Add, and optionally measure, TDVF memory via KVM_TDX_INIT_MEM_REGION as part of finalizing the TD. Signed-off-by: Isaku Yamahata <isaku.yamahata@xxxxxxxxx> Co-developed-by: Sean Christopherson <sean.j.christopherson@xxxxxxxxx> Signed-off-by: Sean Christopherson <sean.j.christopherson@xxxxxxxxx> --- target/i386/kvm/tdx.c | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/target/i386/kvm/tdx.c b/target/i386/kvm/tdx.c index 8e4bf98735..49b4355849 100644 --- a/target/i386/kvm/tdx.c +++ b/target/i386/kvm/tdx.c @@ -83,10 +83,26 @@ static void tdx_finalize_vm(Notifier *notifier, void *unused) { MachineState *ms = MACHINE(qdev_get_machine()); TdxGuest *tdx = TDX_GUEST(ms->cgs); + TdxFirmwareEntry *entry; tdvf_hob_create(tdx, tdx_get_hob_entry(tdx)); + for_each_fw_entry(&tdx->fw, entry) { + struct kvm_tdx_init_mem_region mem_region = { + .source_addr = (__u64)entry->mem_ptr, + .gpa = entry->address, + .nr_pages = entry->size / 4096, + }; + + __u32 metadata = entry->attributes & TDVF_SECTION_ATTRIBUTES_EXTENDMR ? + KVM_TDX_MEASURE_MEMORY_REGION : 0; + + tdx_ioctl(KVM_TDX_INIT_MEM_REGION, metadata, &mem_region); + } + tdx_ioctl(KVM_TDX_FINALIZE_VM, 0, NULL); + + tdx->parent_obj.ready = true; } static Notifier tdx_machine_done_late_notify = { @@ -288,9 +304,6 @@ static void tdx_guest_init(Object *obj) tdx->debug = false; object_property_add_bool(obj, "debug", tdx_guest_get_debug, tdx_guest_set_debug); - - /* TODO: move this after fully TD initialized */ - tdx->parent_obj.ready = true; } static void tdx_guest_finalize(Object *obj) -- 2.17.1