Re: [RFC PATCH v1 00/17] target/riscv: Add KVM CoVE confidential VM support
Alistair <[email protected]>
| Newsgroups | org.nongnu.qemu-riscv,org.nongnu.qemu-devel |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 2026-07-31 at 11:49 +0800, Baolong Duan wrote: > This series adds RISC-V CoVE (Confidential VM Extension) support to > the > virt machine when running with KVM acceleration. > > CoVE is the RISC-V equivalent of AMD SEV / Intel TDX, defined by the > RISC-V AP-TEE specification [1]. A CoVE guest is a TEE VM (TVM) Cool! > whose > memory and vCPU state are owned by the TEE Security Manager (TSM), > making them inaccessible to the host. > > The series adds a "cove-vm" machine property to the virt board and > adapts > the boot flow, interrupt routing, memory registration and device > model to > the constraints of a confidential guest: Awesome! I'm excited to see RISC-V CC coming along. Thanks for the RFC. When it comes time to send patches make sure you check against https://wiki.qemu.org/Documentation/Platforms/RISCV#RISC-V_Foundation_Extensions. Notably: - You need to be clear about which exact spec release you are using - You will need to add tests - The support needs to be experimental for a draft spec - You will need to link to kernel patches to support CoVE > > - kernel, initrd and device tree are measured before the guest > starts > - interrupts are MSI-only (IMSIC mandatory, APLIC emulated by QEMU) > - virtio uses modern PCI transport with VIRTIO_F_ACCESS_PLATFORM > - vhost is disabled (host kernel has no access to guest memory) > - vCPU threads are pinned (TSM binds vCPUs to harts) What firmware are you using? OpenSBI? You must need a fair few changes for this to work right? > > The KVM interface used here (KVM_VM_TYPE_RISCV_COVE and > KVM_RISCV_COVE_MEASURE_REGION) is not yet part of an upstream Linux > release. The definitions are kept locally and will be replaced by a > linux-headers update once the kernel side has been merged. > > Patches 15 and 17 contain known workarounds and explicitly ask for > design > guidance: > > - Patch 15 pins vCPU threads and adds a yield after KVM_RUN to > avoid > host RCU stalls. Thread placement should be left to the user or > management layer. > > - Patch 17 converts system_reset into a shutdown because a TVM > cannot be > recreated. The proper approach may be to implement > ConfidentialGuestSupport and use the existing can_rebuild_state() > machinery. > > Tested with QEMU TCG emulating a CoVE-capable Xuantie C930 platform. Are we able to access and test this setup? > > [1] https://github.com/riscv-non-isa/riscv-ap-tee > > Baolong Duan (17): > docs/system/riscv/virt: document the cove-vm machine option Add the docs after adding the feature > hw/riscv/virt: add the cove-vm machine property This is in the wrong order. We want to add the feature then expose it to users, not the other way around. Alistair > target/riscv/kvm: create and measure a CoVE TEE VM > accel/kvm: add kvm_gpa_to_userspace_addr() > hw/riscv/boot: load and measure the images of a CoVE guest > hw/riscv/virt: measure the device tree of a CoVE guest > hw/riscv: adapt the device tree of a CoVE guest > hw/riscv/virt: use MSIs only for a CoVE guest > hw/intc/riscv_aplic: emulate the APLIC for a CoVE guest > target/riscv/kvm: skip unsupported KVM requests for a CoVE guest > hw/virtio: force modern virtio for a CoVE guest > hw/net/virtio-net: do not use vhost for a CoVE guest > accel/kvm: only register the DRAM slot of a CoVE guest > accel/kvm: skip MSI route updates for a CoVE guest > accel/kvm: pin the vCPU threads of a CoVE guest > accel/kvm: terminate on a system event of a CoVE guest > hw/core/machine-qmp-cmds: shut down a CoVE guest on reset > > MAINTAINERS | 6 ++ > accel/kvm/kvm-accel-ops.c | 16 +++++ > accel/kvm/kvm-all.c | 60 +++++++++++++++++ > docs/system/riscv/virt.rst | 39 +++++++++++ > hw/core/machine-qmp-cmds.c | 10 +++ > hw/core/machine.c | 18 +++++ > hw/intc/riscv_aplic.c | 9 +++ > hw/net/virtio-net.c | 9 +++ > hw/riscv/boot.c | 91 +++++++++++++++++++++++++ > hw/riscv/fdt-common.c | 4 +- > hw/riscv/trace-events | 4 ++ > hw/riscv/virt.c | 125 +++++++++++++++++++++++++++++---- > -- > hw/virtio/virtio-bus.c | 12 ++++ > hw/virtio/virtio-pci.c | 9 ++- > include/hw/riscv/cove.h | 24 +++++++ > include/hw/riscv/virt.h | 1 + > include/system/kvm.h | 18 +++++ > target/riscv/kvm/kvm-cpu.c | 67 ++++++++++++++++++- > target/riscv/kvm/kvm_riscv.h | 10 +++ > 19 files changed, 508 insertions(+), 24 deletions(-) > create mode 100644 include/hw/riscv/cove.h