Introduce a new `boot-certs` machine type option for the s390-ccw-virtio
machine. This allows users to specify one or more certificate file paths
or directories to be used during secure boot.
Each entry is specified using the syntax:
boot-certs.<index>.path=/path/to/cert.pem
Multiple paths can be specify using array properties:
boot-certs.0.path=/path/to/cert.pem,
boot-certs.1.path=/path/to/cert-dir,
boot-certs.2.path=/path/to/another-dir...
Signed-off-by: Zhuoying Cai <[email protected]>
Acked-by: Markus Armbruster <[email protected]>
Reviewed-by: Matthew Rosato <[email protected]>
---
docs/system/s390x/secure-ipl.rst | 20 +++++++++++++++
docs/system/target-s390x.rst | 1 +
hw/s390x/s390-virtio-ccw.c | 40 ++++++++++++++++++++++++++++++
include/hw/s390x/s390-virtio-ccw.h | 3 +++
qapi/machine-s390x.json | 23 +++++++++++++++++
qapi/pragma.json | 1 +
qemu-options.hx | 6 ++++-
7 files changed, 93 insertions(+), 1 deletion(-)
create mode 100644 docs/system/s390x/secure-ipl.rst
diff --git a/docs/system/s390x/secure-ipl.rst b/docs/system/s390x/secure-ipl.rst
new file mode 100644
index 0000000000..88df52ce2f
--- /dev/null
+++ b/docs/system/s390x/secure-ipl.rst
@@ -0,0 +1,20 @@
+.. SPDX-License-Identifier: GPL-2.0-or-later
+
+Secure IPL Command Line Options
+-------------------------------
+
+The s390-ccw-virtio machine type supports secure IPL. These parameters allow
+users to provide certificates and enable secure IPL directly via the command
+line.
+
+Providing Certificates
+^^^^^^^^^^^^^^^^^^^^^^
+
+The certificate store can be populated by supplying a list of X.509 certificate
+file paths or directories containing certificate files on the command-line:
+
+Note: certificate files must have a .pem extension.
+
+.. code-block:: shell
+
+ qemu-system-s390x -machine
s390-ccw-virtio,boot-certs.0.path=/.../qemu/certs,boot-certs.1.path=/another/path/cert.pem
...
diff --git a/docs/system/target-s390x.rst b/docs/system/target-s390x.rst
index 94c981e732..8938a13d10 100644
--- a/docs/system/target-s390x.rst
+++ b/docs/system/target-s390x.rst
@@ -35,3 +35,4 @@ Architectural features
s390x/bootdevices
s390x/protvirt
s390x/cpu-topology
+ s390x/secure-ipl
diff --git a/hw/s390x/s390-virtio-ccw.c b/hw/s390x/s390-virtio-ccw.c
index 25a9fa4955..c68a760f75 100644
--- a/hw/s390x/s390-virtio-ccw.c
+++ b/hw/s390x/s390-virtio-ccw.c
@@ -44,6 +44,7 @@
#include "target/s390x/kvm/pv.h"
#include "migration/blocker.h"
#include "qapi/visitor.h"
+#include "qapi/qapi-visit-machine-s390x.h"
#include "hw/s390x/cpu-topology.h"
#include "kvm/kvm_s390x.h"
#include "hw/virtio/virtio-md-pci.h"
@@ -788,6 +789,36 @@ static void machine_set_loadparm(Object *obj, Visitor *v,
g_free(val);
}
+static void machine_get_boot_certs(Object *obj, Visitor *v,
+ const char *name, void *opaque,
+ Error **errp)
+{
+ S390CcwMachineState *ms = S390_CCW_MACHINE(obj);
+ BootCertificatesList **certs = &ms->boot_certs;
+
+ visit_type_BootCertificatesList(v, name, certs, errp);
+}
+
+static void machine_set_boot_certs(Object *obj, Visitor *v, const char *name,
+ void *opaque, Error **errp)
+{
+ S390CcwMachineClass *s390mc = S390_CCW_MACHINE_GET_CLASS(obj);
+ S390CcwMachineState *ms = S390_CCW_MACHINE(obj);
+ BootCertificatesList *cert_list = NULL;
+
+ if (!s390mc->use_certs) {
+ error_setg(errp, "boot-certs is not supported by this machine
version");
+ return;
+ }
+
+ visit_type_BootCertificatesList(v, name, &cert_list, errp);
+ if (!cert_list) {
+ return;
+ }
+
+ ms->boot_certs = cert_list;
+}
+
/*
* S390x-specific global compatibility properties.
