From: Mathieu Poirier <mathieu.poirier@linaro.org>
To: berrange@redhat.com, kchamart@redhat.com,
pierrick.bouvier@oss.qualcomm.com, peter.maydell@linaro.org,
mst@redhat.com, cohuck@redhat.com, pbonzini@redhat.com,
eblake@redhat.com, armbru@redhat.com,
lorenzo.pieralisi@linaro.org, gshan@redhat.com,
enju.kohei@fujitsu.com
Cc: qemu-devel@nongnu.org, qemu-arm@nongnu.org, kvm@vger.kernel.org,
mathieu.poirier@linaro.org
Subject: [RFC v3 18/24] hw/arm/virt: Disable DTB randomness for confidential VMs
Date: Tue, 25 Aug 2026 16:00:55 -0600 [thread overview]
Message-ID: <20260825220101.3443954-19-mathieu.poirier@linaro.org> (raw)
In-Reply-To: <20260825220101.3443954-1-mathieu.poirier@linaro.org>
From: Jean-Philippe Brucker <jean-philippe@linaro.org>
The dtb-randomness feature, which adds random seeds to the DTB, isn't
really compatible with confidential VMs since it randomizes the Realm
Initial Measurement. Enabling it is not an error, but it prevents
attestation. It also isn't useful to a Realm, which doesn't trust host
input.
Currently the feature is automatically enabled, unless the user disables
it on the command-line. Change it to OnOffAuto, and automatically
disable it for confidential VMs, unless the user explicitly enables it.
Signed-off-by: Jean-Philippe Brucker <jean-philippe@linaro.org>
Signed-off-by: Mathieu Poirier <mathieu.poirier@linaro.org>
---
docs/system/arm/virt.rst | 9 +++++----
hw/arm/virt.c | 41 +++++++++++++++++++++++++---------------
include/hw/arm/virt.h | 2 +-
3 files changed, 32 insertions(+), 20 deletions(-)
diff --git a/docs/system/arm/virt.rst b/docs/system/arm/virt.rst
index f811e662d68d..faae97848d2e 100644
--- a/docs/system/arm/virt.rst
+++ b/docs/system/arm/virt.rst
@@ -237,10 +237,11 @@ dtb-randomness
rng-seed and kaslr-seed nodes (in both "/chosen" and
"/secure-chosen") to use for features like the random number
generator and address space randomisation. The default is
- ``on``. You will want to disable it if your trusted boot chain
- will verify the DTB it is passed, since this option causes the
- DTB to be non-deterministic. It would be the responsibility of
- the firmware to come up with a seed and pass it on if it wants to.
+ ``off`` for confidential VMs, and ``on`` otherwise. You will want
+ to disable it if your trusted boot chain will verify the DTB it is
+ passed, since this option causes the DTB to be non-deterministic.
+ It would be the responsibility of the firmware to come up with a
+ seed and pass it on if it wants to.
dtb-kaslr-seed
A deprecated synonym for dtb-randomness.
diff --git a/hw/arm/virt.c b/hw/arm/virt.c
index 2132e6595baf..c300224f19e7 100644
--- a/hw/arm/virt.c
+++ b/hw/arm/virt.c
@@ -394,6 +394,7 @@ static int gic_fdt_irq_type_spi(const VirtMachineState *vms)
static void create_fdt(VirtMachineState *vms)
{
+ bool dtb_randomness = true;
MachineState *ms = MACHINE(vms);
int nb_numa_nodes = ms->numa_state->num_nodes;
void *fdt = create_device_tree(&vms->fdt_size);
@@ -403,6 +404,16 @@ static void create_fdt(VirtMachineState *vms)
exit(1);
}
+ /*
+ * Including random data in the DTB causes random intial measurement on CCA,
+ * so disable it for confidential VMs.
+ */
+ if (vms->dtb_randomness == ON_OFF_AUTO_OFF ||
+ (vms->dtb_randomness == ON_OFF_AUTO_AUTO &&
+ virt_machine_is_confidential(vms))) {
+ dtb_randomness = false;
+ }
+
ms->fdt = fdt;
/* Header */
@@ -424,13 +435,13 @@ static void create_fdt(VirtMachineState *vms)
/* /chosen must exist for load_dtb to fill in necessary properties later */
qemu_fdt_add_subnode(fdt, "/chosen");
- if (vms->dtb_randomness) {
+ if (dtb_randomness) {
create_randomness(ms, "/chosen");
}
if (vms->secure) {
qemu_fdt_add_subnode(fdt, "/secure-chosen");
- if (vms->dtb_randomness) {
+ if (dtb_randomness) {
create_randomness(ms, "/secure-chosen");
}
}
@@ -3462,18 +3473,21 @@ static void virt_set_virtio_transports(Object *obj, Visitor *v,
vms->virtio_transports = transports;
}
-static bool virt_get_dtb_randomness(Object *obj, Error **errp)
+static void virt_get_dtb_randomness(Object *obj, Visitor *v, const char *name,
+ void *opaque, Error **errp)
{
VirtMachineState *vms = VIRT_MACHINE(obj);
+ OnOffAuto dtb_randomness = vms->dtb_randomness;
- return vms->dtb_randomness;
+ visit_type_OnOffAuto(v, name, &dtb_randomness, errp);
}
-static void virt_set_dtb_randomness(Object *obj, bool value, Error **errp)
+static void virt_set_dtb_randomness(Object *obj, Visitor *v, const char *name,
+ void *opaque, Error **errp)
{
VirtMachineState *vms = VIRT_MACHINE(obj);
- vms->dtb_randomness = value;
+ visit_type_OnOffAuto(v, name, &vms->dtb_randomness, errp);
}
static char *virt_get_oem_id(Object *obj, Error **errp)
@@ -4260,16 +4274,16 @@ static void virt_machine_class_init(ObjectClass *oc, const void *data)
"Set MSI settings. "
"Valid values are auto, gicv2m, its and off");
- object_class_property_add_bool(oc, "dtb-randomness",
- virt_get_dtb_randomness,
- virt_set_dtb_randomness);
+ object_class_property_add(oc, "dtb-randomness", "OnOffAuto",
+ virt_get_dtb_randomness, virt_set_dtb_randomness,
+ NULL, NULL);
object_class_property_set_description(oc, "dtb-randomness",
"Set off to disable passing random or "
"non-deterministic dtb nodes to guest");
- object_class_property_add_bool(oc, "dtb-kaslr-seed",
- virt_get_dtb_randomness,
- virt_set_dtb_randomness);
+ object_class_property_add(oc, "dtb-kaslr-seed", "OnOffAuto",
+ virt_get_dtb_randomness, virt_set_dtb_randomness,
+ NULL, NULL);
object_class_property_set_description(oc, "dtb-kaslr-seed",
"Deprecated synonym of dtb-randomness");
@@ -4332,9 +4346,6 @@ static void virt_instance_init(Object *obj)
/* MTE is disabled by default. */
vms->mte = false;
- /* Supply kaslr-seed and rng-seed by default */
- vms->dtb_randomness = true;
-
vms->irqmap = a15irqmap;
vms->virtio_transports = NUM_VIRTIO_TRANSPORTS;
diff --git a/include/hw/arm/virt.h b/include/hw/arm/virt.h
index 3ba33b4bd274..ef9fe3238022 100644
--- a/include/hw/arm/virt.h
+++ b/include/hw/arm/virt.h
@@ -173,7 +173,7 @@ struct VirtMachineState {
bool virt;
bool ras;
bool mte;
- bool dtb_randomness;
+ OnOffAuto dtb_randomness;
bool second_ns_uart_present;
OnOffAuto acpi;
VirtGICType gic_version;
--
2.43.0
next prev parent reply other threads:[~2026-08-25 22:01 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 22:00 [RFC v3 00/24] Add Realm support to QEMU-VMM Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 01/24] linux-headers: Add RME related definitions Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 02/24] target/arm/kvm: Return immediately on error in kvm_arch_init() Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 03/24] target/arm: Add confidential guest support Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 04/24] target/arm/kvm-rme: Add mechanic to initialize realms Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 05/24] target/arm/kvm: Split kvm_arch_get/put_registers Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 06/24] target/arm/kvm-rme: Initialize vCPU Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 07/24] target/arm/kvm: Create scratch Realm VM when requested Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 08/24] target/arm/kvm: Use kvm_vm_check_extension() where necessary Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 09/24] hw/core/loader: Add a ROM loader notifier Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 10/24] target/arm/kvm-rme: Keep track of images loaded in Realm memory Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 11/24] target/arm/kvm-rme: Populate Realm with runtime images Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 12/24] target/arm/cpu: Set number of breakpoints and watchpoints in KVM Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 13/24] target/arm/cpu: Set number of PMU counters " Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 14/24] target/arm/cpu: Don't read Realm registers Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 15/24] hw/arm/virt: Set proper conduit method for Realms Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 16/24] hw/arm/virt: Embed Realm VM type with IPA address space Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 17/24] hw/arm/virt: Reserve one bit of guest physical address for RME Mathieu Poirier
2026-08-25 22:00 ` Mathieu Poirier [this message]
2026-08-25 22:00 ` [RFC v3 19/24] hw/arm/virt: Move virt_flash_create() to machvirt_init() Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 20/24] hw/arm/virt: Use RAM instead of flash for confidential guest firmware Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 21/24] target/arm/kvm-rme: Add DMA remapping for the shared memory region Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 22/24] docs/interop/firmware.json: Add arm-rme firmware feature Mathieu Poirier
2026-08-25 22:01 ` [RFC v3 23/24] hw/arm/boot: Load DTB as is for confidential VMs Mathieu Poirier
2026-08-25 22:01 ` [RFC v3 24/24] hw/arm/boot: Skip bootloader for confidential guests Mathieu Poirier
2026-08-27 13:06 ` [RFC v3 00/24] Add Realm support to QEMU-VMM Daniel P. Berrangé
2026-08-27 13:28 ` Lorenzo Pieralisi
2026-09-01 13:20 ` Markus Armbruster
2026-09-02 15:45 ` Mathieu Poirier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260825220101.3443954-19-mathieu.poirier@linaro.org \
--to=mathieu.poirier@linaro.org \
--cc=armbru@redhat.com \
--cc=berrange@redhat.com \
--cc=cohuck@redhat.com \
--cc=eblake@redhat.com \
--cc=enju.kohei@fujitsu.com \
--cc=gshan@redhat.com \
--cc=kchamart@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=lorenzo.pieralisi@linaro.org \
--cc=mst@redhat.com \
--cc=pbonzini@redhat.com \
--cc=peter.maydell@linaro.org \
--cc=pierrick.bouvier@oss.qualcomm.com \
--cc=qemu-arm@nongnu.org \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox