public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Christian Ludwig <christian_ludwig@genua.de>
To: <pve-devel@lists.proxmox.com>
Subject: [PATCH qemu-server 4/7] api: add endpoint for SEV attestation data
Date: Thu, 24 Sep 2026 16:14:07 +0200	[thread overview]
Message-ID: <eb3321d89342af5df8027e6b4989d187dc101775.1790236014.git@genua.de> (raw)
In-Reply-To: <chipid.1790235905.git@genua.de>

[-- Attachment #1: Type: text/plain, Size: 2799 bytes --]

Expose the SEV chip ID and the raw reported SNP TCB security patch
levels collected by query-machine-capabilities, so that a remote
attestation client can construct the AMD KDS URL for this host's VCEK
certificate.

If query-machine-capabilities has not run yet, report no data instead
of failing the request.

Signed-off-by: Christian Ludwig <christian_ludwig@genua.de>
---
 src/PVE/API2/Qemu/Makefile |  2 +-
 src/PVE/API2/Qemu/Sev.pm   | 63 ++++++++++++++++++++++++++++++++++++++
 2 files changed, 64 insertions(+), 1 deletion(-)
 create mode 100644 src/PVE/API2/Qemu/Sev.pm

diff --git a/src/PVE/API2/Qemu/Makefile b/src/PVE/API2/Qemu/Makefile
index c348af75..12821bb0 100644
--- a/src/PVE/API2/Qemu/Makefile
+++ b/src/PVE/API2/Qemu/Makefile
@@ -2,7 +2,7 @@ DESTDIR=
 PREFIX=/usr
 PERLDIR=$(PREFIX)/share/perl5
 
-SOURCES=Agent.pm CPU.pm CPUFlags.pm HMPPerms.pm Machine.pm
+SOURCES=Agent.pm CPU.pm CPUFlags.pm HMPPerms.pm Machine.pm Sev.pm
 
 .PHONY: install
 install:
diff --git a/src/PVE/API2/Qemu/Sev.pm b/src/PVE/API2/Qemu/Sev.pm
new file mode 100644
index 00000000..7f8ce9d7
--- /dev/null
+++ b/src/PVE/API2/Qemu/Sev.pm
@@ -0,0 +1,63 @@
+package PVE::API2::Qemu::Sev;
+
+use strict;
+use warnings;
+
+use PVE::JSONSchema qw(get_standard_option);
+use PVE::RESTHandler;
+
+use PVE::QemuServer::CPUConfig;
+
+use base qw(PVE::RESTHandler);
+
+my $sev_status_properties = {
+    'sev-chip-id' => {
+        type => 'string',
+        default => '',
+        description => "Hex-encoded SEV chip unique ID."
+            . " Empty if unavailable.",
+    },
+    'sev-snp-tcb-version' => {
+        type => 'string',
+        default => '',
+        description => "Hex-encoded raw reported SNP TCB version."
+	    . " Empty if unavailable.",
+    },
+};
+
+__PACKAGE__->register_method({
+    name => 'index',
+    path => '',
+    method => 'GET',
+    proxyto => 'node',
+    description => "Get this node's SEV chip identity and reported SNP TCB.",
+    permissions => {
+        check => ['perm', '/nodes/{node}', ['Sys.Audit']],
+    },
+    parameters => {
+        additionalProperties => 0,
+        properties => {
+            node => get_standard_option('pve-node'),
+        },
+    },
+    returns => {
+        type => 'object',
+        properties => $sev_status_properties,
+    },
+    code => sub {
+        my ($param) = @_;
+
+        # may not have probed yet (e.g. early boot); treat as no data, not an error
+        my $hw_caps = eval { PVE::QemuServer::CPUConfig::get_hw_capabilities() };
+        my $sev = $hw_caps->{'amd-sev'} // {};
+
+        my $res = {};
+        for my $key (keys %$sev_status_properties) {
+            $res->{$key} = $sev->{$key} // $sev_status_properties->{$key}->{default};
+        }
+
+        return $res;
+    },
+});
+
+1;
-- 
2.34.1


  parent reply	other threads:[~2026-09-24 14:23 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 14:14 [PATCH 0/7] SEV: Expose chip ID and reported TCB versions Christian Ludwig
2026-09-24 14:14 ` [PATCH pve-common 1/7] procfs: read CPU model and stepping from cpuinfo Christian Ludwig
2026-09-24 14:14 ` [PATCH qemu-server 2/7] sev: Detect SEV- Christian Ludwig
2026-09-24 14:14 ` [PATCH qemu-server 3/7] sev: Expose chip ID and reported TCB versions Christian Ludwig
2026-09-24 14:14 ` Christian Ludwig [this message]
2026-09-24 14:14 ` [PATCH pve-manager 5/7] api: register SEV capabilities endpoint Christian Ludwig
2026-09-24 14:14 ` [PATCH pve-docs 6/7] qm: Describe ASIDs for SEV Christian Ludwig
2026-09-24 14:14 ` [PATCH pve-docs 7/7] sev: Describe VCEK retieval Christian Ludwig

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=eb3321d89342af5df8027e6b4989d187dc101775.1790236014.git@genua.de \
    --to=christian_ludwig@genua.de \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal