[PATCH v2 09/29] KVM: SEV: Explicitly initialize the per vCPU ASID on SEV VM migration
From: Yosry Ahmed
Date: Wed Oct 07 2026 - 20:19:20 EST
Explicitly initialize svm->asid on the destination vCPUs as part of SEV
VM migration, before calling sev_init_vmcb() to make sure the per-vCPU
ASID is initialized before the VMCB. This is currently unnecessary as
sev_init_vmcb() initializes the per-vCPU ASID anyway, but will be needed
when the ASID initialization is moved to vCPU creation.
Add a helper function for the ASID migration as more changes will be
needed with incoming changes.
Note that svm->asid is left as-is on the source vCPUs, even though the
ASID now belongs to the destination VM. Clearing it would be a nice
hardening measure, but it is not as simple as clearing src_svm->asid, as
the source and destination VMs do not necessarily have the same number
of vCPUs (e.g. for non SEV-ES), so NULL-handling would be needed in a
couple of places. Leave it alone for now.
Signed-off-by: Yosry Ahmed <yosry@xxxxxxxxxx>
---
arch/x86/kvm/svm/sev.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c
index 706a91db7b44a..0fbb72d57e6da 100644
--- a/arch/x86/kvm/svm/sev.c
+++ b/arch/x86/kvm/svm/sev.c
@@ -2032,6 +2032,12 @@ static void sev_unlock_two_vms(struct kvm *dst_kvm, struct kvm *src_kvm)
atomic_set_release(&src_sev->migration_in_progress, 0);
}
+static void sev_vcpu_migrate_asid(struct vcpu_svm *dst_svm,
+ unsigned int asid)
+{
+ dst_svm->asid = asid;
+}
+
static void sev_migrate_from(struct kvm *dst_kvm, struct kvm *src_kvm)
{
struct kvm_sev_info *dst = to_kvm_sev_info(dst_kvm);
@@ -2096,6 +2102,7 @@ static void sev_migrate_from(struct kvm *dst_kvm, struct kvm *src_kvm)
kvm_for_each_vcpu(i, dst_vcpu, dst_kvm) {
dst_svm = to_svm(dst_vcpu);
+ sev_vcpu_migrate_asid(dst_svm, dst->asid);
sev_init_vmcb(dst_svm, false);
if (!dst->es_active)
--
2.56.0.360.g66cac248cb-goog