From: "Daniel P. Berrangé" <berrange@redhat.com>
To: Markus Armbruster <armbru@redhat.com>
Cc: Jean-Philippe Brucker <jean-philippe@linaro.org>,
peter.maydell@linaro.org, richard.henderson@linaro.org,
philmd@linaro.org, qemu-arm@nongnu.org, qemu-devel@nongnu.org,
alex.bennee@linaro.org, Eric Blake <eblake@redhat.com>,
Eduardo Habkost <eduardo@habkost.net>
Subject: Re: [PATCH v3 10/26] target/arm/kvm-rme: Add Realm Personalization Value parameter
Date: Tue, 26 Nov 2024 12:47:59 +0000 [thread overview]
Message-ID: <Z0XDfyDWc3OZSoj0@redhat.com> (raw)
In-Reply-To: <87wmgqsbp1.fsf@pond.sub.org>
On Tue, Nov 26, 2024 at 08:20:42AM +0100, Markus Armbruster wrote:
> Jean-Philippe Brucker <jean-philippe@linaro.org> writes:
>
> > The Realm Personalization Value (RPV) is provided by the user to
> > distinguish Realms that have the same initial measurement.
> >
> > The user provides up to 64 hexadecimal bytes. They are stored into the
> > RPV in the same order, zero-padded on the right.
> >
> > Cc: Eric Blake <eblake@redhat.com>
> > Cc: Markus Armbruster <armbru@redhat.com>
> > Cc: Daniel P. Berrangé <berrange@redhat.com>
> > Cc: Eduardo Habkost <eduardo@habkost.net>
> > Acked-by: Markus Armbruster <armbru@redhat.com>
> > Signed-off-by: Jean-Philippe Brucker <jean-philippe@linaro.org>
> > ---
> > v2->v3: Fix documentation
> > ---
> > qapi/qom.json | 15 ++++++
> > target/arm/kvm-rme.c | 111 +++++++++++++++++++++++++++++++++++++++++++
> > 2 files changed, 126 insertions(+)
> >
> > diff --git a/qapi/qom.json b/qapi/qom.json
> > index a8beeabf1f..f982850bca 100644
> > --- a/qapi/qom.json
> > +++ b/qapi/qom.json
> > @@ -1068,6 +1068,19 @@
> > 'data': { '*cpu-affinity': ['uint16'],
> > '*node-affinity': ['uint16'] } }
> >
> > +##
> > +# @RmeGuestProperties:
> > +#
> > +# Properties for rme-guest objects.
> > +#
> > +# @personalization-value: Realm personalization value, as a 64-byte
> > +# hex string. This optional parameter allows to uniquely identify
> > +# the VM instance during attestation. (default: 0)
>
> QMP commonly uses base64 for encoding binary data. Any particular
> reason to deviate?
>
> Is the "hex string" to be mapped to binary in little or big endian? Not
> an issue with base64.
Agreed, using base64 is preferrable for consistency.
>
> Nitpick: (default: all-zero), please, for consistency with similar
> documentation in SevSnpGuestProperties.
>
> > +#
> > +# Since: 9.3
There is never any x.3 version of QEMU, as we bump the major
version once a year. IOW, next release you could target this
for will be 10.0
> > +##
> > +{ 'struct': 'RmeGuestProperties',
> > + 'data': { '*personalization-value': 'str' } }
> >
> > ##
> > # @ObjectType:
> > @@ -1121,6 +1134,7 @@
> > { 'name': 'pr-manager-helper',
> > 'if': 'CONFIG_LINUX' },
> > 'qtest',
> > + 'rme-guest',
> > 'rng-builtin',
> > 'rng-egd',
> > { 'name': 'rng-random',
>
> The commit message claims the patch adds a parameter. It actually adds
> an entire object type.
The object should be added to qom.json earlier in this series when
the RmeGuest class is defined, then this patch would merely be adding
the parameter.
>
> > @@ -1195,6 +1209,7 @@
> > 'pr-manager-helper': { 'type': 'PrManagerHelperProperties',
> > 'if': 'CONFIG_LINUX' },
> > 'qtest': 'QtestProperties',
> > + 'rme-guest': 'RmeGuestProperties',
> > 'rng-builtin': 'RngProperties',
> > 'rng-egd': 'RngEgdProperties',
> > 'rng-random': { 'type': 'RngRandomProperties',
With regards,
Daniel
--
|: https://berrange.com -o- https://www.flickr.com/photos/dberrange :|
|: https://libvirt.org -o- https://fstop138.berrange.com :|
|: https://entangle-photo.org -o- https://www.instagram.com/dberrange :|
next prev parent reply other threads:[~2024-11-26 12:48 UTC|newest]
Thread overview: 71+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-11-25 19:55 [PATCH v3 00/26] arm: Run Arm CCA VMs with KVM Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 01/26] kvm: Merge kvm_check_extension() and kvm_vm_check_extension() Jean-Philippe Brucker
2024-11-26 12:29 ` Daniel P. Berrangé
2024-12-04 19:07 ` Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 02/26] target/arm: Add confidential guest support Jean-Philippe Brucker
2024-11-26 12:37 ` Daniel P. Berrangé
2024-12-04 19:07 ` Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 03/26] target/arm/kvm: Return immediately on error in kvm_arch_init() Jean-Philippe Brucker
2024-12-05 21:47 ` Philippe Mathieu-Daudé
2024-12-10 19:06 ` Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 04/26] target/arm/kvm-rme: Initialize realm Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 05/26] target/arm/kvm: Split kvm_arch_get/put_registers Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 06/26] target/arm/kvm-rme: Initialize vCPU Jean-Philippe Brucker
2025-02-04 5:02 ` Gavin Shan
2025-02-07 15:56 ` Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 07/26] target/arm/kvm: Create scratch VM as Realm if necessary Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 08/26] hw/core/loader: Add ROM loader notifier Jean-Philippe Brucker
2024-12-05 21:59 ` Philippe Mathieu-Daudé
2024-12-10 19:07 ` Jean-Philippe Brucker
2025-02-04 5:33 ` Gavin Shan
2025-02-07 15:57 ` Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 09/26] target/arm/kvm-rme: Initialize Realm memory Jean-Philippe Brucker
2025-02-04 5:30 ` Gavin Shan
2025-02-07 15:59 ` Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 10/26] target/arm/kvm-rme: Add Realm Personalization Value parameter Jean-Philippe Brucker
2024-11-26 7:20 ` Markus Armbruster
2024-11-26 12:47 ` Daniel P. Berrangé [this message]
2024-12-04 19:11 ` Jean-Philippe Brucker
2024-12-04 19:10 ` Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 11/26] target/arm/kvm-rme: Add measurement algorithm property Jean-Philippe Brucker
2024-11-26 12:57 ` Daniel P. Berrangé
2024-11-26 15:11 ` Markus Armbruster
2024-11-26 15:17 ` Daniel P. Berrangé
2024-11-25 19:56 ` [PATCH v3 12/26] target/arm/cpu: Set number of breakpoints and watchpoints in KVM Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 13/26] target/arm/cpu: Set number of PMU counters " Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 14/26] target/arm/cpu: Inform about reading confidential CPU registers Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 15/26] hw/arm/virt: Add support for Arm RME Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 16/26] hw/arm/virt: Disable DTB randomness for confidential VMs Jean-Philippe Brucker
2024-12-05 22:03 ` Philippe Mathieu-Daudé
2024-11-25 19:56 ` [PATCH v3 17/26] hw/arm/virt: Reserve one bit of guest-physical address for RME Jean-Philippe Brucker
2024-12-13 12:03 ` Gavin Shan
2025-01-22 14:56 ` Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 18/26] hw/arm/boot: Mark all guest memory as RIPAS_RAM Jean-Philippe Brucker
2025-02-04 7:27 ` Gavin Shan
2025-02-07 16:02 ` Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 19/26] hw/arm/virt: Move virt_flash_create() to machvirt_init() Jean-Philippe Brucker
2024-11-25 19:56 ` [PATCH v3 20/26] hw/arm/virt: Use RAM instead of flash for confidential guest firmware Jean-Philippe Brucker
2024-11-25 19:56 ` [RFC PATCH v3 21/26] hw/arm/boot: Load DTB as is for confidential VMs Jean-Philippe Brucker
2024-11-25 19:56 ` [RFC PATCH v3 22/26] hw/arm/boot: Skip bootloader for confidential guests Jean-Philippe Brucker
2024-11-25 19:56 ` [RFC PATCH v3 23/26] hw/tpm: Add TPM event log Jean-Philippe Brucker
2024-12-05 22:13 ` Philippe Mathieu-Daudé
2024-12-09 22:34 ` Stefan Berger
2024-12-13 14:31 ` Jean-Philippe Brucker
2024-11-25 19:56 ` [RFC PATCH v3 24/26] hw/core/loader: Add fields to RomLoaderNotify Jean-Philippe Brucker
2024-12-05 22:21 ` Philippe Mathieu-Daudé
2024-12-10 19:04 ` Jean-Philippe Brucker
2024-11-25 19:56 ` [RFC PATCH v3 25/26] target/arm/kvm-rme: Add measurement log Jean-Philippe Brucker
2024-11-25 22:23 ` Stefan Berger
2024-11-26 13:45 ` Daniel P. Berrangé
2024-11-26 16:21 ` Jean-Philippe Brucker
2024-12-02 15:58 ` Stefan Berger
2024-12-05 12:33 ` Jean-Philippe Brucker
2024-12-09 20:22 ` Stefan Berger
2024-12-09 22:08 ` Stefan Berger
2024-12-13 14:21 ` Jean-Philippe Brucker
2024-12-13 16:51 ` Stefan Berger
2024-11-25 19:56 ` [RFC PATCH v3 26/26] hw/arm/virt: Add measurement log for confidential boot Jean-Philippe Brucker
2024-12-05 22:23 ` Philippe Mathieu-Daudé
2024-12-10 19:05 ` Jean-Philippe Brucker
2024-12-11 3:01 ` [PATCH v3 00/26] arm: Run Arm CCA VMs with KVM Gavin Shan
2024-12-11 8:01 ` Gavin Shan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Z0XDfyDWc3OZSoj0@redhat.com \
--to=berrange@redhat.com \
--cc=alex.bennee@linaro.org \
--cc=armbru@redhat.com \
--cc=eblake@redhat.com \
--cc=eduardo@habkost.net \
--cc=jean-philippe@linaro.org \
--cc=peter.maydell@linaro.org \
--cc=philmd@linaro.org \
--cc=qemu-arm@nongnu.org \
--cc=qemu-devel@nongnu.org \
--cc=richard.henderson@linaro.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.