Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Mathieu Poirier <mathieu.poirier@linaro.org>
To: Kohei Enju <enju.kohei@fujitsu.com>
Cc: Lorenzo Pieralisi <lpieralisi@kernel.org>,
	Michael Roth <michael.roth@amd.com>,
	berrange@redhat.com, kchamart@redhat.com,
	pierrick.bouvier@oss.qualcomm.com, peter.maydell@linaro.org,
	mst@redhat.com, cohuck@redhat.com, pbonzini@redhat.com,
	eblake@redhat.com, armbru@redhat.com,
	lorenzo.pieralisi@linaro.org, gshan@redhat.com,
	qemu-devel@nongnu.org, qemu-arm@nongnu.org, kvm@vger.kernel.org
Subject: Re: [RFC v4 03/24] target/arm: Add confidential guest support
Date: Wed, 30 Sep 2026 15:28:14 -0600	[thread overview]
Message-ID: <ar1-7iyCq8Re3htU@p14s> (raw)
In-Reply-To: <arSTQQ5uB6oR-vFe@FCCLS0092175.localdomain>

On Thu, Sep 24, 2026 at 12:12:35PM +0900, Kohei Enju wrote:
> On 09/22 10:01, Lorenzo Pieralisi wrote:
> > On Tue, Sep 15, 2026 at 04:27:21PM -0500, Michael Roth wrote:
> > > On Thu, Sep 03, 2026 at 01:35:50PM -0600, Mathieu Poirier wrote:
> > > > From: Jean-Philippe Brucker <jean-philippe@linaro.org>
> > > > 
> > > > Add a new RmeGuest object, inheriting from ConfidentialGuestSupport, to
> > > > support the Arm Realm Management Extension (RME). It is instantiated by
> > > > passing on the command-line:
> > > > 
> > > >   -M virt,confidential-guest-support=<id>
> > > >   -object rme-guest,id=<id>
> > > > 
> > > > This is only the skeleton. Support will be added in following patches.
> > > > 
> > > > Signed-off-by: Jean-Philippe Brucker <jean-philippe@linaro.org>
> > > > Signed-off-by: Mathieu Poirier <mathieu.poirier@linaro.org>
> > > > ---
> > > >  docs/system/confidential-guest-support.rst |  1 +
> > > >  qapi/qom.json                              | 13 +++++++
> > > >  target/arm/kvm-rme.c                       | 42 ++++++++++++++++++++++
> > > >  target/arm/meson.build                     |  5 ++-
> > > >  4 files changed, 60 insertions(+), 1 deletion(-)
> > > >  create mode 100644 target/arm/kvm-rme.c
> > > > 
> > > > diff --git a/docs/system/confidential-guest-support.rst b/docs/system/confidential-guest-support.rst
> > > > index 562a7c3c2852..abb56923ad13 100644
> > > > --- a/docs/system/confidential-guest-support.rst
> > > > +++ b/docs/system/confidential-guest-support.rst
> > > > @@ -42,5 +42,6 @@ Currently supported confidential guest mechanisms are:
> > > >  * POWER Protected Execution Facility (PEF) (see :ref:`power-papr-protected-execution-facility-pef`)
> > > >  * s390x Protected Virtualization (PV) (see :doc:`s390x/protvirt`)
> > > >  * AWS Nitro Enclaves (see :doc:`nitro`)
> > > > +* Arm Realm Management Extension (RME)
> > > >  
> > > >  Other mechanisms may be supported in future.
> > > > diff --git a/qapi/qom.json b/qapi/qom.json
> > > > index 776b13027fd8..52997c29a32d 100644
> > > > --- a/qapi/qom.json
> > > > +++ b/qapi/qom.json
> > > > @@ -1288,6 +1288,17 @@
> > > >    'data': { '*pretty': 'bool',
> > > >              '*close-action': 'MonitorQMPCloseAction' } }
> > > >  
> > > > +##
> > > > +# @RmeGuestProperties:
> > > > +#
> > > > +# Properties for rme-guest objects.
> > > > +#
> > > > +# Since: 11.1
> > > > +##
> > > > +{ 'struct': 'RmeGuestProperties',
> > > > +  'base': 'ConfidentialGuestSupportProperties',
> > > 
> > > Just FYI, based on input from Markus I'm planning to drop this
> > > ConfidentialGuestSupportProperties base type from my series
> > > since it's probably only SNP/TDX that need to be able to switch
> > > it on/off, whereas this series appears to use/require it from
> > > the start.
> > > 
> > > I'm not exactly sure what it will look like for v3 yet, but if you
> > > were based on v2 you'd instead probably just do the following in the
> > > instance_init function for your rme-guest instance:
> > > 
> > >   cgs->allow_convert_in_place = true;
> > >   cgs->convert_in_place = true;
> > > 
> > > rather than exposing it as a cmdline option.
> > 
> > Yep, it won't be an option for CCA Realms anyway since that will be
> > the baseline.
> 
> IIUC, in-place conversion requires RAM backed by a shared/mappable
> guest_memfd. If in-place conversion is always enabled for CCA Realms,
> could QEMU also select the equivalent of
> 
>   -object memory-backend-guest-memfd,id=ram0,size=...,share=on
> 
> automatically for the default RAM, so that specifying the RAM size with
> `-m` is sufficient?
>

I'm almost done crafting a new revision that will be based on V20 of the KVM
patchset.  I will look into your request for the revision after this one.
 
> Thanks,
> Kohei
> 
> > 
> > Thanks,
> > Lorenzo
> > 
> > > Thanks,
> > > 
> > > Mike
> > > 
> > > > +  'data': {} }
> > > > +
> > > >  ##
> > > >  # @ObjectType:
> > > >  #
> > > > @@ -1346,6 +1357,7 @@
> > > >      { 'name': 'pr-manager-helper',
> > > >        'if': 'CONFIG_LINUX' },
> > > >      'qtest',
> > > > +    'rme-guest',
> > > >      'rng-builtin',
> > > >      'rng-egd',
> > > >      { 'name': 'rng-random',
> > > > @@ -1427,6 +1439,7 @@
> > > >        'pr-manager-helper':          { 'type': 'PrManagerHelperProperties',
> > > >                                        'if': 'CONFIG_LINUX' },
> > > >        'qtest':                      'QtestProperties',
> > > > +      'rme-guest':                  'RmeGuestProperties',
> > > >        'rng-builtin':                'RngProperties',
> > > >        'rng-egd':                    'RngEgdProperties',
> > > >        'rng-random':                 { 'type': 'RngRandomProperties',
> > > > diff --git a/target/arm/kvm-rme.c b/target/arm/kvm-rme.c
> > > > new file mode 100644
> > > > index 000000000000..42e1d1e7b859
> > > > --- /dev/null
> > > > +++ b/target/arm/kvm-rme.c
> > > > @@ -0,0 +1,42 @@
> > > > +/*
> > > > + * QEMU Arm RME support
> > > > + *
> > > > + * SPDX-License-Identifier: GPL-2.0-or-later
> > > > + *
> > > > + * Copyright Linaro 2026
> > > > + */
> > > > +
> > > > +#include "qemu/osdep.h"
> > > > +
> > > > +#include "hw/core/boards.h"
> > > > +#include "hw/core/cpu.h"
> > > > +#include "kvm_arm.h"
> > > > +#include "migration/blocker.h"
> > > > +#include "qapi/error.h"
> > > > +#include "qom/object_interfaces.h"
> > > > +#include "system/confidential-guest-support.h"
> > > > +#include "system/kvm.h"
> > > > +#include "system/runstate.h"
> > > > +
> > > > +#define TYPE_RME_GUEST "rme-guest"
> > > > +OBJECT_DECLARE_SIMPLE_TYPE(RmeGuest, RME_GUEST)
> > > > +
> > > > +struct RmeGuest {
> > > > +    ConfidentialGuestSupport parent_obj;
> > > > +};
> > > > +
> > > > +OBJECT_DEFINE_SIMPLE_TYPE_WITH_INTERFACES(RmeGuest, rme_guest, RME_GUEST,
> > > > +                                          CONFIDENTIAL_GUEST_SUPPORT,
> > > > +                                          { TYPE_USER_CREATABLE }, { })
> > > > +
> > > > +static void rme_guest_class_init(ObjectClass *oc, const void *data)
> > > > +{
> > > > +}
> > > > +
> > > > +static void rme_guest_init(Object *obj)
> > > > +{
> > > > +}
> > > > +
> > > > +static void rme_guest_finalize(Object *obj)
> > > > +{
> > > > +}
> > > > diff --git a/target/arm/meson.build b/target/arm/meson.build
> > > > index 0369f96b4cc6..9d322a7aad28 100644
> > > > --- a/target/arm/meson.build
> > > > +++ b/target/arm/meson.build
> > > > @@ -31,7 +31,10 @@ arm_common_user_system_ss.add(when: 'TARGET_AARCH64', if_true: files(
> > > >  arm_common_system_ss.add(files(
> > > >    'arm-qmp-cmds.c',
> > > >  ))
> > > > -arm_system_ss.add(when: 'CONFIG_KVM', if_true: files('hyp_gdbstub.c', 'kvm.c'))
> > > > +arm_system_ss.add(when: 'CONFIG_KVM', if_true: files(
> > > > +  'hyp_gdbstub.c',
> > > > +  'kvm.c',
> > > > +  'kvm-rme.c'))
> > > >  arm_system_ss.add(when: 'CONFIG_HVF', if_true: files('hyp_gdbstub.c'))
> > > >  
> > > >  arm_user_ss.add(files('cpu.c'))
> > > > -- 
> > > > 2.43.0
> > > > 
> > > > 

  reply	other threads:[~2026-09-30 21:28 UTC|newest]

Thread overview: 51+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03 19:35 [RFC v4 00/24] Add Realm support to QEMU-VMM Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 01/24] linux-headers: Add RME related definitions Mathieu Poirier
2026-09-04  6:07   ` Gavin Shan
2026-09-04 16:24     ` Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 02/24] target/arm/kvm: Return immediately on error in kvm_arch_init() Mathieu Poirier
2026-09-15 21:01   ` Michael Roth
2026-09-30 21:24     ` Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 03/24] target/arm: Add confidential guest support Mathieu Poirier
2026-09-07  8:49   ` Markus Armbruster
2026-09-15 21:27   ` Michael Roth
2026-09-22  8:01     ` Lorenzo Pieralisi
2026-09-24  3:12       ` Kohei Enju
2026-09-30 21:28         ` Mathieu Poirier [this message]
2026-09-03 19:35 ` [RFC v4 04/24] target/arm/kvm-rme: Add mechanic to initialize realms Mathieu Poirier
2026-10-01 23:42   ` Gavin Shan
2026-09-03 19:35 ` [RFC v4 05/24] target/arm/kvm: Split kvm_arch_get/put_registers Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 06/24] target/arm/kvm-rme: Initialize vCPU Mathieu Poirier
2026-10-02  0:53   ` Gavin Shan
2026-09-03 19:35 ` [RFC v4 07/24] target/arm/kvm: Create scratch Realm VM when requested Mathieu Poirier
2026-09-04  3:09   ` Kohei Enju
2026-09-04 16:25     ` Mathieu Poirier
2026-10-02  1:05   ` Gavin Shan
2026-09-03 19:35 ` [RFC v4 08/24] target/arm/kvm: Use kvm_vm_check_extension() where necessary Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 09/24] hw/core/loader: Add a ROM loader notifier Mathieu Poirier
2026-09-15 22:36   ` Michael Roth
2026-10-02  1:15   ` Gavin Shan
2026-09-03 19:35 ` [RFC v4 10/24] target/arm/kvm-rme: Keep track of images loaded in Realm memory Mathieu Poirier
2026-09-15 22:50   ` Michael Roth
2026-09-16 21:40     ` Mathieu Poirier
2026-10-02  1:23   ` Gavin Shan
2026-09-03 19:35 ` [RFC v4 11/24] target/arm/kvm-rme: Populate Realm with runtime images Mathieu Poirier
2026-10-02  3:45   ` Gavin Shan
2026-10-02  9:27     ` Lorenzo Pieralisi
2026-09-03 19:35 ` [RFC v4 12/24] target/arm/cpu: Set number of breakpoints and watchpoints in KVM Mathieu Poirier
2026-10-02  4:06   ` Gavin Shan
2026-09-03 19:36 ` [RFC v4 13/24] target/arm/cpu: Set number of PMU counters " Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 14/24] target/arm/cpu: Don't read Realm registers Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 15/24] hw/arm/virt: Set proper conduit method for Realms Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 16/24] hw/arm/virt: Embed Realm VM type with IPA address space Mathieu Poirier
2026-10-02  4:16   ` Gavin Shan
2026-09-03 19:36 ` [RFC v4 17/24] hw/arm/virt: Reserve one bit of guest physical address for RME Mathieu Poirier
2026-10-02  4:19   ` Gavin Shan
2026-09-03 19:36 ` [RFC v4 18/24] hw/arm/virt: Disable DTB randomness for confidential VMs Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 19/24] hw/arm/virt: Move virt_flash_create() to machvirt_init() Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 20/24] hw/arm/virt: Use RAM instead of flash for confidential guest firmware Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 21/24] target/arm/kvm-rme: Add DMA remapping for the shared memory region Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 22/24] docs/interop/firmware.json: Add arm-rme firmware feature Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 23/24] hw/arm/boot: Load DTB as is for confidential VMs Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 24/24] hw/arm/boot: Skip bootloader for confidential guests Mathieu Poirier
2026-09-21  4:05 ` [RFC v4 00/24] Add Realm support to QEMU-VMM Gavin Shan
2026-10-02 20:31   ` Mathieu Poirier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ar1-7iyCq8Re3htU@p14s \
    --to=mathieu.poirier@linaro.org \
    --cc=armbru@redhat.com \
    --cc=berrange@redhat.com \
    --cc=cohuck@redhat.com \
    --cc=eblake@redhat.com \
    --cc=enju.kohei@fujitsu.com \
    --cc=gshan@redhat.com \
    --cc=kchamart@redhat.com \
    --cc=kvm@vger.kernel.org \
    --cc=lorenzo.pieralisi@linaro.org \
    --cc=lpieralisi@kernel.org \
    --cc=michael.roth@amd.com \
    --cc=mst@redhat.com \
    --cc=pbonzini@redhat.com \
    --cc=peter.maydell@linaro.org \
    --cc=pierrick.bouvier@oss.qualcomm.com \
    --cc=qemu-arm@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox