[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PATCH v4 07/15] target-arm: Add virt machine secure proper
From: |
Greg Bellows |
Subject: |
[Qemu-devel] [PATCH v4 07/15] target-arm: Add virt machine secure property |
Date: |
Mon, 15 Dec 2014 17:09:44 -0600 |
Add "secure" virt machine specific property to allow override of the
default secure state configuration. By default, when using the QEMU
-kernel command line argument, virt machines boot into NS/SVC. When using
the QEMU -bios command line argument, virt machines boot into S/SVC.
The secure state can be changed from the default specifying the secure
state as a machine property. For example, the below command line would disable
security extensions on a -kernel Linux boot:
aarch64-softmmu/qemu-system-aarch64
-machine type=virt,secure=off
-kernel ...
Signed-off-by: Greg Bellows <address@hidden>
Reviewed-by: Peter Maydell <address@hidden>
---
v1 -> v2
- Adapt the machine secure property to Marcel's new dynamic registration
- Change the default machine secure property to true (on).
v3 -> v4
- Revise machine secure property description
---
hw/arm/virt.c | 30 ++++++++++++++++++++++++++++++
1 file changed, 30 insertions(+)
diff --git a/hw/arm/virt.c b/hw/arm/virt.c
index b6bb914..73c68c7 100644
--- a/hw/arm/virt.c
+++ b/hw/arm/virt.c
@@ -93,6 +93,7 @@ typedef struct {
typedef struct {
MachineState parent;
+ bool secure;
} VirtMachineState;
#define TYPE_VIRT_MACHINE "virt"
@@ -632,6 +633,34 @@ static void machvirt_init(MachineState *machine)
arm_load_kernel(ARM_CPU(first_cpu), &vbi->bootinfo);
}
+static bool virt_get_secure(Object *obj, Error **errp)
+{
+ VirtMachineState *vms = VIRT_MACHINE(obj);
+
+ return vms->secure;
+}
+
+static void virt_set_secure(Object *obj, bool value, Error **errp)
+{
+ VirtMachineState *vms = VIRT_MACHINE(obj);
+
+ vms->secure = value;
+}
+
+static void virt_instance_init(Object *obj)
+{
+ VirtMachineState *vms = VIRT_MACHINE(obj);
+
+ /* EL3 is enabled by default on virt */
+ vms->secure = true;
+ object_property_add_bool(obj, "secure", virt_get_secure,
+ virt_set_secure, NULL);
+ object_property_set_description(obj, "secure",
+ "Set on/off to enable/disable the ARM "
+ "Security Extensions (TrustZone)",
+ NULL);
+}
+
static void virt_class_init(ObjectClass *oc, void *data)
{
MachineClass *mc = MACHINE_CLASS(oc);
@@ -646,6 +675,7 @@ static const TypeInfo machvirt_info = {
.name = TYPE_VIRT_MACHINE,
.parent = TYPE_MACHINE,
.instance_size = sizeof(VirtMachineState),
+ .instance_init = virt_instance_init,
.class_size = sizeof(VirtMachineClass),
.class_init = virt_class_init,
};
--
1.8.3.2
- [Qemu-devel] [PATCH v4 00/15] target-arm: Add CPU security extension enablement, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 01/15] target-arm: Add vexpress class and machine types, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 02/15] target-arm: Add vexpress a9 & a15 machine objects, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 03/15] target-arm: Switch to common vexpress machine init, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 05/15] target-arm: Change vexpress daughterboard init arg, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 04/15] target-arm: Add vexpress machine secure property, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 06/15] target-arm: Add virt class and machine types, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 07/15] target-arm: Add virt machine secure property,
Greg Bellows <=
- [Qemu-devel] [PATCH v4 08/15] target-arm: Add feature unset function, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 09/15] target-arm: Add ARMCPU secure property, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 10/15] target-arm: Add arm_boot_info secure_boot control, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 11/15] target-arm: Enable CPU has_el3 prop during VE init, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 12/15] target-arm: Set CPU has_el3 prop during virt init, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 13/15] target-arm: Breakout integratorcp and versatilepb cpu init, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 14/15] target-arm: Disable EL3 on unsupported machines, Greg Bellows, 2014/12/15
- [Qemu-devel] [PATCH v4 15/15] target-arm: add cpu feature EL3 to CPUs with Security Extensions, Greg Bellows, 2014/12/15
- Re: [Qemu-devel] [PATCH v4 00/15] target-arm: Add CPU security extension enablement, Peter Maydell, 2014/12/16