2019-02-19 11:07:46 +01:00
|
|
|
/*
|
|
|
|
* qemu_firmware.c: QEMU firmware
|
|
|
|
*
|
|
|
|
* Copyright (C) 2019 Red Hat, Inc.
|
|
|
|
*
|
|
|
|
* This library is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU Lesser General Public
|
|
|
|
* License as published by the Free Software Foundation; either
|
|
|
|
* version 2.1 of the License, or (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This library is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
|
|
* Lesser General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU Lesser General Public
|
|
|
|
* License along with this library. If not, see
|
|
|
|
* <http://www.gnu.org/licenses/>.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include <config.h>
|
|
|
|
|
|
|
|
#include "qemu_firmware.h"
|
2019-09-23 14:44:24 +04:00
|
|
|
#include "qemu_interop_config.h"
|
2019-02-21 13:16:41 +01:00
|
|
|
#include "configmake.h"
|
2019-02-19 11:07:46 +01:00
|
|
|
#include "qemu_capabilities.h"
|
2019-02-22 15:25:31 +01:00
|
|
|
#include "qemu_domain.h"
|
|
|
|
#include "qemu_process.h"
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
#include "domain_validate.h"
|
2019-02-19 11:07:46 +01:00
|
|
|
#include "virarch.h"
|
|
|
|
#include "virjson.h"
|
|
|
|
#include "virlog.h"
|
2019-04-01 16:28:05 +02:00
|
|
|
#include "viralloc.h"
|
2019-04-01 12:14:26 +02:00
|
|
|
#include "virenum.h"
|
2023-05-30 18:24:40 +02:00
|
|
|
#include "virstring.h"
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
#define VIR_FROM_THIS VIR_FROM_QEMU
|
|
|
|
|
|
|
|
VIR_LOG_INIT("qemu.qemu_firmware");
|
|
|
|
|
|
|
|
|
|
|
|
typedef enum {
|
|
|
|
QEMU_FIRMWARE_OS_INTERFACE_NONE = 0,
|
|
|
|
QEMU_FIRMWARE_OS_INTERFACE_BIOS,
|
|
|
|
QEMU_FIRMWARE_OS_INTERFACE_OPENFIRMWARE,
|
|
|
|
QEMU_FIRMWARE_OS_INTERFACE_UBOOT,
|
|
|
|
QEMU_FIRMWARE_OS_INTERFACE_UEFI,
|
|
|
|
|
|
|
|
QEMU_FIRMWARE_OS_INTERFACE_LAST
|
|
|
|
} qemuFirmwareOSInterface;
|
|
|
|
|
|
|
|
VIR_ENUM_DECL(qemuFirmwareOSInterface);
|
|
|
|
VIR_ENUM_IMPL(qemuFirmwareOSInterface,
|
|
|
|
QEMU_FIRMWARE_OS_INTERFACE_LAST,
|
|
|
|
"",
|
|
|
|
"bios",
|
|
|
|
"openfirmware",
|
|
|
|
"uboot",
|
|
|
|
"uefi",
|
|
|
|
);
|
|
|
|
|
|
|
|
|
2022-02-03 13:43:18 +00:00
|
|
|
typedef enum {
|
|
|
|
QEMU_FIRMWARE_FLASH_MODE_SPLIT,
|
|
|
|
QEMU_FIRMWARE_FLASH_MODE_COMBINED,
|
|
|
|
QEMU_FIRMWARE_FLASH_MODE_STATELESS,
|
|
|
|
|
|
|
|
QEMU_FIRMWARE_FLASH_MODE_LAST,
|
|
|
|
} qemuFirmwareFlashMode;
|
|
|
|
|
|
|
|
VIR_ENUM_DECL(qemuFirmwareFlashMode);
|
|
|
|
VIR_ENUM_IMPL(qemuFirmwareFlashMode,
|
|
|
|
QEMU_FIRMWARE_FLASH_MODE_LAST,
|
|
|
|
"split",
|
|
|
|
"combined",
|
|
|
|
"stateless",
|
|
|
|
);
|
|
|
|
|
2019-02-19 11:07:46 +01:00
|
|
|
typedef struct _qemuFirmwareFlashFile qemuFirmwareFlashFile;
|
|
|
|
struct _qemuFirmwareFlashFile {
|
|
|
|
char *filename;
|
|
|
|
char *format;
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct _qemuFirmwareMappingFlash qemuFirmwareMappingFlash;
|
|
|
|
struct _qemuFirmwareMappingFlash {
|
2022-02-03 13:43:18 +00:00
|
|
|
qemuFirmwareFlashMode mode;
|
2019-02-19 11:07:46 +01:00
|
|
|
qemuFirmwareFlashFile executable;
|
|
|
|
qemuFirmwareFlashFile nvram_template;
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct _qemuFirmwareMappingKernel qemuFirmwareMappingKernel;
|
|
|
|
struct _qemuFirmwareMappingKernel {
|
|
|
|
char *filename;
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct _qemuFirmwareMappingMemory qemuFirmwareMappingMemory;
|
|
|
|
struct _qemuFirmwareMappingMemory {
|
|
|
|
char *filename;
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
typedef enum {
|
|
|
|
QEMU_FIRMWARE_DEVICE_NONE = 0,
|
|
|
|
QEMU_FIRMWARE_DEVICE_FLASH,
|
|
|
|
QEMU_FIRMWARE_DEVICE_KERNEL,
|
|
|
|
QEMU_FIRMWARE_DEVICE_MEMORY,
|
|
|
|
|
|
|
|
QEMU_FIRMWARE_DEVICE_LAST
|
|
|
|
} qemuFirmwareDevice;
|
|
|
|
|
|
|
|
VIR_ENUM_DECL(qemuFirmwareDevice);
|
|
|
|
VIR_ENUM_IMPL(qemuFirmwareDevice,
|
|
|
|
QEMU_FIRMWARE_DEVICE_LAST,
|
|
|
|
"",
|
|
|
|
"flash",
|
|
|
|
"kernel",
|
|
|
|
"memory",
|
|
|
|
);
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct _qemuFirmwareMapping qemuFirmwareMapping;
|
|
|
|
struct _qemuFirmwareMapping {
|
|
|
|
qemuFirmwareDevice device;
|
|
|
|
|
|
|
|
union {
|
|
|
|
qemuFirmwareMappingFlash flash;
|
|
|
|
qemuFirmwareMappingKernel kernel;
|
|
|
|
qemuFirmwareMappingMemory memory;
|
|
|
|
} data;
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct _qemuFirmwareTarget qemuFirmwareTarget;
|
|
|
|
struct _qemuFirmwareTarget {
|
|
|
|
virArch architecture;
|
|
|
|
size_t nmachines;
|
|
|
|
char **machines;
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
typedef enum {
|
|
|
|
QEMU_FIRMWARE_FEATURE_NONE = 0,
|
|
|
|
QEMU_FIRMWARE_FEATURE_ACPI_S3,
|
|
|
|
QEMU_FIRMWARE_FEATURE_ACPI_S4,
|
|
|
|
QEMU_FIRMWARE_FEATURE_AMD_SEV,
|
2021-05-25 09:56:38 +02:00
|
|
|
QEMU_FIRMWARE_FEATURE_AMD_SEV_ES,
|
2019-02-19 11:07:46 +01:00
|
|
|
QEMU_FIRMWARE_FEATURE_ENROLLED_KEYS,
|
|
|
|
QEMU_FIRMWARE_FEATURE_REQUIRES_SMM,
|
|
|
|
QEMU_FIRMWARE_FEATURE_SECURE_BOOT,
|
|
|
|
QEMU_FIRMWARE_FEATURE_VERBOSE_DYNAMIC,
|
|
|
|
QEMU_FIRMWARE_FEATURE_VERBOSE_STATIC,
|
|
|
|
|
|
|
|
QEMU_FIRMWARE_FEATURE_LAST
|
|
|
|
} qemuFirmwareFeature;
|
|
|
|
|
|
|
|
VIR_ENUM_DECL(qemuFirmwareFeature);
|
|
|
|
VIR_ENUM_IMPL(qemuFirmwareFeature,
|
|
|
|
QEMU_FIRMWARE_FEATURE_LAST,
|
|
|
|
"",
|
|
|
|
"acpi-s3",
|
|
|
|
"acpi-s4",
|
|
|
|
"amd-sev",
|
2021-05-25 09:56:38 +02:00
|
|
|
"amd-sev-es",
|
2019-02-19 11:07:46 +01:00
|
|
|
"enrolled-keys",
|
|
|
|
"requires-smm",
|
|
|
|
"secure-boot",
|
|
|
|
"verbose-dynamic",
|
|
|
|
"verbose-static"
|
|
|
|
);
|
|
|
|
|
|
|
|
|
|
|
|
struct _qemuFirmware {
|
|
|
|
/* Description intentionally not parsed. */
|
|
|
|
|
|
|
|
size_t ninterfaces;
|
|
|
|
qemuFirmwareOSInterface *interfaces;
|
|
|
|
|
|
|
|
qemuFirmwareMapping mapping;
|
|
|
|
|
|
|
|
size_t ntargets;
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareTarget **targets;
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
size_t nfeatures;
|
|
|
|
qemuFirmwareFeature *features;
|
|
|
|
|
|
|
|
/* Tags intentionally not parsed. */
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
static void
|
|
|
|
qemuFirmwareOSInterfaceFree(qemuFirmwareOSInterface *interfaces)
|
|
|
|
{
|
2021-02-03 14:36:01 -05:00
|
|
|
g_free(interfaces);
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2019-10-15 14:47:50 +02:00
|
|
|
G_DEFINE_AUTOPTR_CLEANUP_FUNC(qemuFirmwareOSInterface, qemuFirmwareOSInterfaceFree);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
|
|
|
|
static void
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareFlashFileFreeContent(qemuFirmwareFlashFile *flash)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2021-02-03 21:07:20 -05:00
|
|
|
g_free(flash->filename);
|
|
|
|
g_free(flash->format);
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static void
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareMappingFlashFreeContent(qemuFirmwareMappingFlash *flash)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2021-02-03 16:57:57 -05:00
|
|
|
qemuFirmwareFlashFileFreeContent(&flash->executable);
|
|
|
|
qemuFirmwareFlashFileFreeContent(&flash->nvram_template);
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static void
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareMappingKernelFreeContent(qemuFirmwareMappingKernel *kernel)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2021-02-03 21:07:20 -05:00
|
|
|
g_free(kernel->filename);
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static void
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareMappingMemoryFreeContent(qemuFirmwareMappingMemory *memory)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2021-02-03 21:07:20 -05:00
|
|
|
g_free(memory->filename);
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static void
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareMappingFreeContent(qemuFirmwareMapping *mapping)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2021-02-03 16:57:57 -05:00
|
|
|
switch (mapping->device) {
|
2019-02-19 11:07:46 +01:00
|
|
|
case QEMU_FIRMWARE_DEVICE_FLASH:
|
2021-02-03 16:57:57 -05:00
|
|
|
qemuFirmwareMappingFlashFreeContent(&mapping->data.flash);
|
2019-02-19 11:07:46 +01:00
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_DEVICE_KERNEL:
|
2021-02-03 16:57:57 -05:00
|
|
|
qemuFirmwareMappingKernelFreeContent(&mapping->data.kernel);
|
2019-02-19 11:07:46 +01:00
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_DEVICE_MEMORY:
|
2021-02-03 16:57:57 -05:00
|
|
|
qemuFirmwareMappingMemoryFreeContent(&mapping->data.memory);
|
2019-02-19 11:07:46 +01:00
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_DEVICE_NONE:
|
|
|
|
case QEMU_FIRMWARE_DEVICE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static void
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareTargetFree(qemuFirmwareTarget *target)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
|
|
|
if (!target)
|
|
|
|
return;
|
|
|
|
|
2021-06-16 09:29:01 +02:00
|
|
|
g_strfreev(target->machines);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
2021-02-03 14:36:01 -05:00
|
|
|
g_free(target);
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2019-10-15 14:47:50 +02:00
|
|
|
G_DEFINE_AUTOPTR_CLEANUP_FUNC(qemuFirmwareTarget, qemuFirmwareTargetFree);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
|
|
|
|
static void
|
|
|
|
qemuFirmwareFeatureFree(qemuFirmwareFeature *features)
|
|
|
|
{
|
2021-02-03 14:36:01 -05:00
|
|
|
g_free(features);
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2019-10-15 14:47:50 +02:00
|
|
|
G_DEFINE_AUTOPTR_CLEANUP_FUNC(qemuFirmwareFeature, qemuFirmwareFeatureFree);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
|
|
|
|
void
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareFree(qemuFirmware *fw)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
|
|
|
size_t i;
|
|
|
|
|
|
|
|
if (!fw)
|
|
|
|
return;
|
|
|
|
|
|
|
|
qemuFirmwareOSInterfaceFree(fw->interfaces);
|
2021-02-03 16:57:57 -05:00
|
|
|
qemuFirmwareMappingFreeContent(&fw->mapping);
|
2019-02-19 11:07:46 +01:00
|
|
|
for (i = 0; i < fw->ntargets; i++)
|
|
|
|
qemuFirmwareTargetFree(fw->targets[i]);
|
2021-02-03 14:36:01 -05:00
|
|
|
g_free(fw->targets);
|
2019-02-19 11:07:46 +01:00
|
|
|
qemuFirmwareFeatureFree(fw->features);
|
|
|
|
|
2021-02-03 14:36:01 -05:00
|
|
|
g_free(fw);
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
|
|
|
qemuFirmwareInterfaceParse(const char *path,
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *doc,
|
|
|
|
qemuFirmware *fw)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *interfacesJSON;
|
2019-10-15 14:47:50 +02:00
|
|
|
g_autoptr(qemuFirmwareOSInterface) interfaces = NULL;
|
2019-10-15 14:47:50 +02:00
|
|
|
g_auto(virBuffer) buf = VIR_BUFFER_INITIALIZER;
|
2019-02-19 11:07:46 +01:00
|
|
|
size_t ninterfaces;
|
|
|
|
size_t i;
|
|
|
|
|
|
|
|
if (!(interfacesJSON = virJSONValueObjectGetArray(doc, "interface-types"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("failed to get interface-types from '%s'", path);
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
ninterfaces = virJSONValueArraySize(interfacesJSON);
|
|
|
|
|
2020-10-05 12:27:57 +02:00
|
|
|
interfaces = g_new0(qemuFirmwareOSInterface, ninterfaces);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
for (i = 0; i < ninterfaces; i++) {
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *item = virJSONValueArrayGet(interfacesJSON, i);
|
2019-02-19 11:07:46 +01:00
|
|
|
const char *tmpStr = virJSONValueGetString(item);
|
|
|
|
int tmp;
|
|
|
|
|
|
|
|
if ((tmp = qemuFirmwareOSInterfaceTypeFromString(tmpStr)) <= 0) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("unknown interface type: '%s'", tmpStr);
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
virBufferAsprintf(&buf, " %s", tmpStr);
|
|
|
|
interfaces[i] = tmp;
|
|
|
|
}
|
|
|
|
|
|
|
|
VIR_DEBUG("firmware description path '%s' supported interfaces: %s",
|
|
|
|
path, NULLSTR_MINUS(virBufferCurrentContent(&buf)));
|
|
|
|
|
2019-10-16 13:43:18 +02:00
|
|
|
fw->interfaces = g_steal_pointer(&interfaces);
|
2019-02-19 11:07:46 +01:00
|
|
|
fw->ninterfaces = ninterfaces;
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
|
|
|
qemuFirmwareFlashFileParse(const char *path,
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *doc,
|
|
|
|
qemuFirmwareFlashFile *flash)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
|
|
|
const char *filename;
|
|
|
|
const char *format;
|
|
|
|
|
|
|
|
if (!(filename = virJSONValueObjectGetString(doc, "filename"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("missing 'filename' in '%s'", path);
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2019-10-20 13:49:46 +02:00
|
|
|
flash->filename = g_strdup(filename);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
if (!(format = virJSONValueObjectGetString(doc, "format"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("missing 'format' in '%s'", path);
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2019-10-20 13:49:46 +02:00
|
|
|
flash->format = g_strdup(format);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
|
|
|
qemuFirmwareMappingFlashParse(const char *path,
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *doc,
|
|
|
|
qemuFirmwareMappingFlash *flash)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2022-02-03 13:43:18 +00:00
|
|
|
virJSONValue *mode;
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *executable;
|
|
|
|
virJSONValue *nvram_template;
|
2019-02-19 11:07:46 +01:00
|
|
|
|
2022-02-03 13:43:18 +00:00
|
|
|
if (!(mode = virJSONValueObjectGet(doc, "mode"))) {
|
|
|
|
/* Historical default */
|
|
|
|
flash->mode = QEMU_FIRMWARE_FLASH_MODE_SPLIT;
|
|
|
|
} else {
|
|
|
|
const char *modestr = virJSONValueGetString(mode);
|
|
|
|
int modeval;
|
|
|
|
if (!modestr) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("Firmware flash mode value was malformed");
|
2022-02-03 13:43:18 +00:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
modeval = qemuFirmwareFlashModeTypeFromString(modestr);
|
|
|
|
if (modeval < 0) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("Firmware flash mode value '%s' unexpected", modestr);
|
2022-02-03 13:43:18 +00:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
flash->mode = modeval;
|
|
|
|
}
|
|
|
|
|
2019-02-19 11:07:46 +01:00
|
|
|
if (!(executable = virJSONValueObjectGet(doc, "executable"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("missing 'executable' in '%s'", path);
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (qemuFirmwareFlashFileParse(path, executable, &flash->executable) < 0)
|
|
|
|
return -1;
|
|
|
|
|
2022-02-03 13:43:18 +00:00
|
|
|
if (flash->mode == QEMU_FIRMWARE_FLASH_MODE_SPLIT) {
|
|
|
|
if (!(nvram_template = virJSONValueObjectGet(doc, "nvram-template"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("missing 'nvram-template' in '%s'", path);
|
2022-02-03 13:43:18 +00:00
|
|
|
return -1;
|
|
|
|
}
|
2019-02-19 11:07:46 +01:00
|
|
|
|
2022-02-03 13:43:18 +00:00
|
|
|
if (qemuFirmwareFlashFileParse(path, nvram_template, &flash->nvram_template) < 0)
|
|
|
|
return -1;
|
|
|
|
}
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
|
|
|
qemuFirmwareMappingKernelParse(const char *path,
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *doc,
|
|
|
|
qemuFirmwareMappingKernel *kernel)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
|
|
|
const char *filename;
|
|
|
|
|
|
|
|
if (!(filename = virJSONValueObjectGetString(doc, "filename"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("missing 'filename' in '%s'", path);
|
2024-02-29 15:40:08 +01:00
|
|
|
return -1;
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
2019-10-20 13:49:46 +02:00
|
|
|
kernel->filename = g_strdup(filename);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
|
|
|
qemuFirmwareMappingMemoryParse(const char *path,
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *doc,
|
|
|
|
qemuFirmwareMappingMemory *memory)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
|
|
|
const char *filename;
|
|
|
|
|
|
|
|
if (!(filename = virJSONValueObjectGetString(doc, "filename"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("missing 'filename' in '%s'", path);
|
2024-02-29 15:40:08 +01:00
|
|
|
return -1;
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
2019-10-20 13:49:46 +02:00
|
|
|
memory->filename = g_strdup(filename);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
|
|
|
qemuFirmwareMappingParse(const char *path,
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *doc,
|
|
|
|
qemuFirmware *fw)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *mapping;
|
2019-02-19 11:07:46 +01:00
|
|
|
const char *deviceStr;
|
|
|
|
int tmp;
|
|
|
|
|
2020-09-22 23:22:06 +02:00
|
|
|
if (!(mapping = virJSONValueObjectGet(doc, "mapping"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("missing mapping in '%s'", path);
|
2020-09-22 23:22:06 +02:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2019-02-19 11:07:46 +01:00
|
|
|
if (!(deviceStr = virJSONValueObjectGetString(mapping, "device"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("missing device type in '%s'", path);
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ((tmp = qemuFirmwareDeviceTypeFromString(deviceStr)) <= 0) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("unknown device type in '%s'", path);
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
fw->mapping.device = tmp;
|
|
|
|
|
|
|
|
switch (fw->mapping.device) {
|
|
|
|
case QEMU_FIRMWARE_DEVICE_FLASH:
|
|
|
|
if (qemuFirmwareMappingFlashParse(path, mapping, &fw->mapping.data.flash) < 0)
|
|
|
|
return -1;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_DEVICE_KERNEL:
|
|
|
|
if (qemuFirmwareMappingKernelParse(path, mapping, &fw->mapping.data.kernel) < 0)
|
|
|
|
return -1;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_DEVICE_MEMORY:
|
|
|
|
if (qemuFirmwareMappingMemoryParse(path, mapping, &fw->mapping.data.memory) < 0)
|
|
|
|
return -1;
|
|
|
|
break;
|
|
|
|
|
|
|
|
case QEMU_FIRMWARE_DEVICE_NONE:
|
|
|
|
case QEMU_FIRMWARE_DEVICE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
|
|
|
qemuFirmwareTargetParse(const char *path,
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *doc,
|
|
|
|
qemuFirmware *fw)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *targetsJSON;
|
|
|
|
qemuFirmwareTarget **targets = NULL;
|
2019-02-19 11:07:46 +01:00
|
|
|
size_t ntargets;
|
|
|
|
size_t i;
|
|
|
|
int ret = -1;
|
|
|
|
|
|
|
|
if (!(targetsJSON = virJSONValueObjectGetArray(doc, "targets"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("failed to get targets from '%s'", path);
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
ntargets = virJSONValueArraySize(targetsJSON);
|
|
|
|
|
2021-03-11 08:16:13 +01:00
|
|
|
targets = g_new0(qemuFirmwareTarget *, ntargets);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
for (i = 0; i < ntargets; i++) {
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *item = virJSONValueArrayGet(targetsJSON, i);
|
|
|
|
virJSONValue *machines;
|
2019-10-15 14:47:50 +02:00
|
|
|
g_autoptr(qemuFirmwareTarget) t = NULL;
|
2019-02-19 11:07:46 +01:00
|
|
|
const char *architectureStr = NULL;
|
|
|
|
size_t nmachines;
|
|
|
|
size_t j;
|
|
|
|
|
2020-10-05 12:27:57 +02:00
|
|
|
t = g_new0(qemuFirmwareTarget, 1);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
if (!(architectureStr = virJSONValueObjectGetString(item, "architecture"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("missing 'architecture' in '%s'", path);
|
2019-02-19 11:07:46 +01:00
|
|
|
goto cleanup;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ((t->architecture = virQEMUCapsArchFromString(architectureStr)) == VIR_ARCH_NONE) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("unknown architecture '%s'", architectureStr);
|
2019-02-19 11:07:46 +01:00
|
|
|
goto cleanup;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!(machines = virJSONValueObjectGetArray(item, "machines"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("missing 'machines' in '%s'", path);
|
2019-02-19 11:07:46 +01:00
|
|
|
goto cleanup;
|
|
|
|
}
|
|
|
|
|
|
|
|
nmachines = virJSONValueArraySize(machines);
|
|
|
|
|
2021-06-16 09:29:01 +02:00
|
|
|
t->machines = g_new0(char *, nmachines + 1);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
for (j = 0; j < nmachines; j++) {
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *machine = virJSONValueArrayGet(machines, j);
|
2019-10-15 15:16:31 +02:00
|
|
|
g_autofree char *machineStr = NULL;
|
2019-02-19 11:07:46 +01:00
|
|
|
|
2019-10-20 13:49:46 +02:00
|
|
|
machineStr = g_strdup(virJSONValueGetString(machine));
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
VIR_APPEND_ELEMENT_INPLACE(t->machines, t->nmachines, machineStr);
|
|
|
|
}
|
|
|
|
|
2019-10-16 13:43:18 +02:00
|
|
|
targets[i] = g_steal_pointer(&t);
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
2019-10-16 13:43:18 +02:00
|
|
|
fw->targets = g_steal_pointer(&targets);
|
2019-02-19 11:07:46 +01:00
|
|
|
fw->ntargets = ntargets;
|
|
|
|
ntargets = 0;
|
|
|
|
ret = 0;
|
|
|
|
|
|
|
|
cleanup:
|
|
|
|
for (i = 0; i < ntargets; i++)
|
|
|
|
qemuFirmwareTargetFree(targets[i]);
|
|
|
|
VIR_FREE(targets);
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
|
|
|
qemuFirmwareFeatureParse(const char *path,
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *doc,
|
|
|
|
qemuFirmware *fw)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *featuresJSON;
|
2019-10-15 14:47:50 +02:00
|
|
|
g_autoptr(qemuFirmwareFeature) features = NULL;
|
2019-02-19 11:07:46 +01:00
|
|
|
size_t nfeatures;
|
2021-05-10 15:07:09 +02:00
|
|
|
size_t nparsed = 0;
|
2019-02-19 11:07:46 +01:00
|
|
|
size_t i;
|
|
|
|
|
|
|
|
if (!(featuresJSON = virJSONValueObjectGetArray(doc, "features"))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("failed to get features from '%s'", path);
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
nfeatures = virJSONValueArraySize(featuresJSON);
|
|
|
|
|
2020-10-05 12:27:57 +02:00
|
|
|
features = g_new0(qemuFirmwareFeature, nfeatures);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
for (i = 0; i < nfeatures; i++) {
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *item = virJSONValueArrayGet(featuresJSON, i);
|
2019-02-19 11:07:46 +01:00
|
|
|
const char *tmpStr = virJSONValueGetString(item);
|
|
|
|
int tmp;
|
|
|
|
|
|
|
|
if ((tmp = qemuFirmwareFeatureTypeFromString(tmpStr)) <= 0) {
|
2021-05-10 15:07:09 +02:00
|
|
|
VIR_DEBUG("ignoring unknown QEMU firmware feature '%s'", tmpStr);
|
|
|
|
continue;
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
2021-05-10 15:07:09 +02:00
|
|
|
features[nparsed] = tmp;
|
|
|
|
nparsed++;
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
2019-10-16 13:43:18 +02:00
|
|
|
fw->features = g_steal_pointer(&features);
|
2021-05-10 15:07:09 +02:00
|
|
|
fw->nfeatures = nparsed;
|
2019-02-19 11:07:46 +01:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* 1MiB should be enough for everybody (TM) */
|
|
|
|
#define DOCUMENT_SIZE (1024 * 1024)
|
|
|
|
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmware *
|
2019-02-19 11:07:46 +01:00
|
|
|
qemuFirmwareParse(const char *path)
|
|
|
|
{
|
2019-10-15 15:16:31 +02:00
|
|
|
g_autofree char *cont = NULL;
|
2019-10-15 14:47:50 +02:00
|
|
|
g_autoptr(virJSONValue) doc = NULL;
|
|
|
|
g_autoptr(qemuFirmware) fw = NULL;
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
if (virFileReadAll(path, DOCUMENT_SIZE, &cont) < 0)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
if (!(doc = virJSONValueFromString(cont))) {
|
2024-02-29 15:43:45 +01:00
|
|
|
VIR_DEBUG("unable to parse json file '%s'", path);
|
2019-02-19 11:07:46 +01:00
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
|
2020-10-05 12:27:57 +02:00
|
|
|
fw = g_new0(qemuFirmware, 1);
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
if (qemuFirmwareInterfaceParse(path, doc, fw) < 0)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
if (qemuFirmwareMappingParse(path, doc, fw) < 0)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
if (qemuFirmwareTargetParse(path, doc, fw) < 0)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
if (qemuFirmwareFeatureParse(path, doc, fw) < 0)
|
|
|
|
return NULL;
|
|
|
|
|
2019-10-17 10:10:10 +02:00
|
|
|
return g_steal_pointer(&fw);
|
2019-02-19 11:07:46 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareInterfaceFormat(virJSONValue *doc,
|
|
|
|
qemuFirmware *fw)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2019-10-15 14:47:50 +02:00
|
|
|
g_autoptr(virJSONValue) interfacesJSON = NULL;
|
2019-02-19 11:07:46 +01:00
|
|
|
size_t i;
|
|
|
|
|
2020-01-31 08:18:36 +01:00
|
|
|
interfacesJSON = virJSONValueNewArray();
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
for (i = 0; i < fw->ninterfaces; i++) {
|
|
|
|
if (virJSONValueArrayAppendString(interfacesJSON,
|
|
|
|
qemuFirmwareOSInterfaceTypeToString(fw->interfaces[i])) < 0)
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (virJSONValueObjectAppend(doc,
|
|
|
|
"interface-types",
|
2021-02-11 17:57:45 +01:00
|
|
|
&interfacesJSON) < 0)
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2021-03-11 08:16:13 +01:00
|
|
|
static virJSONValue *
|
2019-02-19 11:07:46 +01:00
|
|
|
qemuFirmwareFlashFileFormat(qemuFirmwareFlashFile flash)
|
|
|
|
{
|
2020-03-04 10:04:33 +01:00
|
|
|
g_autoptr(virJSONValue) json = virJSONValueNewObject();
|
2021-03-11 08:16:13 +01:00
|
|
|
virJSONValue *ret;
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
if (virJSONValueObjectAppendString(json,
|
|
|
|
"filename",
|
|
|
|
flash.filename) < 0)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
if (virJSONValueObjectAppendString(json,
|
|
|
|
"format",
|
|
|
|
flash.format) < 0)
|
|
|
|
return NULL;
|
|
|
|
|
2019-10-16 13:43:18 +02:00
|
|
|
ret = g_steal_pointer(&json);
|
2019-02-19 11:07:46 +01:00
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareMappingFlashFormat(virJSONValue *mapping,
|
|
|
|
qemuFirmwareMappingFlash *flash)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2019-10-15 14:47:50 +02:00
|
|
|
g_autoptr(virJSONValue) executable = NULL;
|
|
|
|
g_autoptr(virJSONValue) nvram_template = NULL;
|
2019-02-19 11:07:46 +01:00
|
|
|
|
2022-02-03 13:43:18 +00:00
|
|
|
if (virJSONValueObjectAppendString(mapping,
|
|
|
|
"mode",
|
|
|
|
qemuFirmwareFlashModeTypeToString(flash->mode)) < 0)
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
|
2022-02-03 13:43:18 +00:00
|
|
|
if (!(executable = qemuFirmwareFlashFileFormat(flash->executable)))
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
|
|
|
|
if (virJSONValueObjectAppend(mapping,
|
|
|
|
"executable",
|
2021-02-11 17:57:45 +01:00
|
|
|
&executable) < 0)
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
|
2022-02-03 13:43:18 +00:00
|
|
|
if (flash->mode == QEMU_FIRMWARE_FLASH_MODE_SPLIT) {
|
|
|
|
if (!(nvram_template = qemuFirmwareFlashFileFormat(flash->nvram_template)))
|
|
|
|
return -1;
|
2019-02-19 11:07:46 +01:00
|
|
|
|
2022-02-03 13:43:18 +00:00
|
|
|
if (virJSONValueObjectAppend(mapping,
|
2022-06-13 11:53:09 +02:00
|
|
|
"nvram-template",
|
2022-02-03 13:43:18 +00:00
|
|
|
&nvram_template) < 0)
|
|
|
|
return -1;
|
|
|
|
}
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareMappingKernelFormat(virJSONValue *mapping,
|
|
|
|
qemuFirmwareMappingKernel *kernel)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
|
|
|
if (virJSONValueObjectAppendString(mapping,
|
|
|
|
"filename",
|
|
|
|
kernel->filename) < 0)
|
|
|
|
return -1;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareMappingMemoryFormat(virJSONValue *mapping,
|
|
|
|
qemuFirmwareMappingMemory *memory)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
|
|
|
if (virJSONValueObjectAppendString(mapping,
|
|
|
|
"filename",
|
|
|
|
memory->filename) < 0)
|
|
|
|
return -1;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareMappingFormat(virJSONValue *doc,
|
|
|
|
qemuFirmware *fw)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2020-03-04 10:04:33 +01:00
|
|
|
g_autoptr(virJSONValue) mapping = virJSONValueNewObject();
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
if (virJSONValueObjectAppendString(mapping,
|
|
|
|
"device",
|
|
|
|
qemuFirmwareDeviceTypeToString(fw->mapping.device)) < 0)
|
|
|
|
return -1;
|
|
|
|
|
|
|
|
switch (fw->mapping.device) {
|
|
|
|
case QEMU_FIRMWARE_DEVICE_FLASH:
|
|
|
|
if (qemuFirmwareMappingFlashFormat(mapping, &fw->mapping.data.flash) < 0)
|
|
|
|
return -1;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_DEVICE_KERNEL:
|
|
|
|
if (qemuFirmwareMappingKernelFormat(mapping, &fw->mapping.data.kernel) < 0)
|
|
|
|
return -1;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_DEVICE_MEMORY:
|
|
|
|
if (qemuFirmwareMappingMemoryFormat(mapping, &fw->mapping.data.memory) < 0)
|
|
|
|
return -1;
|
|
|
|
break;
|
|
|
|
|
|
|
|
case QEMU_FIRMWARE_DEVICE_NONE:
|
|
|
|
case QEMU_FIRMWARE_DEVICE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
2021-02-11 17:57:45 +01:00
|
|
|
if (virJSONValueObjectAppend(doc, "mapping", &mapping) < 0)
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareTargetFormat(virJSONValue *doc,
|
|
|
|
qemuFirmware *fw)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2019-10-15 14:47:50 +02:00
|
|
|
g_autoptr(virJSONValue) targetsJSON = NULL;
|
2019-02-19 11:07:46 +01:00
|
|
|
size_t i;
|
|
|
|
|
2020-01-31 08:18:36 +01:00
|
|
|
targetsJSON = virJSONValueNewArray();
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
for (i = 0; i < fw->ntargets; i++) {
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareTarget *t = fw->targets[i];
|
2020-03-04 10:04:33 +01:00
|
|
|
g_autoptr(virJSONValue) target = virJSONValueNewObject();
|
2019-10-15 14:47:50 +02:00
|
|
|
g_autoptr(virJSONValue) machines = NULL;
|
2019-02-19 11:07:46 +01:00
|
|
|
size_t j;
|
|
|
|
|
|
|
|
if (virJSONValueObjectAppendString(target,
|
|
|
|
"architecture",
|
|
|
|
virQEMUCapsArchToString(t->architecture)) < 0)
|
|
|
|
return -1;
|
|
|
|
|
2020-01-31 08:18:36 +01:00
|
|
|
machines = virJSONValueNewArray();
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
for (j = 0; j < t->nmachines; j++) {
|
|
|
|
if (virJSONValueArrayAppendString(machines,
|
|
|
|
t->machines[j]) < 0)
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2021-02-11 17:57:45 +01:00
|
|
|
if (virJSONValueObjectAppend(target, "machines", &machines) < 0)
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
|
2021-02-11 17:57:45 +01:00
|
|
|
if (virJSONValueArrayAppend(targetsJSON, &target) < 0)
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2021-02-11 17:57:45 +01:00
|
|
|
if (virJSONValueObjectAppend(doc, "targets", &targetsJSON) < 0)
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareFeatureFormat(virJSONValue *doc,
|
|
|
|
qemuFirmware *fw)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2019-10-15 14:47:50 +02:00
|
|
|
g_autoptr(virJSONValue) featuresJSON = NULL;
|
2019-02-19 11:07:46 +01:00
|
|
|
size_t i;
|
|
|
|
|
2020-01-31 08:18:36 +01:00
|
|
|
featuresJSON = virJSONValueNewArray();
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
for (i = 0; i < fw->nfeatures; i++) {
|
|
|
|
if (virJSONValueArrayAppendString(featuresJSON,
|
|
|
|
qemuFirmwareFeatureTypeToString(fw->features[i])) < 0)
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (virJSONValueObjectAppend(doc,
|
|
|
|
"features",
|
2021-02-11 17:57:45 +01:00
|
|
|
&featuresJSON) < 0)
|
2019-02-19 11:07:46 +01:00
|
|
|
return -1;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
char *
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmwareFormat(qemuFirmware *fw)
|
2019-02-19 11:07:46 +01:00
|
|
|
{
|
2020-03-04 10:04:33 +01:00
|
|
|
g_autoptr(virJSONValue) doc = virJSONValueNewObject();
|
2019-02-19 11:07:46 +01:00
|
|
|
|
|
|
|
if (!fw)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
if (qemuFirmwareInterfaceFormat(doc, fw) < 0)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
if (qemuFirmwareMappingFormat(doc, fw) < 0)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
if (qemuFirmwareTargetFormat(doc, fw) < 0)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
if (qemuFirmwareFeatureFormat(doc, fw) < 0)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
return virJSONValueToString(doc, true);
|
|
|
|
}
|
2019-02-21 13:16:41 +01:00
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
qemuFirmwareFetchConfigs(char ***firmwares,
|
|
|
|
bool privileged)
|
|
|
|
{
|
2019-09-23 14:44:24 +04:00
|
|
|
return qemuInteropFetchConfigs("firmware", firmwares, privileged);
|
2019-02-21 13:16:41 +01:00
|
|
|
}
|
2019-02-22 15:25:31 +01:00
|
|
|
|
|
|
|
|
2019-04-04 15:51:47 +02:00
|
|
|
static bool
|
|
|
|
qemuFirmwareMatchesMachineArch(const qemuFirmware *fw,
|
|
|
|
const char *machine,
|
|
|
|
virArch arch)
|
|
|
|
{
|
|
|
|
size_t i;
|
|
|
|
|
|
|
|
for (i = 0; i < fw->ntargets; i++) {
|
|
|
|
size_t j;
|
|
|
|
|
|
|
|
if (arch != fw->targets[i]->architecture)
|
|
|
|
continue;
|
|
|
|
|
|
|
|
for (j = 0; j < fw->targets[i]->nmachines; j++) {
|
2019-12-20 16:02:49 +00:00
|
|
|
if (g_pattern_match_simple(fw->targets[i]->machines[j], machine))
|
2019-04-04 15:51:47 +02:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2023-03-15 18:12:58 +01:00
|
|
|
/**
|
|
|
|
* qemuFirmwareMatchesPaths:
|
|
|
|
* @fw: firmware definition
|
|
|
|
* @loader: loader definition
|
|
|
|
* @kernelPath: path to kernel image
|
|
|
|
*
|
|
|
|
* Checks whether @fw is compatible with the information provided as
|
|
|
|
* part of the domain definition.
|
|
|
|
*
|
|
|
|
* Returns: true if @fw is compatible with @loader and @kernelPath,
|
|
|
|
* false otherwise
|
|
|
|
*/
|
|
|
|
static bool
|
|
|
|
qemuFirmwareMatchesPaths(const qemuFirmware *fw,
|
|
|
|
const virDomainLoaderDef *loader,
|
|
|
|
const char *kernelPath)
|
|
|
|
{
|
|
|
|
const qemuFirmwareMappingFlash *flash = &fw->mapping.data.flash;
|
|
|
|
const qemuFirmwareMappingKernel *kernel = &fw->mapping.data.kernel;
|
|
|
|
const qemuFirmwareMappingMemory *memory = &fw->mapping.data.memory;
|
|
|
|
|
|
|
|
switch (fw->mapping.device) {
|
|
|
|
case QEMU_FIRMWARE_DEVICE_FLASH:
|
|
|
|
if (loader && loader->path &&
|
|
|
|
STRNEQ(loader->path, flash->executable.filename))
|
|
|
|
return false;
|
2023-05-26 17:47:42 +02:00
|
|
|
if (loader && loader->nvramTemplate) {
|
|
|
|
if (flash->mode != QEMU_FIRMWARE_FLASH_MODE_SPLIT)
|
|
|
|
return false;
|
|
|
|
if (STRNEQ(loader->nvramTemplate, flash->nvram_template.filename))
|
|
|
|
return false;
|
|
|
|
}
|
2023-03-15 18:12:58 +01:00
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_DEVICE_MEMORY:
|
|
|
|
if (loader && loader->path &&
|
|
|
|
STRNEQ(loader->path, memory->filename))
|
|
|
|
return false;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_DEVICE_KERNEL:
|
|
|
|
if (kernelPath &&
|
|
|
|
STRNEQ(kernelPath, kernel->filename))
|
|
|
|
return false;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_DEVICE_NONE:
|
|
|
|
case QEMU_FIRMWARE_DEVICE_LAST:
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2020-01-07 10:10:02 +01:00
|
|
|
static qemuFirmwareOSInterface
|
2022-01-10 13:03:42 -05:00
|
|
|
qemuFirmwareOSInterfaceTypeFromOsDefFirmware(virDomainOsDefFirmware fw)
|
2020-01-07 10:10:02 +01:00
|
|
|
{
|
|
|
|
switch (fw) {
|
|
|
|
case VIR_DOMAIN_OS_DEF_FIRMWARE_BIOS:
|
|
|
|
return QEMU_FIRMWARE_OS_INTERFACE_BIOS;
|
|
|
|
case VIR_DOMAIN_OS_DEF_FIRMWARE_EFI:
|
|
|
|
return QEMU_FIRMWARE_OS_INTERFACE_UEFI;
|
|
|
|
case VIR_DOMAIN_OS_DEF_FIRMWARE_NONE:
|
|
|
|
case VIR_DOMAIN_OS_DEF_FIRMWARE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
return QEMU_FIRMWARE_OS_INTERFACE_NONE;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2023-03-15 17:53:02 +01:00
|
|
|
static virDomainOsDefFirmware
|
|
|
|
qemuFirmwareOSInterfaceTypeToOsDefFirmware(qemuFirmwareOSInterface interface)
|
|
|
|
{
|
|
|
|
switch (interface) {
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_BIOS:
|
|
|
|
return VIR_DOMAIN_OS_DEF_FIRMWARE_BIOS;
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_UEFI:
|
|
|
|
return VIR_DOMAIN_OS_DEF_FIRMWARE_EFI;
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_UBOOT:
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_OPENFIRMWARE:
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_NONE:
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
return VIR_DOMAIN_OS_DEF_FIRMWARE_NONE;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2022-01-10 13:03:42 -05:00
|
|
|
static qemuFirmwareOSInterface
|
|
|
|
qemuFirmwareOSInterfaceTypeFromOsDefLoaderType(virDomainLoader type)
|
|
|
|
{
|
|
|
|
switch (type) {
|
|
|
|
case VIR_DOMAIN_LOADER_TYPE_ROM:
|
|
|
|
return QEMU_FIRMWARE_OS_INTERFACE_BIOS;
|
|
|
|
case VIR_DOMAIN_LOADER_TYPE_PFLASH:
|
|
|
|
return QEMU_FIRMWARE_OS_INTERFACE_UEFI;
|
|
|
|
case VIR_DOMAIN_LOADER_TYPE_NONE:
|
|
|
|
case VIR_DOMAIN_LOADER_TYPE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
return QEMU_FIRMWARE_OS_INTERFACE_NONE;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2023-02-03 19:21:03 +01:00
|
|
|
/**
|
|
|
|
* qemuFirmwareEnsureNVRAM:
|
|
|
|
* @def: domain definition
|
2023-05-26 14:40:02 +02:00
|
|
|
* @driver: QEMU driver
|
2023-05-30 18:24:40 +02:00
|
|
|
* @abiUpdate: whether a new domain is being defined
|
2023-02-03 19:21:03 +01:00
|
|
|
*
|
|
|
|
* Make sure that a source for the NVRAM file exists, possibly by
|
|
|
|
* creating it. This might involve automatically generating the
|
|
|
|
* corresponding path.
|
|
|
|
*/
|
2023-01-27 15:49:36 +01:00
|
|
|
static void
|
2023-02-03 19:21:03 +01:00
|
|
|
qemuFirmwareEnsureNVRAM(virDomainDef *def,
|
2023-05-30 18:24:40 +02:00
|
|
|
virQEMUDriver *driver,
|
|
|
|
bool abiUpdate)
|
2023-01-27 15:49:36 +01:00
|
|
|
{
|
2023-05-26 14:40:02 +02:00
|
|
|
g_autoptr(virQEMUDriverConfig) cfg = virQEMUDriverGetConfig(driver);
|
2023-02-03 19:21:03 +01:00
|
|
|
virDomainLoaderDef *loader = def->os.loader;
|
2023-01-31 19:16:18 +01:00
|
|
|
const char *ext = NULL;
|
2023-02-03 19:21:03 +01:00
|
|
|
|
|
|
|
if (!loader)
|
|
|
|
return;
|
|
|
|
|
2023-05-26 14:40:02 +02:00
|
|
|
if (loader->type != VIR_DOMAIN_LOADER_TYPE_PFLASH)
|
|
|
|
return;
|
|
|
|
|
|
|
|
if (loader->readonly != VIR_TRISTATE_BOOL_YES)
|
|
|
|
return;
|
|
|
|
|
|
|
|
if (loader->stateless == VIR_TRISTATE_BOOL_YES)
|
|
|
|
return;
|
|
|
|
|
2023-05-16 19:50:50 +02:00
|
|
|
/* If the NVRAM format hasn't been set yet, inherit the same as
|
|
|
|
* the loader */
|
|
|
|
if (loader->nvram && !loader->nvram->format)
|
|
|
|
loader->nvram->format = loader->format;
|
|
|
|
|
2023-01-31 14:35:28 +01:00
|
|
|
/* If the source already exists and is fully specified, including
|
|
|
|
* the path, leave it alone */
|
|
|
|
if (loader->nvram && loader->nvram->path)
|
2023-02-03 19:21:03 +01:00
|
|
|
return;
|
|
|
|
|
2023-01-31 14:35:28 +01:00
|
|
|
if (loader->nvram)
|
|
|
|
virObjectUnref(loader->nvram);
|
|
|
|
|
2023-02-03 19:21:03 +01:00
|
|
|
loader->nvram = virStorageSourceNew();
|
|
|
|
loader->nvram->type = VIR_STORAGE_TYPE_FILE;
|
2023-05-26 14:40:02 +02:00
|
|
|
loader->nvram->format = loader->format;
|
2023-02-03 19:21:03 +01:00
|
|
|
|
2023-05-30 18:24:40 +02:00
|
|
|
if (loader->nvram->format == VIR_STORAGE_FILE_RAW) {
|
|
|
|
/* The extension used by raw edk2 builds has historically
|
|
|
|
* been .fd, but more recent aarch64 builds have started
|
|
|
|
* using the .raw extension instead.
|
|
|
|
*
|
|
|
|
* If we're defining a new domain, we should try to match the
|
|
|
|
* extension for the file backing its NVRAM store with the
|
|
|
|
* one used by the template to keep things nice and
|
|
|
|
* consistent.
|
|
|
|
*
|
|
|
|
* If we're loading an existing domain, however, we need to
|
|
|
|
* stick with the .fd extension to ensure compatibility */
|
|
|
|
if (abiUpdate &&
|
|
|
|
loader->nvramTemplate &&
|
|
|
|
virStringHasSuffix(loader->nvramTemplate, ".raw"))
|
|
|
|
ext = ".raw";
|
|
|
|
else
|
|
|
|
ext = ".fd";
|
|
|
|
}
|
2023-05-26 14:40:02 +02:00
|
|
|
if (loader->nvram->format == VIR_STORAGE_FILE_QCOW2)
|
2023-02-07 18:59:00 +01:00
|
|
|
ext = ".qcow2";
|
2023-01-31 19:16:18 +01:00
|
|
|
|
|
|
|
loader->nvram->path = g_strdup_printf("%s/%s_VARS%s",
|
|
|
|
cfg->nvramDir, def->name,
|
|
|
|
ext ? ext : "");
|
2023-01-27 15:49:36 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2023-03-15 17:53:02 +01:00
|
|
|
|
|
|
|
/**
|
|
|
|
* qemuFirmwareSetOsFeatures:
|
|
|
|
* @def: domain definition
|
|
|
|
* @secureBoot: whether the 'secure-boot' feature is enabled
|
|
|
|
* @enrolledKeys: whether the 'enrolled-keys' feature is enabled
|
|
|
|
*
|
|
|
|
* Set firmware features for @def to match those declared by the JSON
|
|
|
|
* descriptor that was found to match autoselection requirements.
|
|
|
|
*/
|
|
|
|
static void
|
|
|
|
qemuFirmwareSetOsFeatures(virDomainDef *def,
|
|
|
|
bool secureBoot,
|
|
|
|
bool enrolledKeys)
|
|
|
|
{
|
|
|
|
int *features = def->os.firmwareFeatures;
|
|
|
|
virDomainLoaderDef *loader = def->os.loader;
|
|
|
|
|
|
|
|
if (!features) {
|
|
|
|
features = g_new0(int, VIR_DOMAIN_OS_DEF_FIRMWARE_FEATURE_LAST);
|
|
|
|
def->os.firmwareFeatures = features;
|
|
|
|
}
|
|
|
|
|
|
|
|
features[VIR_DOMAIN_OS_DEF_FIRMWARE_FEATURE_SECURE_BOOT] = virTristateBoolFromBool(secureBoot);
|
|
|
|
features[VIR_DOMAIN_OS_DEF_FIRMWARE_FEATURE_ENROLLED_KEYS] = virTristateBoolFromBool(enrolledKeys);
|
|
|
|
|
|
|
|
/* If the NVRAM template is blank at this point and we're not dealing
|
|
|
|
* with a stateless firmware image, then it means that the NVRAM file
|
|
|
|
* is not local. In this scenario we can't really make any assumptions
|
|
|
|
* about its contents, so it's preferable to leave the state of the
|
|
|
|
* enrolled-keys feature unspecified */
|
|
|
|
if (loader &&
|
|
|
|
loader->type == VIR_DOMAIN_LOADER_TYPE_PFLASH &&
|
|
|
|
loader->stateless != VIR_TRISTATE_BOOL_YES &&
|
|
|
|
!loader->nvramTemplate) {
|
|
|
|
features[VIR_DOMAIN_OS_DEF_FIRMWARE_FEATURE_ENROLLED_KEYS] = VIR_TRISTATE_BOOL_ABSENT;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2021-05-25 09:56:38 +02:00
|
|
|
#define VIR_QEMU_FIRMWARE_AMD_SEV_ES_POLICY (1 << 2)
|
|
|
|
|
|
|
|
|
2019-02-22 15:25:31 +01:00
|
|
|
static bool
|
|
|
|
qemuFirmwareMatchDomain(const virDomainDef *def,
|
|
|
|
const qemuFirmware *fw,
|
|
|
|
const char *path)
|
|
|
|
{
|
2023-01-27 17:35:30 +01:00
|
|
|
const virDomainLoaderDef *loader = def->os.loader;
|
2019-02-22 15:25:31 +01:00
|
|
|
size_t i;
|
2020-01-07 10:10:02 +01:00
|
|
|
qemuFirmwareOSInterface want;
|
2019-02-22 15:25:31 +01:00
|
|
|
bool supportsS3 = false;
|
|
|
|
bool supportsS4 = false;
|
|
|
|
bool requiresSMM = false;
|
|
|
|
bool supportsSEV = false;
|
2021-05-25 09:56:38 +02:00
|
|
|
bool supportsSEVES = false;
|
2021-03-17 16:34:24 +01:00
|
|
|
bool supportsSecureBoot = false;
|
|
|
|
bool hasEnrolledKeys = false;
|
|
|
|
int reqSecureBoot;
|
|
|
|
int reqEnrolledKeys;
|
2019-02-22 15:25:31 +01:00
|
|
|
|
2020-01-07 10:10:02 +01:00
|
|
|
want = qemuFirmwareOSInterfaceTypeFromOsDefFirmware(def->os.firmware);
|
|
|
|
|
2023-01-27 17:35:30 +01:00
|
|
|
if (want == QEMU_FIRMWARE_OS_INTERFACE_NONE && loader) {
|
|
|
|
want = qemuFirmwareOSInterfaceTypeFromOsDefLoaderType(loader->type);
|
2019-12-17 17:45:50 +01:00
|
|
|
}
|
|
|
|
|
2019-02-22 15:25:31 +01:00
|
|
|
for (i = 0; i < fw->ninterfaces; i++) {
|
2020-01-07 10:10:02 +01:00
|
|
|
if (fw->interfaces[i] == want)
|
2019-02-22 15:25:31 +01:00
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (i == fw->ninterfaces) {
|
|
|
|
VIR_DEBUG("No matching interface in '%s'", path);
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2023-03-15 18:12:58 +01:00
|
|
|
if (!qemuFirmwareMatchesPaths(fw, def->os.loader, def->os.kernel)) {
|
|
|
|
VIR_DEBUG("No matching path in '%s'", path);
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2019-04-04 15:51:47 +02:00
|
|
|
if (!qemuFirmwareMatchesMachineArch(fw, def->os.machine, def->os.arch)) {
|
2019-02-22 15:25:31 +01:00
|
|
|
VIR_DEBUG("No matching machine type in '%s'", path);
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
for (i = 0; i < fw->nfeatures; i++) {
|
|
|
|
switch (fw->features[i]) {
|
|
|
|
case QEMU_FIRMWARE_FEATURE_ACPI_S3:
|
|
|
|
supportsS3 = true;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_FEATURE_ACPI_S4:
|
|
|
|
supportsS4 = true;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_FEATURE_AMD_SEV:
|
|
|
|
supportsSEV = true;
|
|
|
|
break;
|
2021-05-25 09:56:38 +02:00
|
|
|
|
|
|
|
case QEMU_FIRMWARE_FEATURE_AMD_SEV_ES:
|
|
|
|
supportsSEVES = true;
|
|
|
|
break;
|
|
|
|
|
2019-02-22 15:25:31 +01:00
|
|
|
case QEMU_FIRMWARE_FEATURE_REQUIRES_SMM:
|
|
|
|
requiresSMM = true;
|
|
|
|
break;
|
|
|
|
|
|
|
|
case QEMU_FIRMWARE_FEATURE_SECURE_BOOT:
|
2021-03-17 16:34:24 +01:00
|
|
|
supportsSecureBoot = true;
|
|
|
|
break;
|
|
|
|
|
2019-02-22 15:25:31 +01:00
|
|
|
case QEMU_FIRMWARE_FEATURE_ENROLLED_KEYS:
|
2021-03-17 16:34:24 +01:00
|
|
|
hasEnrolledKeys = true;
|
|
|
|
break;
|
|
|
|
|
2019-02-22 15:25:31 +01:00
|
|
|
case QEMU_FIRMWARE_FEATURE_VERBOSE_DYNAMIC:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_VERBOSE_STATIC:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_NONE:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if (def->pm.s3 == VIR_TRISTATE_BOOL_YES &&
|
|
|
|
!supportsS3) {
|
|
|
|
VIR_DEBUG("Domain requires S3, firmware '%s' doesn't support it", path);
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (def->pm.s4 == VIR_TRISTATE_BOOL_YES &&
|
|
|
|
!supportsS4) {
|
|
|
|
VIR_DEBUG("Domain requires S4, firmware '%s' doesn't support it", path);
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2021-03-17 16:34:24 +01:00
|
|
|
if (def->os.firmwareFeatures) {
|
|
|
|
reqSecureBoot = def->os.firmwareFeatures[VIR_DOMAIN_OS_DEF_FIRMWARE_FEATURE_SECURE_BOOT];
|
2022-06-09 19:09:31 +02:00
|
|
|
if (reqSecureBoot == VIR_TRISTATE_BOOL_YES && !supportsSecureBoot) {
|
|
|
|
VIR_DEBUG("User requested Secure Boot, firmware '%s' doesn't support it",
|
|
|
|
path);
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
if (reqSecureBoot == VIR_TRISTATE_BOOL_NO && supportsSecureBoot) {
|
|
|
|
VIR_DEBUG("User refused Secure Boot, firmware '%s' supports it", path);
|
|
|
|
return false;
|
2021-03-17 16:34:24 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
reqEnrolledKeys = def->os.firmwareFeatures[VIR_DOMAIN_OS_DEF_FIRMWARE_FEATURE_ENROLLED_KEYS];
|
2022-06-09 19:09:31 +02:00
|
|
|
if (reqEnrolledKeys == VIR_TRISTATE_BOOL_YES && !hasEnrolledKeys) {
|
|
|
|
VIR_DEBUG("User requested Enrolled keys, firmware '%s' doesn't have them",
|
|
|
|
path);
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
if (reqEnrolledKeys == VIR_TRISTATE_BOOL_NO && hasEnrolledKeys) {
|
|
|
|
VIR_DEBUG("User refused Enrolled keys, firmware '%s' has them", path);
|
|
|
|
return false;
|
2021-03-17 16:34:24 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-01-27 17:22:24 +01:00
|
|
|
if (requiresSMM) {
|
|
|
|
if (def->features[VIR_DOMAIN_FEATURE_SMM] == VIR_TRISTATE_SWITCH_OFF) {
|
|
|
|
VIR_DEBUG("Domain explicitly disables SMM, "
|
|
|
|
"but firmware '%s' requires it to be enabled", path);
|
|
|
|
return false;
|
|
|
|
}
|
2023-03-16 19:42:56 +01:00
|
|
|
if (loader && loader->secure == VIR_TRISTATE_BOOL_NO) {
|
|
|
|
VIR_DEBUG("Domain doesn't restrict pflash programming to SMM, "
|
|
|
|
"but firmware '%s' requires use of SMM", path);
|
|
|
|
return false;
|
|
|
|
}
|
2023-01-27 17:22:24 +01:00
|
|
|
} else {
|
|
|
|
if (loader && loader->secure == VIR_TRISTATE_BOOL_YES) {
|
|
|
|
VIR_DEBUG("Domain restricts pflash programming to SMM, "
|
|
|
|
"but firmware '%s' doesn't support SMM", path);
|
|
|
|
return false;
|
|
|
|
}
|
2019-02-22 15:25:31 +01:00
|
|
|
}
|
|
|
|
|
2022-07-22 16:59:43 +01:00
|
|
|
if (fw->mapping.device == QEMU_FIRMWARE_DEVICE_FLASH) {
|
2023-01-27 17:35:30 +01:00
|
|
|
const qemuFirmwareMappingFlash *flash = &fw->mapping.data.flash;
|
|
|
|
|
|
|
|
if (loader && loader->stateless == VIR_TRISTATE_BOOL_YES) {
|
|
|
|
if (flash->mode != QEMU_FIRMWARE_FLASH_MODE_STATELESS) {
|
2022-07-22 16:59:43 +01:00
|
|
|
VIR_DEBUG("Discarding loader without stateless flash");
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
} else {
|
2023-01-27 17:35:30 +01:00
|
|
|
if (flash->mode != QEMU_FIRMWARE_FLASH_MODE_SPLIT) {
|
2022-07-22 16:59:43 +01:00
|
|
|
VIR_DEBUG("Discarding loader without split flash");
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
2023-01-27 17:39:25 +01:00
|
|
|
|
2023-05-30 18:01:58 +02:00
|
|
|
if (loader &&
|
|
|
|
loader->readonly == VIR_TRISTATE_BOOL_NO &&
|
|
|
|
flash->mode != QEMU_FIRMWARE_FLASH_MODE_COMBINED) {
|
|
|
|
VIR_DEBUG("Discarding readonly loader");
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2023-02-07 18:59:00 +01:00
|
|
|
if (STRNEQ(flash->executable.format, "raw") &&
|
|
|
|
STRNEQ(flash->executable.format, "qcow2")) {
|
2023-01-27 17:39:25 +01:00
|
|
|
VIR_DEBUG("Discarding loader with unsupported flash format '%s'",
|
|
|
|
flash->executable.format);
|
|
|
|
return false;
|
|
|
|
}
|
2023-05-16 19:50:50 +02:00
|
|
|
if (loader && loader->format &&
|
2023-01-31 17:46:58 +01:00
|
|
|
STRNEQ(flash->executable.format, virStorageFileFormatTypeToString(loader->format))) {
|
|
|
|
VIR_DEBUG("Discarding loader with mismatching flash format '%s' != '%s'",
|
|
|
|
flash->executable.format,
|
|
|
|
virStorageFileFormatTypeToString(loader->format));
|
|
|
|
return false;
|
|
|
|
}
|
2023-01-27 17:39:25 +01:00
|
|
|
if (flash->mode == QEMU_FIRMWARE_FLASH_MODE_SPLIT) {
|
2023-02-07 18:59:00 +01:00
|
|
|
if (STRNEQ(flash->nvram_template.format, "raw") &&
|
|
|
|
STRNEQ(flash->nvram_template.format, "qcow2")) {
|
2023-01-27 17:39:25 +01:00
|
|
|
VIR_DEBUG("Discarding loader with unsupported nvram template format '%s'",
|
|
|
|
flash->nvram_template.format);
|
|
|
|
return false;
|
|
|
|
}
|
2023-05-16 19:50:50 +02:00
|
|
|
if (loader && loader->nvram && loader->nvram->format &&
|
2023-01-31 17:46:58 +01:00
|
|
|
STRNEQ(flash->nvram_template.format, virStorageFileFormatTypeToString(loader->nvram->format))) {
|
|
|
|
VIR_DEBUG("Discarding loader with mismatching nvram template format '%s' != '%s'",
|
|
|
|
flash->nvram_template.format,
|
|
|
|
virStorageFileFormatTypeToString(loader->nvram->format));
|
|
|
|
return false;
|
|
|
|
}
|
2023-01-27 17:39:25 +01:00
|
|
|
}
|
2022-02-03 13:43:18 +00:00
|
|
|
}
|
|
|
|
|
2021-07-21 13:07:51 +02:00
|
|
|
if (def->sec) {
|
2024-06-12 10:06:57 +02:00
|
|
|
switch (def->sec->sectype) {
|
2021-07-21 13:07:51 +02:00
|
|
|
case VIR_DOMAIN_LAUNCH_SECURITY_SEV:
|
|
|
|
if (!supportsSEV) {
|
|
|
|
VIR_DEBUG("Domain requires SEV, firmware '%s' doesn't support it",
|
|
|
|
path);
|
|
|
|
return false;
|
|
|
|
}
|
2021-05-25 09:56:38 +02:00
|
|
|
|
2021-07-21 13:07:51 +02:00
|
|
|
if (def->sec->data.sev.policy & VIR_QEMU_FIRMWARE_AMD_SEV_ES_POLICY &&
|
|
|
|
!supportsSEVES) {
|
|
|
|
VIR_DEBUG("Domain requires SEV-ES, firmware '%s' doesn't support it",
|
|
|
|
path);
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
break;
|
2024-06-11 11:58:41 +02:00
|
|
|
|
|
|
|
case VIR_DOMAIN_LAUNCH_SECURITY_SEV_SNP:
|
|
|
|
break;
|
2021-07-21 13:17:40 +02:00
|
|
|
case VIR_DOMAIN_LAUNCH_SECURITY_PV:
|
|
|
|
break;
|
2021-07-21 13:07:51 +02:00
|
|
|
case VIR_DOMAIN_LAUNCH_SECURITY_NONE:
|
|
|
|
case VIR_DOMAIN_LAUNCH_SECURITY_LAST:
|
|
|
|
virReportEnumRangeError(virDomainLaunchSecurity, def->sec->sectype);
|
|
|
|
return -1;
|
2021-05-25 09:56:38 +02:00
|
|
|
}
|
2019-02-22 15:25:31 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
VIR_DEBUG("Firmware '%s' matches domain requirements", path);
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static int
|
2023-05-26 14:40:02 +02:00
|
|
|
qemuFirmwareEnableFeaturesModern(virDomainDef *def,
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
const qemuFirmware *fw)
|
2019-02-22 15:25:31 +01:00
|
|
|
{
|
|
|
|
const qemuFirmwareMappingFlash *flash = &fw->mapping.data.flash;
|
|
|
|
const qemuFirmwareMappingKernel *kernel = &fw->mapping.data.kernel;
|
|
|
|
const qemuFirmwareMappingMemory *memory = &fw->mapping.data.memory;
|
2023-01-27 17:35:30 +01:00
|
|
|
virDomainLoaderDef *loader = NULL;
|
2023-01-31 19:16:18 +01:00
|
|
|
virStorageFileFormat format;
|
2023-03-15 17:53:02 +01:00
|
|
|
bool hasSecureBoot = false;
|
|
|
|
bool hasEnrolledKeys = false;
|
2019-02-22 15:25:31 +01:00
|
|
|
size_t i;
|
|
|
|
|
|
|
|
switch (fw->mapping.device) {
|
|
|
|
case QEMU_FIRMWARE_DEVICE_FLASH:
|
2023-01-31 19:16:18 +01:00
|
|
|
if ((format = virStorageFileFormatTypeFromString(flash->executable.format)) < 0)
|
|
|
|
return -1;
|
|
|
|
|
2020-10-05 12:27:57 +02:00
|
|
|
if (!def->os.loader)
|
2023-01-31 17:05:44 +01:00
|
|
|
def->os.loader = virDomainLoaderDefNew();
|
2023-01-27 17:35:30 +01:00
|
|
|
loader = def->os.loader;
|
2019-02-22 15:25:31 +01:00
|
|
|
|
2023-01-27 17:35:30 +01:00
|
|
|
loader->type = VIR_DOMAIN_LOADER_TYPE_PFLASH;
|
|
|
|
loader->readonly = VIR_TRISTATE_BOOL_YES;
|
2023-01-31 19:16:18 +01:00
|
|
|
loader->format = format;
|
2019-02-22 15:25:31 +01:00
|
|
|
|
2023-01-27 17:35:30 +01:00
|
|
|
VIR_FREE(loader->path);
|
|
|
|
loader->path = g_strdup(flash->executable.filename);
|
2019-02-22 15:25:31 +01:00
|
|
|
|
2022-07-22 16:59:43 +01:00
|
|
|
if (flash->mode == QEMU_FIRMWARE_FLASH_MODE_SPLIT) {
|
2023-05-26 14:40:02 +02:00
|
|
|
/* Only fill in nvramTemplate if the NVRAM location is already
|
|
|
|
* known to be a local path or hasn't been provided, in which
|
|
|
|
* case a local path will be generated by libvirt later.
|
|
|
|
*
|
|
|
|
* We can't create or reset non-local NVRAM files, so filling
|
|
|
|
* in nvramTemplate for those would be misleading */
|
2023-02-10 19:43:53 +01:00
|
|
|
VIR_FREE(loader->nvramTemplate);
|
2023-05-26 14:40:02 +02:00
|
|
|
if (!loader->nvram ||
|
|
|
|
(loader->nvram && virStorageSourceIsLocalStorage(loader->nvram))) {
|
2023-02-10 19:43:53 +01:00
|
|
|
loader->nvramTemplate = g_strdup(flash->nvram_template.filename);
|
|
|
|
}
|
2022-05-04 09:51:11 -07:00
|
|
|
}
|
2019-02-22 15:25:31 +01:00
|
|
|
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
VIR_DEBUG("decided on firmware '%s' template '%s'",
|
|
|
|
loader->path, NULLSTR(loader->nvramTemplate));
|
2019-02-22 15:25:31 +01:00
|
|
|
break;
|
|
|
|
|
|
|
|
case QEMU_FIRMWARE_DEVICE_KERNEL:
|
|
|
|
VIR_FREE(def->os.kernel);
|
2019-10-20 13:49:46 +02:00
|
|
|
def->os.kernel = g_strdup(kernel->filename);
|
2019-02-22 15:25:31 +01:00
|
|
|
|
|
|
|
VIR_DEBUG("decided on kernel '%s'",
|
|
|
|
def->os.kernel);
|
|
|
|
break;
|
|
|
|
|
|
|
|
case QEMU_FIRMWARE_DEVICE_MEMORY:
|
2020-10-05 12:27:57 +02:00
|
|
|
if (!def->os.loader)
|
2023-01-31 17:05:44 +01:00
|
|
|
def->os.loader = virDomainLoaderDefNew();
|
2023-01-27 17:35:30 +01:00
|
|
|
loader = def->os.loader;
|
2019-02-22 15:25:31 +01:00
|
|
|
|
2023-01-27 17:35:30 +01:00
|
|
|
loader->type = VIR_DOMAIN_LOADER_TYPE_ROM;
|
2023-03-22 00:22:43 +01:00
|
|
|
|
|
|
|
VIR_FREE(loader->path);
|
2023-01-27 17:35:30 +01:00
|
|
|
loader->path = g_strdup(memory->filename);
|
2019-02-22 15:25:31 +01:00
|
|
|
|
|
|
|
VIR_DEBUG("decided on loader '%s'",
|
2023-01-27 17:35:30 +01:00
|
|
|
loader->path);
|
2019-02-22 15:25:31 +01:00
|
|
|
break;
|
|
|
|
|
|
|
|
case QEMU_FIRMWARE_DEVICE_NONE:
|
|
|
|
case QEMU_FIRMWARE_DEVICE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
for (i = 0; i < fw->nfeatures; i++) {
|
|
|
|
switch (fw->features[i]) {
|
|
|
|
case QEMU_FIRMWARE_FEATURE_REQUIRES_SMM:
|
2023-01-27 17:22:24 +01:00
|
|
|
VIR_DEBUG("Enabling SMM feature");
|
|
|
|
def->features[VIR_DOMAIN_FEATURE_SMM] = VIR_TRISTATE_SWITCH_ON;
|
|
|
|
|
2022-06-09 17:59:33 +02:00
|
|
|
VIR_DEBUG("Enabling secure loader");
|
|
|
|
def->os.loader->secure = VIR_TRISTATE_BOOL_YES;
|
2019-02-22 15:25:31 +01:00
|
|
|
break;
|
|
|
|
|
2023-03-15 17:53:02 +01:00
|
|
|
case QEMU_FIRMWARE_FEATURE_SECURE_BOOT:
|
|
|
|
hasSecureBoot = true;
|
|
|
|
break;
|
|
|
|
|
|
|
|
case QEMU_FIRMWARE_FEATURE_ENROLLED_KEYS:
|
|
|
|
hasEnrolledKeys = true;
|
|
|
|
break;
|
|
|
|
|
2019-02-22 15:25:31 +01:00
|
|
|
case QEMU_FIRMWARE_FEATURE_ACPI_S3:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_ACPI_S4:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_AMD_SEV:
|
2021-05-25 09:56:38 +02:00
|
|
|
case QEMU_FIRMWARE_FEATURE_AMD_SEV_ES:
|
2019-02-22 15:25:31 +01:00
|
|
|
case QEMU_FIRMWARE_FEATURE_VERBOSE_DYNAMIC:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_VERBOSE_STATIC:
|
2023-03-15 17:53:02 +01:00
|
|
|
case QEMU_FIRMWARE_FEATURE_NONE:
|
2019-02-22 15:25:31 +01:00
|
|
|
case QEMU_FIRMWARE_FEATURE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-03-15 17:53:02 +01:00
|
|
|
if (!def->os.firmware) {
|
|
|
|
/* If a firmware type for autoselection was not already present,
|
|
|
|
* pick the first reasonable one from the descriptor list */
|
|
|
|
for (i = 0; i < fw->ninterfaces; i++) {
|
|
|
|
def->os.firmware = qemuFirmwareOSInterfaceTypeToOsDefFirmware(fw->interfaces[i]);
|
|
|
|
if (def->os.firmware)
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if (def->os.firmware) {
|
|
|
|
qemuFirmwareSetOsFeatures(def, hasSecureBoot, hasEnrolledKeys);
|
|
|
|
}
|
|
|
|
|
2019-02-22 15:25:31 +01:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static void
|
|
|
|
qemuFirmwareSanityCheck(const qemuFirmware *fw,
|
|
|
|
const char *filename)
|
|
|
|
{
|
|
|
|
size_t i;
|
|
|
|
bool requiresSMM = false;
|
|
|
|
bool supportsSecureBoot = false;
|
2022-06-09 19:02:15 +02:00
|
|
|
bool hasEnrolledKeys = false;
|
2019-02-22 15:25:31 +01:00
|
|
|
|
|
|
|
for (i = 0; i < fw->nfeatures; i++) {
|
|
|
|
switch (fw->features[i]) {
|
|
|
|
case QEMU_FIRMWARE_FEATURE_REQUIRES_SMM:
|
|
|
|
requiresSMM = true;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_FEATURE_SECURE_BOOT:
|
|
|
|
supportsSecureBoot = true;
|
|
|
|
break;
|
2022-06-09 19:02:15 +02:00
|
|
|
case QEMU_FIRMWARE_FEATURE_ENROLLED_KEYS:
|
|
|
|
hasEnrolledKeys = true;
|
|
|
|
break;
|
2019-02-22 15:25:31 +01:00
|
|
|
case QEMU_FIRMWARE_FEATURE_NONE:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_ACPI_S3:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_ACPI_S4:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_AMD_SEV:
|
2021-05-25 09:56:38 +02:00
|
|
|
case QEMU_FIRMWARE_FEATURE_AMD_SEV_ES:
|
2019-02-22 15:25:31 +01:00
|
|
|
case QEMU_FIRMWARE_FEATURE_VERBOSE_DYNAMIC:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_VERBOSE_STATIC:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-06-09 19:02:15 +02:00
|
|
|
if ((supportsSecureBoot != requiresSMM) ||
|
|
|
|
(hasEnrolledKeys && !supportsSecureBoot)) {
|
2019-02-22 15:25:31 +01:00
|
|
|
VIR_WARN("Firmware description '%s' has invalid set of features: "
|
2022-06-09 19:02:15 +02:00
|
|
|
"%s = %d, %s = %d, %s = %d",
|
2019-02-22 15:25:31 +01:00
|
|
|
filename,
|
|
|
|
qemuFirmwareFeatureTypeToString(QEMU_FIRMWARE_FEATURE_REQUIRES_SMM),
|
|
|
|
requiresSMM,
|
|
|
|
qemuFirmwareFeatureTypeToString(QEMU_FIRMWARE_FEATURE_SECURE_BOOT),
|
2022-06-09 19:02:15 +02:00
|
|
|
supportsSecureBoot,
|
|
|
|
qemuFirmwareFeatureTypeToString(QEMU_FIRMWARE_FEATURE_ENROLLED_KEYS),
|
|
|
|
hasEnrolledKeys);
|
2019-02-22 15:25:31 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2019-04-04 15:20:37 +02:00
|
|
|
static ssize_t
|
|
|
|
qemuFirmwareFetchParsedConfigs(bool privileged,
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmware ***firmwaresRet,
|
2019-04-04 15:20:37 +02:00
|
|
|
char ***pathsRet)
|
|
|
|
{
|
2024-02-29 16:16:53 +01:00
|
|
|
g_auto(GStrv) possiblePaths = NULL;
|
|
|
|
char **currentPath = NULL;
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmware **firmwares = NULL;
|
2024-02-29 16:16:53 +01:00
|
|
|
char **paths = NULL;
|
|
|
|
size_t nfirmwares = 0;
|
|
|
|
size_t npaths = 0;
|
2019-04-04 15:20:37 +02:00
|
|
|
|
2024-02-29 16:16:53 +01:00
|
|
|
if (qemuFirmwareFetchConfigs(&possiblePaths, privileged) < 0)
|
2019-04-04 15:20:37 +02:00
|
|
|
return -1;
|
|
|
|
|
2024-02-29 16:16:53 +01:00
|
|
|
if (!possiblePaths)
|
2021-02-05 18:03:26 +01:00
|
|
|
return 0;
|
|
|
|
|
2024-02-29 16:16:53 +01:00
|
|
|
for (currentPath = possiblePaths; *currentPath; currentPath++) {
|
|
|
|
qemuFirmware *firmware = qemuFirmwareParse(*currentPath);
|
2019-04-04 15:20:37 +02:00
|
|
|
|
2024-02-29 16:16:53 +01:00
|
|
|
if (!firmware)
|
2024-02-29 15:43:45 +01:00
|
|
|
continue;
|
2024-02-29 16:16:53 +01:00
|
|
|
|
|
|
|
VIR_APPEND_ELEMENT(firmwares, nfirmwares, firmware);
|
|
|
|
|
|
|
|
if (pathsRet) {
|
|
|
|
char *path = g_strdup(*currentPath);
|
|
|
|
VIR_APPEND_ELEMENT(paths, npaths, path);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
*firmwaresRet = firmwares;
|
|
|
|
if (pathsRet) {
|
|
|
|
char *terminator = NULL;
|
|
|
|
VIR_APPEND_ELEMENT(paths, npaths, terminator);
|
|
|
|
*pathsRet = paths;
|
2019-04-04 15:20:37 +02:00
|
|
|
}
|
|
|
|
|
2024-02-29 16:16:53 +01:00
|
|
|
return nfirmwares;
|
2019-04-04 15:20:37 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
/**
|
|
|
|
* qemuFirmwareFillDomainLegacy:
|
|
|
|
* @driver: QEMU driver
|
|
|
|
* @def: domain definition
|
|
|
|
*
|
|
|
|
* Go through the legacy list of CODE:VARS pairs looking for a
|
|
|
|
* suitable NVRAM template for the user-provided firmware path.
|
|
|
|
*
|
|
|
|
* Should only be used as a fallback in case looking at the firmware
|
|
|
|
* descriptors yielded no results.
|
|
|
|
*
|
|
|
|
* Returns: 0 on success,
|
|
|
|
* 1 if a matching firmware could not be found,
|
|
|
|
* -1 on error.
|
|
|
|
*/
|
|
|
|
static int
|
|
|
|
qemuFirmwareFillDomainLegacy(virQEMUDriver *driver,
|
|
|
|
virDomainDef *def)
|
2019-02-22 15:25:31 +01:00
|
|
|
{
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
g_autoptr(virQEMUDriverConfig) cfg = virQEMUDriverGetConfig(driver);
|
|
|
|
virDomainLoaderDef *loader = def->os.loader;
|
2019-02-22 15:25:31 +01:00
|
|
|
size_t i;
|
|
|
|
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
if (!loader)
|
2023-08-02 17:18:32 +02:00
|
|
|
return 1;
|
2022-05-04 09:51:11 -07:00
|
|
|
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
if (loader->type != VIR_DOMAIN_LOADER_TYPE_PFLASH) {
|
|
|
|
VIR_DEBUG("Ignoring legacy entries for '%s' loader",
|
|
|
|
virDomainLoaderTypeToString(loader->type));
|
2023-08-02 17:18:32 +02:00
|
|
|
return 1;
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
}
|
2022-06-03 13:22:42 +02:00
|
|
|
|
2023-05-30 18:01:58 +02:00
|
|
|
if (loader->readonly == VIR_TRISTATE_BOOL_NO) {
|
|
|
|
VIR_DEBUG("Ignoring legacy entries for read-write loader");
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
if (loader->stateless == VIR_TRISTATE_BOOL_YES) {
|
|
|
|
VIR_DEBUG("Ignoring legacy entries for stateless loader");
|
2023-08-02 17:18:32 +02:00
|
|
|
return 1;
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
}
|
|
|
|
|
2023-05-16 19:50:50 +02:00
|
|
|
if (loader->format &&
|
|
|
|
loader->format != VIR_STORAGE_FILE_RAW) {
|
2023-01-31 17:46:58 +01:00
|
|
|
VIR_DEBUG("Ignoring legacy entries for loader with flash format '%s'",
|
|
|
|
virStorageFileFormatTypeToString(loader->format));
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
for (i = 0; i < cfg->nfirmwares; i++) {
|
|
|
|
virFirmware *fw = cfg->firmwares[i];
|
|
|
|
|
|
|
|
if (STRNEQ(fw->name, loader->path)) {
|
|
|
|
VIR_DEBUG("Not matching loader path '%s' for user provided path '%s'",
|
|
|
|
fw->name, loader->path);
|
|
|
|
continue;
|
2022-06-03 13:22:42 +02:00
|
|
|
}
|
2019-12-17 17:45:50 +01:00
|
|
|
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
loader->type = VIR_DOMAIN_LOADER_TYPE_PFLASH;
|
|
|
|
loader->readonly = VIR_TRISTATE_BOOL_YES;
|
2023-05-26 14:40:02 +02:00
|
|
|
loader->format = VIR_STORAGE_FILE_RAW;
|
2023-03-22 00:22:43 +01:00
|
|
|
|
2023-05-26 19:59:06 +02:00
|
|
|
/* Only use the default template path if one hasn't been
|
|
|
|
* provided by the user.
|
|
|
|
*
|
|
|
|
* In addition to fully-custom templates, which are a valid
|
|
|
|
* use case, we could simply be in a situation where
|
|
|
|
* qemu.conf contains
|
|
|
|
*
|
|
|
|
* nvram = [
|
|
|
|
* "/path/to/OVMF_CODE.secboot.fd:/path/to/OVMF_VARS.fd",
|
|
|
|
* "/path/to/OVMF_CODE.secboot.fd:/path/to/OVMF_VARS.secboot.fd"
|
|
|
|
* ]
|
|
|
|
*
|
|
|
|
* and the domain has been configured as
|
|
|
|
*
|
|
|
|
* <os>
|
|
|
|
* <loader readonly='yes' type='pflash'>/path/to/OVMF_CODE.secboot.fd</loader>
|
|
|
|
* <nvram template='/path/to/OVMF/OVMF_VARS.secboot.fd'>
|
|
|
|
* </os>
|
|
|
|
*
|
|
|
|
* In this case, the global default is to have Secure Boot
|
|
|
|
* disabled, but the domain configuration explicitly enables
|
|
|
|
* it, and we shouldn't overrule this choice */
|
|
|
|
if (!loader->nvramTemplate)
|
|
|
|
loader->nvramTemplate = g_strdup(cfg->firmwares[i]->nvram);
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
|
|
|
|
VIR_DEBUG("decided on firmware '%s' template '%s'",
|
|
|
|
loader->path, NULLSTR(loader->nvramTemplate));
|
|
|
|
|
|
|
|
return 0;
|
2019-12-17 17:45:50 +01:00
|
|
|
}
|
2019-02-22 15:25:31 +01:00
|
|
|
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
* qemuFirmwareFillDomainModern:
|
|
|
|
* @driver: QEMU driver
|
|
|
|
* @def: domain definition
|
|
|
|
*
|
|
|
|
* Look at the firmware descriptors available on the system and try
|
|
|
|
* to find one that matches the user's requested configuration. If
|
|
|
|
* successful, @def will be updated so that it explicitly points to
|
|
|
|
* the corresponding paths.
|
|
|
|
*
|
|
|
|
* Returns: 0 on success,
|
|
|
|
* 1 if a matching firmware could not be found,
|
|
|
|
* -1 on error.
|
|
|
|
*/
|
|
|
|
static int
|
|
|
|
qemuFirmwareFillDomainModern(virQEMUDriver *driver,
|
|
|
|
virDomainDef *def)
|
|
|
|
{
|
|
|
|
g_auto(GStrv) paths = NULL;
|
|
|
|
qemuFirmware **firmwares = NULL;
|
|
|
|
ssize_t nfirmwares = 0;
|
|
|
|
const qemuFirmware *theone = NULL;
|
|
|
|
size_t i;
|
|
|
|
int ret = -1;
|
|
|
|
|
2019-04-04 15:20:37 +02:00
|
|
|
if ((nfirmwares = qemuFirmwareFetchParsedConfigs(driver->privileged,
|
|
|
|
&firmwares, &paths)) < 0)
|
2019-02-22 15:25:31 +01:00
|
|
|
return -1;
|
|
|
|
|
|
|
|
for (i = 0; i < nfirmwares; i++) {
|
2019-12-13 15:41:16 +01:00
|
|
|
if (qemuFirmwareMatchDomain(def, firmwares[i], paths[i])) {
|
2019-02-22 15:25:31 +01:00
|
|
|
theone = firmwares[i];
|
|
|
|
VIR_DEBUG("Found matching firmware (description path '%s')",
|
|
|
|
paths[i]);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!theone) {
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
ret = 1;
|
2019-02-22 15:25:31 +01:00
|
|
|
goto cleanup;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Firstly, let's do some sanity checks. If either of these
|
|
|
|
* fail we can still start the domain successfully, but it's
|
|
|
|
* likely that admin/FW manufacturer messed up. */
|
|
|
|
qemuFirmwareSanityCheck(theone, paths[i]);
|
|
|
|
|
2023-05-26 14:40:02 +02:00
|
|
|
if (qemuFirmwareEnableFeaturesModern(def, theone) < 0)
|
2019-02-22 15:25:31 +01:00
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
ret = 0;
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
|
2019-02-22 15:25:31 +01:00
|
|
|
cleanup:
|
|
|
|
for (i = 0; i < nfirmwares; i++)
|
|
|
|
qemuFirmwareFree(firmwares[i]);
|
|
|
|
VIR_FREE(firmwares);
|
|
|
|
return ret;
|
|
|
|
}
|
2019-04-04 15:52:53 +02:00
|
|
|
|
|
|
|
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
/**
|
|
|
|
* qemuFirmwareFillDomain:
|
|
|
|
* @driver: QEMU driver
|
|
|
|
* @def: domain definition
|
2023-05-30 18:24:40 +02:00
|
|
|
* @abiUpdate: whether a new domain is being defined
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
*
|
|
|
|
* Perform firmware selection.
|
|
|
|
*
|
|
|
|
* When firmware autoselection is used, this means looking at the
|
|
|
|
* firmware descriptors available on the system and finding one that
|
|
|
|
* matches the user's requested parameters; when manual firmware
|
|
|
|
* selection is used, the path to the firmware itself is usually
|
|
|
|
* already provided, but other information such as the path to the
|
|
|
|
* NVRAM template might be missing.
|
|
|
|
*
|
|
|
|
* The idea is that calling this function a first time (at PostParse
|
|
|
|
* time) will convert whatever partial configuration the user might
|
|
|
|
* have provided into a fully specified firmware configuration, such
|
|
|
|
* as that calling it a second time (at domain start time) will
|
|
|
|
* result in an early successful exit. The same thing should happen
|
|
|
|
* if the input configuration wasn't missing any information in the
|
|
|
|
* first place.
|
|
|
|
*
|
|
|
|
* Returns: 0 on success,
|
|
|
|
* -1 on error.
|
|
|
|
*/
|
|
|
|
int
|
|
|
|
qemuFirmwareFillDomain(virQEMUDriver *driver,
|
2023-05-30 18:24:40 +02:00
|
|
|
virDomainDef *def,
|
|
|
|
bool abiUpdate)
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
{
|
|
|
|
virDomainLoaderDef *loader = def->os.loader;
|
2023-02-07 19:12:44 +01:00
|
|
|
virStorageSource *nvram = loader ? loader->nvram : NULL;
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
bool autoSelection = (def->os.firmware != VIR_DOMAIN_OS_DEF_FIRMWARE_NONE);
|
|
|
|
int ret;
|
|
|
|
|
|
|
|
/* Start by performing a thorough validation of the input.
|
|
|
|
*
|
|
|
|
* We need to do this here because the firmware selection logic
|
|
|
|
* can only work correctly if the request is constructed
|
|
|
|
* properly; at the same time, we can't rely on Validate having
|
|
|
|
* been called ahead of time, because in some situations (such as
|
|
|
|
* when loading the configuration of existing domains from disk)
|
|
|
|
* that entire phase is intentionally skipped */
|
|
|
|
if (virDomainDefOSValidate(def, NULL) < 0)
|
|
|
|
return -1;
|
|
|
|
|
2023-02-07 19:12:44 +01:00
|
|
|
if (loader &&
|
2023-05-16 19:50:50 +02:00
|
|
|
loader->format &&
|
2023-02-07 18:59:00 +01:00
|
|
|
loader->format != VIR_STORAGE_FILE_RAW &&
|
|
|
|
loader->format != VIR_STORAGE_FILE_QCOW2) {
|
2023-02-07 19:12:44 +01:00
|
|
|
virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
|
2023-03-09 13:15:22 +01:00
|
|
|
_("Unsupported loader format '%1$s'"),
|
2023-02-07 19:12:44 +01:00
|
|
|
virStorageFileFormatTypeToString(loader->format));
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
if (nvram &&
|
2023-05-16 19:50:50 +02:00
|
|
|
nvram->format &&
|
2023-02-07 18:59:00 +01:00
|
|
|
nvram->format != VIR_STORAGE_FILE_RAW &&
|
|
|
|
nvram->format != VIR_STORAGE_FILE_QCOW2) {
|
2023-02-07 19:12:44 +01:00
|
|
|
virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
|
2023-03-09 13:15:22 +01:00
|
|
|
_("Unsupported nvram format '%1$s'"),
|
2023-02-07 19:12:44 +01:00
|
|
|
virStorageFileFormatTypeToString(nvram->format));
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
/* If firmware autoselection is disabled and the loader is a ROM
|
|
|
|
* instead of a PFLASH device, then we're using BIOS and we don't
|
|
|
|
* need any information at all */
|
|
|
|
if (!autoSelection &&
|
|
|
|
(!loader || (loader && loader->type == VIR_DOMAIN_LOADER_TYPE_ROM))) {
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Look for the information we need in firmware descriptors */
|
|
|
|
if ((ret = qemuFirmwareFillDomainModern(driver, def)) < 0)
|
|
|
|
return -1;
|
|
|
|
|
|
|
|
if (ret == 1) {
|
|
|
|
/* If we haven't found any match among firmware descriptors,
|
|
|
|
* that would normally be the end of it.
|
|
|
|
*
|
|
|
|
* However, in order to handle legacy configurations
|
|
|
|
* correctly, we make another attempt at locating the missing
|
|
|
|
* information by going through the hardcoded list of
|
|
|
|
* CODE:NVRAM pairs that might have been provided at build
|
|
|
|
* time */
|
|
|
|
if (!autoSelection) {
|
2023-05-16 19:50:50 +02:00
|
|
|
if ((ret = qemuFirmwareFillDomainLegacy(driver, def)) < 0)
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
return -1;
|
2023-05-16 19:50:50 +02:00
|
|
|
|
|
|
|
/* If we've gotten this far without finding a match, it
|
|
|
|
* means that we're dealing with a set of completely
|
|
|
|
* custom paths. In that case, unless the user has
|
|
|
|
* specified otherwise, we have to assume that they're in
|
|
|
|
* raw format */
|
|
|
|
if (ret == 1) {
|
|
|
|
if (loader && !loader->format) {
|
|
|
|
loader->format = VIR_STORAGE_FILE_RAW;
|
|
|
|
}
|
|
|
|
}
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
} else {
|
|
|
|
virReportError(VIR_ERR_OPERATION_FAILED,
|
2023-09-22 15:19:46 +02:00
|
|
|
_("Unable to find '%1$s' firmware that is compatible with the current configuration"),
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
virDomainOsDefFirmwareTypeToString(def->os.firmware));
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-05-26 14:40:02 +02:00
|
|
|
/* Always ensure that the NVRAM path is present, even if we
|
|
|
|
* haven't found a match: the configuration might simply be
|
|
|
|
* referring to a custom firmware build */
|
2023-05-30 18:24:40 +02:00
|
|
|
qemuFirmwareEnsureNVRAM(def, driver, abiUpdate);
|
2023-05-26 14:40:02 +02:00
|
|
|
|
qemu: Move firmware selection from startup to postparse
Currently, firmware selection is performed as part of the
domain startup process. This mostly works fine, but there's a
significant downside to this approach: since the process is
affected by factors outside of libvirt's control, specifically
the contents of the various JSON firmware descriptors and
their names, it's pretty much impossible to guarantee that the
outcome is always going to be the same. It would only take an
edk2 update, or a change made by the local admin, to render a
domain unbootable or downgrade its boot security.
To avoid this, move firmware selection to the postparse phase.
This way it will only be performed once, when the domain is
first defined; subsequent boots will not need to go through
the process again, as all the paths that were picked during
firmware selection are recorded in the domain XML.
Care is taken to ensure that existing domains are handled
correctly, even if their firmware configuration can't be
successfully resolved. Failure to complete the firmware
selection process is only considered fatal when defining a
new domain; in all other cases the error will be reported
during startup, as is already the case today.
Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
2023-01-24 17:01:48 +01:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2019-08-05 12:02:50 +02:00
|
|
|
/**
|
|
|
|
* qemuFirmwareGetSupported:
|
|
|
|
* @machine: machine type
|
|
|
|
* @arch: architecture
|
|
|
|
* @privileged: whether running as privileged user
|
|
|
|
* @supported: returned bitmap of supported interfaces
|
|
|
|
* @secure: true if at least one secure boot enabled FW was found
|
2019-08-05 14:56:32 +02:00
|
|
|
* @fws: (optional) list of found firmwares
|
|
|
|
* @nfws: (optional) number of members in @fws
|
2019-08-05 12:02:50 +02:00
|
|
|
*
|
|
|
|
* Parse all FW descriptors (depending whether running as @privileged this may
|
|
|
|
* or may not include user's $HOME) and for given combination of @machine and
|
|
|
|
* @arch extract information to be later reported in domain capabilities.
|
|
|
|
* The @supported contains a bitmap of found interfaces (and ORed values of 1
|
|
|
|
* << VIR_DOMAIN_OS_DEF_FIRMWARE_*). Then, @supported is true if at least one
|
|
|
|
* FW descriptor signalizes secure boot (although, this is checked against SMM
|
|
|
|
* rather than SECURE_BOOT because reasons).
|
|
|
|
*
|
2019-08-05 14:56:32 +02:00
|
|
|
* If @fws and @nfws are not NULL, then @fws is allocated (must be freed by
|
|
|
|
* caller when no longer needed) and contains list of firmwares found in form
|
|
|
|
* of virFirmware. This can be useful if caller wants to know the paths to
|
|
|
|
* firmware images (e.g. to present them in domain capabilities XML).
|
|
|
|
* Moreover, to allow the caller distinguish between no FW descriptors found
|
|
|
|
* and no matching FW descriptors found (nfws == 0 in both cases), the @fws is
|
|
|
|
* going to be allocated in case of the latter anyway (with no real content
|
|
|
|
* though).
|
|
|
|
*
|
2019-08-05 12:02:50 +02:00
|
|
|
* Returns: 0 on success,
|
|
|
|
* -1 otherwise.
|
|
|
|
*/
|
2019-04-04 15:52:53 +02:00
|
|
|
int
|
|
|
|
qemuFirmwareGetSupported(const char *machine,
|
|
|
|
virArch arch,
|
|
|
|
bool privileged,
|
|
|
|
uint64_t *supported,
|
2019-08-05 14:56:32 +02:00
|
|
|
bool *secure,
|
2021-03-11 08:16:13 +01:00
|
|
|
virFirmware ***fws,
|
2019-08-05 14:56:32 +02:00
|
|
|
size_t *nfws)
|
2019-04-04 15:52:53 +02:00
|
|
|
{
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmware **firmwares = NULL;
|
2019-04-04 15:52:53 +02:00
|
|
|
ssize_t nfirmwares = 0;
|
|
|
|
size_t i;
|
|
|
|
|
|
|
|
*supported = VIR_DOMAIN_OS_DEF_FIRMWARE_NONE;
|
|
|
|
*secure = false;
|
|
|
|
|
2019-08-05 14:56:32 +02:00
|
|
|
if (fws) {
|
|
|
|
*fws = NULL;
|
|
|
|
*nfws = 0;
|
|
|
|
}
|
|
|
|
|
2019-04-04 15:52:53 +02:00
|
|
|
if ((nfirmwares = qemuFirmwareFetchParsedConfigs(privileged,
|
|
|
|
&firmwares, NULL)) < 0)
|
|
|
|
return -1;
|
|
|
|
|
|
|
|
for (i = 0; i < nfirmwares; i++) {
|
2021-03-11 08:16:13 +01:00
|
|
|
qemuFirmware *fw = firmwares[i];
|
2019-08-05 14:56:32 +02:00
|
|
|
const qemuFirmwareMappingFlash *flash = &fw->mapping.data.flash;
|
|
|
|
const qemuFirmwareMappingMemory *memory = &fw->mapping.data.memory;
|
|
|
|
const char *fwpath = NULL;
|
|
|
|
const char *nvrampath = NULL;
|
2019-04-04 15:52:53 +02:00
|
|
|
size_t j;
|
|
|
|
|
|
|
|
if (!qemuFirmwareMatchesMachineArch(fw, machine, arch))
|
|
|
|
continue;
|
|
|
|
|
|
|
|
for (j = 0; j < fw->ninterfaces; j++) {
|
|
|
|
switch (fw->interfaces[j]) {
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_UEFI:
|
|
|
|
*supported |= 1ULL << VIR_DOMAIN_OS_DEF_FIRMWARE_EFI;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_BIOS:
|
|
|
|
*supported |= 1ULL << VIR_DOMAIN_OS_DEF_FIRMWARE_BIOS;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_NONE:
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_OPENFIRMWARE:
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_UBOOT:
|
|
|
|
case QEMU_FIRMWARE_OS_INTERFACE_LAST:
|
|
|
|
default:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
for (j = 0; j < fw->nfeatures; j++) {
|
|
|
|
switch (fw->features[j]) {
|
|
|
|
case QEMU_FIRMWARE_FEATURE_REQUIRES_SMM:
|
|
|
|
*secure = true;
|
|
|
|
break;
|
|
|
|
case QEMU_FIRMWARE_FEATURE_NONE:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_ACPI_S3:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_ACPI_S4:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_AMD_SEV:
|
2021-05-25 09:56:38 +02:00
|
|
|
case QEMU_FIRMWARE_FEATURE_AMD_SEV_ES:
|
2019-04-04 15:52:53 +02:00
|
|
|
case QEMU_FIRMWARE_FEATURE_ENROLLED_KEYS:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_SECURE_BOOT:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_VERBOSE_DYNAMIC:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_VERBOSE_STATIC:
|
|
|
|
case QEMU_FIRMWARE_FEATURE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
2019-08-05 14:56:32 +02:00
|
|
|
|
|
|
|
switch (fw->mapping.device) {
|
|
|
|
case QEMU_FIRMWARE_DEVICE_FLASH:
|
|
|
|
fwpath = flash->executable.filename;
|
|
|
|
nvrampath = flash->nvram_template.filename;
|
|
|
|
break;
|
|
|
|
|
|
|
|
case QEMU_FIRMWARE_DEVICE_MEMORY:
|
|
|
|
fwpath = memory->filename;
|
|
|
|
break;
|
|
|
|
|
|
|
|
case QEMU_FIRMWARE_DEVICE_KERNEL:
|
|
|
|
case QEMU_FIRMWARE_DEVICE_NONE:
|
|
|
|
case QEMU_FIRMWARE_DEVICE_LAST:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (fws && fwpath) {
|
2019-10-15 14:47:50 +02:00
|
|
|
g_autoptr(virFirmware) tmp = NULL;
|
2019-08-05 14:56:32 +02:00
|
|
|
|
|
|
|
/* Append only unique pairs. */
|
|
|
|
for (j = 0; j < *nfws; j++) {
|
|
|
|
if (STREQ((*fws)[j]->name, fwpath) &&
|
|
|
|
STREQ_NULLABLE((*fws)[j]->nvram, nvrampath))
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
2019-10-20 13:49:46 +02:00
|
|
|
if (j == *nfws) {
|
2020-10-05 12:27:57 +02:00
|
|
|
tmp = g_new0(virFirmware, 1);
|
2019-10-20 13:49:46 +02:00
|
|
|
|
|
|
|
tmp->name = g_strdup(fwpath);
|
|
|
|
tmp->nvram = g_strdup(nvrampath);
|
2021-08-03 14:14:20 +02:00
|
|
|
VIR_APPEND_ELEMENT(*fws, *nfws, tmp);
|
2019-10-20 13:49:46 +02:00
|
|
|
}
|
2019-08-05 14:56:32 +02:00
|
|
|
}
|
2019-04-04 15:52:53 +02:00
|
|
|
}
|
|
|
|
|
2021-03-20 00:37:05 +01:00
|
|
|
if (fws && !*fws && nfirmwares)
|
|
|
|
VIR_REALLOC_N(*fws, 0);
|
2019-08-05 14:56:32 +02:00
|
|
|
|
2019-04-04 15:52:53 +02:00
|
|
|
for (i = 0; i < nfirmwares; i++)
|
|
|
|
qemuFirmwareFree(firmwares[i]);
|
|
|
|
VIR_FREE(firmwares);
|
|
|
|
return 0;
|
|
|
|
}
|