Debug_swap in sev_features

Melody Wang <[email protected]> Mon, 9 Mar 2026 11:35:45 -0700
Newsgroups dev.linux.lists.coconut-svsm
Message-ID <[email protected]>
( Sorry for resending, had mail issue. )

Hi guys,

I am working on PoC of Alternate Injection with Planes support.

I have run into one issue where the AP_CREATION for VMPL2 fails.

The failure happens in validate_sev_features() in kvm as it requires the 
creating vcpu and new vcpu have the same sev_features, but the new vcpu 
does not have debug_swap enabled:

[2561459.191929] kvm_amd: kvm [675275]: vcpu0, guest rIP: 0x0 
validate_sev_features: vmgexit: mismatched AP sev_features [0x11] != 
[0x29] from guest, vmpl: 2

I checked back to the SVSM and found when the guest vmsa is initialized 
in the
init_guest_vmsa, where debug_swap is removed, the comment there says:

   // TODO: find a way to make this optional so guests that expect debug
   // register protection can achieve it.

After I commented out this code:

  sev_status.remove(SEVStatusFlags::DBGSWP);

The issue is resolved.

This works as a dirty hack but I thought I should let you know and perhaps
hear your opinions about it and what would the right fix be.

-- 
Thanks,
Melody