RE: [EXTERNAL] Debug_swap in sev_features

Jon Lange <[email protected]> Mon, 9 Mar 2026 18:39:18 +0000
Newsgroups dev.linux.lists.coconut-svsm
Message-ID <SA1PR21MB64164C2337DEAF85CCE9959ACA79A@SA1PR21MB6416.namprd21.prod.outlook.com>
Joerg identified a similar issue at one point about consistency of SEV features across different VMPLs.  I believe he had an opinion about the right way to solve this.

-Jon

-----Original Message-----
From: Melody Wang <[email protected]> 
Sent: Monday, March 9, 2026 11:36 AM
To: Jon Lange <[email protected]>; Rödel, Jörg <[email protected]>; thomas.lendacky <[email protected]>
Cc: [email protected]
Subject: [EXTERNAL] Debug_swap in sev_features

( Sorry for resending, had mail issue. )

Hi guys,

I am working on PoC of Alternate Injection with Planes support.

I have run into one issue where the AP_CREATION for VMPL2 fails.

The failure happens in validate_sev_features() in kvm as it requires the creating vcpu and new vcpu have the same sev_features, but the new vcpu does not have debug_swap enabled:

[2561459.191929] kvm_amd: kvm [675275]: vcpu0, guest rIP: 0x0
validate_sev_features: vmgexit: mismatched AP sev_features [0x11] != [0x29] from guest, vmpl: 2

I checked back to the SVSM and found when the guest vmsa is initialized in the init_guest_vmsa, where debug_swap is removed, the comment there says:

   // TODO: find a way to make this optional so guests that expect debug
   // register protection can achieve it.

After I commented out this code:

  sev_status.remove(SEVStatusFlags::DBGSWP);

The issue is resolved.

This works as a dirty hack but I thought I should let you know and perhaps hear your opinions about it and what would the right fix be.

--
Thanks,
Melody