diff --git a/.github/workflows/build-kata-static-tarball-arm64.yaml b/.github/workflows/build-kata-static-tarball-arm64.yaml index c895185296..160c27846a 100644 --- a/.github/workflows/build-kata-static-tarball-arm64.yaml +++ b/.github/workflows/build-kata-static-tarball-arm64.yaml @@ -53,7 +53,6 @@ jobs: - kernel-debug - kernel-dragonball-experimental - kernel-nvidia-gpu - - kernel-cca-confidential - nydus - ovmf - pause-image diff --git a/src/runtime/Makefile b/src/runtime/Makefile index 6be0b79ba6..440955ff37 100644 --- a/src/runtime/Makefile +++ b/src/runtime/Makefile @@ -111,7 +111,6 @@ GENERATED_VARS = \ CONFIG_QEMU_NVIDIA_GPU_TDX_IN \ CONFIG_QEMU_TDX_IN \ CONFIG_QEMU_SNP_IN \ - CONFIG_QEMU_CCA_IN \ CONFIG_CLH_IN \ CONFIG_FC_IN \ CONFIG_STRATOVIRT_IN \ @@ -195,9 +194,6 @@ QEMUVALIDHYPERVISORPATHS := [\"$(QEMUPATH)\"] QEMUTDXEXPERIMENTALPATH := $(QEMUBINDIR)/$(QEMUTDXEXPERIMENTALCMD) QEMUTDXEXPERIMENTALVALIDHYPERVISORPATHS := [\"$(QEMUTDXEXPERIMENTALPATH)\"] -QEMUCCAEXPERIMENTALPATH := $(QEMUBINDIR)/$(QEMUCCAEXPERIMENTALCMD) -QEMUCCAEXPERIMENTALVALIDHYPERVISORPATHS := [\"$(QEMUCCAEXPERIMENTALPATH)\"] - QEMUTDXQUOTEGENERATIONSERVICESOCKETPORT := 0 QEMUSNPPATH := $(QEMUBINDIR)/$(QEMUSNPCMD) @@ -205,8 +201,6 @@ QEMUSNPVALIDHYPERVISORPATHS := [\"$(QEMUSNPPATH)\"] QEMUVIRTIOFSPATH := $(QEMUBINDIR)/$(QEMUVIRTIOFSCMD) -DEFCCAMEASUREMENTALGO := sha512 - CLHPATH := $(CLHBINDIR)/$(CLHCMD) CLHVALIDHYPERVISORPATHS := [\"$(CLHPATH)\"] @@ -277,7 +271,6 @@ DEFSHAREDFS_STRATOVIRT_VIRTIOFS := virtio-fs DEFSHAREDFS_QEMU_TDX_VIRTIOFS := none DEFSHAREDFS_QEMU_SNP_VIRTIOFS := none DEFSHAREDFS_QEMU_SEL_VIRTIOFS := none -DEFSHAREDFS_QEMU_CCA_VIRTIOFS := none DEFVIRTIOFSDAEMON := $(LIBEXECDIR)/virtiofsd DEFVALIDVIRTIOFSDAEMONPATHS := [\"$(DEFVIRTIOFSDAEMON)\"] # Default DAX mapping cache size in MiB @@ -404,18 +397,6 @@ ifneq (,$(QEMUCMD)) CONFIGS += $(CONFIG_QEMU_SNP) - CONFIG_FILE_QEMU_CCA = configuration-qemu-cca.toml - CONFIG_QEMU_CCA = config/$(CONFIG_FILE_QEMU_CCA) - CONFIG_QEMU_CCA_IN = $(CONFIG_QEMU_CCA).in - - CONFIG_PATH_QEMU_CCA = $(abspath $(CONFDIR)/$(CONFIG_FILE_QEMU_CCA)) - CONFIG_PATHS += $(CONFIG_PATH_QEMU_CCA) - - SYSCONFIG_QEMU_CCA = $(abspath $(SYSCONFDIR)/$(CONFIG_FILE_QEMU_CCA)) - SYSCONFIG_PATHS_CCA += $(SYSCONFIG_QEMU_CCA) - - CONFIGS += $(CONFIG_QEMU_CCA) - CONFIG_FILE_QEMU_NVIDIA_GPU = configuration-qemu-nvidia-gpu.toml CONFIG_QEMU_NVIDIA_GPU = config/$(CONFIG_FILE_QEMU_NVIDIA_GPU) CONFIG_QEMU_NVIDIA_GPU_IN = $(CONFIG_QEMU_NVIDIA_GPU).in @@ -492,10 +473,6 @@ ifneq (,$(QEMUCMD)) KERNELCONFIDENTIALNAME = $(call MAKE_KERNEL_NAME,$(KERNELCONFIDENTIALTYPE)) KERNELCONFIDENTIALPATH = $(KERNELDIR)/$(KERNELCONFIDENTIALNAME) - KERNELCONFIDENTIALTYPE_CCA = compressed - KERNELCONFIDENTIALNAME_CCA = $(call MAKE_KERNEL_CONFIDENTIAL_NAME,$(KERNELCONFIDENTIALTYPE_CCA)) - KERNELCONFIDENTIALPATH_CCA = $(KERNELDIR)/$(KERNELCONFIDENTIALNAME_CCA) - KERNELSENAME = kata-containers-se.img KERNELSEPATH = $(KERNELDIR)/$(KERNELSENAME) @@ -736,7 +713,6 @@ USER_VARS += KERNELTYPE_FC USER_VARS += KERNELTYPE_CLH USER_VARS += KERNELPATH USER_VARS += KERNELCONFIDENTIALPATH -USER_VARS += KERNELCONFIDENTIALPATH_CCA USER_VARS += KERNELSEPATH USER_VARS += KERNELPATH_CLH USER_VARS += KERNELPATH_CLH_AZURE @@ -778,17 +754,13 @@ USER_VARS += PROJECT_URL USER_VARS += QEMUBINDIR USER_VARS += QEMUCMD USER_VARS += QEMUTDXEXPERIMENTALCMD -USER_VARS += QEMUCCAEXPERIMENTALCMD USER_VARS += QEMUSNPCMD USER_VARS += QEMUPATH USER_VARS += QEMUTDXEXPERIMENTALPATH USER_VARS += QEMUTDXQUOTEGENERATIONSERVICESOCKETPORT USER_VARS += QEMUSNPPATH -USER_VARS += QEMUCCAEXPERIMENTALPATH USER_VARS += QEMUVALIDHYPERVISORPATHS USER_VARS += QEMUTDXEXPERIMENTALVALIDHYPERVISORPATHS -USER_VARS += QEMUCCAVALIDHYPERVISORPATHS -USER_VARS += QEMUCCAEXPERIMENTALVALIDHYPERVISORPATHS USER_VARS += QEMUSNPVALIDHYPERVISORPATHS USER_VARS += QEMUVIRTIOFSCMD USER_VARS += QEMUVIRTIOFSPATH @@ -863,8 +835,6 @@ USER_VARS += BUILDFLAGS USER_VARS += DEFDISABLEIMAGENVDIMM USER_VARS += DEFDISABLEIMAGENVDIMM_NV USER_VARS += DEFDISABLEIMAGENVDIMM_CLH -USER_VARS += DEFCCAMEASUREMENTALGO -USER_VARS += DEFSHAREDFS_QEMU_CCA_VIRTIOFS USER_VARS += DEFPODRESOURCEAPISOCK USER_VARS += DEFPODRESOURCEAPISOCK_NV @@ -961,10 +931,6 @@ define MAKE_KERNEL_VIRTIOFS_NAME $(if $(findstring uncompressed,$1),vmlinux-virtiofs.container,vmlinuz-virtiofs.container) endef -define MAKE_KERNEL_CONFIDENTIAL_NAME -$(if $(findstring uncompressed,$1),vmlinux-confidential.container,vmlinuz-confidential.container) -endef - define MAKE_KERNEL_NAME_NV $(if $(findstring uncompressed,$1),vmlinux-nvidia-gpu.container,vmlinuz-nvidia-gpu.container) endef diff --git a/src/runtime/arch/arm64-options.mk b/src/runtime/arch/arm64-options.mk index e951c020a3..749504cfca 100644 --- a/src/runtime/arch/arm64-options.mk +++ b/src/runtime/arch/arm64-options.mk @@ -11,7 +11,6 @@ MACHINEACCELERATORS := CPUFEATURES := pmu=off QEMUCMD := qemu-system-aarch64 -QEMUCCAEXPERIMENTALCMD := qemu-system-aarch64-cca-experimental QEMUFW := AAVMF_CODE.fd QEMUFWVOL := AAVMF_VARS.fd diff --git a/src/runtime/config/configuration-qemu-cca.toml.in b/src/runtime/config/configuration-qemu-cca.toml.in deleted file mode 100644 index c6761df64f..0000000000 --- a/src/runtime/config/configuration-qemu-cca.toml.in +++ /dev/null @@ -1,715 +0,0 @@ -# Copyright 2022 Advanced Micro Devices, Inc. -# -# SPDX-License-Identifier: Apache-2.0 -# - -# XXX: WARNING: this file is auto-generated. -# XXX: -# XXX: Source file: "@CONFIG_QEMU_CCA_IN@" -# XXX: Project: -# XXX: Name: @PROJECT_NAME@ -# XXX: Type: @PROJECT_TYPE@ - -[hypervisor.qemu] -path = "@QEMUCCAEXPERIMENTALPATH@" -kernel = "@KERNELCONFIDENTIALPATH_CCA@" -image = "@IMAGECONFIDENTIALPATH@" -machine_type = "@MACHINETYPE@" - -# rootfs filesystem type: -# - ext4 (default) -# - xfs -# - erofs -rootfs_type = @DEFROOTFSTYPE@ - -# Enable confidential guest support. -# Toggling that setting may trigger different hardware features, ranging -# from memory encryption to both memory and CPU-state encryption and integrity. -# The Kata Containers runtime dynamically detects the available feature set and -# aims at enabling the largest possible one, returning an error if none is -# available, or none is supported by the hypervisor. -# -# Known limitations: -# * Does not work by design: -# - CPU Hotplug -# - Memory Hotplug -# - NVDIMM devices -# -# Default false -confidential_guest = true - -# Enable running QEMU VMM as a non-root user. -# By default QEMU VMM run as root. When this is set to true, QEMU VMM process runs as -# a non-root random user. See documentation for the limitations of this mode. -rootless = false - -# List of valid annotation names for the hypervisor -# Each member of the list is a regular expression, which is the base name -# of the annotation, e.g. "path" for io.katacontainers.config.hypervisor.path" -enable_annotations = @DEFENABLEANNOTATIONS@ - -# List of valid annotations values for the hypervisor -# Each member of the list is a path pattern as described by glob(3). -# The default if not set is empty (all annotations rejected.) -# Your distribution recommends: @QEMUVALIDHYPERVISORPATHS@ -valid_hypervisor_paths = @QEMUCCAEXPERIMENTALVALIDHYPERVISORPATHS@ - -# Optional space-separated list of options to pass to the guest kernel. -# For example, use `kernel_params = "vsyscall=emulate"` if you are having -# trouble running pre-2.15 glibc. -# -# WARNING: - any parameter specified here will take priority over the default -# parameter value of the same name used to start the virtual machine. -# Do not set values here unless you understand the impact of doing so as you -# may stop the virtual machine from booting. -# To see the list of default parameters, enable hypervisor debug, create a -# container and look for 'default-kernel-parameters' log entries. -kernel_params = "@KERNELPARAMS@" - -# Path to the firmware. -# If you want that qemu uses the default firmware leave this option empty -firmware = "@FIRMWAREPATH@" - -# Path to the firmware volume. -# firmware TDVF or OVMF can be split into FIRMWARE_VARS.fd (UEFI variables -# as configuration) and FIRMWARE_CODE.fd (UEFI program image). UEFI variables -# can be customized per each user while UEFI code is kept same. -firmware_volume = "@FIRMWAREVOLUMEPATH@" - -# Machine accelerators -# comma-separated list of machine accelerators to pass to the hypervisor. -# For example, `machine_accelerators = "nosmm,nosmbus,nosata,nopit,static-prt,nofw"` -machine_accelerators = "@MACHINEACCELERATORS@" - -# Qemu seccomp sandbox feature -# comma-separated list of seccomp sandbox features to control the syscall access. -# For example, `seccompsandbox= "on,obsolete=deny,spawn=deny,resourcecontrol=deny"` -# Note: "elevateprivileges=deny" doesn't work with daemonize option, so it's removed from the seccomp sandbox -# Another note: enabling this feature may reduce performance, you may enable -# /proc/sys/net/core/bpf_jit_enable to reduce the impact. see https://man7.org/linux/man-pages/man8/bpfc.8.html -# Recommended value when enabling: "on,obsolete=deny,spawn=deny,resourcecontrol=deny" -seccompsandbox = "@DEFSECCOMPSANDBOXPARAM@" - -# CPU features -# comma-separated list of cpu features to pass to the cpu -# For example, `cpu_features = "pmu=off,vmx=off" -cpu_features = "@CPUFEATURES@" - -# Default number of vCPUs per SB/VM: -# unspecified or 0 --> will be set to @DEFVCPUS@ -# < 0 --> will be set to the actual number of physical cores -# > 0 <= number of physical cores --> will be set to the specified number -# > number of physical cores --> will be set to the actual number of physical cores -default_vcpus = 1 - -# Default maximum number of vCPUs per SB/VM: -# unspecified or == 0 --> will be set to the actual number of physical cores or to the maximum number -# of vCPUs supported by KVM if that number is exceeded -# > 0 <= number of physical cores --> will be set to the specified number -# > number of physical cores --> will be set to the actual number of physical cores or to the maximum number -# of vCPUs supported by KVM if that number is exceeded -# WARNING: Depending of the architecture, the maximum number of vCPUs supported by KVM is used when -# the actual number of physical cores is greater than it. -# WARNING: Be aware that this value impacts the virtual machine's memory footprint and CPU -# the hotplug functionality. For example, `default_maxvcpus = 240` specifies that until 240 vCPUs -# can be added to a SB/VM, but the memory footprint will be big. Another example, with -# `default_maxvcpus = 8` the memory footprint will be small, but 8 will be the maximum number of -# vCPUs supported by the SB/VM. In general, we recommend that you do not edit this variable, -# unless you know what are you doing. -# NOTICE: on arm platform with gicv2 interrupt controller, set it to 8. -default_maxvcpus = @DEFMAXVCPUS@ - -# Bridges can be used to hot plug devices. -# Limitations: -# * Currently only pci bridges are supported -# * Until 30 devices per bridge can be hot plugged. -# * Until 5 PCI bridges can be cold plugged per VM. -# This limitation could be a bug in qemu or in the kernel -# Default number of bridges per SB/VM: -# unspecified or 0 --> will be set to @DEFBRIDGES@ -# > 1 <= 5 --> will be set to the specified number -# > 5 --> will be set to 5 -default_bridges = @DEFBRIDGES@ - -# Default memory size in MiB for SB/VM. -# If unspecified then it will be set @DEFMEMSZ@ MiB. -default_memory = @DEFMEMSZ@ -# -# Default memory slots per SB/VM. -# If unspecified then it will be set @DEFMEMSLOTS@. -# This is will determine the times that memory will be hotadded to sandbox/VM. -memory_slots = @DEFMEMSLOTS@ - -# Default maximum memory in MiB per SB / VM -# unspecified or == 0 --> will be set to the actual amount of physical RAM -# > 0 <= amount of physical RAM --> will be set to the specified number -# > amount of physical RAM --> will be set to the actual amount of physical RAM -default_maxmemory = @DEFMAXMEMSZ@ - -# The size in MiB will be plused to max memory of hypervisor. -# It is the memory address space for the NVDIMM device. -# If set block storage driver (block_device_driver) to "nvdimm", -# should set memory_offset to the size of block device. -# Default 0 -memory_offset = 0 - -# Specifies virtio-mem will be enabled or not. -# Please note that this option should be used with the command -# "echo 1 > /proc/sys/vm/overcommit_memory". -# Default false -enable_virtio_mem = false - -# Disable hotplugging host block devices to guest VMs for container rootfs. -# In case of a storage driver like devicemapper where a container's -# root file system is backed by a block device, the block device is passed -# directly to the hypervisor for performance reasons. -# This flag prevents the block device from being passed to the hypervisor, -# virtio-fs is used instead to pass the rootfs. -# WARNING: -# Don't set this flag to false if you don't understand well the behavior of -# your container runtime and image snapshotter. Some snapshotters might use -# container image storage devices that are not meant to be hotplugged into a -# guest VM - e.g., because they contain files used by the host or by other -# guests. -disable_block_device_use = @DEFDISABLEBLOCK@ - -# Shared file system type: -# - virtio-fs (default) -# - virtio-9p -# - virtio-fs-nydus -# - none -shared_fs = "@DEFSHAREDFS_QEMU_CCA_VIRTIOFS@" - -# Path to vhost-user-fs daemon. -virtio_fs_daemon = "@DEFVIRTIOFSDAEMON@" - -# List of valid annotations values for the virtiofs daemon -# The default if not set is empty (all annotations rejected.) -# Your distribution recommends: @DEFVALIDVIRTIOFSDAEMONPATHS@ -valid_virtio_fs_daemon_paths = @DEFVALIDVIRTIOFSDAEMONPATHS@ - -# Default size of DAX cache in MiB -virtio_fs_cache_size = @DEFVIRTIOFSCACHESIZE@ - -# Extra args for virtiofsd daemon -# -# Format example: -# ["-o", "arg1=xxx,arg2", "-o", "hello world", "--arg3=yyy"] -# Examples: -# Set virtiofsd log level to debug : ["-o", "log_level=debug"] or ["-d"] -# -# see `virtiofsd -h` for possible options. -virtio_fs_extra_args = @DEFVIRTIOFSEXTRAARGS@ - -# Cache mode: -# -# - none -# Metadata, data, and pathname lookup are not cached in guest. They are -# always fetched from host and any changes are immediately pushed to host. -# -# - auto -# Metadata and pathname lookup cache expires after a configured amount of -# time (default is 1 second). Data is cached while the file is open (close -# to open consistency). -# -# - always -# Metadata, data, and pathname lookup are cached in guest and never expire. -virtio_fs_cache = "@DEFVIRTIOFSCACHE@" - -# Block storage driver to be used for the hypervisor in case the container -# rootfs is backed by a block device. This is virtio-scsi, virtio-blk -# or nvdimm. -block_device_driver = "@DEFBLOCKSTORAGEDRIVER_QEMU@" - -# Specifies cache-related options will be set to block devices or not. -# Default false -block_device_cache_set = false - -# Specifies cache-related options for block devices. -# Denotes whether use of O_DIRECT (bypass the host page cache) is enabled. -# Default false -block_device_cache_direct = false - -# Specifies cache-related options for block devices. -# Denotes whether flush requests for the device are ignored. -# Default false -block_device_cache_noflush = false - -# Specifies the logical sector size, in bytes, reported by block devices to the guest. -# Common values are 512 and 4096. Set to 0 to use the QEMU/hypervisor default. -# Default 0 -block_device_logical_sector_size = 0 - -# Specifies the physical sector size, in bytes, reported by block devices to the guest. -# Common values are 512 and 4096. Set to 0 to use the QEMU/hypervisor default. -# Default 0 -block_device_physical_sector_size = 0 - -# Enable iothreads (data-plane) to be used. This causes IO to be -# handled in a separate IO thread. This is currently only implemented -# for SCSI. -# -enable_iothreads = @DEFENABLEIOTHREADS@ - -# Enable pre allocation of VM RAM, default false -# Enabling this will result in lower container density -# as all of the memory will be allocated and locked -# This is useful when you want to reserve all the memory -# upfront or in the cases where you want memory latencies -# to be very predictable -# Default false -enable_mem_prealloc = false - -# Enable huge pages for VM RAM, default false -# Enabling this will result in the VM memory -# being allocated using huge pages. -# This is useful when you want to use vhost-user network -# stacks within the container. This will automatically -# result in memory pre allocation -enable_hugepages = false - -# Enable vhost-user storage device, default false -# Enabling this will result in some Linux reserved block type -# major range 240-254 being chosen to represent vhost-user devices. -enable_vhost_user_store = @DEFENABLEVHOSTUSERSTORE@ - -# The base directory specifically used for vhost-user devices. -# Its sub-path "block" is used for block devices; "block/sockets" is -# where we expect vhost-user sockets to live; "block/devices" is where -# simulated block device nodes for vhost-user devices to live. -vhost_user_store_path = "@DEFVHOSTUSERSTOREPATH@" - -# Enable vIOMMU, default false -# Enabling this will result in the VM having a vIOMMU device -# This will also add the following options to the kernel's -# command line: intel_iommu=on,iommu=pt -enable_iommu = false - -# Enable IOMMU_PLATFORM, default false -# Enabling this will result in the VM device having iommu_platform=on set -enable_iommu_platform = false - -# Enable NUMA topology, default false -# When enable_numa is enabled, the hypervisor will expose host NUMA topology -# as is: map VM NUMA nodes to host 1:1 and bind vCPUs to related CPUs. -# Note: To take proper advantage of NUMA, static_sandbox_resource_mgmt should -# also be enabled for memory pre-allocation. -enable_numa = false - -# NUMA node mapping allows customizing how VM NUMA nodes map to host NUMA nodes. -# Each entry defines a VM NUMA node and the host NUMA node(s) it maps to. -# Format: ["", "", ...] -# Example: ["0", "1"] creates 2 VM NUMA nodes, mapping to host nodes 0 and 1 -# Example: ["0-1", "2-3"] creates 2 VM NUMA nodes, first maps to host 0-1, second to 2-3 -# If empty and enable_numa is true, VM NUMA nodes map 1:1 to host NUMA nodes. -numa_mapping = [] - -# List of valid annotations values for the vhost user store path -# The default if not set is empty (all annotations rejected.) -# Your distribution recommends: @DEFVALIDVHOSTUSERSTOREPATHS@ -valid_vhost_user_store_paths = @DEFVALIDVHOSTUSERSTOREPATHS@ - -# -pflash can add image file to VM. The arguments of it should be in format -# of ["/path/to/flash0.img", "/path/to/flash1.img"] -pflashes = [] - -# This option changes the default hypervisor and kernel parameters -# to enable debug output where available. -# -# Default false -enable_debug = false - -# Disable the customizations done in the runtime when it detects -# that it is running on top a VMM. This will result in the runtime -# behaving as it would when running on bare metal. -# -disable_nesting_checks = false - -# This is the msize used for 9p shares. It is the number of bytes -# used for 9p packet payload. -msize_9p = @DEFMSIZE9P@ - -# If false and nvdimm is supported, use nvdimm device to plug guest image. -# Otherwise virtio-block device is used. -# -# nvdimm is not supported when `confidential_guest = true`. -disable_image_nvdimm = true - -# Before hot plugging a PCIe device, you need to add a pcie_root_port device. -# Use this parameter when using some large PCI bar devices, such as Nvidia GPU -# The value means the number of pcie_root_port -# Default 0 -pcie_root_port = 0 - -# If vhost-net backend for virtio-net is not desired, set to true. Default is false, which trades off -# security (vhost-net runs ring0) for network I/O performance. -disable_vhost_net = false - -# -# Default entropy source. -# The path to a host source of entropy (including a real hardware RNG) -# /dev/urandom and /dev/random are two main options. -# Be aware that /dev/random is a blocking source of entropy. If the host -# runs out of entropy, the VMs boot time will increase leading to get startup -# timeouts. -# The source of entropy /dev/urandom is non-blocking and provides a -# generally acceptable source of entropy. It should work well for pretty much -# all practical purposes. -entropy_source= "@DEFENTROPYSOURCE@" - -# List of valid