[PATCH v17 01/34] Add boot-certs to s390-ccw-virtio machine type option
Zhuoying Cai <[email protected]>
| Newsgroups | gmane.comp.emulators.qemu |
|---|---|
| Message-ID | <[email protected]> |
Introduce a new `boot-certs` machine type option for the s390-ccw-virtio machine. This allows users to specify one or more certificate file paths or directories to be used during secure boot. Each entry is specified using the syntax: boot-certs.<index>.path=/path/to/cert.pem Multiple paths can be specify using array properties: boot-certs.0.path=/path/to/cert.pem, boot-certs.1.path=/path/to/cert-dir, boot-certs.2.path=/path/to/another-dir... Signed-off-by: Zhuoying Cai <[email protected]> Acked-by: Markus Armbruster <[email protected]> Reviewed-by: Matthew Rosato <[email protected]> --- docs/system/s390x/secure-ipl.rst | 20 +++++++++++++++ docs/system/target-s390x.rst | 1 + hw/s390x/s390-virtio-ccw.c | 41 ++++++++++++++++++++++++++++++ include/hw/s390x/s390-virtio-ccw.h | 3 +++ qapi/machine-s390x.json | 23 +++++++++++++++++ qapi/pragma.json | 1 + qemu-options.hx | 6 ++++- 7 files changed, 94 insertions(+), 1 deletion(-) create mode 100644 docs/system/s390x/secure-ipl.rst diff --git a/docs/system/s390x/secure-ipl.rst b/docs/system/s390x/secure-ipl.rst new file mode 100644 index 0000000000..88df52ce2f --- /dev/null +++ b/docs/system/s390x/secure-ipl.rst @@ -0,0 +1,20 @@ +.. SPDX-License-Identifier: GPL-2.0-or-later + +Secure IPL Command Line Options +------------------------------- + +The s390-ccw-virtio machine type supports secure IPL. These parameters allow +users to provide certificates and enable secure IPL directly via the command +line. + +Providing Certificates +^^^^^^^^^^^^^^^^^^^^^^ + +The certificate store can be populated by supplying a list of X.509 certificate +file paths or directories containing certificate files on the command-line: + +Note: certificate files must have a .pem extension. + +.. code-block:: shell + + qemu-system-s390x -machine s390-ccw-virtio,boot-certs.0.path=/.../qemu/certs,boot-certs.1.path=/another/path/cert.pem ... diff --git a/docs/system/target-s390x.rst b/docs/system/target-s390x.rst index 94c981e732..8938a13d10 100644 --- a/docs/system/target-s390x.rst +++ b/docs/system/target-s390x.rst @@ -35,3 +35,4 @@ Architectural features s390x/bootdevices s390x/protvirt s390x/cpu-topology + s390x/secure-ipl diff --git a/hw/s390x/s390-virtio-ccw.c b/hw/s390x/s390-virtio-ccw.c index 55131c1a44..b69cd49418 100644 --- a/hw/s390x/s390-virtio-ccw.c +++ b/hw/s390x/s390-virtio-ccw.c @@ -44,6 +44,7 @@ #include "target/s390x/kvm/pv.h" #include "migration/blocker.h" #include "qapi/visitor.h" +#include "qapi/qapi-visit-machine-s390x.h" #include "hw/s390x/cpu-topology.h" #include "kvm/kvm_s390x.h" #include "hw/virtio/virtio-md-pci.h" @@ -788,6 +789,36 @@ static void machine_set_loadparm(Object *obj, Visitor *v, g_free(val); } +static void machine_get_boot_certs(Object *obj, Visitor *v, + const char *name, void *opaque, + Error **errp) +{ + S390CcwMachineState *ms = S390_CCW_MACHINE(obj); + BootCertificatesList **certs = &ms->boot_certs; + + visit_type_BootCertificatesList(v, name, certs, errp); +} + +static void machine_set_boot_certs(Object *obj, Visitor *v, const char *name, + void *opaque, Error **errp) +{ + S390CcwMachineClass *s390mc = S390_CCW_MACHINE_GET_CLASS(obj); + S390CcwMachineState *ms = S390_CCW_MACHINE(obj); + BootCertificatesList *cert_list = NULL; + + if (!s390mc->use_certs) { + error_setg(errp, "boot-certs is not supported by this machine version"); + return; + } + + visit_type_BootCertificatesList(v, name, &cert_list, errp); + if (!cert_list) { + return; + } + + ms->boot_certs = cert_list; +} + /* * S390x-specific global compatibility properties. * @@ -813,6 +844,7 @@ static void ccw_machine_class_init(ObjectClass *oc, const void *data) s390mc->max_threads = 1; s390mc->use_cpi = true; + s390mc->use_certs = true; mc->reset = s390_machine_reset; mc->block_default_type = IF_VIRTIO; mc->no_cdrom = 1; @@ -856,6 +888,11 @@ static void ccw_machine_class_init(ObjectClass *oc, const void *data) "Up to 8 chars in set of [A-Za-z0-9. ] (lower case chars converted" " to upper case) to pass to machine loader, boot manager," " and guest kernel"); + + object_class_property_add(oc, "boot-certs", "BootCertificatesList", + machine_get_boot_certs, machine_set_boot_certs, NULL, NULL); + object_class_property_set_description(oc, "boot-certs", + "provide paths to a directory and/or a certificate file for secure boot"); } static inline void s390_machine_initfn(Object *obj) @@ -941,6 +978,10 @@ static void ccw_machine_11_1_instance_options(MachineState *machine) static void ccw_machine_11_1_class_options(MachineClass *mc) { + S390CcwMachineClass *s390mc = S390_CCW_MACHINE_CLASS(mc); + + s390mc->use_certs = false; + ccw_machine_11_2_class_options(mc); compat_props_add(mc->compat_props, hw_compat_11_1, hw_compat_11_1_len); } diff --git a/include/hw/s390x/s390-virtio-ccw.h b/include/hw/s390x/s390-virtio-ccw.h index f1f06119d6..d30f1fcc4c 100644 --- a/include/hw/s390x/s390-virtio-ccw.h +++ b/include/hw/s390x/s390-virtio-ccw.h @@ -14,6 +14,7 @@ #include "hw/core/boards.h" #include "qom/object.h" #include "hw/s390x/sclp.h" +#include "qapi/qapi-types-machine-s390x.h" #define TYPE_S390_CCW_MACHINE "s390-ccw-machine" @@ -31,6 +32,7 @@ struct S390CcwMachineState { uint8_t loadparm[8]; uint64_t memory_limit; uint64_t max_pagesize; + BootCertificatesList *boot_certs; SCLPDevice *sclp; }; @@ -55,6 +57,7 @@ struct S390CcwMachineClass { /*< public >*/ int max_threads; bool use_cpi; + bool use_certs; }; #endif diff --git a/qapi/machine-s390x.json b/qapi/machine-s390x.json index ea430e1b88..f79864f417 100644 --- a/qapi/machine-s390x.json +++ b/qapi/machine-s390x.json @@ -140,3 +140,26 @@ { 'event': 'SCLP_CPI_INFO_AVAILABLE', 'features': [ 'unstable' ] } + +## +# @BootCertificates: +# +# Boot certificates for secure IPL. +# +# @path: path to an X.509 certificate file or a directory containing +# certificate files. +# +# Since: 11.2 +## +{ 'struct': 'BootCertificates', + 'data': {'path': 'str'} } + +## +# @DummyBootCertificates: +# +# Not used by QMP; hack to let us use BootCertificatesList internally. +# +# Since: 11.2 +## +{ 'struct': 'DummyBootCertificates', + 'data': {'unused-boot-certs': ['BootCertificates'] } } diff --git a/qapi/pragma.json b/qapi/pragma.json index 24aebbe8f5..342cedc42e 100644 --- a/qapi/pragma.json +++ b/qapi/pragma.json @@ -49,6 +49,7 @@ 'DisplayProtocol', 'DriveBackupWrapper', 'DummyBlockCoreForceArrays', + 'DummyBootCertificates', 'DummyForceArrays', 'DummyVirtioForceArrays', 'HotKeyMod', diff --git a/qemu-options.hx b/qemu-options.hx index 34970fffc9..107f74aeb5 100644 --- a/qemu-options.hx +++ b/qemu-options.hx @@ -46,7 +46,8 @@ DEF("machine", HAS_ARG, QEMU_OPTION_machine, \ " memory-backend='backend-id' specifies explicitly provided backend for main RAM (default=none)\n" " cxl-fmw.0.targets.0=firsttarget,cxl-fmw.0.targets.1=secondtarget,cxl-fmw.0.size=size[,cxl-fmw.0.interleave-granularity=granularity]\n" " sgx-epc.0.memdev=memid,sgx-epc.0.node=numaid\n" - " smp-cache.0.cache=cachename,smp-cache.0.topology=topologylevel\n", + " smp-cache.0.cache=cachename,smp-cache.0.topology=topologylevel\n" + " boot-certs.0.path=/path/directory,boot-certs.1.path=/path/file provides paths to a directory and/or a certificate file\n", QEMU_ARCH_ALL) SRST ``-machine [type=]name[,prop=value[,...]]`` @@ -214,6 +215,9 @@ SRST :: -machine smp-cache.0.cache=l1d,smp-cache.0.topology=core,smp-cache.1.cache=l1i,smp-cache.1.topology=core + + ``boot-certs.0.path=/path/directory,boot-certs.1.path=/path/file`` + Provide paths to a directory and/or a certificate file on the host [s390x only]. ERST DEF("M", HAS_ARG, QEMU_OPTION_M, -- 2.55.0