RE: [EXTERNAL] Debug_swap in sev_features

"Rodel, Jorg" <[email protected]> Wed, 11 Mar 2026 16:51:41 +0000
Newsgroups dev.linux.lists.coconut-svsm
Message-ID <PH0PR12MB788719376187484D48D4C1FD9347A@PH0PR12MB7887.namprd12.prod.outlook.com>
[AMD Official Use Only - AMD Internal Distribution Only]

I think the problem was that OVMF does not expect DEBUG_SWP to be enabled, therefore it needs to be disabled in VMPL2 for now. You can update your KVM branch to accept this configuration (or live with your hack for now until the new planes code is ready for testing).

-Joerg

> -----Original Message-----
> From: Jon Lange <[email protected]>
> Sent: Monday, March 9, 2026 7:39 PM
> To: Wang, Huibo <[email protected]>; Rodel, Jorg
> <[email protected]>; Lendacky, Thomas <[email protected]>
> Cc: [email protected]
> Subject: RE: [EXTERNAL] Debug_swap in sev_features
>
> Joerg identified a similar issue at one point about consistency of SEV features
> across different VMPLs.  I believe he had an opinion about the right way to solve
> this.
>
> -Jon
>
> -----Original Message-----
> From: Melody Wang <[email protected]>
> Sent: Monday, March 9, 2026 11:36 AM
> To: Jon Lange <[email protected]>; Rödel, Jörg <[email protected]>;
> thomas.lendacky <[email protected]>
> Cc: [email protected]
> Subject: [EXTERNAL] Debug_swap in sev_features
>
> ( Sorry for resending, had mail issue. )
>
> Hi guys,
>
> I am working on PoC of Alternate Injection with Planes support.
>
> I have run into one issue where the AP_CREATION for VMPL2 fails.
>
> The failure happens in validate_sev_features() in kvm as it requires the creating
> vcpu and new vcpu have the same sev_features, but the new vcpu does not have
> debug_swap enabled:
>
> [2561459.191929] kvm_amd: kvm [675275]: vcpu0, guest rIP: 0x0
> validate_sev_features: vmgexit: mismatched AP sev_features [0x11] != [0x29]
> from guest, vmpl: 2
>
> I checked back to the SVSM and found when the guest vmsa is initialized in the
> init_guest_vmsa, where debug_swap is removed, the comment there says:
>
>    // TODO: find a way to make this optional so guests that expect debug
>    // register protection can achieve it.
>
> After I commented out this code:
>
>   sev_status.remove(SEVStatusFlags::DBGSWP);
>
> The issue is resolved.
>
> This works as a dirty hack but I thought I should let you know and perhaps hear
> your opinions about it and what would the right fix be.
>
> --
> Thanks,
> Melody