All of lore.kernel.org
 help / color / mirror / Atom feed
From: Luigi Leonardi <leonardi@redhat.com>
To: Stefano Garzarella <sgarzare@redhat.com>
Cc: qemu-devel@nongnu.org, Gerd Hoffmann <kraxel@redhat.com>,
	 Ani Sinha <anisinha@redhat.com>,
	Paolo Bonzini <pbonzini@redhat.com>,
	 Zhao Liu <zhao1.liu@intel.com>,
	Marcelo Tosatti <mtosatti@redhat.com>,
	kvm@vger.kernel.org
Subject: Re: [PATCH 2/4] igvm: move set_id_block call into the SNP ID block directive handler
Date: Thu, 3 Sep 2026 15:29:35 +0200	[thread overview]
Message-ID: <aplyuTrLtvtrT0Kb@leonardi-redhat> (raw)
In-Reply-To: <aplM8ZVCrsjuELHT@sgarzare-redhat>

On Thu, Sep 03, 2026 at 02:57:44PM +0200, Stefano Garzarella wrote:
>On Tue, Sep 01, 2026 at 12:09:19PM +0200, Luigi Leonardi wrote:
>>set_id_block only makes sense when the IGVM file contains an
>>IGVM_VHT_SNP_ID_BLOCK directive. Move the call from the removed
>>qigvm_handle_policy into qigvm_directive_snp_id_block, where the ID
>>block and ID auth are populated. This avoids a no-op call to
>>set_id_block when no ID block is present.
>>
>>The ID block embeds the guest policy, so the policy must be known by the
>>time the directive is handled. Process the initialization section (which
>>carries the GUEST_POLICY header) before the directive section, and
>>copy ctx->sev_policy into the ID block in the directive handler.
>>
>>Signed-off-by: Luigi Leonardi <leonardi@redhat.com>
>>---
>>backends/igvm.c | 81 +++++++++++++++++++++++++++------------------------------
>>1 file changed, 38 insertions(+), 43 deletions(-)
>>
>>diff --git a/backends/igvm.c b/backends/igvm.c
>>index 85de0d54ec..6545382546 100644
>>--- a/backends/igvm.c
>>+++ b/backends/igvm.c
>>@@ -778,6 +778,8 @@ static int qigvm_directive_snp_id_block(QIgvm *ctx, const uint8_t *header_data,
>>    ctx->id_block->version = IGVM_SEV_ID_BLOCK_VERSION;
>>    memcpy(ctx->id_block->ld, igvm_id->ld, sizeof(ctx->id_block->ld));
>>
>>+    ctx->id_block->policy = ctx->sev_policy;
>
>Is it fine to copy the sev_policy in the id_block in any case?
>
>I mean, what happen if IGVM_VHT_GUEST_POLICY is not in the IGVM file, 
>so IIUC sev_policy is 0, but the user set the policy by the CLI?
>
>Maybe this was pre-existing and handled in the next patches.

This is a very good question: id block per snp spec *requires* a policy
to be set. So can we consider an IGVM file that contains a id block directive
but not guest policy to be valid? If so, I need to modify the code and read
the policy from `kvm_start_conf` with a new callback.

Luigi


  reply	other threads:[~2026-09-03 13:29 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-01 10:09 [PATCH 0/4] igvm/sev: apply the IGVM guest policy before launch Luigi Leonardi
2026-09-01 10:09 ` [PATCH 1/4] sev: rename set_guest_policy to set_id_block and remove dead policy code Luigi Leonardi
2026-09-03  8:47   ` Ani Sinha
2026-09-03 10:32   ` Stefano Garzarella
2026-09-03 10:47     ` Luigi Leonardi
2026-09-03 13:55       ` Stefano Garzarella
2026-09-04  5:29         ` Gerd Hoffmann
2026-09-01 10:09 ` [PATCH 2/4] igvm: move set_id_block call into the SNP ID block directive handler Luigi Leonardi
2026-09-03 12:57   ` Stefano Garzarella
2026-09-03 13:29     ` Luigi Leonardi [this message]
2026-09-03 15:53       ` Stefano Garzarella
2026-09-01 10:09 ` [PATCH 3/4] i386/sev: convert the guest policy properties to custom accessors Luigi Leonardi
2026-09-03  8:46   ` Ani Sinha
2026-09-01 10:09 ` [PATCH 4/4] igvm/sev: forward the IGVM guest policy to the platform before launch Luigi Leonardi
2026-09-03  8:46   ` Ani Sinha
2026-09-03  9:01     ` Luigi Leonardi
2026-09-03 10:03       ` Ani Sinha
2026-09-03 11:02         ` Luigi Leonardi
2026-09-03 11:34           ` Ani Sinha
2026-09-03 11:50           ` Daniel P. Berrangé
2026-09-03 13:28             ` Stefano Garzarella
2026-09-03 13:40               ` Luigi Leonardi
2026-09-04  5:45                 ` Gerd Hoffmann
2026-09-03 13:14   ` Stefano Garzarella

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aplyuTrLtvtrT0Kb@leonardi-redhat \
    --to=leonardi@redhat.com \
    --cc=anisinha@redhat.com \
    --cc=kraxel@redhat.com \
    --cc=kvm@vger.kernel.org \
    --cc=mtosatti@redhat.com \
    --cc=pbonzini@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=sgarzare@redhat.com \
    --cc=zhao1.liu@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.