From: Joshua Daley <jdaley@linux.ibm.com>
To: qemu-s390x@nongnu.org
Cc: qemu-devel@nongnu.org, jrossi@linux.ibm.com, zycai@linux.ibm.com,
borntraeger@linux.ibm.com, jjherne@linux.ibm.com,
pasic@linux.ibm.com, farman@linux.ibm.com,
mjrosato@linux.ibm.com, richard.henderson@linaro.org,
iii@linux.ibm.com, david@kernel.org, cohuck@redhat.com,
jdaley@linux.ibm.com
Subject: [PATCH v2 0/3] Extend secure IPL support to virtio-blk-pci boot devices
Date: Wed, 26 Aug 2026 16:57:53 +0200 [thread overview]
Message-ID: <20260826145756.2324598-1-jdaley@linux.ibm.com> (raw)
Changes v1 -> v2:
- Added RB tags to patches 1 & 2
- Patch 3:
The setup step is now run only once, as originally intended.
setUpClass and tearDownClass manage a shared workdir for the
subtests to use. Instance vars are now class-level vars.
v1 cover letter:
This series is based on Zhuoying Cai's series,
"[PATCH v17 00/34] Secure IPL Support for SCSI Scheme of virtio-blk/virtio-scsi Devices"
https://lore.kernel.org/qemu-devel/20260730214624.2328883-1-zycai@linux.ibm.com/
Note, the above series is based on Cornelia Huck's patch,
"[PATCH for-11.2] hw: add compat machines for 11.2"
https://lore.kernel.org/qemu-devel/20260723163806.368127-1-cohuck@redhat.com/
which requires a small fix to apply (see Eric Farman's reply).
---
To add support for secure IPL with a virtio-blk-pci boot device, we simply
write secure boot flags to the IPLB when using such a boot device.
This is achieved by calling s390_apply_secure_boot() in the PCI boot
device case of s390_build_iplb().
The secure IPL functional verification test is updated with an additional
subtest for the virtio-blk-pci boot device case. To run the FVT:
make check-functional-s390x MTESTARGS="func-s390x-secure_ipl" \
QEMU_TEST_ALLOW_LARGE_STORAGE=1
To test secure IPL yourself, view the "Secure IPL Quickstart" guide in:
docs/system/s390x/secure-ipl.rst
Joshua Daley (3):
hw/s390x/ipl: Add secure boot support to PCI dev IPLB builder
tests/functional/s390x/test_secure_ipl: Skip test if SIPL not
supported by hypervisor
tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev
case
hw/s390x/ipl.c | 8 +-
tests/functional/s390x/test_secure_ipl.py | 149 +++++++++++++++-------
2 files changed, 108 insertions(+), 49 deletions(-)
--
2.34.1
next reply other threads:[~2026-08-26 14:59 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-26 14:57 Joshua Daley [this message]
2026-08-26 14:57 ` [PATCH v2 1/3] hw/s390x/ipl: Add secure boot support to PCI dev IPLB builder Joshua Daley
2026-08-26 14:57 ` [PATCH v2 2/3] tests/functional/s390x/test_secure_ipl: Skip test if SIPL not supported by hypervisor Joshua Daley
2026-08-26 14:57 ` [PATCH v2 3/3] tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev case Joshua Daley
2026-09-01 20:36 ` Matthew Rosato
2026-09-02 14:27 ` Joshua Daley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260826145756.2324598-1-jdaley@linux.ibm.com \
--to=jdaley@linux.ibm.com \
--cc=borntraeger@linux.ibm.com \
--cc=cohuck@redhat.com \
--cc=david@kernel.org \
--cc=farman@linux.ibm.com \
--cc=iii@linux.ibm.com \
--cc=jjherne@linux.ibm.com \
--cc=jrossi@linux.ibm.com \
--cc=mjrosato@linux.ibm.com \
--cc=pasic@linux.ibm.com \
--cc=qemu-devel@nongnu.org \
--cc=qemu-s390x@nongnu.org \
--cc=richard.henderson@linaro.org \
--cc=zycai@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.