RE: [EXTERNAL] Debug_swap in sev_features
Jon Lange <[email protected]> Mon, 9 Mar 2026 18:39:18 +0000
| Newsgroups | dev.linux.lists.coconut-svsm |
|---|---|
| Message-ID | <SA1PR21MB64164C2337DEAF85CCE9959ACA79A@SA1PR21MB6416.namprd21.prod.outlook.com> |
Joerg identified a similar issue at one point about consistency of SEV features across different VMPLs. I believe he had an opinion about the right way to solve this. -Jon -----Original Message----- From: Melody Wang <[email protected]> Sent: Monday, March 9, 2026 11:36 AM To: Jon Lange <[email protected]>; Rödel, Jörg <[email protected]>; thomas.lendacky <[email protected]> Cc: [email protected] Subject: [EXTERNAL] Debug_swap in sev_features ( Sorry for resending, had mail issue. ) Hi guys, I am working on PoC of Alternate Injection with Planes support. I have run into one issue where the AP_CREATION for VMPL2 fails. The failure happens in validate_sev_features() in kvm as it requires the creating vcpu and new vcpu have the same sev_features, but the new vcpu does not have debug_swap enabled: [2561459.191929] kvm_amd: kvm [675275]: vcpu0, guest rIP: 0x0 validate_sev_features: vmgexit: mismatched AP sev_features [0x11] != [0x29] from guest, vmpl: 2 I checked back to the SVSM and found when the guest vmsa is initialized in the init_guest_vmsa, where debug_swap is removed, the comment there says: // TODO: find a way to make this optional so guests that expect debug // register protection can achieve it. After I commented out this code: sev_status.remove(SEVStatusFlags::DBGSWP); The issue is resolved. This works as a dirty hack but I thought I should let you know and perhaps hear your opinions about it and what would the right fix be. -- Thanks, Melody