| # -*- Mode: Python -*- |
| # vim: filetype=python |
| # |
| # SPDX-License-Identifier: GPL-2.0-or-later |
| |
| ## |
| # @rtc-reset-reinjection: |
| # |
| # Reset the RTC interrupt reinjection backlog. Can be used if another |
| # mechanism to synchronize guest time is in effect, for example QEMU |
| # guest agent's `guest-set-time` command. |
| # |
| # Use of this command is only applicable for x86 machines with an RTC, |
| # and on other machines will silently return without performing any |
| # action. |
| # |
| # Since: 2.1 |
| # |
| # .. qmp-example:: |
| # |
| # -> { "execute": "rtc-reset-reinjection" } |
| # <- { "return": {} } |
| ## |
| { 'command': 'rtc-reset-reinjection' } |
| |
| ## |
| # @SevState: |
| # |
| # An enumeration of SEV state information used during `query-sev`. |
| # |
| # @uninit: The guest is uninitialized. |
| # |
| # @launch-update: The guest is currently being launched; plaintext |
| # data and register state is being imported. |
| # |
| # @launch-secret: The guest is currently being launched; ciphertext |
| # data is being imported. |
| # |
| # @running: The guest is fully launched or migrated in. |
| # |
| # @send-update: The guest is currently being migrated out to another |
| # machine. |
| # |
| # @receive-update: The guest is currently being migrated from another |
| # machine. |
| # |
| # Since: 2.12 |
| ## |
| { 'enum': 'SevState', |
| 'data': ['uninit', 'launch-update', 'launch-secret', 'running', |
| 'send-update', 'receive-update' ] } |
| |
| ## |
| # @SevGuestType: |
| # |
| # An enumeration indicating the type of SEV guest being run. |
| # |
| # @sev: The guest is a legacy SEV or SEV-ES guest. |
| # |
| # @sev-snp: The guest is an SEV-SNP guest. |
| # |
| # Since: 6.2 |
| ## |
| { 'enum': 'SevGuestType', |
| 'data': [ 'sev', 'sev-snp' ] } |
| |
| ## |
| # @SevGuestInfo: |
| # |
| # Information specific to legacy SEV/SEV-ES guests. |
| # |
| # @policy: SEV policy value |
| # |
| # @handle: SEV firmware handle |
| # |
| # Since: 2.12 |
| ## |
| { 'struct': 'SevGuestInfo', |
| 'data': { 'policy': 'uint32', |
| 'handle': 'uint32' } } |
| |
| ## |
| # @SevSnpGuestInfo: |
| # |
| # Information specific to SEV-SNP guests. |
| # |
| # @snp-policy: SEV-SNP policy value |
| # |
| # Since: 9.1 |
| ## |
| { 'struct': 'SevSnpGuestInfo', |
| 'data': { 'snp-policy': 'uint64' } } |
| |
| ## |
| # @SevInfo: |
| # |
| # Information about Secure Encrypted Virtualization (SEV) support |
| # |
| # @enabled: true if SEV is active |
| # |
| # @api-major: SEV API major version |
| # |
| # @api-minor: SEV API minor version |
| # |
| # @build-id: SEV FW build id |
| # |
| # @state: SEV guest state |
| # |
| # @sev-type: Type of SEV guest being run |
| # |
| # Since: 2.12 |
| ## |
| { 'union': 'SevInfo', |
| 'base': { 'enabled': 'bool', |
| 'api-major': 'uint8', |
| 'api-minor' : 'uint8', |
| 'build-id' : 'uint8', |
| 'state' : 'SevState', |
| 'sev-type' : 'SevGuestType' }, |
| 'discriminator': 'sev-type', |
| 'data': { |
| 'sev': 'SevGuestInfo', |
| 'sev-snp': 'SevSnpGuestInfo' } } |
| |
| |
| ## |
| # @query-sev: |
| # |
| # Return information about SEV/SEV-ES/SEV-SNP. |
| # |
| # If unavailable due to an incompatible configuration the returned |
| # @enabled field is set to 'false' and the state of all other fields |
| # is unspecified. |
| # |
| # Since: 2.12 |
| # |
| # .. qmp-example:: |
| # |
| # -> { "execute": "query-sev" } |
| # <- { "return": { "enabled": true, "api-major" : 0, "api-minor" : 0, |
| # "build-id" : 0, "policy" : 0, "state" : "running", |
| # "handle" : 1 } } |
| ## |
| { 'command': 'query-sev', 'returns': 'SevInfo' } |
| |
| ## |
| # @SevLaunchMeasureInfo: |
| # |
| # SEV Guest Launch measurement information |
| # |
| # @data: the measurement value encoded in base64 |
| # |
| # Since: 2.12 |
| ## |
| { 'struct': 'SevLaunchMeasureInfo', 'data': {'data': 'str'} } |
| |
| ## |
| # @query-sev-launch-measure: |
| # |
| # Query the SEV/SEV-ES guest launch information. |
| # |
| # This is only valid on x86 machines configured with KVM and the |
| # 'sev-guest' confidential virtualization object. The launch |
| # measurement for SEV-SNP guests is only available within the guest. |
| # |
| # Returns: The guest's SEV guest launch measurement info |
| # |
| # Errors: |
| # - If the launch measurement is unavailable, either due to an |
| # invalid guest configuration or if the guest has not reached |
| # the required SEV state, GenericError |
| # |
| # Since: 2.12 |
| # |
| # .. qmp-example:: |
| # |
| # -> { "execute": "query-sev-launch-measure" } |
| # <- { "return": { "data": "4l8LXeNlSPUDlXPJG5966/8%YZ" } } |
| ## |
| { 'command': 'query-sev-launch-measure', 'returns': 'SevLaunchMeasureInfo' } |
| |
| ## |
| # @SevCapability: |
| # |
| # The struct describes capability for a Secure Encrypted |
| # Virtualization feature. |
| # |
| # @pdh: Platform Diffie-Hellman key (base64 encoded) |
| # |
| # @cert-chain: PDH certificate chain (base64 encoded) |
| # |
| # @cpu0-id: Unique ID of CPU0 (base64 encoded) (since 7.1) |
| # |
| # @cbitpos: C-bit location in page table entry |
| # |
| # @reduced-phys-bits: Number of physical address bit reduction when |
| # SEV is enabled |
| # |
| # Since: 2.12 |
| ## |
| { 'struct': 'SevCapability', |
| 'data': { 'pdh': 'str', |
| 'cert-chain': 'str', |
| 'cpu0-id': 'str', |
| 'cbitpos': 'int', |
| 'reduced-phys-bits': 'int'} } |
| |
| ## |
| # @query-sev-capabilities: |
| # |
| # Get SEV capabilities. |
| # |
| # This is only supported on AMD X86 platforms with KVM enabled. |
| # |
| # Errors: |
| # - If SEV is not available on the platform, GenericError |
| # |
| # Since: 2.12 |
| # |
| # .. qmp-example:: |
| # |
| # -> { "execute": "query-sev-capabilities" } |
| # <- { "return": { "pdh": "8CCDD8DDD", "cert-chain": "888CCCDDDEE", |
| # "cpu0-id": "2lvmGwo+...61iEinw==", |
| # "cbitpos": 47, "reduced-phys-bits": 1}} |
| ## |
| { 'command': 'query-sev-capabilities', 'returns': 'SevCapability' } |
| |
| ## |
| # @sev-inject-launch-secret: |
| # |
| # Inject a secret blob into a SEV/SEV-ES guest's memory. |
| # |
| # This is only valid on x86 machines configured with KVM and the |
| # 'sev-guest' confidential virtualization object. SEV-SNP guests do |
| # not support launch secret injection. |
| # |
| # @packet-header: the launch secret packet header encoded in base64 |
| # |
| # @secret: the launch secret data to be injected encoded in base64 |
| # |
| # @gpa: the guest physical address where secret will be injected. |
| # |
| # Errors: |
| # - If launch secret injection is not possible, either due to |
| # an invalid guest configuration, or if the guest has not |
| # reached the required SEV state, GenericError |
| # |
| # Since: 6.0 |
| ## |
| { 'command': 'sev-inject-launch-secret', |
| 'data': { 'packet-header': 'str', 'secret': 'str', '*gpa': 'uint64' } } |
| |
| ## |
| # @SevAttestationReport: |
| # |
| # The struct describes attestation report for a Secure Encrypted |
| # Virtualization feature. |
| # |
| # @data: guest attestation report (base64 encoded) |
| # |
| # Since: 6.1 |
| ## |
| { 'struct': 'SevAttestationReport', |
| 'data': { 'data': 'str'} } |
| |
| ## |
| # @query-sev-attestation-report: |
| # |
| # Get the SEV attestation report. |
| # |
| # This is only valid on x86 machines configured with KVM and the |
| # 'sev-guest' confidential virtualization object. The attestation |
| # report for SEV-SNP guests is only available within the guest. |
| # |
| # @mnonce: a random 16 bytes value encoded in base64 (it will be |
| # included in report) |
| # |
| # Errors: |
| # - If the attestation report is unavailable, either due to an |
| # invalid guest configuration or because the guest has not |
| # reached the required SEV state, GenericError |
| # |
| # Since: 6.1 |
| # |
| # .. qmp-example:: |
| # |
| # -> { "execute" : "query-sev-attestation-report", |
| # "arguments": { "mnonce": "aaaaaaa" } } |
| # <- { "return" : { "data": "aaaaaaaabbbddddd"} } |
| ## |
| { 'command': 'query-sev-attestation-report', |
| 'data': { 'mnonce': 'str' }, |
| 'returns': 'SevAttestationReport' } |
| |
| ## |
| # @SgxEpcSection: |
| # |
| # Information about intel SGX EPC section |
| # |
| # @node: the numa node |
| # |
| # @size: the size of EPC section |
| # |
| # Since: 7.0 |
| ## |
| { 'struct': 'SgxEpcSection', |
| 'data': { 'node': 'int', |
| 'size': 'uint64'}} |
| |
| ## |
| # @SgxInfo: |
| # |
| # Information about intel Safe Guard eXtension (SGX) support |
| # |
| # @sgx: true if SGX is supported |
| # |
| # @sgx1: true if SGX1 is supported |
| # |
| # @sgx2: true if SGX2 is supported |
| # |
| # @flc: true if FLC is supported |
| # |
| # @sections: The EPC sections information (Since: 7.0) |
| # |
| # Since: 6.2 |
| ## |
| { 'struct': 'SgxInfo', |
| 'data': { 'sgx': 'bool', |
| 'sgx1': 'bool', |
| 'sgx2': 'bool', |
| 'flc': 'bool', |
| 'sections': ['SgxEpcSection']} } |
| |
| ## |
| # @query-sgx: |
| # |
| # Return information about configured SGX capabilities of guest |
| # |
| # Since: 6.2 |
| # |
| # .. qmp-example:: |
| # |
| # -> { "execute": "query-sgx" } |
| # <- { "return": { "sgx": true, "sgx1" : true, "sgx2" : true, |
| # "flc": true, |
| # "sections": [{"node": 0, "size": 67108864}, |
| # {"node": 1, "size": 29360128}]} } |
| ## |
| { 'command': 'query-sgx', 'returns': 'SgxInfo' } |
| |
| ## |
| # @query-sgx-capabilities: |
| # |
| # Return information about SGX capabilities of host |
| # |
| # Since: 6.2 |
| # |
| # .. qmp-example:: |
| # |
| # -> { "execute": "query-sgx-capabilities" } |
| # <- { "return": { "sgx": true, "sgx1" : true, "sgx2" : true, |
| # "flc": true, |
| # "section" : [{"node": 0, "size": 67108864}, |
| # {"node": 1, "size": 29360128}]} } |
| ## |
| { 'command': 'query-sgx-capabilities', 'returns': 'SgxInfo' } |
| |
| ## |
| # @EvtchnPortType: |
| # |
| # An enumeration of Xen event channel port types. |
| # |
| # @closed: The port is unused. |
| # |
| # @unbound: The port is allocated and ready to be bound. |
| # |
| # @interdomain: The port is connected as an interdomain interrupt. |
| # |
| # @pirq: The port is bound to a physical IRQ (PIRQ). |
| # |
| # @virq: The port is bound to a virtual IRQ (VIRQ). |
| # |
| # @ipi: The post is an inter-processor interrupt (IPI). |
| # |
| # Since: 8.0 |
| ## |
| { 'enum': 'EvtchnPortType', |
| 'data': ['closed', 'unbound', 'interdomain', 'pirq', 'virq', 'ipi'] } |
| |
| ## |
| # @EvtchnInfo: |
| # |
| # Information about a Xen event channel port |
| # |
| # @port: the port number |
| # |
| # @vcpu: target vCPU for this port |
| # |
| # @type: the port type |
| # |
| # @remote-domain: remote domain for interdomain ports |
| # |
| # @target: remote port ID, or virq/pirq number |
| # |
| # @pending: port is currently active pending delivery |
| # |
| # @masked: port is masked |
| # |
| # Since: 8.0 |
| ## |
| { 'struct': 'EvtchnInfo', |
| 'data': {'port': 'uint16', |
| 'vcpu': 'uint32', |
| 'type': 'EvtchnPortType', |
| 'remote-domain': 'str', |
| 'target': 'uint16', |
| 'pending': 'bool', |
| 'masked': 'bool'} } |
| |
| |
| ## |
| # @xen-event-list: |
| # |
| # Query the Xen event channels opened by the guest. |
| # |
| # Returns: list of open event channel ports. |
| # |
| # Since: 8.0 |
| # |
| # .. qmp-example:: |
| # |
| # -> { "execute": "xen-event-list" } |
| # <- { "return": [ |
| # { |
| # "pending": false, |
| # "port": 1, |
| # "vcpu": 1, |
| # "remote-domain": "qemu", |
| # "masked": false, |
| # "type": "interdomain", |
| # "target": 1 |
| # }, |
| # { |
| # "pending": false, |
| # "port": 2, |
| # "vcpu": 0, |
| # "remote-domain": "", |
| # "masked": false, |
| # "type": "virq", |
| # "target": 0 |
| # } |
| # ] |
| # } |
| ## |
| { 'command': 'xen-event-list', |
| 'returns': ['EvtchnInfo'] } |
| |
| ## |
| # @xen-event-inject: |
| # |
| # Inject a Xen event channel port (interrupt) to the guest. |
| # |
| # @port: The port number |
| # |
| # Since: 8.0 |
| # |
| # .. qmp-example:: |
| # |
| # -> { "execute": "xen-event-inject", "arguments": { "port": 1 } } |
| # <- { "return": { } } |
| ## |
| { 'command': 'xen-event-inject', |
| 'data': { 'port': 'uint32' } } |