[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PATCH v11 20/28] hw/i386: set ram_debug_ops when memory en
From: |
Brijesh Singh |
Subject: |
[Qemu-devel] [PATCH v11 20/28] hw/i386: set ram_debug_ops when memory encryption is enabled |
Date: |
Wed, 7 Mar 2018 10:50:30 -0600 |
When memory encryption is enabled, the guest RAM and boot flash ROM will
contain the encrypted data. By setting the debug ops allow us to invoke
encryption APIs when accessing the memory for the debug purposes.
Cc: Paolo Bonzini <address@hidden>
Cc: Richard Henderson <address@hidden>
Cc: Eduardo Habkost <address@hidden>
Cc: "Michael S. Tsirkin" <address@hidden>
Signed-off-by: Brijesh Singh <address@hidden>
---
hw/i386/pc.c | 9 +++++++++
hw/i386/pc_sysfw.c | 6 ++++++
2 files changed, 15 insertions(+)
diff --git a/hw/i386/pc.c b/hw/i386/pc.c
index 94cfd40ef2c8..2aed48cdf13d 100644
--- a/hw/i386/pc.c
+++ b/hw/i386/pc.c
@@ -1360,6 +1360,15 @@ void pc_memory_init(PCMachineState *pcms,
e820_add_entry(0x100000000ULL, pcms->above_4g_mem_size, E820_RAM);
}
+ /*
+ * When memory encryption is enabled, the guest RAM will be encrypted with
+ * a guest unique key. Set the debug ops so that any debug access to the
+ * guest RAM will go through the memory encryption APIs.
+ */
+ if (kvm_memcrypt_enabled()) {
+ kvm_memcrypt_set_debug_ops(ram);
+ }
+
if (!pcmc->has_reserved_memory &&
(machine->ram_slots ||
(machine->maxram_size > machine->ram_size))) {
diff --git a/hw/i386/pc_sysfw.c b/hw/i386/pc_sysfw.c
index 73ac783f2055..845240f97293 100644
--- a/hw/i386/pc_sysfw.c
+++ b/hw/i386/pc_sysfw.c
@@ -181,6 +181,12 @@ static void pc_system_flash_init(MemoryRegion *rom_memory)
error_report("failed to encrypt pflash rom");
exit(1);
}
+
+ /*
+ * The pflash ROM is encrypted, set the debug ops so that any
+ * debug accesses will use memory encryption APIs.
+ */
+ kvm_memcrypt_set_debug_ops(flash_mem);
}
}
}
--
2.14.3
- [Qemu-devel] [PATCH v11 03/28] exec: add debug version of physical memory read and write API, (continued)
- [Qemu-devel] [PATCH v11 03/28] exec: add debug version of physical memory read and write API, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 04/28] monitor/i386: use debug APIs when accessing guest memory, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 06/28] kvm: update kvm.h to include memory encryption ioctls, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 05/28] machine: add -memory-encryption property, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 07/28] docs: add AMD Secure Encrypted Virtualization (SEV), Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 09/28] qmp: add query-sev command, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 08/28] target/i386: add Secure Encrypted Virtulization (SEV) object, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 12/28] sev/i386: register the guest memory range which may contain encrypted data, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 10/28] include: add psp-sev.h header file, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 15/28] sev/i386: add command to create launch memory encryption context, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 20/28] hw/i386: set ram_debug_ops when memory encryption is enabled,
Brijesh Singh <=
- [Qemu-devel] [PATCH v11 19/28] sev/i386: finalize the SEV guest launch flow, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 16/28] sev/i386: add command to encrypt guest memory region, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 18/28] sev/i386: add support to LAUNCH_MEASURE command, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 23/28] qmp: add query-sev-launch-measure command, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 11/28] sev/i386: add command to initialize the memory encryption context, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 14/28] hmp: add 'info sev' command, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 13/28] kvm: introduce memory encryption APIs, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 17/28] target/i386: encrypt bios rom, Brijesh Singh, 2018/03/07
- [Qemu-devel] [PATCH v11 21/28] sev/i386: add debug encrypt and decrypt commands, Brijesh Singh, 2018/03/07