]> git.hungrycats.org Git - linux/commitdiff
KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests
authorSean Christopherson <seanjc@google.com>
Thu, 9 Jul 2026 20:49:31 +0000 (13:49 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 2 Sep 2026 12:31:48 +0000 (14:31 +0200)
commit 42a39ad5d592aec87a70527a4e694f6210694482 upstream.

Track the GPA of the guest-provided VMSA used after AP_CREATION events when
running SNP guests, instead of simply tracking whether or not the vCPU is
using a guest-provided VMSA.  KVM needs to know the GPA of the VMSA that's
actively being used so that it can react to MMU invalidation events, i.e.
so that KVM can drop the VMSA if its backing guest_memfd page is punched
out of existence.

Opportunistically rename snp_vmsa_gpa to clarify that it tracks the pending
VMSA GPA, whereas snp_guest_vmsa_gpa now tracks the in-use VMSA GPA.

Note!  Take care to track the GPA, not the GFN, as VALID_PAGE() won't
behave correctly if an invalid GFN is converted to a GPA for checking.

Note #2!  Keep snp_has_guest_vmsa so that switching to a guest-provided
VMSA is sticky, even if the guest-provided VMSA becomes invalid.

No functional change intended.

Cc: stable@vger.kernel.org # 6.12.x
Reviewed-by: Michael Roth <michael.roth@amd.com>
Link: https://patch.msgid.link/20260709204948.1988414-2-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
arch/x86/kvm/svm/sev.c
arch/x86/kvm/svm/svm.h

index 606fad42ee82c756c7b864d48fee10346db0467f..b7596d7a29d3202dfc2a5cfb01906186c99392dd 100644 (file)
@@ -4037,6 +4037,7 @@ static void sev_snp_init_protected_guest_state(struct kvm_vcpu *vcpu)
 
        /* Clear use of the VMSA */
        svm->vmcb->control.vmsa_pa = INVALID_PAGE;
+       svm->sev_es.snp_guest_vmsa_gpa = INVALID_PAGE;
 
        /*
         * When replacing the VMSA during SEV-SNP AP creation,
@@ -4044,11 +4045,11 @@ static void sev_snp_init_protected_guest_state(struct kvm_vcpu *vcpu)
         */
        vmcb_mark_all_dirty(svm->vmcb);
 
-       if (!VALID_PAGE(svm->sev_es.snp_vmsa_gpa))
+       if (!VALID_PAGE(svm->sev_es.snp_pending_vmsa_gpa))
                return;
 
-       gfn = gpa_to_gfn(svm->sev_es.snp_vmsa_gpa);
-       svm->sev_es.snp_vmsa_gpa = INVALID_PAGE;
+       gfn = gpa_to_gfn(svm->sev_es.snp_pending_vmsa_gpa);
+       svm->sev_es.snp_pending_vmsa_gpa = INVALID_PAGE;
 
        slot = gfn_to_memslot(vcpu->kvm, gfn);
        if (!slot)
@@ -4073,6 +4074,7 @@ static void sev_snp_init_protected_guest_state(struct kvm_vcpu *vcpu)
        svm->sev_es.snp_has_guest_vmsa = true;
 
        /* Use the new VMSA */
+       svm->sev_es.snp_guest_vmsa_gpa = gfn_to_gpa(gfn);
        svm->vmcb->control.vmsa_pa = pfn_to_hpa(pfn);
 
        /* Mark the vCPU as runnable */
@@ -4139,10 +4141,10 @@ static int sev_snp_ap_creation(struct vcpu_svm *svm)
                        return -EINVAL;
                }
 
-               target_svm->sev_es.snp_vmsa_gpa = svm->vmcb->control.exit_info_2;
+               target_svm->sev_es.snp_pending_vmsa_gpa = svm->vmcb->control.exit_info_2;
                break;
        case SVM_VMGEXIT_AP_DESTROY:
-               target_svm->sev_es.snp_vmsa_gpa = INVALID_PAGE;
+               target_svm->sev_es.snp_pending_vmsa_gpa = INVALID_PAGE;
                break;
        default:
                vcpu_unimpl(vcpu, "vmgexit: invalid AP creation request [%#x] from guest\n",
@@ -4731,6 +4733,8 @@ int sev_vcpu_create(struct kvm_vcpu *vcpu)
                return -ENOMEM;
 
        svm->sev_es.vmsa = page_address(vmsa_page);
+       svm->sev_es.snp_pending_vmsa_gpa = INVALID_PAGE;
+       svm->sev_es.snp_guest_vmsa_gpa = INVALID_PAGE;
 
        vcpu->arch.guest_tsc_protected = snp_is_secure_tsc_enabled(vcpu->kvm);
 
index d06823ee0e755043ca54b8d310ed1ad15b68284e..ffaec038902c4b4727778c2be1d79ac1631a734f 100644 (file)
@@ -248,7 +248,8 @@ struct vcpu_sev_es_state {
        u64 ghcb_registered_gpa;
 
        struct mutex snp_vmsa_mutex; /* Used to handle concurrent updates of VMSA. */
-       gpa_t snp_vmsa_gpa;
+       gpa_t snp_pending_vmsa_gpa;
+       gpa_t snp_guest_vmsa_gpa;
        bool snp_ap_waiting_for_reset;
        bool snp_has_guest_vmsa;
 };