@@ -73,6 +73,7 @@ fn build_kernel_command_line(
7373 cmdline : & mut ArrayString < COMMAND_LINE_SIZE > ,
7474 partition_info : & PartitionInfo ,
7575 can_trust_host : bool ,
76+ is_confidential_debug : bool ,
7677 sidecar : Option < & SidecarConfig < ' _ > > ,
7778) -> Result < ( ) , CommandLineTooLong > {
7879 // For reference:
@@ -254,6 +255,14 @@ fn build_kernel_command_line(
254255 ) ?;
255256 }
256257
258+ if is_confidential_debug {
259+ write ! (
260+ cmdline,
261+ "{}=1 " ,
262+ underhill_confidentiality:: OPENHCL_CONFIDENTIAL_DEBUG_ENV_VAR_NAME
263+ ) ?;
264+ }
265+
257266 // Only when explicitly supported by Host.
258267 // TODO: Move from command line to device tree when stabilized.
259268 if partition_info. nvme_keepalive && !partition_info. vtl2_pool_memory . is_empty ( ) {
@@ -581,6 +590,29 @@ fn get_ref_time(isolation: IsolationType) -> Option<u64> {
581590 }
582591}
583592
593+ fn get_hw_debug_bit ( isolation : IsolationType ) -> bool {
594+ match isolation {
595+ #[ cfg( target_arch = "x86_64" ) ]
596+ IsolationType :: Tdx => {
597+ use tdx_guest_device:: protocol:: TdReport ;
598+
599+ use crate :: arch:: tdx:: get_tdreport;
600+
601+ let mut report = off_stack ! ( PageAlign <TdReport >, zeroed( ) ) ;
602+ match get_tdreport ( & mut report. 0 ) {
603+ Ok ( ( ) ) => report. 0 . td_info . td_info_base . attributes . debug ( ) ,
604+ Err ( _) => false ,
605+ }
606+ }
607+ #[ cfg( target_arch = "x86_64" ) ]
608+ IsolationType :: Snp => {
609+ // Not implemented yet for SNP.
610+ false
611+ }
612+ _ => false ,
613+ }
614+ }
615+
584616fn shim_main ( shim_params_raw_offset : isize ) -> ! {
585617 let p = shim_parameters ( shim_params_raw_offset) ;
586618 if p. isolation_type == IsolationType :: None {
@@ -615,8 +647,10 @@ fn shim_main(shim_params_raw_offset: isize) -> ! {
615647 log ! ( "openhcl_boot: early debugging enabled" ) ;
616648 }
617649
618- let can_trust_host =
619- p. isolation_type == IsolationType :: None || static_options. confidential_debug ;
650+ let hw_debug_bit = get_hw_debug_bit ( p. isolation_type ) ;
651+ let can_trust_host = p. isolation_type == IsolationType :: None
652+ || static_options. confidential_debug
653+ || hw_debug_bit;
620654
621655 let boot_reftime = get_ref_time ( p. isolation_type ) ;
622656
@@ -628,6 +662,12 @@ fn shim_main(shim_params_raw_offset: isize) -> ! {
628662 Err ( e) => panic ! ( "unable to read device tree params {}" , e) ,
629663 } ;
630664
665+ // Confidential debug will show up in boot_options only if included in the
666+ // static command line, or if can_trust_host is true (so the dynamic command
667+ // line has been parsed).
668+ let is_confidential_debug = ( can_trust_host && p. isolation_type != IsolationType :: None )
669+ || partition_info. boot_options . confidential_debug ;
670+
631671 // Fill out the non-devicetree derived parts of PartitionInfo.
632672 if !p. isolation_type . is_hardware_isolated ( )
633673 && hvcall ( ) . vtl ( ) == Vtl :: Vtl2
@@ -697,6 +737,7 @@ fn shim_main(shim_params_raw_offset: isize) -> ! {
697737 & mut cmdline,
698738 partition_info,
699739 can_trust_host,
740+ is_confidential_debug,
700741 sidecar. as_ref ( ) ,
701742 )
702743 . unwrap ( ) ;
0 commit comments