[PATCH 06/21] KVM: SEV: Lock all vCPUs for the duration of SEV-ES VMSA synchronization
From: Sean Christopherson
Date: Tue Mar 10 2026 - 19:52:16 EST
Lock and unlock all vCPUs in a single batch when synchronizing SEV-ES VMSAs
during launch finish, partly to dedup the code by a tiny amount, but mostly
so that sev_launch_update_vmsa() uses the same logic/flow as all other SEV
ioctls that lock all vCPUs.
Signed-off-by: Sean Christopherson <seanjc@xxxxxxxxxx>
---
arch/x86/kvm/svm/sev.c | 15 +++++++--------
1 file changed, 7 insertions(+), 8 deletions(-)
diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c
index c10c71608208..1bdcc5bef7c3 100644
--- a/arch/x86/kvm/svm/sev.c
+++ b/arch/x86/kvm/svm/sev.c
@@ -1035,19 +1035,18 @@ static int sev_launch_update_vmsa(struct kvm *kvm, struct kvm_sev_cmd *argp)
if (kvm_is_vcpu_creation_in_progress(kvm))
return -EBUSY;
- kvm_for_each_vcpu(i, vcpu, kvm) {
- ret = mutex_lock_killable(&vcpu->mutex);
- if (ret)
- return ret;
+ ret = kvm_lock_all_vcpus(kvm);
+ if (ret)
+ return ret;
+ kvm_for_each_vcpu(i, vcpu, kvm) {
ret = __sev_launch_update_vmsa(kvm, vcpu, &argp->error);
-
- mutex_unlock(&vcpu->mutex);
if (ret)
- return ret;
+ break;
}
- return 0;
+ kvm_unlock_all_vcpus(kvm);
+ return ret;
}
static int sev_launch_measure(struct kvm *kvm, struct kvm_sev_cmd *argp)
--
2.53.0.473.g4a7958ca14-goog