[RFC PATCH v2 0/1] qemu: KVM VM Planes host support for VBS

Sriram Nambakam <[email protected]>
Newsgroups org.kernel.vger.kvm,org.nongnu.qemu-devel
Message-ID <[email protected]>
This RFC adds the QEMU support needed to run Virtualization-Based
Security (VBS) across KVM VM Planes.  It handles the guest's plane
configure and activate hypercalls in userspace: allocating and mapping
each plane's RAM, creating the plane and its sibling vCPUs, and
initialising them to enter the loaded plane kernel.

This is v2 of the series.  Based on feedback from maintainers, the KVM
host, guest, and QEMU changes are now being posted as three separate,
layered RFCs to make it easier to understand the context of these
changes as they pertain to the KVM host, guest, and QEMU.  This
patchset does not yet include memory protection between planes; that
will be added in a future version.

This series is based on the QEMU VM Planes prerequisite patchset obtained
from Joerg Roedel's tree (qemu-planes-linux-v7.1).

This is the userspace counterpart to the separately posted four-patch
KVM host RFC.  This remains prototype code and is not intended for
production use.

The implementation and integration tooling are available at:

  Linux and KVM support:
  https://github.com/safe-tee/linux/tree/vm-planes-layered

  QEMU support:
  https://github.com/safe-tee/qemu/tree/vm-planes-layered

  Build, test, and integration tooling:
  https://github.com/safe-tee/lvbs

Acknowledgments
===============

This work stands on top of, and is indebted to, several prior efforts:

  - Joerg Roedel, whose QEMU and KVM VM Planes work provides the
    infrastructure that the VBS/VSM secure plane relies on.

  - Paolo Bonzini, whose "[RFC PATCH 00/29] KVM: VM planes" introduced
    the VM Plane concept to KVM as a common in-kernel model for AMD VMPLs,
    Intel TDX partitions, Hyper-V VTLs, and Arm CCA planes.
    https://lwn.net/Articles/1016113/

  - James Bottomley and James Morris, for their ongoing VSM-on-KVM work,
    which informed the design and direction of this series.

Feedback on the plane configuration/activation handling and the
memory/vCPU setup it performs is welcome.

Sriram Nambakam (1):
  kvm: handle VM-plane configure/activate hypercalls

 accel/kvm/kvm-all.c                       |  20 +
 include/standard-headers/linux/kvm_para.h |   2 +
 include/system/kvm_int.h                  |  20 +
 target/i386/kvm/kvm.c                     | 517 ++++++++++++++++++++++
 4 files changed, 559 insertions(+)


base-commit: e94b8abef8617a074fac3cfc2797c0c2359ceb8c
-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.