|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [PATCH 03/28] hw: mark all virtio PCI devices as secure
On Fri, Oct 02, 2026 at 09:21:01PM +0400, marcandre.lureau@xxxxxxxxxx wrote:
> > These are all intended for use in a virtualization scenario and must
> > provide a security boundary. This can be done for almost all virtio
> > PCI devices by modifying the common type register helper.
> >
> > The virtio-gpu devices are unusual in not using the common
> > virtio_pci_types_register() method, so need marking directly.
> >
> > Signed-off-by: Daniel P. Berrangé <berrange@xxxxxxxxxx>
> > Message-ID: <20260911143627.2743803-4-berrange@xxxxxxxxxx>
> >
> > diff --git a/hw/display/virtio-gpu-pci-rutabaga.c
> > b/hw/display/virtio-gpu-pci-rutabaga.c
> > index 4db77cb868db..a8e5e1d96cf3 100644
> > --- a/hw/display/virtio-gpu-pci-rutabaga.c
> > +++ b/hw/display/virtio-gpu-pci-rutabaga.c
> > @@ -34,6 +34,7 @@ static const TypeInfo virtio_gpu_rutabaga_pci_info[] = {
> > .parent = TYPE_VIRTIO_GPU_PCI_BASE,
> > .instance_size = sizeof(VirtIOGPURutabagaPCI),
> > .instance_init = virtio_gpu_rutabaga_initfn,
> > + .secure = true,
>
> This is unusual, I wonder why it's not using the VirtioPCIDeviceTypeInfo
Yeah, I don't know the reason for that choice.
>
> > .interfaces = (const InterfaceInfo[]) {
> > { INTERFACE_CONVENTIONAL_PCI_DEVICE },
> > { },
> > diff --git a/hw/display/virtio-gpu-pci.c b/hw/display/virtio-gpu-pci.c
> > index 22659ca196b5..0b0d926a5b95 100644
> > --- a/hw/display/virtio-gpu-pci.c
> > +++ b/hw/display/virtio-gpu-pci.c
> > @@ -75,7 +75,8 @@ static const TypeInfo virtio_gpu_pci_base_info = {
> > .parent = TYPE_VIRTIO_PCI,
> > .instance_size = sizeof(VirtIOGPUPCIBase),
> > .class_init = virtio_gpu_pci_base_class_init,
> > - .abstract = true
> > + .abstract = true,
> > + .secure = true,
>
> This is a base class, probably doesn't need marking.
Not /yet/. I have a follow on series to this, not yet posted,
which will enforce that all parent classes are marked secure,
when any leaf is marked secure. There will be many more base
classes to add besides this one, which crept in here.
With regards,
Daniel
--
|: https://berrange.com ~~ https://hachyderm.io/@berrange :|
|: https://libvirt.org ~~ https://entangle-photo.org :|
|: https://pixelfed.art/berrange ~~ https://fstop138.berrange.com :|
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |