All of lore.kernel.org
 help / color / mirror / Atom feed
From: Joshua Daley <jdaley@linux.ibm.com>
To: qemu-s390x@nongnu.org
Cc: qemu-devel@nongnu.org, jrossi@linux.ibm.com, zycai@linux.ibm.com,
	borntraeger@linux.ibm.com, jjherne@linux.ibm.com,
	pasic@linux.ibm.com, farman@linux.ibm.com,
	mjrosato@linux.ibm.com, richard.henderson@linaro.org,
	iii@linux.ibm.com, david@kernel.org, cohuck@redhat.com,
	jdaley@linux.ibm.com
Subject: [PATCH v3 0/3] Extend secure IPL support to virtio-blk-pci boot devices
Date: Thu,  3 Sep 2026 17:58:02 +0200	[thread overview]
Message-ID: <20260903155805.1881366-1-jdaley@linux.ibm.com> (raw)

Changes v2 -> v3:

- Patch 3:
   Added _host_lacks_sipl_support flag to skip vm setup if
   we've already found that the host does not support SIPL.

---

v2 cover letter:

Changes v1 -> v2:

- Added RB tags to patches 1 & 2
- Patch 3:
   The setup step is now run only once, as originally intended.
   setUpClass and tearDownClass manage a shared workdir for the
   subtests to use. Instance vars are now class-level vars.

---

v1 cover letter:

This series is based on Zhuoying Cai's series,
"[PATCH v17 00/34] Secure IPL Support for SCSI Scheme of virtio-blk/virtio-scsi Devices"
https://lore.kernel.org/qemu-devel/20260730214624.2328883-1-zycai@linux.ibm.com/

Note, the above series is based on Cornelia Huck's patch,
"[PATCH for-11.2] hw: add compat machines for 11.2"
https://lore.kernel.org/qemu-devel/20260723163806.368127-1-cohuck@redhat.com/
which requires a small fix to apply (see Eric Farman's reply).

---

To add support for secure IPL with a virtio-blk-pci boot device, we simply
write secure boot flags to the IPLB when using such a boot device.
This is achieved by calling s390_apply_secure_boot() in the PCI boot
device case of s390_build_iplb().

The secure IPL functional verification test is updated with an additional
subtest for the virtio-blk-pci boot device case. To run the FVT:

  make check-functional-s390x MTESTARGS="func-s390x-secure_ipl" \
  QEMU_TEST_ALLOW_LARGE_STORAGE=1

To test secure IPL yourself, view the "Secure IPL Quickstart" guide in:
docs/system/s390x/secure-ipl.rst

Joshua Daley (3):
  hw/s390x/ipl: Add secure boot support to PCI dev IPLB builder
  tests/functional/s390x/test_secure_ipl: Skip test if SIPL not
    supported by hypervisor
  tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev
    case

 hw/s390x/ipl.c                            |   8 +-
 tests/functional/s390x/test_secure_ipl.py | 157 ++++++++++++++++------
 2 files changed, 116 insertions(+), 49 deletions(-)

-- 
2.34.1



             reply	other threads:[~2026-09-03 15:59 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03 15:58 Joshua Daley [this message]
2026-09-03 15:58 ` [PATCH v3 1/3] hw/s390x/ipl: Add secure boot support to PCI dev IPLB builder Joshua Daley
2026-09-03 15:58 ` [PATCH v3 2/3] tests/functional/s390x/test_secure_ipl: Skip test if SIPL not supported by hypervisor Joshua Daley
2026-09-03 15:58 ` [PATCH v3 3/3] tests/functional/s390x/test_secure_ipl: Add virtio-blk-pci boot dev case Joshua Daley
2026-09-08 15:52   ` Matthew Rosato
2026-09-09 14:51 ` [PATCH v3 0/3] Extend secure IPL support to virtio-blk-pci boot devices Eric Farman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260903155805.1881366-1-jdaley@linux.ibm.com \
    --to=jdaley@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=cohuck@redhat.com \
    --cc=david@kernel.org \
    --cc=farman@linux.ibm.com \
    --cc=iii@linux.ibm.com \
    --cc=jjherne@linux.ibm.com \
    --cc=jrossi@linux.ibm.com \
    --cc=mjrosato@linux.ibm.com \
    --cc=pasic@linux.ibm.com \
    --cc=qemu-devel@nongnu.org \
    --cc=qemu-s390x@nongnu.org \
    --cc=richard.henderson@linaro.org \
    --cc=zycai@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.