QEMU-Arm Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Mathieu Poirier <mathieu.poirier@linaro.org>
To: Gavin Shan <gshan@redhat.com>
Cc: berrange@redhat.com, kchamart@redhat.com,
	pierrick.bouvier@oss.qualcomm.com, peter.maydell@linaro.org,
	mst@redhat.com, cohuck@redhat.com, pbonzini@redhat.com,
	eblake@redhat.com, armbru@redhat.com, jpb@kernel.org,
	lorenzo.pieralisi@linaro.org, qemu-devel@nongnu.org,
	qemu-arm@nongnu.org, kvm@vger.kernel.org
Subject: Re: [RFC v1 10/25] hw/core/loader: Add a ROM loader notifier
Date: Mon, 20 Jul 2026 13:56:19 -0600	[thread overview]
Message-ID: <al59Y0S_DLMbAESK@p14s> (raw)
In-Reply-To: <2ad36e97-63d7-4464-b909-2a28d496e887@redhat.com>

On Mon, Jul 20, 2026 at 04:47:53PM +1000, Gavin Shan wrote:
> On 7/17/26 7:10 AM, Mathieu Poirier wrote:
> > On Tue, Jul 14, 2026 at 08:52:43PM +1000, Gavin Shan wrote:
> > > On 7/8/26 8:42 AM, Mathieu Poirier wrote:
> > > > From: Jean-Philippe Brucker <jean-philippe@linaro.org>
> > > > 
> > > > Add a function to register a notifier that is invoked when ROMs get
> > > > loaded into guest memory.
> > > > 
> > > > It will be used by Arm confidential guest support, in order to register
> > > > all blobs loaded into memory with KVM, so that their content is moved
> > > > into Realm state and measured into the initial VM state.
> > > > 
> > > > Signed-off-by: Jean-Philippe Brucker <jean-philippe@linaro.org>
> > > > Signed-off-by: Mathieu Poirier <mathieu.poirier@linaro.org>
> > > > ---
> > > >    hw/core/loader.c         | 15 +++++++++++++++
> > > >    include/hw/core/loader.h | 17 +++++++++++++++++
> > > >    2 files changed, 32 insertions(+)
> > > > 
> > > > diff --git a/hw/core/loader.c b/hw/core/loader.c
> > > > index 5cbfba0a86d2..b3d769bec5cb 100644
> > > > --- a/hw/core/loader.c
> > > > +++ b/hw/core/loader.c
> > > > @@ -74,6 +74,8 @@
> > > >    #endif
> > > 
> > > The (edk2) firmware for the realm guest can be specified by the legacy
> > > '-drive if=pflash' or '-bios'. The memory region corresponding to the
> > > firmware image specified by '-bios' is recorded by the newly added notifier
> > > and populated to TF-RMM properly.
> > > 
> > > I don't see how the memory region corresponding to (edk2) firmware image
> > > specified by '-drive if=pflash' is recorded and populated to TF-RMM
> > > accordingly in this series. So I guess '-drive if=pflash' isn't supported
> > > yet?
> > 
> > Please give '-drive if=pflash' a try and let me know how you fare.  Edk2 is not
> > part of the bootstack I'm currently testing with but I know of configurations
> > where it does work.
> > 
> > I'll add it to my list of things to do if it doesn't work, though I may not
> > address it in this patchset.  We'll see how busy things get.
> > 
> 
> Ok, I don't think '-driver if=pflash' or the 'pflash0' property of the virt machine
> aren't supported any more due to [RFC v1 21/25], where the 'pflash0' property has
> been removed.
> 
>   [RFC v1 21/25] hw/arm/virt: Use RAM instead of flash for confidential guest firmware
> 
> - Tried to boot the realm guest with '-driver if=pflash' and I was told it's not supported.
> 
>   qemu-system-aarch64: -drive if=pflash,format=raw,unit=0,file=/mnt/edk2/Build/ArmVirtQemu-AARCH64/RELEASE_GCC5/FV/QEMU_EFI.fd,readonly=on: machine type   does not support if=pflash,bus=0,unit=0
> 
> - Tried to use 'pflash0' property, and I was told it's not supported either.
> 
>   qemu-system-aarch64: Property 'virt-11.1-machine.pflash0' not found
> 
> So the only option to specify the firmware image is '-bios', which worked for me.

Thanks for the follow-up.

> 
> Thanks,
> Gavin
> 
> 
> > > 
> > > Note that I didn't give '-drive if=pflash' a try yet.
> > > 
> > > >    static int roms_loaded;
> > > > +static NotifierList rom_loader_notifier =
> > > > +    NOTIFIER_LIST_INITIALIZER(rom_loader_notifier);
> > > >    /* return the size or -1 if error */
> > > >    int64_t get_image_size(const char *filename, Error **errp)
> > > > @@ -1201,6 +1203,11 @@ MemoryRegion *rom_add_blob(const char *name, const void *blob, size_t len,
> > > >        return mr;
> > > >    }
> > > > +void rom_add_load_notifier(Notifier *notifier)
> > > > +{
> > > > +    notifier_list_add(&rom_loader_notifier, notifier);
> > > > +}
> > > > +
> > > >    /* This function is specific for elf program because we don't need to allocate
> > > >     * all the rom. We just allocate the first part and the rest is just zeros. This
> > > >     * is why romsize and datasize are different. Also, this function takes its own
> > > > @@ -1242,6 +1249,7 @@ ssize_t rom_add_option(const char *file, int32_t bootindex)
> > > >    static void rom_reset(void *unused)
> > > >    {
> > > >        Rom *rom;
> > > > +    RomLoaderNotifyData notify;
> > > >        QTAILQ_FOREACH(rom, &roms, next) {
> > > >            if (rom->fw_file) {
> > > > @@ -1290,6 +1298,13 @@ static void rom_reset(void *unused)
> > > >            address_space_flush_icache_range(rom->as, rom->addr, rom->datasize);
> > > >            trace_loader_write_rom(rom->name, rom->addr, rom->datasize, rom->isrom);
> > > > +
> > > > +        notify = (RomLoaderNotifyData) {
> > > > +            .addr = rom->addr,
> > > > +            .len = rom->datasize,
> > > > +            .as = rom->as,
> > > > +        };
> > > > +        notifier_list_notify(&rom_loader_notifier, &notify);
> > > >        }
> > > >    }
> > > > diff --git a/include/hw/core/loader.h b/include/hw/core/loader.h
> > > > index d9431e8a8d12..94cf6ad2e26b 100644
> > > > --- a/include/hw/core/loader.h
> > > > +++ b/include/hw/core/loader.h
> > > > @@ -342,6 +342,23 @@ void *rom_ptr_for_as(AddressSpace *as, hwaddr addr, size_t size);
> > > >    ssize_t rom_add_vga(const char *file);
> > > >    ssize_t rom_add_option(const char *file, int32_t bootindex);
> > > > +typedef struct RomLoaderNotifyData {
> > > > +    /* Address of the blob in guest memory */
> > > > +    hwaddr addr;
> > > > +    /* Length of the blob */
> > > > +    size_t len;
> > > > +    /* Address space of the blob */
> > > > +    AddressSpace *as;
> > > > +} RomLoaderNotifyData;
> > > > +
> > > > +/**
> > > > + * rom_add_load_notifier - Add a notifier for loaded images
> > > > + *
> > > > + * Add a notifier that will be invoked with a RomLoaderNotifyData structure for
> > > > + * each blob loaded into guest memory, after the blob is loaded.
> > > > + */
> > > > +void rom_add_load_notifier(Notifier *notifier);
> > > > +
> > > >    /* This is the usual maximum in uboot, so if a uImage overflows this, it would
> > > >     * overflow on real hardware too. */
> > > >    #define UBOOT_MAX_DECOMPRESSED_BYTES (64 << 20)
> > > 
> > > Thanks,
> > > Gavin
> > > 
> > 
> 


  reply	other threads:[~2026-07-20 19:56 UTC|newest]

Thread overview: 55+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-07 22:42 [RFC v1 00/25] Add Realm support to QEMU-VMM Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 01/25] linux-headers: Add RME related definitions Mathieu Poirier
2026-07-10  1:09   ` Gavin Shan
2026-07-10  7:36     ` Lorenzo Pieralisi
2026-07-10 10:46     ` Lorenzo Pieralisi
2026-07-13  0:41       ` Gavin Shan
2026-07-13 21:11     ` Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 02/25] target/arm/kvm: Return immediately on error in kvm_arch_init() Mathieu Poirier
2026-07-08  5:08   ` Philippe Mathieu-Daudé
2026-07-07 22:42 ` [RFC v1 03/25] target/arm: Add confidential guest support Mathieu Poirier
2026-07-08  4:39   ` Markus Armbruster
2026-07-09 20:22     ` Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 04/25] target/arm/kvm-rme: Add mechanic to initialize realms Mathieu Poirier
2026-07-13  5:14   ` Gavin Shan
2026-07-13 22:44     ` Mathieu Poirier
2026-07-13  5:34   ` Gavin Shan
2026-07-15 20:21     ` Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 05/25] target/arm/kvm: Split kvm_arch_get/put_registers Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 06/25] target/arm/kvm-rme: Initialize vCPU Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 07/25] target/arm/kvm: Create scratch Realm VM when requested Mathieu Poirier
2026-07-13  5:30   ` Gavin Shan
2026-07-16 20:54     ` Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 08/25] target/arm/kvm: Use kvm_vm_check_extension() where necessary Mathieu Poirier
2026-07-13  0:43   ` Gavin Shan
2026-07-16 20:54     ` Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 09/25] target/arm/kvm-rme: Initialise Realm Initial Address space Mathieu Poirier
2026-07-09 23:44   ` Gavin Shan
2026-07-10  7:37     ` Lorenzo Pieralisi
2026-07-16 22:04     ` Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 10/25] hw/core/loader: Add a ROM loader notifier Mathieu Poirier
2026-07-14 10:52   ` Gavin Shan
2026-07-16 21:10     ` Mathieu Poirier
2026-07-20  6:47       ` Gavin Shan
2026-07-20 19:56         ` Mathieu Poirier [this message]
2026-07-07 22:42 ` [RFC v1 11/25] target/arm/kvm-rme: Keep track of images loaded in Realm memory Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 12/25] target/arm/kvm-rme: Populate Realm with runtime images Mathieu Poirier
2026-07-14 10:56   ` Gavin Shan
2026-07-20 20:02     ` Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 13/25] target/arm/cpu: Set number of breakpoints and watchpoints in KVM Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 14/25] target/arm/cpu: Set number of PMU counters " Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 15/25] target/arm/cpu: Don't read Realm registers Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 16/25] hw/arm/virt: Set proper conduit method for Realms Mathieu Poirier
2026-07-08  5:12   ` Philippe Mathieu-Daudé
2026-07-07 22:42 ` [RFC v1 17/25] hw/arm/virt: Embed Realm VM type with IPA address space Mathieu Poirier
2026-07-07 22:42 ` [RFC v1 18/25] hw/arm/virt: Reserve one bit of guest physical address for RME Mathieu Poirier
2026-07-07 22:43 ` [RFC v1 19/25] hw/arm/virt: Disable DTB randomness for confidential VMs Mathieu Poirier
2026-07-07 22:43 ` [RFC v1 20/25] hw/arm/virt: Move virt_flash_create() to machvirt_init() Mathieu Poirier
2026-07-08  5:14   ` Philippe Mathieu-Daudé
2026-07-07 22:43 ` [RFC v1 21/25] hw/arm/virt: Use RAM instead of flash for confidential guest firmware Mathieu Poirier
2026-07-07 22:43 ` [RFC v1 22/25] target/arm/kvm-rme: Add DMA remapping for the shared memory region Mathieu Poirier
2026-07-07 22:43 ` [RFC v1 23/25] docs/interop/firmware.json: Add arm-rme firmware feature Mathieu Poirier
2026-07-08  4:37   ` Markus Armbruster
2026-07-08  5:16   ` Philippe Mathieu-Daudé
2026-07-07 22:43 ` [RFC v1 24/25] hw/arm/boot: Load DTB as is for confidential VMs Mathieu Poirier
2026-07-07 22:43 ` [RFC v1 25/25] hw/arm/boot: Skip bootloader for confidential guests Mathieu Poirier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=al59Y0S_DLMbAESK@p14s \
    --to=mathieu.poirier@linaro.org \
    --cc=armbru@redhat.com \
    --cc=berrange@redhat.com \
    --cc=cohuck@redhat.com \
    --cc=eblake@redhat.com \
    --cc=gshan@redhat.com \
    --cc=jpb@kernel.org \
    --cc=kchamart@redhat.com \
    --cc=kvm@vger.kernel.org \
    --cc=lorenzo.pieralisi@linaro.org \
    --cc=mst@redhat.com \
    --cc=pbonzini@redhat.com \
    --cc=peter.maydell@linaro.org \
    --cc=pierrick.bouvier@oss.qualcomm.com \
    --cc=qemu-arm@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox