From: Mathieu Poirier <mathieu.poirier@linaro.org>
To: berrange@redhat.com, kchamart@redhat.com,
pierrick.bouvier@oss.qualcomm.com, peter.maydell@linaro.org,
mst@redhat.com, cohuck@redhat.com, pbonzini@redhat.com,
eblake@redhat.com, armbru@redhat.com,
lorenzo.pieralisi@linaro.org, gshan@redhat.com,
enju.kohei@fujitsu.com
Cc: qemu-devel@nongnu.org, qemu-arm@nongnu.org, kvm@vger.kernel.org,
mathieu.poirier@linaro.org
Subject: [RFC v3 03/24] target/arm: Add confidential guest support
Date: Tue, 25 Aug 2026 16:00:40 -0600 [thread overview]
Message-ID: <20260825220101.3443954-4-mathieu.poirier@linaro.org> (raw)
In-Reply-To: <20260825220101.3443954-1-mathieu.poirier@linaro.org>
From: Jean-Philippe Brucker <jean-philippe@linaro.org>
Add a new RmeGuest object, inheriting from ConfidentialGuestSupport, to
support the Arm Realm Management Extension (RME). It is instantiated by
passing on the command-line:
-M virt,confidential-guest-support=<id>
-object rme-guest,id=<id>
This is only the skeleton. Support will be added in following patches.
Signed-off-by: Jean-Philippe Brucker <jean-philippe@linaro.org>
Signed-off-by: Mathieu Poirier <mathieu.poirier@linaro.org>
---
docs/system/confidential-guest-support.rst | 1 +
qapi/qom.json | 13 +++++++
target/arm/kvm-rme.c | 42 ++++++++++++++++++++++
target/arm/meson.build | 5 ++-
4 files changed, 60 insertions(+), 1 deletion(-)
create mode 100644 target/arm/kvm-rme.c
diff --git a/docs/system/confidential-guest-support.rst b/docs/system/confidential-guest-support.rst
index 562a7c3c2852..abb56923ad13 100644
--- a/docs/system/confidential-guest-support.rst
+++ b/docs/system/confidential-guest-support.rst
@@ -42,5 +42,6 @@ Currently supported confidential guest mechanisms are:
* POWER Protected Execution Facility (PEF) (see :ref:`power-papr-protected-execution-facility-pef`)
* s390x Protected Virtualization (PV) (see :doc:`s390x/protvirt`)
* AWS Nitro Enclaves (see :doc:`nitro`)
+* Arm Realm Management Extension (RME)
Other mechanisms may be supported in future.
diff --git a/qapi/qom.json b/qapi/qom.json
index 037c07879986..edc902c88c36 100644
--- a/qapi/qom.json
+++ b/qapi/qom.json
@@ -1216,6 +1216,17 @@
'data': { '*cpu-affinity': ['uint16'],
'*node-affinity': ['uint16'] } }
+##
+# @RmeGuestProperties:
+#
+# Properties for rme-guest objects.
+#
+# Since: 11.0
+##
+{ 'struct': 'RmeGuestProperties',
+ 'base': 'ConfidentialGuestSupportProperties',
+ 'data': {} }
+
##
# @ObjectType:
#
@@ -1272,6 +1283,7 @@
{ 'name': 'pr-manager-helper',
'if': 'CONFIG_LINUX' },
'qtest',
+ 'rme-guest',
'rng-builtin',
'rng-egd',
{ 'name': 'rng-random',
@@ -1351,6 +1363,7 @@
'pr-manager-helper': { 'type': 'PrManagerHelperProperties',
'if': 'CONFIG_LINUX' },
'qtest': 'QtestProperties',
+ 'rme-guest': 'RmeGuestProperties',
'rng-builtin': 'RngProperties',
'rng-egd': 'RngEgdProperties',
'rng-random': { 'type': 'RngRandomProperties',
diff --git a/target/arm/kvm-rme.c b/target/arm/kvm-rme.c
new file mode 100644
index 000000000000..42e1d1e7b859
--- /dev/null
+++ b/target/arm/kvm-rme.c
@@ -0,0 +1,42 @@
+/*
+ * QEMU Arm RME support
+ *
+ * SPDX-License-Identifier: GPL-2.0-or-later
+ *
+ * Copyright Linaro 2026
+ */
+
+#include "qemu/osdep.h"
+
+#include "hw/core/boards.h"
+#include "hw/core/cpu.h"
+#include "kvm_arm.h"
+#include "migration/blocker.h"
+#include "qapi/error.h"
+#include "qom/object_interfaces.h"
+#include "system/confidential-guest-support.h"
+#include "system/kvm.h"
+#include "system/runstate.h"
+
+#define TYPE_RME_GUEST "rme-guest"
+OBJECT_DECLARE_SIMPLE_TYPE(RmeGuest, RME_GUEST)
+
+struct RmeGuest {
+ ConfidentialGuestSupport parent_obj;
+};
+
+OBJECT_DEFINE_SIMPLE_TYPE_WITH_INTERFACES(RmeGuest, rme_guest, RME_GUEST,
+ CONFIDENTIAL_GUEST_SUPPORT,
+ { TYPE_USER_CREATABLE }, { })
+
+static void rme_guest_class_init(ObjectClass *oc, const void *data)
+{
+}
+
+static void rme_guest_init(Object *obj)
+{
+}
+
+static void rme_guest_finalize(Object *obj)
+{
+}
diff --git a/target/arm/meson.build b/target/arm/meson.build
index 4723f9f170ad..544df5c84d79 100644
--- a/target/arm/meson.build
