diff mbox series

[v3,11/22] target/i386/sev: Restrict SEV to system emulation

Message ID 20211002125317.3418648-12-philmd@redhat.com (mailing list archive)
State New, archived
Headers show
Series target/i386/sev: Housekeeping SEV + measured Linux SEV guest | expand

Commit Message

Philippe Mathieu-Daudé Oct. 2, 2021, 12:53 p.m. UTC
SEV is irrelevant on user emulation, so restrict it to sysemu.
Some stubs are still required because used in cpu.c by
x86_register_cpudef_types(), so move the sysemu specific stubs
to sev-sysemu-stub.c instead. This will allow us to simplify
monitor.c (which is not available in user emulation) in the
next commit.

Signed-off-by: Philippe Mathieu-Daudé <philmd@redhat.com>
---
 target/i386/sev-stub.c        | 43 -------------------------
 target/i386/sev-sysemu-stub.c | 60 +++++++++++++++++++++++++++++++++++
 target/i386/meson.build       |  4 ++-
 3 files changed, 63 insertions(+), 44 deletions(-)
 create mode 100644 target/i386/sev-sysemu-stub.c

Comments

Paolo Bonzini Oct. 4, 2021, 8:14 a.m. UTC | #1
On 02/10/21 14:53, Philippe Mathieu-Daudé wrote:
> SEV is irrelevant on user emulation, so restrict it to sysemu.
> Some stubs are still required because used in cpu.c by
> x86_register_cpudef_types(), so move the sysemu specific stubs
> to sev-sysemu-stub.c instead. This will allow us to simplify
> monitor.c (which is not available in user emulation) in the
> next commit.
> 
> Signed-off-by: Philippe Mathieu-Daudé <philmd@redhat.com>
> ---
>   target/i386/sev-stub.c        | 43 -------------------------
>   target/i386/sev-sysemu-stub.c | 60 +++++++++++++++++++++++++++++++++++
>   target/i386/meson.build       |  4 ++-
>   3 files changed, 63 insertions(+), 44 deletions(-)
>   create mode 100644 target/i386/sev-sysemu-stub.c
> 
> diff --git a/target/i386/sev-stub.c b/target/i386/sev-stub.c
> index 4668365fd3e..8eae5d2fa8d 100644
> --- a/target/i386/sev-stub.c
> +++ b/target/i386/sev-stub.c
> @@ -15,11 +15,6 @@
>   #include "qapi/error.h"
>   #include "sev_i386.h"
>   
> -SevInfo *sev_get_info(void)
> -{
> -    return NULL;
> -}
> -
>   bool sev_enabled(void)
>   {
>       return false;
> @@ -35,45 +30,7 @@ uint32_t sev_get_reduced_phys_bits(void)
>       return 0;
>   }
>   
> -char *sev_get_launch_measurement(void)
> -{
> -    return NULL;
> -}
> -
> -SevCapability *sev_get_capabilities(Error **errp)
> -{
> -    error_setg(errp, "SEV is not available in this QEMU");
> -    return NULL;
> -}
> -
> -int sev_inject_launch_secret(const char *hdr, const char *secret,
> -                             uint64_t gpa, Error **errp)
> -{
> -    return 1;
> -}
> -
> -int sev_encrypt_flash(uint8_t *ptr, uint64_t len, Error **errp)
> -{
> -    g_assert_not_reached();
> -}
> -
>   bool sev_es_enabled(void)
>   {
>       return false;
>   }
> -
> -void sev_es_set_reset_vector(CPUState *cpu)
> -{
> -}
> -
> -int sev_es_save_reset_vector(void *flash_ptr, uint64_t flash_size)
> -{
> -    g_assert_not_reached();
> -}
> -
> -SevAttestationReport *
> -sev_get_attestation_report(const char *mnonce, Error **errp)
> -{
> -    error_setg(errp, "SEV is not available in this QEMU");
> -    return NULL;
> -}
> diff --git a/target/i386/sev-sysemu-stub.c b/target/i386/sev-sysemu-stub.c
> new file mode 100644
> index 00000000000..d556b4f091f
> --- /dev/null
> +++ b/target/i386/sev-sysemu-stub.c
> @@ -0,0 +1,60 @@
> +/*
> + * QEMU SEV system stub
> + *
> + * Copyright Advanced Micro Devices 2018
> + *
> + * Authors:
> + *      Brijesh Singh <brijesh.singh@amd.com>
> + *
> + * This work is licensed under the terms of the GNU GPL, version 2 or later.
> + * See the COPYING file in the top-level directory.
> + *
> + */
> +
> +#include "qemu/osdep.h"
> +#include "qapi/qapi-commands-misc-target.h"
> +#include "qapi/error.h"
> +#include "sev_i386.h"
> +
> +SevInfo *sev_get_info(void)
> +{
> +    return NULL;
> +}
> +
> +char *sev_get_launch_measurement(void)
> +{
> +    return NULL;
> +}
> +
> +SevCapability *sev_get_capabilities(Error **errp)
> +{
> +    error_setg(errp, "SEV is not available in this QEMU");
> +    return NULL;
> +}
> +
> +int sev_inject_launch_secret(const char *hdr, const char *secret,
> +                             uint64_t gpa, Error **errp)
> +{
> +    return 1;
> +}
> +
> +int sev_encrypt_flash(uint8_t *ptr, uint64_t len, Error **errp)
> +{
> +    g_assert_not_reached();
> +}
> +
> +void sev_es_set_reset_vector(CPUState *cpu)
> +{
> +}
> +
> +int sev_es_save_reset_vector(void *flash_ptr, uint64_t flash_size)
> +{
> +    g_assert_not_reached();
> +}
> +
> +SevAttestationReport *sev_get_attestation_report(const char *mnonce,
> +                                                 Error **errp)
> +{
> +    error_setg(errp, "SEV is not available in this QEMU");
> +    return NULL;
> +}
> diff --git a/target/i386/meson.build b/target/i386/meson.build
> index dac19ec00d4..a4f45c3ec1d 100644
> --- a/target/i386/meson.build
> +++ b/target/i386/meson.build
> @@ -6,7 +6,7 @@
>     'xsave_helper.c',
>     'cpu-dump.c',
>   ))
> -i386_ss.add(when: 'CONFIG_SEV', if_true: files('host-cpu.c', 'sev.c'), if_false: files('sev-stub.c'))
> +i386_ss.add(when: 'CONFIG_SEV', if_true: files('host-cpu.c'), if_false: files('sev-stub.c'))
>   
>   # x86 cpu type
>   i386_ss.add(when: 'CONFIG_KVM', if_true: files('host-cpu.c'))
> @@ -20,6 +20,8 @@
>     'monitor.c',
>     'cpu-sysemu.c',
>   ))
> +i386_softmmu_ss.add(when: 'CONFIG_SEV', if_true: files('sev.c'), if_false: files('sev-sysemu-stub.c'))
> +
>   i386_user_ss = ss.source_set()
>   
>   subdir('kvm')
> 

Reviewed-by: Paolo Bonzini <pbonzini@redhat.com>
diff mbox series

Patch

diff --git a/target/i386/sev-stub.c b/target/i386/sev-stub.c
index 4668365fd3e..8eae5d2fa8d 100644
--- a/target/i386/sev-stub.c
+++ b/target/i386/sev-stub.c
@@ -15,11 +15,6 @@ 
 #include "qapi/error.h"
 #include "sev_i386.h"
 
-SevInfo *sev_get_info(void)
-{
-    return NULL;
-}
-
 bool sev_enabled(void)
 {
     return false;
@@ -35,45 +30,7 @@  uint32_t sev_get_reduced_phys_bits(void)
     return 0;
 }
 
-char *sev_get_launch_measurement(void)
-{
-    return NULL;
-}
-
-SevCapability *sev_get_capabilities(Error **errp)
-{
-    error_setg(errp, "SEV is not available in this QEMU");
-    return NULL;
-}
-
-int sev_inject_launch_secret(const char *hdr, const char *secret,
-                             uint64_t gpa, Error **errp)
-{
-    return 1;
-}
-
-int sev_encrypt_flash(uint8_t *ptr, uint64_t len, Error **errp)
-{
-    g_assert_not_reached();
-}
-
 bool sev_es_enabled(void)
 {
     return false;
 }
-
-void sev_es_set_reset_vector(CPUState *cpu)
-{
-}
-
-int sev_es_save_reset_vector(void *flash_ptr, uint64_t flash_size)
-{
-    g_assert_not_reached();
-}
-
-SevAttestationReport *
-sev_get_attestation_report(const char *mnonce, Error **errp)
-{
-    error_setg(errp, "SEV is not available in this QEMU");
-    return NULL;
-}
diff --git a/target/i386/sev-sysemu-stub.c b/target/i386/sev-sysemu-stub.c
new file mode 100644
index 00000000000..d556b4f091f
--- /dev/null
+++ b/target/i386/sev-sysemu-stub.c
@@ -0,0 +1,60 @@ 
+/*
+ * QEMU SEV system stub
+ *
+ * Copyright Advanced Micro Devices 2018
+ *
+ * Authors:
+ *      Brijesh Singh <brijesh.singh@amd.com>
+ *
+ * This work is licensed under the terms of the GNU GPL, version 2 or later.
+ * See the COPYING file in the top-level directory.
+ *
+ */
+
+#include "qemu/osdep.h"
+#include "qapi/qapi-commands-misc-target.h"
+#include "qapi/error.h"
+#include "sev_i386.h"
+
+SevInfo *sev_get_info(void)
+{
+    return NULL;
+}
+
+char *sev_get_launch_measurement(void)
+{
+    return NULL;
+}
+
+SevCapability *sev_get_capabilities(Error **errp)
+{
+    error_setg(errp, "SEV is not available in this QEMU");
+    return NULL;
+}
+
+int sev_inject_launch_secret(const char *hdr, const char *secret,
+                             uint64_t gpa, Error **errp)
+{
+    return 1;
+}
+
+int sev_encrypt_flash(uint8_t *ptr, uint64_t len, Error **errp)
+{
+    g_assert_not_reached();
+}
+
+void sev_es_set_reset_vector(CPUState *cpu)
+{
+}
+
+int sev_es_save_reset_vector(void *flash_ptr, uint64_t flash_size)
+{
+    g_assert_not_reached();
+}
+
+SevAttestationReport *sev_get_attestation_report(const char *mnonce,
+                                                 Error **errp)
+{
+    error_setg(errp, "SEV is not available in this QEMU");
+    return NULL;
+}
diff --git a/target/i386/meson.build b/target/i386/meson.build
index dac19ec00d4..a4f45c3ec1d 100644
--- a/target/i386/meson.build
+++ b/target/i386/meson.build
@@ -6,7 +6,7 @@ 
   'xsave_helper.c',
   'cpu-dump.c',
 ))
-i386_ss.add(when: 'CONFIG_SEV', if_true: files('host-cpu.c', 'sev.c'), if_false: files('sev-stub.c'))
+i386_ss.add(when: 'CONFIG_SEV', if_true: files('host-cpu.c'), if_false: files('sev-stub.c'))
 
 # x86 cpu type
 i386_ss.add(when: 'CONFIG_KVM', if_true: files('host-cpu.c'))
@@ -20,6 +20,8 @@ 
   'monitor.c',
   'cpu-sysemu.c',
 ))
+i386_softmmu_ss.add(when: 'CONFIG_SEV', if_true: files('sev.c'), if_false: files('sev-sysemu-stub.c'))
+
 i386_user_ss = ss.source_set()
 
 subdir('kvm')