riscv_cove_measure_region(uint64_t user_addr, uint64_t gpa,
+ uint64_t size)
+{
+ struct kvm_riscv_cove_measure_region mr;
+ int ret;
+
+ if (!riscv_cove_vm_active()) {
+ return;
+ }
+
+ mr.user_addr = user_addr;
+ mr.gpa = gpa;
+ mr.size = size;
+
+ ret = kvm_vm_ioctl(kvm_state, KVM_RISCV_COVE_MEASURE_REGION, &mr);
+ if (ret < 0) {
+ error_report("Unable to measure CoVE region at 0x%" PRIx64 ": %s",
+ gpa, strerror(-ret));
+ exit(EXIT_FAILURE);
+ }
+}
+
void kvm_riscv_aia_create(MachineState *machine, uint64_t group_shift,
uint64_t aia_irq_num, uint64_t aia_msi_num,
uint64_t aplic_base, uint64_t imsic_base,
diff --git a/target/riscv/kvm/kvm_riscv.h b/target/riscv/kvm/kvm_riscv.h
index b2bcd1041f..cd45f1266b 100644
--- a/target/riscv/kvm/kvm_riscv.h
+++ b/target/riscv/kvm/kvm_riscv.h
@@ -23,6 +23,16 @@
void kvm_riscv_reset_vcpu(RISCVCPU *cpu);
void kvm_riscv_set_irq(RISCVCPU *cpu, int irq, int level);
+#ifdef CONFIG_KVM
+void kvm_riscv_cove_measure_region(uint64_t user_addr, uint64_t gpa,
+ uint64_t size);
+#else
+static inline void kvm_riscv_cove_measure_region(uint64_t user_addr,
+ uint64_t gpa, uint64_t size)
+{
+ /* A CoVE guest cannot be created without KVM, nothing to measure. */
+}
+#endif
void kvm_riscv_aia_create(MachineState *machine, uint64_t group_shift,
uint64_t aia_irq_num, uint64_t aia_msi_num,
uint64_t aplic_base, uint64_t imsic_base,
--
2.34.1
next prev parent reply other threads:[~2026-07-31 5:59 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 3:49 [RFC PATCH v1 00/17] target/riscv: Add KVM CoVE confidential VM support Baolong Duan
2026-07-31 3:49 ` [RFC PATCH v1 01/17] docs/system/riscv/virt: document the cove-vm machine option Baolong Duan
2026-07-31 3:49 ` [RFC PATCH v1 02/17] hw/riscv/virt: add the cove-vm machine property Baolong Duan
2026-07-31 3:49 ` Baolong Duan [this message]
2026-07-31 3:49 ` [RFC PATCH v1 04/17] accel/kvm: add kvm_gpa_to_userspace_addr() Baolong Duan
2026-07-31 3:49 ` [RFC PATCH v1 05/17] hw/riscv/boot: load and measure the images of a CoVE guest Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 06/17] hw/riscv/virt: measure the device tree " Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 07/17] hw/riscv: adapt " Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 08/17] hw/riscv/virt: use MSIs only for " Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 09/17] hw/intc/riscv_aplic: emulate the APLIC " Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 10/17] target/riscv/kvm: skip unsupported KVM requests " Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 11/17] hw/virtio: force modern virtio " Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 12/17] hw/net/virtio-net: do not use vhost " Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 13/17] accel/kvm: only register the DRAM slot of " Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 14/17] accel/kvm: skip MSI route updates for " Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 15/17] accel/kvm: pin the vCPU threads of " Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 16/17] accel/kvm: terminate on a system event " Baolong Duan
2026-07-31 3:50 ` [RFC PATCH v1 17/17] hw/core/machine-qmp-cmds: shut down a CoVE guest on reset Baolong Duan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260731035011.4178103-4-blduan@linux.alibaba.com \
--to=blduan@linux.alibaba.com \
--cc=alistair23@gmail.com \
--cc=cxx194832@alibaba-inc.com \
--cc=dbarboza@ventanamicro.com \
--cc=qemu-devel@nongnu.org \
--cc=qemu-riscv@nongnu.org \
--cc=zengxiangyi.zxy@alibaba-inc.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.