Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Mathieu Poirier <mathieu.poirier@linaro.org>
To: berrange@redhat.com, kchamart@redhat.com,
	pierrick.bouvier@oss.qualcomm.com, peter.maydell@linaro.org,
	mst@redhat.com, cohuck@redhat.com, pbonzini@redhat.com,
	eblake@redhat.com, armbru@redhat.com,
	lorenzo.pieralisi@linaro.org, gshan@redhat.com,
	enju.kohei@fujitsu.com
Cc: qemu-devel@nongnu.org, qemu-arm@nongnu.org, kvm@vger.kernel.org,
	mathieu.poirier@linaro.org
Subject: [RFC v3 03/24] target/arm: Add confidential guest support
Date: Tue, 25 Aug 2026 16:00:40 -0600	[thread overview]
Message-ID: <20260825220101.3443954-4-mathieu.poirier@linaro.org> (raw)
In-Reply-To: <20260825220101.3443954-1-mathieu.poirier@linaro.org>

From: Jean-Philippe Brucker <jean-philippe@linaro.org>

Add a new RmeGuest object, inheriting from ConfidentialGuestSupport, to
support the Arm Realm Management Extension (RME). It is instantiated by
passing on the command-line:

  -M virt,confidential-guest-support=<id>
  -object rme-guest,id=<id>

This is only the skeleton. Support will be added in following patches.

Signed-off-by: Jean-Philippe Brucker <jean-philippe@linaro.org>
Signed-off-by: Mathieu Poirier <mathieu.poirier@linaro.org>
---
 docs/system/confidential-guest-support.rst |  1 +
 qapi/qom.json                              | 13 +++++++
 target/arm/kvm-rme.c                       | 42 ++++++++++++++++++++++
 target/arm/meson.build                     |  5 ++-
 4 files changed, 60 insertions(+), 1 deletion(-)
 create mode 100644 target/arm/kvm-rme.c

diff --git a/docs/system/confidential-guest-support.rst b/docs/system/confidential-guest-support.rst
index 562a7c3c2852..abb56923ad13 100644
--- a/docs/system/confidential-guest-support.rst
+++ b/docs/system/confidential-guest-support.rst
@@ -42,5 +42,6 @@ Currently supported confidential guest mechanisms are:
 * POWER Protected Execution Facility (PEF) (see :ref:`power-papr-protected-execution-facility-pef`)
 * s390x Protected Virtualization (PV) (see :doc:`s390x/protvirt`)
 * AWS Nitro Enclaves (see :doc:`nitro`)
+* Arm Realm Management Extension (RME)
 
 Other mechanisms may be supported in future.
diff --git a/qapi/qom.json b/qapi/qom.json
index 037c07879986..edc902c88c36 100644
--- a/qapi/qom.json
+++ b/qapi/qom.json
@@ -1216,6 +1216,17 @@
   'data': { '*cpu-affinity': ['uint16'],
             '*node-affinity': ['uint16'] } }
 
+##
+# @RmeGuestProperties:
+#
+# Properties for rme-guest objects.
+#
+# Since: 11.0
+##
+{ 'struct': 'RmeGuestProperties',
+  'base': 'ConfidentialGuestSupportProperties',
+  'data': {} }
+
 ##
 # @ObjectType:
 #
@@ -1272,6 +1283,7 @@
     { 'name': 'pr-manager-helper',
       'if': 'CONFIG_LINUX' },
     'qtest',
+    'rme-guest',
     'rng-builtin',
     'rng-egd',
     { 'name': 'rng-random',
@@ -1351,6 +1363,7 @@
       'pr-manager-helper':          { 'type': 'PrManagerHelperProperties',
                                       'if': 'CONFIG_LINUX' },
       'qtest':                      'QtestProperties',
+      'rme-guest':                  'RmeGuestProperties',
       'rng-builtin':                'RngProperties',
       'rng-egd':                    'RngEgdProperties',
       'rng-random':                 { 'type': 'RngRandomProperties',
diff --git a/target/arm/kvm-rme.c b/target/arm/kvm-rme.c
new file mode 100644
index 000000000000..42e1d1e7b859
--- /dev/null
+++ b/target/arm/kvm-rme.c
@@ -0,0 +1,42 @@
+/*
+ * QEMU Arm RME support
+ *
+ * SPDX-License-Identifier: GPL-2.0-or-later
+ *
+ * Copyright Linaro 2026
+ */
+
+#include "qemu/osdep.h"
+
+#include "hw/core/boards.h"
+#include "hw/core/cpu.h"
+#include "kvm_arm.h"
+#include "migration/blocker.h"
+#include "qapi/error.h"
+#include "qom/object_interfaces.h"
+#include "system/confidential-guest-support.h"
+#include "system/kvm.h"
+#include "system/runstate.h"
+
+#define TYPE_RME_GUEST "rme-guest"
+OBJECT_DECLARE_SIMPLE_TYPE(RmeGuest, RME_GUEST)
+
+struct RmeGuest {
+    ConfidentialGuestSupport parent_obj;
+};
+
+OBJECT_DEFINE_SIMPLE_TYPE_WITH_INTERFACES(RmeGuest, rme_guest, RME_GUEST,
+                                          CONFIDENTIAL_GUEST_SUPPORT,
+                                          { TYPE_USER_CREATABLE }, { })
+
+static void rme_guest_class_init(ObjectClass *oc, const void *data)
+{
+}
+
+static void rme_guest_init(Object *obj)
+{
+}
+
+static void rme_guest_finalize(Object *obj)
+{
+}
diff --git a/target/arm/meson.build b/target/arm/meson.build
index 4723f9f170ad..544df5c84d79 100644
--- a/target/arm/meson.build
+++ b/target/arm/meson.build
@@ -20,7 +20,10 @@ arm_common_ss.add(files(
 arm_common_system_ss.add(files(
   'arm-qmp-cmds.c',
 ))
-arm_system_ss.add(when: 'CONFIG_KVM', if_true: files('hyp_gdbstub.c', 'kvm.c'))
+arm_system_ss.add(when: 'CONFIG_KVM', if_true: files(
+  'hyp_gdbstub.c',
+  'kvm.c',
+  'kvm-rme.c'))
 arm_system_ss.add(when: 'CONFIG_HVF', if_true: files('hyp_gdbstub.c'))
 