annotations values for entropy_source -# The default if not set is empty (all annotations rejected.) -# Your distribution recommends: @DEFVALIDENTROPYSOURCES@ -valid_entropy_sources = @DEFVALIDENTROPYSOURCES@ - -# Path to OCI hook binaries in the *guest rootfs*. -# This does not affect host-side hooks which must instead be added to -# the OCI spec passed to the runtime. -# -# You can create a rootfs with hooks by customizing the osbuilder scripts: -# https://github.com/kata-containers/kata-containers/tree/main/tools/osbuilder -# -# Hooks must be stored in a subdirectory of guest_hook_path according to their -# hook type, i.e. "guest_hook_path/{prestart,poststart,poststop}". -# The agent will scan these directories for executable files and add them, in -# lexicographical order, to the lifecycle of the guest container. -# Hooks are executed in the runtime namespace of the guest. See the official documentation: -# https://github.com/opencontainers/runtime-spec/blob/v1.0.1/config.md#posix-platform-hooks -# Warnings will be logged if any error is encountered while scanning for hooks, -# but it will not abort container execution. -guest_hook_path = "" -# -# Use rx Rate Limiter to control network I/O inbound bandwidth(size in bits/sec for SB/VM). -# In Qemu, we use classful qdiscs HTB(Hierarchy Token Bucket) to discipline traffic. -# Default 0-sized value means unlimited rate. -rx_rate_limiter_max_rate = 0 -# Use tx Rate Limiter to control network I/O outbound bandwidth(size in bits/sec for SB/VM). -# In Qemu, we use classful qdiscs HTB(Hierarchy Token Bucket) and ifb(Intermediate Functional Block) -# to discipline traffic. -# Default 0-sized value means unlimited rate. -tx_rate_limiter_max_rate = 0 - -# Set where to save the guest memory dump file. -# If set, when GUEST_PANICKED event occurred, -# guest memeory will be dumped to host filesystem under guest_memory_dump_path, -# This directory will be created automatically if it does not exist. -# -# The dumped file(also called vmcore) can be processed with crash or gdb. -# -# WARNING: -# Dump guest's memory can take very long depending on the amount of guest memory -# and use much disk space. -# Recommended value when enabling: "/var/crash/kata" -guest_memory_dump_path = "" - -# If enable paging. -# Basically, if you want to use "gdb" rather than "crash", -# or need the guest-virtual addresses in the ELF vmcore, -# then you should enable paging. -# -# See: https://www.qemu.org/docs/master/qemu-qmp-ref.html#Dump-guest-memory for details -guest_memory_dump_paging = false - -# Enable swap in the guest. Default false. -# When enable_guest_swap is enabled, insert a raw file to the guest as the swap device -# if the swappiness of a container (set by annotation "io.katacontainers.container.resource.swappiness") -# is bigger than 0. -# The size of the swap device should be -# swap_in_bytes (set by annotation "io.katacontainers.container.resource.swap_in_bytes") - memory_limit_in_bytes. -# If swap_in_bytes is not set, the size should be memory_limit_in_bytes. -# If swap_in_bytes and memory_limit_in_bytes is not set, the size should -# be default_memory. -enable_guest_swap = false - -# use legacy serial for guest console if available and implemented for architecture. Default false -use_legacy_serial = false - -# disable applying SELinux on the VMM process (default false) -disable_selinux = @DEFDISABLESELINUX@ - -# disable applying SELinux on the container process -# If set to false, the type `container_t` is applied to the container process by default. -# Note: To enable guest SELinux, the guest rootfs must be CentOS that is created and built -# with `SELINUX=yes`. -# (default: true) -disable_guest_selinux = @DEFDISABLEGUESTSELINUX@ - -# In QEMU, the Realm Management Extension (RME) measurement algorithm is used for attestation, and it supports -# sha256 and sha512 as options. The default is sha512. This algorithm is crucial for verifying the integrity of a -# Realm, a secure execution environment within the larger system. QEMU supports sha256 and sha512 for CCA RME -# measurements. sha512 is generally preferred on 64-bit architectures due to potential hardware acceleration. -measurement_algo = "@DEFCCAMEASUREMENTALGO@" - -[factory] -# VM templating support. Once enabled, new VMs are created from template -# using vm cloning. They will share the same initial kernel, initramfs and -# agent memory by mapping it readonly. It helps speeding up new container -# creation and saves a lot of memory if there are many kata containers running -# on the same host. -# -# When disabled, new VMs are created from scratch. -# -# Note: Requires "initrd=" to be set ("image=" is not supported). -# -# Default false -enable_template = false - -# Specifies the path of template. -# -# Default "/run/vc/vm/template" -template_path = "/run/vc/vm/template" - -# The number of caches of VMCache: -# unspecified or == 0 --> VMCache is disabled -# > 0 --> will be set to the specified number -# -# VMCache is a function that creates VMs as caches before using it. -# It helps speed up new container creation. -# The function consists of a server and some clients communicating -# through Unix socket. The protocol is gRPC in protocols/cache/cache.proto. -# The VMCache server will create some VMs and cache them by factory cache. -# It will convert the VM to gRPC format and transport it when gets -# requestion from clients. -# Factory grpccache is the VMCache client. It will request gRPC format -# VM and convert it back to a VM. If VMCache function is enabled, -# kata-runtime will request VM from factory grpccache when it creates -# a new sandbox. -# -# Default 0 -vm_cache_number = 0 - -# Specify the address of the Unix socket that is used by VMCache. -# -# Default /var/run/kata-containers/cache.sock -vm_cache_endpoint = "/var/run/kata-containers/cache.sock" - -[agent.@PROJECT_TYPE@] -# If enabled, make the agent display debug-level messages. -# (default: disabled) -enable_debug = false - -# Enable agent tracing. -# -# If enabled, the agent will generate OpenTelemetry trace spans. -# -# Notes: -# -# - If the runtime also has tracing enabled, the agent spans will be -# associated with the appropriate runtime parent span. -# - If enabled, the runtime will wait for the container to shutdown, -# increasing the container shutdown time slightly. -# -# (default: disabled) -enable_tracing = false - -# Comma separated list of kernel modules and their parameters. -# These modules will be loaded in the guest kernel using modprobe(8). -# The following example can be used to load two kernel modules with parameters -# - kernel_modules=["e1000e InterruptThrottleRate=3000,3000,3000 EEE=1", "i915 enable_ppgtt=0"] -# The first word is considered as the module name and the rest as its parameters. -# Container will not be started when: -# * A kernel module is specified and the modprobe command is not installed in the guest -# or it fails loading the module. -# * The module is not available in the guest or it doesn't met the guest kernel -# requirements, like architecture and version. -# -kernel_modules = [] - -# Enable debug console. - -# If enabled, user can connect guest OS running inside hypervisor -# through "kata-runtime exec " command - -debug_console_enabled = false - -# Agent connection dialing timeout value in seconds -# (default: 90) -dial_timeout = 90 - -# Timeout in seconds for guest components (attestation-agent, confidential-data-hub) -# to create their Unix sockets after being spawned by the agent. -# (agent default when unset: 6) -launch_process_timeout = 6 - -[runtime] -# If enabled, the runtime will log additional debug messages to the -# system log -# (default: disabled) -enable_debug = false -# -# Internetworking model -# Determines how the VM should be connected to the -# the container network interface -# Options: -# -# - macvtap -# Used when the Container network interface can be bridged using -# macvtap. -# -# - none -# Used when customize network. Only creates a tap device. No veth pair. -# -# - tcfilter -# Uses tc filter rules to redirect traffic from the network interface -# provided by plugin to a tap interface connected to the VM. -# -internetworking_model = "@DEFNETWORKMODEL_QEMU@" - -# disable guest seccomp -# Determines whether container seccomp profiles are passed to the virtual -# machine and applied by the kata agent. If set to true, seccomp is not applied -# within the guest -# (default: true) -disable_guest_seccomp = @DEFDISABLEGUESTSECCOMP@ - -# Apply a custom SELinux security policy to the container process inside the VM. -# This is used when you want to apply a type other than the default `container_t`, -# so general users should not uncomment and apply it. -# (format: "user:role:type") -# Note: You cannot specify MCS policy with the label because the sensitivity levels and -# categories are determined automatically by high-level container runtimes such as containerd. -# Example value when enabling: "system_u:system_r:container_t" -guest_selinux_label = "@DEFGUESTSELINUXLABEL@" - -# If enabled, the runtime will create opentracing.io traces and spans. -# (See https://www.jaegertracing.io/docs/getting-started). -# (default: disabled) -enable_tracing = false - -# Set the full url to the Jaeger HTTP Thrift collector. -# The default if not set will be "http://localhost:14268/api/traces" -jaeger_endpoint = "" - -# Sets the username to be used if basic auth is required for Jaeger. -jaeger_user = "" - -# Sets the password to be used if basic auth is required for Jaeger. -jaeger_password = "" - -# If enabled, the runtime will not create a network namespace for shim and hypervisor processes. -# This option may have some potential impacts to your host. It should only be used when you know what you're doing. -# `disable_new_netns` conflicts with `internetworking_model=tcfilter` and `internetworking_model=macvtap`. It works only -# with `internetworking_model=none`. The tap device will be in the host network namespace and can connect to a bridge -# (like OVS) directly. -# (default: false) -disable_new_netns = false - -# if enabled, the runtime will add all the kata processes inside one dedicated cgroup. -# The container cgroups in the host are not created, just one single cgroup per sandbox. -# The runtime caller is free to restrict or collect cgroup stats of the overall Kata sandbox. -# The sandbox cgroup path is the parent cgroup of a container with the PodSandbox annotation. -# The sandbox cgroup is constrained if there is no container type annotation. -# See: https://pkg.go.dev/github.com/kata-containers/kata-containers/src/runtime/virtcontainers#ContainerType -sandbox_cgroup_only = @DEFSANDBOXCGROUPONLY@ - -# If enabled, the runtime will attempt to determine appropriate sandbox size (memory, CPU) before booting the virtual machine. In -# this case, the runtime will not dynamically update the amount of memory and CPU in the virtual machine. This is generally helpful -# when a hardware architecture or hypervisor solutions is utilized which does not support CPU and/or memory hotplug. -# Compatibility for determining appropriate sandbox (VM) size: -# - When running with pods, sandbox sizing information will only be available if using Kubernetes >= 1.23 and containerd >= 1.6. CRI-O -# does not yet support sandbox sizing annotations. -# - When running single containers using a tool like ctr, container sizing information will be available. -static_sandbox_resource_mgmt = @DEFSTATICRESOURCEMGMT_TEE@ - -# If specified, sandbox_bind_mounts identifieds host paths to be mounted (ro) into the sandboxes shared path. -# This is only valid if filesystem sharing is utilized. The provided path(s) will be bindmounted into the shared fs directory. -# If defaults are utilized, these mounts should be available in the guest at `/run/kata-containers/shared/containers/sandbox-mounts` -# These will not be exposed to the container workloads, and are only provided for potential guest services. -sandbox_bind_mounts = @DEFBINDMOUNTS@ - -# VFIO Mode -# Determines how VFIO devices should be be presented to the container. -# Options: -# -# - vfio -# Matches behaviour of OCI runtimes (e.g. runc) as much as -# possible. VFIO devices will appear in the container as VFIO -# character devices under /dev/vfio. The exact names may differ -# from the host (they need to match the VM's IOMMU group numbers -# rather than the host's) -# -# - guest-kernel -# This is a Kata-specific behaviour that's useful in certain cases. -# The VFIO device is managed by whatever driver in the VM kernel -# claims it. This means it will appear as one or more device nodes -# or network interfaces depending on the nature of the device. -# Using this mode requires specially built workloads that know how -# to locate the relevant device interfaces within the VM. -# -vfio_mode = "@DEFVFIOMODE@" - -# If enabled, the runtime will not create Kubernetes emptyDir mounts on the guest filesystem. Instead, emptyDir mounts will -# be created on the host and shared via virtio-fs. This is potentially slower, but allows sharing of files from host to guest. -disable_guest_empty_dir = @DEFDISABLEGUESTEMPTYDIR@ - -# Specifies how Kubernetes emptyDir volumes are handled. -# Options: -# -# - shared-fs (default) -# Shares the emptyDir folder with the guest using the method given -# by the `shared_fs` setting. -# -# - block-encrypted -# Plugs a block device to be encrypted in the guest. -# -# - block-plain -# Plugs a block device to be mounted directly in the guest. -# -emptydir_mode = "@DEFEMPTYDIRMODE@" - -# Enabled experimental feature list, format: ["a", "b"]. -# Experimental features are features not stable enough for production, -# they may break compatibility, and are prepared for a big version bump. -# Supported experimental features: -# (default: []) -experimental = @DEFAULTEXPFEATURES@ - -# If enabled, user can run pprof tools with shim v2 process through kata-monitor. -# (default: false) -enable_pprof = false - -# Indicates the CreateContainer request timeout needed for the workload(s) -# It using guest_pull this includes the time to pull the image inside the guest -# Defaults to @DEFCREATECONTAINERTIMEOUT@ second(s) -# Note: The effective timeout is determined by the lesser of two values: runtime-request-timeout from kubelet config -# (https://kubernetes.io/docs/reference/command-line-tools-reference/kubelet/#:~:text=runtime%2Drequest%2Dtimeout) and create_container_timeout. -# In essence, the timeout used for guest pull=runtime-request-timeout no cold plug -# cold_plug_vfio != no_port AND pod_resource_api_sock = "" => need -# explicit CDI annotation for cold plug (applies mainly -# to non-k8s cases) -# cold_plug_vfio != no_port AND pod_resource_api_sock != "" => kubelet -# based cold plug. -pod_resource_api_sock = "@DEFPODRESOURCEAPISOCK@" diff --git a/tests/gha-run-k8s-common.sh b/tests/gha-run-k8s-common.sh index 81155cd889..9eadf8dc0e 100644 --- a/tests/gha-run-k8s-common.sh +++ b/tests/gha-run-k8s-common.sh @@ -772,7 +772,7 @@ function helm_helper() { # Enable each shim and set supported architectures # TEE shims that need defaults unset (will be set based on env vars) # shellcheck disable=SC2034 - tee_shims="qemu-se qemu-se-runtime-rs qemu-cca qemu-snp qemu-snp-runtime-rs qemu-tdx qemu-tdx-runtime-rs qemu-coco-dev qemu-coco-dev-runtime-rs qemu-nvidia-gpu-snp qemu-nvidia-gpu-tdx" + tee_shims="qemu-se qemu-se-runtime-rs qemu-snp qemu-snp-runtime-rs qemu-tdx qemu-tdx-runtime-rs qemu-coco-dev qemu-coco-dev-runtime-rs qemu-nvidia-gpu-snp qemu-nvidia-gpu-tdx" for shim in ${HELM_SHIMS}; do # Determine supported architectures based on shim name @@ -781,8 +781,6 @@ function helm_helper() { if is_se_hypervisor "${shim}"; then yq -i ".shims.${shim}.supportedArches = [\"s390x\"]" "${values_yaml}" - elif is_cca_hypervisor "${shim}"; then - yq -i ".shims.${shim}.supportedArches = [\"arm64\"]" "${values_yaml}" elif is_snp_hypervisor "${shim}" || is_tdx_hypervisor "${shim}" || is_confidential_gpu_hypervisor "${shim}"; then yq -i ".shims.${shim}.supportedArches = [\"amd64\"]" "${values_yaml}" # qemu-coco-dev-runtime-rs is checked explicitly because diff --git a/tests/hypervisor_helpers.sh b/tests/hypervisor_helpers.sh index db60c976dc..3e8e37c6b7 100644 --- a/tests/hypervisor_helpers.sh +++ b/tests/hypervisor_helpers.sh @@ -7,9 +7,8 @@ SNP_HYPERVISORS=("qemu-snp" "qemu-snp-runtime-rs") TDX_HYPERVISORS=("qemu-tdx" "qemu-tdx-runtime-rs") SE_HYPERVISORS=("qemu-se" "qemu-se-runtime-rs") -CCA_HYPERVISORS=("qemu-cca") GPU_TEE_HYPERVISORS=("qemu-nvidia-gpu-snp" "qemu-nvidia-gpu-tdx" "qemu-nvidia-gpu-snp-runtime-rs" "qemu-nvidia-gpu-tdx-runtime-rs") -TEE_HYPERVISORS=("${SNP_HYPERVISORS[@]}" "${TDX_HYPERVISORS[@]}" "${SE_HYPERVISORS[@]}" "${CCA_HYPERVISORS[@]}" "${GPU_TEE_HYPERVISORS[@]}") +TEE_HYPERVISORS=("${SNP_HYPERVISORS[@]}" "${TDX_HYPERVISORS[@]}" "${SE_HYPERVISORS[@]}" "${GPU_TEE_HYPERVISORS[@]}") NON_TEE_HYPERVISORS=("qemu-coco-dev" "qemu-coco-dev-runtime-rs") FIRECRACKER_HYPERVISORS=("firecracker" "fc") # CPU-only NVIDIA classes: boot the verity-backed nvidia base image, no GPU. @@ -55,13 +54,6 @@ function is_se_hypervisor() { return 1 } -function is_cca_hypervisor() { - local hypervisor="${1:-${KATA_HYPERVISOR}}" - # shellcheck disable=SC2076 # intentionally use literal string matching - [[ " ${CCA_HYPERVISORS[*]} " =~ " ${hypervisor} " ]] && return 0 - return 1 -} - function is_non_tee_hypervisor() { local hypervisor="${1:-${KATA_HYPERVISOR}}" # shellcheck disable=SC2076 # intentionally use literal string matching diff --git a/tests/integration/kubernetes/confidential_common.sh b/tests/integration/kubernetes/confidential_common.sh index 941b9e6739..1a27ce9efd 100644 --- a/tests/integration/kubernetes/confidential_common.sh +++ b/tests/integration/kubernetes/confidential_common.sh @@ -42,8 +42,6 @@ function get_remote_command_per_hypervisor() { echo "dmesg | grep \"Memory Encryption Features active:.*SEV-SNP\"" elif is_tdx_hypervisor "${KATA_HYPERVISOR}"; then echo "cpuid | grep TDX_GUEST" - elif is_cca_hypervisor "${KATA_HYPERVISOR}"; then - echo "echo 'Remote TEE verification is not implemented for qemu-cca' >&2; exit 1" else echo "" fi diff --git a/tools/packaging/kata-deploy/binary/src/artifacts/install.rs b/tools/packaging/kata-deploy/binary/src/artifacts/install.rs index 8b27c12723..920529cd45 100644 --- a/tools/packaging/kata-deploy/binary/src/artifacts/install.rs +++ b/tools/packaging/kata-deploy/binary/src/artifacts/install.rs @@ -30,7 +30,6 @@ const ALL_SHIMS: &[&str] = &[ "remote", // QEMU shims "qemu", - "qemu-cca", "qemu-coco-dev", "qemu-coco-dev-runtime-rs", "qemu-nvidia-cpu", @@ -1029,7 +1028,6 @@ fn get_qemu_share_name(shim: &str) -> Option { } let share_name = match shim { - "qemu-cca" => "qemu-cca-experimental", "qemu-nvidia-gpu-snp" => "qemu-snp-experimental", "qemu-nvidia-gpu-snp-runtime-rs" => "qemu-snp-experimental", "qemu-nvidia-gpu-tdx" => "qemu-tdx-experimental", @@ -1370,7 +1368,6 @@ mod tests { #[case("qemu-snp", "qemu")] #[case("qemu-se", "qemu")] #[case("qemu-coco-dev", "qemu")] - #[case("qemu-cca", "qemu")] #[case("qemu-nvidia-cpu", "qemu")] #[case("qemu-nvidia-cpu-runtime-rs", "qemu")] #[case("qemu-nvidia-gpu", "qemu")] diff --git a/tools/packaging/kata-deploy/binary/src/config.rs b/tools/packaging/kata-deploy/binary/src/config.rs index 45333ce305..5c145554b3 100644 --- a/tools/packaging/kata-deploy/binary/src/config.rs +++ b/tools/packaging/kata-deploy/binary/src/config.rs @@ -888,7 +888,7 @@ fn parse_custom_runtimes() -> Result> { fn get_default_shims_for_arch(arch: &str) -> &'static str { match arch { "x86_64" => "clh clh-runtime-rs dragonball fc qemu qemu-coco-dev qemu-coco-dev-runtime-rs qemu-runtime-rs qemu-nvidia-cpu qemu-nvidia-cpu-runtime-rs qemu-nvidia-gpu qemu-nvidia-gpu-runtime-rs qemu-nvidia-gpu-snp qemu-nvidia-gpu-snp-runtime-rs qemu-nvidia-gpu-tdx qemu-nvidia-gpu-tdx-runtime-rs qemu-snp qemu-snp-runtime-rs qemu-tdx qemu-tdx-runtime-rs", - "aarch64" => "clh clh-runtime-rs dragonball fc qemu qemu-coco-dev-runtime-rs qemu-runtime-rs qemu-nvidia-cpu qemu-nvidia-cpu-runtime-rs qemu-nvidia-gpu qemu-cca", + "aarch64" => "clh clh-runtime-rs dragonball fc qemu qemu-coco-dev-runtime-rs qemu-runtime-rs qemu-nvidia-cpu qemu-nvidia-cpu-runtime-rs qemu-nvidia-gpu", "s390x" => "qemu qemu-runtime-rs qemu-se qemu-se-runtime-rs qemu-coco-dev