+++ b/target/arm/meson.build
@@ -20,7 +20,10 @@ arm_common_ss.add(files(
arm_common_system_ss.add(files(
'arm-qmp-cmds.c',
))
-arm_system_ss.add(when: 'CONFIG_KVM', if_true: files('hyp_gdbstub.c', 'kvm.c'))
+arm_system_ss.add(when: 'CONFIG_KVM', if_true: files(
+ 'hyp_gdbstub.c',
+ 'kvm.c',
+ 'kvm-rme.c'))
arm_system_ss.add(when: 'CONFIG_HVF', if_true: files('hyp_gdbstub.c'))
arm_user_ss.add(files('cpu.c'))
--
2.43.0
next prev parent reply other threads:[~2026-08-25 22:01 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 22:00 [RFC v3 00/24] Add Realm support to QEMU-VMM Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 01/24] linux-headers: Add RME related definitions Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 02/24] target/arm/kvm: Return immediately on error in kvm_arch_init() Mathieu Poirier
2026-08-25 22:00 ` Mathieu Poirier [this message]
2026-08-25 22:00 ` [RFC v3 04/24] target/arm/kvm-rme: Add mechanic to initialize realms Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 05/24] target/arm/kvm: Split kvm_arch_get/put_registers Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 06/24] target/arm/kvm-rme: Initialize vCPU Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 07/24] target/arm/kvm: Create scratch Realm VM when requested Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 08/24] target/arm/kvm: Use kvm_vm_check_extension() where necessary Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 09/24] hw/core/loader: Add a ROM loader notifier Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 10/24] target/arm/kvm-rme: Keep track of images loaded in Realm memory Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 11/24] target/arm/kvm-rme: Populate Realm with runtime images Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 12/24] target/arm/cpu: Set number of breakpoints and watchpoints in KVM Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 13/24] target/arm/cpu: Set number of PMU counters " Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 14/24] target/arm/cpu: Don't read Realm registers Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 15/24] hw/arm/virt: Set proper conduit method for Realms Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 16/24] hw/arm/virt: Embed Realm VM type with IPA address space Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 17/24] hw/arm/virt: Reserve one bit of guest physical address for RME Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 18/24] hw/arm/virt: Disable DTB randomness for confidential VMs Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 19/24] hw/arm/virt: Move virt_flash_create() to machvirt_init() Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 20/24] hw/arm/virt: Use RAM instead of flash for confidential guest firmware Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 21/24] target/arm/kvm-rme: Add DMA remapping for the shared memory region Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 22/24] docs/interop/firmware.json: Add arm-rme firmware feature Mathieu Poirier
2026-08-25 22:01 ` [RFC v3 23/24] hw/arm/boot: Load DTB as is for confidential VMs Mathieu Poirier
2026-08-25 22:01 ` [RFC v3 24/24] hw/arm/boot: Skip bootloader for confidential guests Mathieu Poirier
2026-08-27 13:06 ` [RFC v3 00/24] Add Realm support to QEMU-VMM Daniel P. Berrangé
2026-08-27 13:28 ` Lorenzo Pieralisi
2026-09-01 13:20 ` Markus Armbruster
2026-09-02 15:45 ` Mathieu Poirier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260825220101.3443954-4-mathieu.poirier@linaro.org \
--to=mathieu.poirier@linaro.org \
--cc=armbru@redhat.com \
--cc=berrange@redhat.com \
--cc=cohuck@redhat.com \
--cc=eblake@redhat.com \
--cc=enju.kohei@fujitsu.com \
--cc=gshan@redhat.com \
--cc=kchamart@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=lorenzo.pieralisi@linaro.org \
--cc=mst@redhat.com \
--cc=pbonzini@redhat.com \
--cc=peter.maydell@linaro.org \
--cc=pierrick.bouvier@oss.qualcomm.com \
--cc=qemu-arm@nongnu.org \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox