mirror of
https://github.com/qemu/qemu.git
synced 2025-07-22 18:27:05 +00:00

For confidential guests a policy can be provided that defines the security level, debug status, expected launch measurement and other parameters that define the configuration of the confidential platform. This commit adds a new function named set_guest_policy() that can be implemented by each confidential platform, such as AMD SEV to set the policy. This will allow configuration of the policy from a multi-platform resource such as an IGVM file without the IGVM processor requiring specific implementation details for each platform. Signed-off-by: Roy Hopkins <roy.hopkins@randomman.co.uk> Reviewed-by: Daniel P. Berrangé <berrange@redhat.com> Reviewed-by: Stefano Garzarella <sgarzare@redhat.com> Reviewed-by: Ani Sinha <anisinha@redhat.com> Acked-by: Michael S. Tsirkin <mst@redhat.com> Acked-by: Gerd Hoffman <kraxel@redhat.com> Link: https://lore.kernel.org/r/d3888a2eb170c8d8c85a1c4b7e99accf3a15589c.1751554099.git.roy.hopkins@randomman.co.uk Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
78 lines
2.3 KiB
C
78 lines
2.3 KiB
C
/*
|
|
* QEMU Confidential Guest support
|
|
*
|
|
* Copyright Red Hat.
|
|
*
|
|
* Authors:
|
|
* David Gibson <david@gibson.dropbear.id.au>
|
|
*
|
|
* This work is licensed under the terms of the GNU GPL, version 2 or
|
|
* later. See the COPYING file in the top-level directory.
|
|
*
|
|
*/
|
|
|
|
#include "qemu/osdep.h"
|
|
|
|
#include "system/confidential-guest-support.h"
|
|
#include "qapi/error.h"
|
|
|
|
OBJECT_DEFINE_ABSTRACT_TYPE(ConfidentialGuestSupport,
|
|
confidential_guest_support,
|
|
CONFIDENTIAL_GUEST_SUPPORT,
|
|
OBJECT)
|
|
|
|
static bool check_support(ConfidentialGuestPlatformType platform,
|
|
uint16_t platform_version, uint8_t highest_vtl,
|
|
uint64_t shared_gpa_boundary)
|
|
{
|
|
/* Default: no support. */
|
|
return false;
|
|
}
|
|
|
|
static int set_guest_state(hwaddr gpa, uint8_t *ptr, uint64_t len,
|
|
ConfidentialGuestPageType memory_type,
|
|
uint16_t cpu_index, Error **errp)
|
|
{
|
|
error_setg(errp,
|
|
"Setting confidential guest state is not supported for this platform");
|
|
return -1;
|
|
}
|
|
|
|
static int set_guest_policy(ConfidentialGuestPolicyType policy_type,
|
|
uint64_t policy,
|
|
void *policy_data1, uint32_t policy_data1_size,
|
|
void *policy_data2, uint32_t policy_data2_size,
|
|
Error **errp)
|
|
{
|
|
error_setg(errp,
|
|
"Setting confidential guest policy is not supported for this platform");
|
|
return -1;
|
|
}
|
|
|
|
static int get_mem_map_entry(int index, ConfidentialGuestMemoryMapEntry *entry,
|
|
Error **errp)
|
|
{
|
|
error_setg(
|
|
errp,
|
|
"Obtaining the confidential guest memory map is not supported for this platform");
|
|
return -1;
|
|
}
|
|
|
|
static void confidential_guest_support_class_init(ObjectClass *oc,
|
|
const void *data)
|
|
{
|
|
ConfidentialGuestSupportClass *cgsc = CONFIDENTIAL_GUEST_SUPPORT_CLASS(oc);
|
|
cgsc->check_support = check_support;
|
|
cgsc->set_guest_state = set_guest_state;
|
|
cgsc->set_guest_policy = set_guest_policy;
|
|
cgsc->get_mem_map_entry = get_mem_map_entry;
|
|
}
|
|
|
|
static void confidential_guest_support_init(Object *obj)
|
|
{
|
|
}
|
|
|
|
static void confidential_guest_support_finalize(Object *obj)
|
|
{
|
|
}
|