qemu-coco-dev-runtime-rs", "ppc64le" => "qemu", _ => "qemu", // Fallback to qemu for unknown architectures diff --git a/tools/packaging/kata-deploy/binary/src/utils/system.rs b/tools/packaging/kata-deploy/binary/src/utils/system.rs index bf15e31c9f..90f7a5226f 100644 --- a/tools/packaging/kata-deploy/binary/src/utils/system.rs +++ b/tools/packaging/kata-deploy/binary/src/utils/system.rs @@ -215,7 +215,6 @@ mod tests { "qemu-snp", "qemu-se", "qemu-coco-dev", - "qemu-cca", "qemu-nvidia-cpu", "qemu-nvidia-gpu", "qemu-nvidia-gpu-tdx", diff --git a/tools/packaging/kata-deploy/helm-chart/kata-deploy/templates/runtimeclasses.yaml b/tools/packaging/kata-deploy/helm-chart/kata-deploy/templates/runtimeclasses.yaml index a1d0c23ae1..787ec56759 100644 --- a/tools/packaging/kata-deploy/helm-chart/kata-deploy/templates/runtimeclasses.yaml +++ b/tools/packaging/kata-deploy/helm-chart/kata-deploy/templates/runtimeclasses.yaml @@ -34,7 +34,6 @@ "qemu-nvidia-gpu-snp-runtime-rs" (dict "memory" "10240Mi" "cpu" "1.0") "qemu-nvidia-gpu-tdx" (dict "memory" "10240Mi" "cpu" "1.0") "qemu-nvidia-gpu-tdx-runtime-rs" (dict "memory" "10240Mi" "cpu" "1.0") - "qemu-cca" (dict "memory" "2048Mi" "cpu" "1.0") "stratovirt" (dict "memory" "130Mi" "cpu" "250m") "remote" (dict "memory" "120Mi" "cpu" "250m") ) -}} diff --git a/tools/packaging/kata-deploy/local-build/Makefile b/tools/packaging/kata-deploy/local-build/Makefile index 92c7366190..24f156cfc7 100644 --- a/tools/packaging/kata-deploy/local-build/Makefile +++ b/tools/packaging/kata-deploy/local-build/Makefile @@ -55,19 +55,15 @@ BASE_SERIAL_TARBALLS = rootfs-image-tarball \ rootfs-initrd-tarball else ifeq ($(ARCH), aarch64) BASE_TARBALLS = serial-targets \ - kernel-cca-confidential-tarball \ kernel-debug-tarball \ kernel-tarball \ qemu-tarball \ - qemu-cca-experimental-tarball \ shim-v2-go-tarball \ shim-v2-rust-tarball \ virtiofsd-tarball BASE_SERIAL_TARBALLS = rootfs-image-tarball \ rootfs-image-confidential-tarball \ rootfs-image-coco-extension-tarball \ - rootfs-cca-confidential-image-tarball \ - rootfs-cca-confidential-initrd-tarball \ rootfs-initrd-tarball endif @@ -226,9 +222,6 @@ kernel-tarball: kernel-debug-tarball: ${MAKE} $@-build -kernel-cca-confidential-tarball: - ${MAKE} $@-build - nydus-tarball: ${MAKE} $@-build @@ -238,9 +231,6 @@ ovmf-sev-tarball: ovmf-tdx-tarball: ${MAKE} $@-build -ovmf-cca-tarball: - ${MAKE} $@-build - ovmf-tarball: ${MAKE} $@-build @@ -250,9 +240,6 @@ qemu-snp-experimental-tarball: qemu-tdx-experimental-tarball: ${MAKE} $@-build -qemu-cca-experimental-tarball: - ${MAKE} $@-build - qemu-tarball: ${MAKE} $@-build @@ -312,14 +299,6 @@ DEPS := agent-tarball busybox-tarball kernel-nvidia-gpu-tarball rootfs-image-nvidia-gpu-extension-tarball: $(DEPS) ${MAKE} $@-build -DEPS := agent-tarball pause-image-tarball coco-guest-components-tarball kernel-cca-confidential-tarball -rootfs-cca-confidential-image-tarball: $(DEPS) - ${MAKE} $@-build - -DEPS := agent-tarball pause-image-tarball coco-guest-components-tarball kernel-cca-confidential-tarball -rootfs-cca-confidential-initrd-tarball: $(DEPS) - ${MAKE} $@-build - shim-v2-go-tarball: ${MAKE} $@-build diff --git a/tools/packaging/kata-deploy/local-build/kata-deploy-binaries.sh b/tools/packaging/kata-deploy/local-build/kata-deploy-binaries.sh index efe70ff583..45057c92b9 100755 --- a/tools/packaging/kata-deploy/local-build/kata-deploy-binaries.sh +++ b/tools/packaging/kata-deploy/local-build/kata-deploy-binaries.sh @@ -135,7 +135,6 @@ options: kata-ctl kata-manager kernel - kernel-cca-confidential kernel-debug kernel-dragonball-experimental kernel-experimental @@ -145,9 +144,7 @@ options: ovmf ovmf-sev ovmf-tdx - ovmf-cca qemu - qemu-cca-experimental qemu-snp-experimental qemu-tdx-experimental stratovirt @@ -1073,16 +1070,6 @@ install_kernel_debug() { "" } -install_kernel_cca_confidential() { - export CONFIDENTIAL_GUEST="yes" - export MEASURED_ROOTFS="yes" - - install_kernel_helper \ - "assets.kernel-arm-experimental.confidential" \ - "kernel-confidential" \ - "-x -H deb" -} - install_kernel_dragonball_experimental() { install_kernel_helper \ "assets.kernel-dragonball-experimental" \ @@ -1144,17 +1131,6 @@ install_qemu() { "${qemu_builder}" } -install_qemu_cca_experimental() { - export qemu_suffix="cca-experimental" - export qemu_tarball_name="kata-static-qemu-${qemu_suffix}.tar.gz" - - install_qemu_helper \ - "assets.hypervisor.qemu-${qemu_suffix}.url" \ - "assets.hypervisor.qemu-${qemu_suffix}.tag" \ - "qemu-${qemu_suffix}" \ - "${qemu_experimental_builder}" -} - install_qemu_snp_experimental() { export qemu_suffix="snp-experimental" export qemu_tarball_name="kata-static-qemu-${qemu_suffix}.tar.gz" @@ -1397,10 +1373,8 @@ install_ovmf() { ovmf_type="${1:-x86_64}" tarball_name="${2:-edk2-x86_64.tar.gz}" if [[ "${ARCH}" == "aarch64" ]]; then - if [[ "${ovmf_type}" != "cca" ]]; then - ovmf_type="arm64" - tarball_name="edk2-arm64.tar.gz" - fi + ovmf_type="arm64" + tarball_name="edk2-arm64.tar.gz" fi local component_name="ovmf" @@ -1432,11 +1406,6 @@ install_ovmf_tdx() { install_ovmf "tdx" "edk2-tdx.tar.gz" } -# Install OVMF CCA -install_ovmf_cca() { - install_ovmf "cca" "edk2-cca.tar.gz" -} - install_busybox() { latest_artefact="$(get_from_kata_deps ".externals.busybox.version")" latest_builder_image="$(get_busybox_image_name)" @@ -1682,7 +1651,6 @@ handle_build() { install_kata_ctl install_kata_manager install_kernel - install_kernel_cca_confidential install_kernel_dragonball_experimental install_log_parser_rs install_nydus @@ -1723,8 +1691,6 @@ handle_build() { kernel-debug) install_kernel_debug ;; - kernel-cca-confidential) install_kernel_cca_confidential ;; - kernel-dragonball-experimental) install_kernel_dragonball_experimental ;; kernel-nvidia-gpu-dragonball-experimental) install_kernel_nvidia_gpu_dragonball_experimental ;; @@ -1739,14 +1705,10 @@ handle_build() { ovmf-tdx) install_ovmf_tdx ;; - ovmf-cca) install_ovmf_cca ;; - pause-image) install_pause_image ;; qemu) install_qemu ;; - qemu-cca-experimental) install_qemu_cca_experimental ;; - qemu-snp-experimental) install_qemu_snp_experimental ;; qemu-tdx-experimental) install_qemu_tdx_experimental ;; @@ -1773,10 +1735,6 @@ handle_build() { rootfs-image-nvidia-gpu-extension) install_image_nvidia_gpu_extension ;; - rootfs-cca-confidential-image) install_image_confidential ;; - - rootfs-cca-confidential-initrd) install_initrd_confidential ;; - shim-v2-go) install_shim_v2_go ;; shim-v2-rust) install_shim_v2_rust ;; diff --git a/tools/packaging/kernel/build-kernel.sh b/tools/packaging/kernel/build-kernel.sh index 7243982548..7ade097301 100755 --- a/tools/packaging/kernel/build-kernel.sh +++ b/tools/packaging/kernel/build-kernel.sh @@ -101,7 +101,6 @@ Options: -c : Path to config file to build the kernel. -d : Enable bash debug. -e : Enable experimental kernel. - -E : Enable arch-specific experimental kernel, arch info offered by "-a". -f : Enable force generate config when setup, old kernel path and config will be removed. -g : GPU vendor, intel or nvidia. -h : Display this help. @@ -587,14 +586,6 @@ install_kata() { if [[ ${gpu_vendor} != "" ]]; then suffix="-${gpu_vendor}-gpu${suffix}" - elif [[ ${conf_guest} != "" ]]; then - # CCA kernel on arm64 needs a -confidential suffix to coexist - # with the unified kernel; the regular kernel with -x does not - # get the suffix (matching x86_64/s390x unified kernel behavior). - # CCA builds are identified by -H (linux_headers) being set. - if [[ "${arch_target}" == "arm64" ]] && [[ -n "${linux_headers}" ]]; then - suffix="-${conf_guest}${suffix}" - fi fi if [[ ${KERNEL_DEBUG_ENABLED} == "yes" ]]; then @@ -639,7 +630,7 @@ install_kata() { } main() { - while getopts "a:b:c:deEfg:hH:k:mp:r:st:u:v:x" opt; do + while getopts "a:b:c:defg:hH:k:mp:r:st:u:v:x" opt; do case "${opt}" in a) arch_target="${OPTARG}" @@ -657,9 +648,6 @@ main() { e) build_type="experimental" ;; - E) - build_type="arch-experimental" - ;; f) force_setup_generate_config="true" ;; @@ -727,17 +715,6 @@ main() { if [[ -z "${kernel_version}" ]]; then if [[ ${build_type} == "experimental" ]]; then kernel_version=$(get_from_kata_deps ".assets.kernel-experimental.tag") - elif [[ ${build_type} == "arch-experimental" ]]; then - case "${arch_target}" in - "aarch64") - build_type="arm-experimental" - kernel_version=$(get_from_kata_deps ".assets.kernel-arm-experimental.version") - ;; - *) - info "No arch-specific experimental kernel supported, using experimental one instead" - kernel_version=$(get_from_kata_deps ".assets.kernel-experimental.tag") - ;; - esac elif [[ ${build_type} == "dragonball-experimental" ]]; then kernel_version=$(get_from_kata_deps ".assets.kernel-dragonball-experimental.version") elif [[ "${conf_guest}" != "" ]]; then diff --git a/tools/packaging/kernel/kata_config_version b/tools/packaging/kernel/kata_config_version index aa34eab5fe..08839f6bb2 100644 --- a/tools/packaging/kernel/kata_config_version +++ b/tools/packaging/kernel/kata_config_version @@ -1 +1 @@ -199 +200 diff --git a/tools/packaging/static-build/ovmf/build-ovmf.sh b/tools/packaging/static-build/ovmf/build-ovmf.sh index 645d4f6479..029b6616a6 100755 --- a/tools/packaging/static-build/ovmf/build-ovmf.sh +++ b/tools/packaging/static-build/ovmf/build-ovmf.sh @@ -23,7 +23,7 @@ package_output_dir="${package_output_dir:-}" DESTDIR=${DESTDIR:-${PWD}} PREFIX="${PREFIX:-/opt/kata}" architecture="${architecture:-X64}" -if [[ "${ovmf_build}" == "arm64" ]] || [[ "${ovmf_build}" == "cca" ]]; then +if [[ "${ovmf_build}" == "arm64" ]]; then architecture="AARCH64" fi toolchain="${toolchain:-GCC5}" @@ -72,7 +72,7 @@ if [[ "${ovmf_build}" == "tdx" ]]; then # shellcheck disable=SC2034 build_path_arch="${build_path_target_toolchain}/X64" stat "${build_path_fv}/OVMF.fd" -elif [[ "${ovmf_build}" == "arm64" ]] || [[ "${ovmf_build}" == "cca" ]]; then +elif [[ "${ovmf_build}" == "arm64" ]]; then stat "${build_path_fv}/QEMU_EFI.fd" stat "${build_path_fv}/QEMU_VARS.fd" else @@ -83,7 +83,7 @@ fi popd info "Install fd to destdir" -if [[ "${ovmf_build}" == "arm64" ]] || [[ "${ovmf_build}" == "cca" ]]; then +if [[ "${ovmf_build}" == "arm64" ]]; then install_dir="${DESTDIR}/${PREFIX}/share/aavmf" else install_dir="${DESTDIR}/${PREFIX}/share/ovmf" @@ -94,7 +94,7 @@ if [[ "${ovmf_build}" == "sev" ]]; then install "${build_root}"/"${ovmf_dir}"/"${build_path_fv}"/OVMF.fd "${install_dir}/AMDSEV.fd" elif [[ "${ovmf_build}" == "tdx" ]]; then install "${build_root}"/"${ovmf_dir}"/"${build_path_fv}"/OVMF.fd "${install_dir}/OVMF.inteltdx.fd" -elif [[ "${ovmf_build}" == "arm64" ]] || [[ "${ovmf_build}" == "cca" ]]; then +elif [[ "${ovmf_build}" == "arm64" ]]; then install "${build_root}"/"${ovmf_dir}"/"${build_path_fv}"/QEMU_EFI.fd "${install_dir}/AAVMF_CODE.fd" install "${build_root}"/"${ovmf_dir}"/"${build_path_fv}"/QEMU_VARS.fd "${install_dir}/AAVMF_VARS.fd" # QEMU expects 64MiB CODE and VARS files on ARM/AARCH64 architectures diff --git a/tools/packaging/static-build/ovmf/build.sh b/tools/packaging/static-build/ovmf/build.sh index 13d4db132f..1bc93cd4bd 100755 --- a/tools/packaging/static-build/ovmf/build.sh +++ b/tools/packaging/static-build/ovmf/build.sh @@ -47,11 +47,6 @@ elif [[ "${ovmf_build}" == "arm64" ]]; then [[ -n "${ovmf_version}" ]] || ovmf_version=$(get_from_kata_deps ".externals.ovmf.arm64.version") [[ -n "${ovmf_package}" ]] || ovmf_package=$(get_from_kata_deps ".externals.ovmf.arm64.package") [[ -n "${package_output_dir}" ]] || package_output_dir=$(get_from_kata_deps ".externals.ovmf.arm64.package_output_dir") -elif [[ "${ovmf_build}" == "cca" ]]; then - ovmf_repo=$(get_from_kata_deps ".externals.ovmf.cca.url") - [[ -n "${ovmf_version}" ]] || ovmf_version=$(get_from_kata_deps ".externals.ovmf.cca.version") - [[ -n "${ovmf_package}" ]] || ovmf_package=$(get_from_kata_deps ".externals.ovmf.cca.package") - [[ -n "${package_output_dir}" ]] || package_output_dir=$(get_from_kata_deps ".externals.ovmf.cca.package_output_dir") fi [[ -n "${ovmf_version}" ]] || die "failed to get ovmf package or commit" diff --git a/versions.yaml b/versions.yaml index 30daf77d39..0b893ee72a 100644 --- a/versions.yaml +++ b/versions.yaml @@ -85,11 +85,6 @@ assets: url: "https://github.com/qemu/qemu" version: "v11.0.1" - qemu-cca-experimental: - description: "QEMU with experimental CCA support" - url: "https://git.codelinaro.org/linaro/dcap/qemu.git" - tag: "97345ddc501d3eb45bbbf15d97608fba0c2c0c7b" - qemu-snp-experimental: description: "QEMU with GPU+SNP support" url: "https://github.com/confidential-containers/qemu.git" @@ -208,16 +203,6 @@ assets: url: "https://cdn.kernel.org/pub/linux/kernel/v6.x/" version: "v6.18.35" - kernel-arm-experimental: - description: "Linux kernel with cpu/mem hotplug support on arm64" - url: "https://cdn.kernel.org/pub/linux/kernel/v5.x/" - version: "v5.15.138" - confidential: - description: "Linux kernel with RME support on arm64" - url: "https://gitlab.arm.com/linux-arm/linux-cca" - version: "v6.15.0-rc1-916aeec68dd4500a1cdf4ebf214c5620955daf3f" - ref: "916aeec68dd4500a1cdf4ebf214c5620955daf3f" - kernel-dragonball-experimental: description: "Linux kernel with Dragonball VMM optimizations like upcall" url: "https://cdn.kernel.org/pub/linux/kernel/v6.x/" @@ -375,12 +360,6 @@ externals: version: "edk2-stable202508" package: "ArmVirtPkg/ArmVirtQemu.dsc" package_output_dir: "ArmVirtQemu-AARCH64" - cca: - description: "UEFI for arm64 CCA virtual machines." - version: "cca/2025-02-06" - url: "https://git.codelinaro.org/linaro/dcap/edk2" - package: "ArmVirtPkg/ArmVirtQemu.dsc" - package_output_dir: "ArmVirtQemu-AARCH64" protoc: description: "Protobuf compiler"