Commit 48f15f62 authored by Sean Christopherson's avatar Sean Christopherson
Browse files

KVM: SVM: Initialize vmsa_pa in VMCB to INVALID_PAGE if VMSA page is NULL



When creating an SEV-ES vCPU for intra-host migration, set its vmsa_pa to
INVALID_PAGE to harden against doing VMRUN with a bogus VMSA (KVM checks
for a valid VMSA page in pre_sev_run()).

Cc: Tom Lendacky <thomas.lendacky@amd.com>
Reviewed-by: default avatarLiam Merwick <liam.merwick@oracle.com>
Tested-by: default avatarLiam Merwick <liam.merwick@oracle.com>
Link: https://lore.kernel.org/r/20250602224459.41505-3-seanjc@google.com


Signed-off-by: default avatarSean Christopherson <seanjc@google.com>
parent ecf371f8
Loading
Loading
Loading
Loading
+6 −2
Original line number Diff line number Diff line
@@ -4449,8 +4449,12 @@ static void sev_es_init_vmcb(struct vcpu_svm *svm)
	 * the VMSA will be NULL if this vCPU is the destination for intrahost
	 * migration, and will be copied later.
	 */
	if (svm->sev_es.vmsa && !svm->sev_es.snp_has_guest_vmsa)
	if (!svm->sev_es.snp_has_guest_vmsa) {
		if (svm->sev_es.vmsa)
			svm->vmcb->control.vmsa_pa = __pa(svm->sev_es.vmsa);
		else
			svm->vmcb->control.vmsa_pa = INVALID_PAGE;
	}

	if (cpu_feature_enabled(X86_FEATURE_ALLOWED_SEV_FEATURES))
		svm->vmcb->control.allowed_sev_features = sev->vmsa_features |