I would like to understand the design of the KVM/ARM implementation with regard to making ARM's TrustZone capabilities available to a VM.
I have read on several mailing lists that Qemu will have some limited support for TrustZone, so that at least you will be able to run secure firmware inside a VM. E.g. this will enable to use the smc instruction in a VM's boot loader, so that secure firmware implementations can be used and run on Qemu. So the first question is: is that already implemented and usable when running KVM on ARM? The second question is: in this design where TrustZone is "emulated" by Qemu, does KVM play a role in this as well? I assume that it cannot provide monitor mode in hardware (because it is running in hyp mode), so therefore it cannot provide any form of acceleration. Thanks, James |
_______________________________________________ kvmarm mailing list kvmarm@xxxxxxxxxxxxxxxxxxxxx https://lists.cs.columbia.edu/cucslists/listinfo/kvmarm