Files
kata-containers/tests/hypervisor_helpers.sh
Fabiano Fidêncio 62a398e56c tests: exercise qemu-nvidia-cpu in docker, nerdctl and k8s
Add qemu-nvidia-cpu and qemu-nvidia-cpu-runtime-rs to the shared hypervisor
allow-lists and to the docker, nerdctl and free-runner k8s matrices, so the
CPU-only NVIDIA classes get the same smoke coverage as the other qemu
variants on x86_64.

Add run-k8s-tests-on-nvidia-cpu-arm64.yaml and wire it into ci.yaml: it
runs the k8s test suite for qemu-nvidia-cpu and qemu-nvidia-cpu-runtime-rs
on real arm64 (GH200) hardware, giving the CPU-only classes aarch64
coverage without disturbing the existing GPU arm64 CI.

The NVIDIA NUMA bats and the nv-test allow-list learn about the CPU-only
classes too, so they can be run by hand on a multi-node host, but the arm64
CI deliberately runs only the standard k8s suite: the GH200 it uses exposes
a single CPU-bearing NUMA node, so the multi-NUMA tests would merely skip.

While here, add an is_verity_enabled_runtime_class helper (the CPU-only
classes boot the verity-backed nvidia base image without being
confidential) and an is_nvidia_hypervisor helper, and use them in
k8s-measured-rootfs.bats and the kata-deploy Helm arch wiring.

Signed-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>
Assisted-by: Cursor <cursoragent@cursor.com>
2026-07-14 10:20:59 +02:00

149 lines
5.0 KiB
Bash

#!/usr/bin/env bash
# Copyright 2026 IBM Corporation
#
# SPDX-License-Identifier: Apache-2.0
#
SNP_HYPERVISORS=("qemu-snp" "qemu-snp-runtime-rs")
TDX_HYPERVISORS=("qemu-tdx" "qemu-tdx-runtime-rs")
SE_HYPERVISORS=("qemu-se" "qemu-se-runtime-rs")
CCA_HYPERVISORS=("qemu-cca")
GPU_TEE_HYPERVISORS=("qemu-nvidia-gpu-snp" "qemu-nvidia-gpu-tdx" "qemu-nvidia-gpu-snp-runtime-rs" "qemu-nvidia-gpu-tdx-runtime-rs")
TEE_HYPERVISORS=("${SNP_HYPERVISORS[@]}" "${TDX_HYPERVISORS[@]}" "${SE_HYPERVISORS[@]}" "${CCA_HYPERVISORS[@]}" "${GPU_TEE_HYPERVISORS[@]}")
NON_TEE_HYPERVISORS=("qemu-coco-dev" "qemu-coco-dev-runtime-rs")
FIRECRACKER_HYPERVISORS=("firecracker" "fc")
# CPU-only NVIDIA classes: boot the verity-backed nvidia base image, no GPU.
NVIDIA_CPU_HYPERVISORS=("qemu-nvidia-cpu" "qemu-nvidia-cpu-runtime-rs")
# All non-confidential NVIDIA classes (CPU-only + plain GPU passthrough).
NVIDIA_HYPERVISORS=("${NVIDIA_CPU_HYPERVISORS[@]}" "qemu-nvidia-gpu" "qemu-nvidia-gpu-runtime-rs")
ALL_HYPERVISORS=(
"clh"
"clh-azure"
"clh-runtime-rs"
"clh-azure-runtime-rs"
"dragonball"
"qemu"
"qemu-runtime-rs"
"qemu-nvidia-cpu"
"qemu-nvidia-cpu-runtime-rs"
"qemu-nvidia-gpu"
"qemu-nvidia-gpu-runtime-rs"
"${TEE_HYPERVISORS[@]}"
"${NON_TEE_HYPERVISORS[@]}"
"${FIRECRACKER_HYPERVISORS[@]}"
)
function is_snp_hypervisor() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
# shellcheck disable=SC2076 # intentionally use literal string matching
[[ " ${SNP_HYPERVISORS[*]} " =~ " ${hypervisor} " ]] && return 0
return 1
}
function is_tdx_hypervisor() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
# shellcheck disable=SC2076 # intentionally use literal string matching
[[ " ${TDX_HYPERVISORS[*]} " =~ " ${hypervisor} " ]] && return 0
return 1
}
function is_se_hypervisor() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
# shellcheck disable=SC2076 # intentionally use literal string matching
[[ " ${SE_HYPERVISORS[*]} " =~ " ${hypervisor} " ]] && return 0
return 1
}
function is_cca_hypervisor() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
# shellcheck disable=SC2076 # intentionally use literal string matching
[[ " ${CCA_HYPERVISORS[*]} " =~ " ${hypervisor} " ]] && return 0
return 1
}
function is_non_tee_hypervisor() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
# shellcheck disable=SC2076 # intentionally use literal string matching
[[ " ${NON_TEE_HYPERVISORS[*]} " =~ " ${hypervisor} " ]] && return 0
return 1
}
function is_confidential_gpu_hypervisor() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
# shellcheck disable=SC2076 # intentionally use literal string matching
[[ " ${GPU_TEE_HYPERVISORS[*]} " =~ " ${hypervisor} " ]] && return 0
return 1
}
function is_firecracker_hypervisor() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
# shellcheck disable=SC2076 # intentionally use literal string matching
[[ " ${FIRECRACKER_HYPERVISORS[*]} " =~ " ${hypervisor} " ]] && return 0
return 1
}
# Common check for the non-confidential NVIDIA runtime classes (CPU-only and
# plain GPU passthrough). The confidential GPU classes are matched by
# is_confidential_gpu_hypervisor instead.
function is_nvidia_hypervisor() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
# shellcheck disable=SC2076 # intentionally use literal string matching
[[ " ${NVIDIA_HYPERVISORS[*]} " =~ " ${hypervisor} " ]] && return 0
return 1
}
function is_supported_hypervisor() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
# shellcheck disable=SC2076 # intentionally use literal string matching
[[ " ${ALL_HYPERVISORS[*]} " =~ " ${hypervisor} " ]] && return 0
return 1
}
# Common check for confidential hardware (TEE) runtime class.
function is_confidential_hardware() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
# This check must be done with "<SPACE>${KATA_HYPERVISOR}<SPACE>" to avoid
# having substrings, like qemu, being matched with qemu-$something.
# shellcheck disable=SC2076 # intentionally use literal string matching
if [[ " ${TEE_HYPERVISORS[*]} " =~ " ${hypervisor} " ]]; then
return 0
fi
return 1
}
# Common check for confidential runtime class.
function is_confidential_runtime_class() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
if is_confidential_hardware "${hypervisor}" || is_non_tee_hypervisor "${hypervisor}"; then
return 0
else
return 1
fi
}
# Runtime classes that boot a measured (dm-verity) rootfs: the confidential
# classes plus the CPU-only NVIDIA classes, which boot the verity-backed
# nvidia base image without being confidential.
function is_verity_enabled_runtime_class() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
if is_confidential_runtime_class "${hypervisor}"; then
return 0
fi
# shellcheck disable=SC2076 # intentionally use literal string matching
[[ " ${NVIDIA_CPU_HYPERVISORS[*]} " =~ " ${hypervisor} " ]] && return 0
return 1
}
is_hotplug_supported() {
local hypervisor="${1:-${KATA_HYPERVISOR}}"
if is_confidential_runtime_class "${hypervisor}"; then
echo "Confidential computing hypervisors don't support hotplug" >&2
return 1
elif is_firecracker_hypervisor "${hypervisor}"; then
echo "FC doesn't support hotplug" >&2
return 1
fi
return 0
}