*
@@ -813,6 +844,7 @@ static void ccw_machine_class_init(ObjectClass *oc, const
void *data)
s390mc->max_threads = 1;
s390mc->use_cpi = true;
+ s390mc->use_certs = true;
mc->reset = s390_machine_reset;
mc->block_default_type = IF_VIRTIO;
mc->no_cdrom = 1;
@@ -856,6 +888,11 @@ static void ccw_machine_class_init(ObjectClass *oc, const
void *data)
"Up to 8 chars in set of [A-Za-z0-9. ] (lower case chars converted"
" to upper case) to pass to machine loader, boot manager,"
" and guest kernel");
+
+ object_class_property_add(oc, "boot-certs", "BootCertificatesList",
+ machine_get_boot_certs, machine_set_boot_certs,
NULL, NULL);
+ object_class_property_set_description(oc, "boot-certs",
+ "provide paths to a directory and/or a certificate file for secure
boot");
}
static inline void s390_machine_initfn(Object *obj)
@@ -941,6 +978,9 @@ static void ccw_machine_11_0_instance_options(MachineState
*machine)
static void ccw_machine_11_0_class_options(MachineClass *mc)
{
+ S390CcwMachineClass *s390mc = S390_CCW_MACHINE_CLASS(mc);
+
+ s390mc->use_certs = false;
/*
* Preserve v11.0 and older version behavior:
* keep legacy virtio-pci enabled.
diff --git a/include/hw/s390x/s390-virtio-ccw.h
b/include/hw/s390x/s390-virtio-ccw.h
index f1f06119d6..d30f1fcc4c 100644
--- a/include/hw/s390x/s390-virtio-ccw.h
+++ b/include/hw/s390x/s390-virtio-ccw.h
@@ -14,6 +14,7 @@
#include "hw/core/boards.h"
#include "qom/object.h"
#include "hw/s390x/sclp.h"
+#include "qapi/qapi-types-machine-s390x.h"
#define TYPE_S390_CCW_MACHINE "s390-ccw-machine"
@@ -31,6 +32,7 @@ struct S390CcwMachineState {
uint8_t loadparm[8];
uint64_t memory_limit;
uint64_t max_pagesize;
+ BootCertificatesList *boot_certs;
SCLPDevice *sclp;
};
@@ -55,6 +57,7 @@ struct S390CcwMachineClass {
/*< public >*/
int max_threads;
bool use_cpi;
+ bool use_certs;
};
#endif
diff --git a/qapi/machine-s390x.json b/qapi/machine-s390x.json
index ea430e1b88..bbe3646e91 100644
--- a/qapi/machine-s390x.json
+++ b/qapi/machine-s390x.json
@@ -140,3 +140,26 @@
{ 'event': 'SCLP_CPI_INFO_AVAILABLE',
'features': [ 'unstable' ]
}
+
+##
+# @BootCertificates:
+#
+# Boot certificates for secure IPL.
+#
+# @path: path to an X.509 certificate file or a directory containing
+# certificate files.
+#
+# Since: 11.1
+##
+{ 'struct': 'BootCertificates',
+ 'data': {'path': 'str'} }
+
+##
+# @DummyBootCertificates:
+#
+# Not used by QMP; hack to let us use BootCertificatesList internally.
+#
+# Since: 11.1
+##
+{ 'struct': 'DummyBootCertificates',
+ 'data': {'unused-boot-certs': ['BootCertificates'] } }
diff --git a/qapi/pragma.json b/qapi/pragma.json
index 24aebbe8f5..342cedc42e 100644
--- a/qapi/pragma.json
+++ b/qapi/pragma.json
@@ -49,6 +49,7 @@
'DisplayProtocol',
'DriveBackupWrapper',
'DummyBlockCoreForceArrays',
+ 'DummyBootCertificates',
'DummyForceArrays',
'DummyVirtioForceArrays',
'HotKeyMod',
diff --git a/qemu-options.hx b/qemu-options.hx
index e44b47de68..83915bd7ef 100644
--- a/qemu-options.hx
+++ b/qemu-options.hx
@@ -46,7 +46,8 @@ DEF("machine", HAS_ARG, QEMU_OPTION_machine, \
" memory-backend='backend-id' specifies explicitly provided
backend for main RAM (default=none)\n"
"
cxl-fmw.0.targets.0=firsttarget,cxl-fmw.0.targets.1=secondtarget,cxl-fmw.0.size=size[,cxl-fmw.0.interleave-granularity=granularity]\n"
" sgx-epc.0.memdev=memid,sgx-epc.0.node=numaid\n"
- "
smp-cache.0.cache=cachename,smp-cache.0.topology=topologylevel\n",
+ "
smp-cache.0.cache=cachename,smp-cache.0.topology=topologylevel\n"
+ "
boot-certs.0.path=/path/directory,boot-certs.1.path=/path/file provides paths
to a directory and/or a certificate file\n",
QEMU_ARCH_ALL)
SRST
``-machine [type=]name[,prop=value[,...]]``
@@ -214,6 +215,9 @@ SRST
::
-machine
smp-cache.0.cache=l1d,smp-cache.0.topology=core,smp-cache.1.cache=l1i,smp-cache.1.topology=core
+
+ ``boot-certs.0.path=/path/directory,boot-certs.1.path=/path/file``
+ Provide paths to a directory and/or a certificate file on the host
[s390x only].
ERST
DEF("M", HAS_ARG, QEMU_OPTION_M,
--
2.54.0