qom: add 'confidential-guest-reset' property for x86 confidential vms
Through the new 'confidential-guest-reset' property, control plane should be able to detect if the hypervisor supports x86 confidential guest resets. Older hypervisors that do not support resets will not have this property populated. Suggested-by: Daniel P. Berrangé <berrange@redhat.com> Reviewed-by: Markus Armbruster <armbru@redhat.com> Reviewed-by: Daniel P. Berrangé <berrange@redhat.com> Signed-off-by: Ani Sinha <anisinha@redhat.com> Link: https://lore.kernel.org/r/20260225035000.385950-35-anisinha@redhat.com Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Ani Sinha committed
Feb 25, 2026 at 09:19 UTC
a9b328611143d2a14b287cf2916dacb82e58ef74
1 file changed
+14
-2
qapi/qom.json
+14
-2
@@ -1009,13 +1009,19 @@
1009
# designated guest firmware page for measured boot with -kernel
1010
# (default: false) (since 6.2)
1011
#
1012
+# Features:
1013
+#
1014
+# @confidential-guest-reset: If present, the hypervisor supports
1015
+# confidential guest resets (since 11.0).
1016
+#
1017
# Since: 9.1
1018
##
1019
{ 'struct': 'SevCommonProperties',
1020
'data': { '*sev-device': 'str',
1021
'*cbitpos': 'uint32',
1022
'reduced-phys-bits': 'uint32',
1018
- '*kernel-hashes': 'bool' } }
1023
+ '*kernel-hashes': 'bool' },
1024
+ 'features': ['confidential-guest-reset']}
1025
1026
##
1027
# @SevGuestProperties:
@@ -1136,6 +1142,11 @@
1142
# it, the guest will not be able to get a TD quote for
1143
# attestation.
1144
#
1145
+# Features:
1146
+#
1147
+# @confidential-guest-reset: If present, the hypervisor supports
1148
+# confidential guest resets (since 11.0).
1149
+#
1150
# Since: 10.1
1151
##
1152
{ 'struct': 'TdxGuestProperties',
@@ -1144,7 +1155,8 @@
1155
'*mrconfigid': 'str',
1156
'*mrowner': 'str',
1157
'*mrownerconfig': 'str',
1147
- '*quote-generation-socket': 'SocketAddress' } }
1158
+ '*quote-generation-socket': 'SocketAddress' },
1159
+ 'features': ['confidential-guest-reset']}
1160
1161
##
1162
# @ThreadContextProperties: