[PATCH v16 25/33] s390x: Guest support for Secure-IPL Code Loading Attributes Facility (SCLAF)

2026-07-07 Thread Zhuoying Cai
The secure-IPL-code-loading-attributes facility (SCLAF)
provides additional security during secure IPL.

Availability of SCLAF is determined by byte 136 bit 3 of the
SCLP Read SCP Info.

This feature is available starting with the gen16 CPU model.

Signed-off-by: Zhuoying Cai 
Reviewed-by: Collin Walling 
Reviewed-by: Matthew Rosato 
---
 docs/specs/s390x-secure-ipl.rst | 18 ++
 target/s390x/cpu_features.c |  2 ++
 target/s390x/cpu_features_def.h.inc |  1 +
 target/s390x/cpu_models.c   |  3 +++
 target/s390x/gen-features.c |  2 ++
 target/s390x/kvm/kvm.c  |  1 +
 6 files changed, 27 insertions(+)

diff --git a/docs/specs/s390x-secure-ipl.rst b/docs/specs/s390x-secure-ipl.rst
index 113acbeda9..7a603eb956 100644
--- a/docs/specs/s390x-secure-ipl.rst
+++ b/docs/specs/s390x-secure-ipl.rst
@@ -122,3 +122,21 @@ The guest kernel uses the contents in the IIRB for:
 * Boot logging: reports which components were loaded and verified.
 * kexec operations: builds the next kernel’s IPL report from the existing one.
 * Keying: installs IPL certificates into the platform trusted keyring.
+
+Secure Code Loading Attributes Facility
+^^^
+
+The Secure Code Loading Attributes Facility (SCLAF) enhances system security
+during the IPL by enforcing additional verification rules.
+
+When SCLAF is available, its behavior depends on the IPL mode. It introduces
+verification of both signed and unsigned components to help ensure that only
+authorized code is loaded during the IPL process. Any errors detected by SCLAF
+are reported in the IIRB.
+
+Unsigned components are restricted to load addresses at or above absolute
+storage address ``0x2000``.
+
+Signed components must include a Secure Code Loading Attribute Block (SCLAB),
+which is appended at the very end of the component. The SCLAB defines security
+attributes for handling the signed code.
diff --git a/target/s390x/cpu_features.c b/target/s390x/cpu_features.c
index 27f38636a9..c634e74123 100644
--- a/target/s390x/cpu_features.c
+++ b/target/s390x/cpu_features.c
@@ -120,6 +120,7 @@ void s390_fill_feat_block(const S390FeatBitmap features, 
S390FeatType type,
  * - All SIE facilities because SIE is not available
  * - DIAG318
  * - Secure IPL Facility
+ * - Secure IPL Code Loading Attributes Facility
  *
  * As VMs can move in and out of protected mode the CPU model
  * doesn't protect us from that problem because it is only
@@ -152,6 +153,7 @@ void s390_fill_feat_block(const S390FeatBitmap features, 
S390FeatType type,
 break;
 case S390_FEAT_TYPE_SCLP_FAC_IPL:
 clear_be_bit(s390_feat_def(S390_FEAT_SIPL)->bit, data);
+clear_be_bit(s390_feat_def(S390_FEAT_SCLAF)->bit, data);
 break;
 case S390_FEAT_TYPE_SCLP_FAC139:
 clear_be_bit(s390_feat_def(S390_FEAT_SIE_ASTFLEIE2)->bit, data);
diff --git a/target/s390x/cpu_features_def.h.inc 
b/target/s390x/cpu_features_def.h.inc
index 0153a6aa67..a5aa19112a 100644
--- a/target/s390x/cpu_features_def.h.inc
+++ b/target/s390x/cpu_features_def.h.inc
@@ -142,6 +142,7 @@ DEF_FEAT(CERT_STORE, "cstore", SCLP_FAC134, 5, "Certificate 
Store functions")
 
 /* Features exposed via SCLP SCCB Facilities byte 136 - 137 (bit numbers 
relative to byte-136) */
 DEF_FEAT(SIPL, "sipl", SCLP_FAC_IPL, 1, "Secure-IPL facility")
+DEF_FEAT(SCLAF, "sclaf", SCLP_FAC_IPL, 3, "Secure-IPL-code-loading-attributes 
facility")
 
 /* Features exposed via SCLP SCCB Facilities byte 139 (bit numbers relative to 
byte-139) */
 DEF_FEAT(SIE_ASTFLEIE2, "astfleie2", SCLP_FAC139, 1, "SIE: ASTFLE 
interpretation execution facility 2")
diff --git a/target/s390x/cpu_models.c b/target/s390x/cpu_models.c
index b22841c2bc..2e62559679 100644
--- a/target/s390x/cpu_models.c
+++ b/target/s390x/cpu_models.c
@@ -264,6 +264,7 @@ bool s390_has_feat(S390Feat feat)
 case S390_FEAT_SIE_PFMFI:
 case S390_FEAT_SIE_IBS:
 case S390_FEAT_SIPL:
+case S390_FEAT_SCLAF:
 case S390_FEAT_CONFIGURATION_TOPOLOGY:
 case S390_FEAT_SIE_ASTFLEIE2:
 return false;
@@ -510,6 +511,8 @@ static void check_consistency(const S390CPUModel *model)
 { S390_FEAT_DIAG_318, S390_FEAT_EXTENDED_LENGTH_SCCB },
 { S390_FEAT_CERT_STORE, S390_FEAT_EXTENDED_LENGTH_SCCB },
 { S390_FEAT_SIPL, S390_FEAT_EXTENDED_LENGTH_SCCB },
+{ S390_FEAT_SCLAF, S390_FEAT_EXTENDED_LENGTH_SCCB },
+{ S390_FEAT_SCLAF, S390_FEAT_SIPL },
 { S390_FEAT_NNPA, S390_FEAT_VECTOR },
 { S390_FEAT_RDP, S390_FEAT_LOCAL_TLB_CLEARING },
 { S390_FEAT_UV_FEAT_AP, S390_FEAT_AP },
diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c
index 6bf61447de..a99a75d14e 100644
--- a/target/s390x/gen-features.c
+++ b/target/s390x/gen-features.c
@@ -723,6 +723,7 @@ static uint16_t full_GEN16_GA1[] = {
 S390_FEAT_SIE_ASTFLEIE2,
 S390_FEAT_CERT_STORE,
 S390_FEAT_SIPL,
+ 

[PATCH v16 25/33] s390x: Guest support for Secure-IPL Code Loading Attributes Facility (SCLAF)

2026-07-07 Thread Zhuoying Cai
The secure-IPL-code-loading-attributes facility (SCLAF)
provides additional security during secure IPL.

Availability of SCLAF is determined by byte 136 bit 3 of the
SCLP Read SCP Info.

This feature is available starting with the gen16 CPU model.

Signed-off-by: Zhuoying Cai 
Reviewed-by: Collin Walling 
Reviewed-by: Matthew Rosato 
---
 docs/specs/s390x-secure-ipl.rst | 18 ++
 target/s390x/cpu_features.c |  2 ++
 target/s390x/cpu_features_def.h.inc |  1 +
 target/s390x/cpu_models.c   |  3 +++
 target/s390x/gen-features.c |  2 ++
 target/s390x/kvm/kvm.c  |  1 +
 6 files changed, 27 insertions(+)

diff --git a/docs/specs/s390x-secure-ipl.rst b/docs/specs/s390x-secure-ipl.rst
index 113acbeda9..7a603eb956 100644
--- a/docs/specs/s390x-secure-ipl.rst
+++ b/docs/specs/s390x-secure-ipl.rst
@@ -122,3 +122,21 @@ The guest kernel uses the contents in the IIRB for:
 * Boot logging: reports which components were loaded and verified.
 * kexec operations: builds the next kernel’s IPL report from the existing one.
 * Keying: installs IPL certificates into the platform trusted keyring.
+
+Secure Code Loading Attributes Facility
+^^^
+
+The Secure Code Loading Attributes Facility (SCLAF) enhances system security
+during the IPL by enforcing additional verification rules.
+
+When SCLAF is available, its behavior depends on the IPL mode. It introduces
+verification of both signed and unsigned components to help ensure that only
+authorized code is loaded during the IPL process. Any errors detected by SCLAF
+are reported in the IIRB.
+
+Unsigned components are restricted to load addresses at or above absolute
+storage address ``0x2000``.
+
+Signed components must include a Secure Code Loading Attribute Block (SCLAB),
+which is appended at the very end of the component. The SCLAB defines security
+attributes for handling the signed code.
diff --git a/target/s390x/cpu_features.c b/target/s390x/cpu_features.c
index 27f38636a9..c634e74123 100644
--- a/target/s390x/cpu_features.c
+++ b/target/s390x/cpu_features.c
@@ -120,6 +120,7 @@ void s390_fill_feat_block(const S390FeatBitmap features, 
S390FeatType type,
  * - All SIE facilities because SIE is not available
  * - DIAG318
  * - Secure IPL Facility
+ * - Secure IPL Code Loading Attributes Facility
  *
  * As VMs can move in and out of protected mode the CPU model
  * doesn't protect us from that problem because it is only
@@ -152,6 +153,7 @@ void s390_fill_feat_block(const S390FeatBitmap features, 
S390FeatType type,
 break;
 case S390_FEAT_TYPE_SCLP_FAC_IPL:
 clear_be_bit(s390_feat_def(S390_FEAT_SIPL)->bit, data);
+clear_be_bit(s390_feat_def(S390_FEAT_SCLAF)->bit, data);
 break;
 case S390_FEAT_TYPE_SCLP_FAC139:
 clear_be_bit(s390_feat_def(S390_FEAT_SIE_ASTFLEIE2)->bit, data);
diff --git a/target/s390x/cpu_features_def.h.inc 
b/target/s390x/cpu_features_def.h.inc
index 0153a6aa67..a5aa19112a 100644
--- a/target/s390x/cpu_features_def.h.inc
+++ b/target/s390x/cpu_features_def.h.inc
@@ -142,6 +142,7 @@ DEF_FEAT(CERT_STORE, "cstore", SCLP_FAC134, 5, "Certificate 
Store functions")
 
 /* Features exposed via SCLP SCCB Facilities byte 136 - 137 (bit numbers 
relative to byte-136) */
 DEF_FEAT(SIPL, "sipl", SCLP_FAC_IPL, 1, "Secure-IPL facility")
+DEF_FEAT(SCLAF, "sclaf", SCLP_FAC_IPL, 3, "Secure-IPL-code-loading-attributes 
facility")
 
 /* Features exposed via SCLP SCCB Facilities byte 139 (bit numbers relative to 
byte-139) */
 DEF_FEAT(SIE_ASTFLEIE2, "astfleie2", SCLP_FAC139, 1, "SIE: ASTFLE 
interpretation execution facility 2")
diff --git a/target/s390x/cpu_models.c b/target/s390x/cpu_models.c
index b22841c2bc..2e62559679 100644
--- a/target/s390x/cpu_models.c
+++ b/target/s390x/cpu_models.c
@@ -264,6 +264,7 @@ bool s390_has_feat(S390Feat feat)
 case S390_FEAT_SIE_PFMFI:
 case S390_FEAT_SIE_IBS:
 case S390_FEAT_SIPL:
+case S390_FEAT_SCLAF:
 case S390_FEAT_CONFIGURATION_TOPOLOGY:
 case S390_FEAT_SIE_ASTFLEIE2:
 return false;
@@ -510,6 +511,8 @@ static void check_consistency(const S390CPUModel *model)
 { S390_FEAT_DIAG_318, S390_FEAT_EXTENDED_LENGTH_SCCB },
 { S390_FEAT_CERT_STORE, S390_FEAT_EXTENDED_LENGTH_SCCB },
 { S390_FEAT_SIPL, S390_FEAT_EXTENDED_LENGTH_SCCB },
+{ S390_FEAT_SCLAF, S390_FEAT_EXTENDED_LENGTH_SCCB },
+{ S390_FEAT_SCLAF, S390_FEAT_SIPL },
 { S390_FEAT_NNPA, S390_FEAT_VECTOR },
 { S390_FEAT_RDP, S390_FEAT_LOCAL_TLB_CLEARING },
 { S390_FEAT_UV_FEAT_AP, S390_FEAT_AP },
diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c
index 6bf61447de..a99a75d14e 100644
--- a/target/s390x/gen-features.c
+++ b/target/s390x/gen-features.c
@@ -723,6 +723,7 @@ static uint16_t full_GEN16_GA1[] = {
 S390_FEAT_SIE_ASTFLEIE2,
 S390_FEAT_CERT_STORE,
 S390_FEAT_SIPL,
+