Re: Debug_swap in sev_features

Melody Wang <[email protected]> Mon, 9 Mar 2026 11:39:22 -0700
Newsgroups dev.linux.lists.coconut-svsm
Message-ID <[email protected]>
Hi Jon,

Good to know. Thanks.

Thanks,
Melody

On 3/9/26 11:35 AM, Jon Lange wrote:
> Joerg identified a similar issue at one point about consistency of SEV 
> features across different VMPLs.  I believe he had an opinion about the 
> right way to solve this.
> 
> -Jon
> 
> *From:*Wang, Huibo <[email protected]>
> *Sent:* Monday, March 9, 2026 11:31 AM
> *To:* Jon Lange <[email protected]>; Rodel, Jorg 
> <[email protected]>; thomas.lendacky <[email protected]>
> *Cc:* [email protected]
> *Subject:* [EXTERNAL] Debug_swap in sev_features
> 
> [AMD Official Use Only - AMD Internal Distribution Only]
> 
> Hi guys,
> 
> I am working on PoC of Alternate Injection with Planes support.
> 
> I have run into one issue where the AP_CREATION for VMPL2 fails.
> 
> The failure happens in validate_sev_features() in kvm as it requires the 
> creating vcpu and new vcpu have the same sev_features, but the new vcpu 
> does not have debug_swap enabled:
> 
> [2561459.191929] kvm_amd: kvm [675275]: vcpu0, guest rIP: 0x0 
> validate_sev_features: vmgexit: mismatched AP sev_features [0x11] != 
> [0x29] from guest, vmpl: 2
> 
> I checked back to the SVSM and found when the guest vmsa is initialized 
> in the init_guest_vmsa, where debug_swap is removed, the comment there says:
> 
>    // TODO: find a way to make this optional so guests that expect debug
> 
>    // register protection can achieve it.
> 
> After I commented out this code:
> 
>   sev_status.remove(SEVStatusFlags::DBGSWP);
> 
> The issue is resolved.
> 
> This works as a dirty hack but I thought I should let you know and 
> perhaps hear your opinions about it and what would the right fix be.
> 
> Thanks,
> 
> Melody.
> 

-- 
Thanks,
Melody