 arm_user_ss.add(files('cpu.c'))
-- 
2.43.0


  parent reply	other threads:[~2026-08-25 22:01 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-25 22:00 [RFC v3 00/24] Add Realm support to QEMU-VMM Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 01/24] linux-headers: Add RME related definitions Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 02/24] target/arm/kvm: Return immediately on error in kvm_arch_init() Mathieu Poirier
2026-08-25 22:00 ` Mathieu Poirier [this message]
2026-08-25 22:00 ` [RFC v3 04/24] target/arm/kvm-rme: Add mechanic to initialize realms Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 05/24] target/arm/kvm: Split kvm_arch_get/put_registers Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 06/24] target/arm/kvm-rme: Initialize vCPU Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 07/24] target/arm/kvm: Create scratch Realm VM when requested Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 08/24] target/arm/kvm: Use kvm_vm_check_extension() where necessary Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 09/24] hw/core/loader: Add a ROM loader notifier Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 10/24] target/arm/kvm-rme: Keep track of images loaded in Realm memory Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 11/24] target/arm/kvm-rme: Populate Realm with runtime images Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 12/24] target/arm/cpu: Set number of breakpoints and watchpoints in KVM Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 13/24] target/arm/cpu: Set number of PMU counters " Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 14/24] target/arm/cpu: Don't read Realm registers Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 15/24] hw/arm/virt: Set proper conduit method for Realms Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 16/24] hw/arm/virt: Embed Realm VM type with IPA address space Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 17/24] hw/arm/virt: Reserve one bit of guest physical address for RME Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 18/24] hw/arm/virt: Disable DTB randomness for confidential VMs Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 19/24] hw/arm/virt: Move virt_flash_create() to machvirt_init() Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 20/24] hw/arm/virt: Use RAM instead of flash for confidential guest firmware Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 21/24] target/arm/kvm-rme: Add DMA remapping for the shared memory region Mathieu Poirier
2026-08-25 22:00 ` [RFC v3 22/24] docs/interop/firmware.json: Add arm-rme firmware feature Mathieu Poirier
2026-08-25 22:01 ` [RFC v3 23/24] hw/arm/boot: Load DTB as is for confidential VMs Mathieu Poirier
2026-08-25 22:01 ` [RFC v3 24/24] hw/arm/boot: Skip bootloader for confidential guests Mathieu Poirier
2026-08-27 13:06 ` [RFC v3 00/24] Add Realm support to QEMU-VMM Daniel P. Berrangé
2026-08-27 13:28   ` Lorenzo Pieralisi
2026-09-01 13:20 ` Markus Armbruster
2026-09-02 15:45   ` Mathieu Poirier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260825220101.3443954-4-mathieu.poirier@linaro.org \
    --to=mathieu.poirier@linaro.org \
    --cc=armbru@redhat.com \
    --cc=berrange@redhat.com \
    --cc=cohuck@redhat.com \
    --cc=eblake@redhat.com \
    --cc=enju.kohei@fujitsu.com \
    --cc=gshan@redhat.com \
    --cc=kchamart@redhat.com \
    --cc=kvm@vger.kernel.org \
    --cc=lorenzo.pieralisi@linaro.org \
    --cc=mst@redhat.com \
    --cc=pbonzini@redhat.com \
    --cc=peter.maydell@linaro.org \
    --cc=pierrick.bouvier@oss.qualcomm.com \
    --cc=qemu-arm@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox