{"id":2197711,"url":"http://patchwork.ozlabs.org/api/1.0/patches/2197711/?format=json","project":{"id":14,"url":"http://patchwork.ozlabs.org/api/1.0/projects/14/?format=json","name":"QEMU Development","link_name":"qemu-devel","list_id":"qemu-devel.nongnu.org","list_email":"qemu-devel@nongnu.org","web_url":"","scm_url":"","webscm_url":""},"msgid":"<20260218114233.266178-6-anisinha@redhat.com>","date":"2026-02-18T11:41:58","name":"[v5,05/34] accel/kvm: add changes required to support KVM VM file descriptor change","commit_ref":null,"pull_url":null,"state":"new","archived":false,"hash":"c9203e9fc75bdac91cd8d9d170f2ce6a22f02c48","submitter":{"id":86030,"url":"http://patchwork.ozlabs.org/api/1.0/people/86030/?format=json","name":"Ani Sinha","email":"anisinha@redhat.com"},"delegate":null,"mbox":"http://patchwork.ozlabs.org/project/qemu-devel/patch/20260218114233.266178-6-anisinha@redhat.com/mbox/","series":[{"id":492541,"url":"http://patchwork.ozlabs.org/api/1.0/series/492541/?format=json","date":"2026-02-18T11:41:56","name":"Introduce support for confidential guest reset (x86)","version":5,"mbox":"http://patchwork.ozlabs.org/series/492541/mbox/"}],"check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2197711/checks/","tags":{},"headers":{"Return-Path":"<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@legolas.ozlabs.org","Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (1024-bit key;\n unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256\n header.s=mimecast20190719 header.b=Cnnm872S;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256\n header.s=google header.b=O/CK4/ZB;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=nongnu.org\n (client-ip=209.51.188.17; helo=lists.gnu.org;\n envelope-from=qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org;\n receiver=patchwork.ozlabs.org)"],"Received":["from lists.gnu.org (lists.gnu.org [209.51.188.17])\n\t(using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits))\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fGF7D2x0mz1xvq\n\tfor <incoming@patchwork.ozlabs.org>; Wed, 18 Feb 2026 22:45:12 +1100 (AEDT)","from localhost ([::1] helo=lists1p.gnu.org)\n\tby lists.gnu.org with esmtp (Exim 4.90_1)\n\t(envelope-from <qemu-devel-bounces@nongnu.org>)\n\tid 1vsfxu-0003KG-P0; Wed, 18 Feb 2026 06:43:34 -0500","from eggs.gnu.org ([2001:470:142:3::10])\n by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)\n (Exim 4.90_1) (envelope-from <anisinha@redhat.com>)\n id 1vsfxb-000396-N8\n for qemu-devel@nongnu.org; Wed, 18 Feb 2026 06:43:16 -0500","from us-smtp-delivery-124.mimecast.com ([170.10.129.124])\n by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)\n (Exim 4.90_1) (envelope-from <anisinha@redhat.com>)\n id 1vsfxU-0007oQ-O4\n for qemu-devel@nongnu.org; Wed, 18 Feb 2026 06:43:15 -0500","from mail-pl1-f199.google.com (mail-pl1-f199.google.com\n [209.85.214.199]) by relay.mimecast.com with ESMTP with STARTTLS\n (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id\n us-mta-505-fkYppRocNDKHUs0nEAn8iA-1; Wed, 18 Feb 2026 06:43:03 -0500","by mail-pl1-f199.google.com with SMTP id\n d9443c01a7336-2aae146bab0so63746785ad.0\n for <qemu-devel@nongnu.org>; Wed, 18 Feb 2026 03:43:03 -0800 (PST)","from rhel9-box.lan ([117.99.83.54])\n by smtp.googlemail.com with ESMTPSA id\n d9443c01a7336-2ad1aaeab38sm127803425ad.82.2026.02.18.03.42.59\n (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n Wed, 18 Feb 2026 03:43:01 -0800 (PST)"],"DKIM-Signature":["v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com;\n s=mimecast20190719; t=1771414984;\n h=from:from:reply-to:subject:subject:date:date:message-id:message-id:\n to:to:cc:cc:mime-version:mime-version:\n content-transfer-encoding:content-transfer-encoding:\n in-reply-to:in-reply-to:references:references;\n bh=vfhdy46mQEUlcerqq6xzArv8NlC5Gx5+51xsaBuia6g=;\n b=Cnnm872SjsAj2hQt+Y6DX3UU9I5432aGIuUVygOXFkR+Zlbm1aitZAxnzjBiyEZOMHSxyd\n t808AFo2C8vWrF7N3tFs0+PUb6H3xqlFnmKXwDaq9bAfsVWdCoEN/brbxNIKKCIwTxPAFX\n EUgqy7ueFkiFAYFDgP0N0DX3ZwLxbok=","v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=redhat.com; s=google; t=1771414982; x=1772019782; darn=nongnu.org;\n h=content-transfer-encoding:mime-version:references:in-reply-to\n :message-id:date:subject:cc:to:from:from:to:cc:subject:date\n :message-id:reply-to;\n bh=vfhdy46mQEUlcerqq6xzArv8NlC5Gx5+51xsaBuia6g=;\n b=O/CK4/ZBETncYiP66mXMjSLcpUQYULPT5Kil8ArwWVNDCHVokyV1ABK8CyIuRt2YEm\n mJDUXIslKhqblpQ8WWAJzosBhMDc7s0s5ITuDDyof+1LHoSHeVvtWWPp3dartRsIV+3d\n J0uaOKVfC6rmzTvW9PHpNscp+HfUu0cGbUI20kK8iD77tR+Wq/pyYcjgF59ps5B0d3DN\n jC3/iX2jO7xRERnS0vmLhPy+BBG8Ov1VN8MWDbykbJXGuf8lM+2MOCFbY5lOzqGtMcuW\n EItjr7kISfQZRTs2K47sFLN6skUoKCZ/pUpQbreYPwLvToo92KlBz77hhihZ9Br6NRs6\n RWRg=="],"X-MC-Unique":"fkYppRocNDKHUs0nEAn8iA-1","X-Mimecast-MFC-AGG-ID":"fkYppRocNDKHUs0nEAn8iA_1771414982","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=1e100.net; s=20230601; t=1771414982; x=1772019782;\n h=content-transfer-encoding:mime-version:references:in-reply-to\n :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from\n :to:cc:subject:date:message-id:reply-to;\n bh=vfhdy46mQEUlcerqq6xzArv8NlC5Gx5+51xsaBuia6g=;\n b=a+JWxVsq7iuYTG9zOx9AmD503qkFghjAMQZXp/60HSpRtzvhbJL1cwcKgMFFVNa4Uq\n VT+0q2ExdeMDaCzAq8GXqa097dzUvy3Tgak7o61oThavUjs83gPl+ndQq4R4wc+H9IXS\n mfEt+3mW8Kv/ZGcqas8Jy46SyWZlLrGF3sdbP3XPXreGvNMTpSZFNAu3jXXlQpsKd5VL\n NBBx9SMuyb8y27l5JUKH2EAVryvwRRu+eyNMLpBj0XQWH/ip/CBnAJe7G0/NmnzyIeQ2\n jj2JycnUvX7nLGN8k3Jv6yy+Wdybie8WdmhqUL3FRmtZT2bxOJmcVnITj35ehBgnzdeh\n i5jQ==","X-Forwarded-Encrypted":"i=1;\n AJvYcCVjUlvEYN6p8bf+4rlERQ/RlIvVkFqrY7cua1WABR3ZpnrdAgvW8ihwFajMeSxnp/BEEHtlmvPS9Fi1@nongnu.org","X-Gm-Message-State":"AOJu0Yx4dMs3NckEgbn9AKOO7BZqbBDKnOBrpf3tEnpaZE5KstnmUBMl\n jIG4K9ubzMZrqkGFEmUVheRvzIk6xJXZ08PSWrwztaa5aNm8HSG/RpQWbCathMrHGawqDKq7k1U\n NLLX9RmYMYcPxORWKJEV1h8WYZU2KCq5qi+WziPbALkF17VXEdKus5rbcRdVbibJd","X-Gm-Gg":"AZuq6aLMBVxEO1bY0WdNUgsauS+szXnXmYH94VLV1MBrWkBbEcrLwY7URo2C8GJFbw4\n VSqajwS7FhRu1N6gbbhwStqa2D9kUU+TTCMbgkxg7iSbponyLrKs3MqNudRENsuWGVnoNjHFKL9\n VuLf8lb8VR+LX/tjXdycfep2Jg/UaOqAhWPcixgvC0anFIiNUfTmrHntNuSGk9sNUHF4Zg7NU3b\n sDBK+LQHyX0BDGjCHaoL33/stQwlUIHaadKZ0ZN6Qs2qE2+dRKTWF9YLPcPxA3jxC4PL9q2IsUl\n qOsERFyAFwkYVr4YvE85GRwtbY2qJvXkxhDXCezmzzGzcT7ESIQG0vOuS9pFuWZgOfQg9yrjU8s\n sdnxQNaJHl8q9io+iRtdkFsjO2+nfdG5q+x5GbKz/fb15nXuqSHFo","X-Received":["by 2002:a17:902:d509:b0:29f:301a:f6cf with SMTP id\n d9443c01a7336-2ab505c056emr182651445ad.35.1771414981952;\n Wed, 18 Feb 2026 03:43:01 -0800 (PST)","by 2002:a17:902:d509:b0:29f:301a:f6cf with SMTP id\n d9443c01a7336-2ab505c056emr182651275ad.35.1771414981518;\n Wed, 18 Feb 2026 03:43:01 -0800 (PST)"],"From":"Ani Sinha <anisinha@redhat.com>","To":"Paolo Bonzini <pbonzini@redhat.com>, Ani Sinha <anisinha@redhat.com>,\n Marcelo Tosatti <mtosatti@redhat.com>","Cc":"kraxel@redhat.com,\n\tqemu-devel@nongnu.org,\n\tkvm@vger.kernel.org","Subject":"[PATCH v5 05/34] accel/kvm: add changes required to support KVM VM\n file descriptor change","Date":"Wed, 18 Feb 2026 17:11:58 +0530","Message-ID":"<20260218114233.266178-6-anisinha@redhat.com>","X-Mailer":"git-send-email 2.42.0","In-Reply-To":"<20260218114233.266178-1-anisinha@redhat.com>","References":"<20260218114233.266178-1-anisinha@redhat.com>","MIME-Version":"1.0","Content-Transfer-Encoding":"8bit","Received-SPF":"pass client-ip=170.10.129.124;\n envelope-from=anisinha@redhat.com;\n helo=us-smtp-delivery-124.mimecast.com","X-Spam_score_int":"-20","X-Spam_score":"-2.1","X-Spam_bar":"--","X-Spam_report":"(-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.043,\n DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,\n RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001,\n RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001,\n SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no","X-Spam_action":"no action","X-BeenThere":"qemu-devel@nongnu.org","X-Mailman-Version":"2.1.29","Precedence":"list","List-Id":"qemu development <qemu-devel.nongnu.org>","List-Unsubscribe":"<https://lists.nongnu.org/mailman/options/qemu-devel>,\n <mailto:qemu-devel-request@nongnu.org?subject=unsubscribe>","List-Archive":"<https://lists.nongnu.org/archive/html/qemu-devel>","List-Post":"<mailto:qemu-devel@nongnu.org>","List-Help":"<mailto:qemu-devel-request@nongnu.org?subject=help>","List-Subscribe":"<https://lists.nongnu.org/mailman/listinfo/qemu-devel>,\n <mailto:qemu-devel-request@nongnu.org?subject=subscribe>","Errors-To":"qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org","Sender":"qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org"},"content":"This change adds common kvm specific support to handle KVM VM file descriptor\nchange. KVM VM file descriptor can change as a part of confidential guest reset\nmechanism. A new function api kvm_arch_on_vmfd_change() per\narchitecture platform is added in order to implement architecture specific\nchanges required to support it. A subsequent patch will add x86 specific\nimplementation for kvm_arch_on_vmfd_change() as currently only x86 supports\nconfidential guest reset.\n\nSigned-off-by: Ani Sinha <anisinha@redhat.com>\n---\n MAINTAINERS            |  6 ++++\n accel/kvm/kvm-all.c    | 80 ++++++++++++++++++++++++++++++++++++++++--\n accel/kvm/trace-events |  1 +\n include/system/kvm.h   |  3 ++\n stubs/kvm.c            | 22 ++++++++++++\n stubs/meson.build      |  1 +\n target/i386/kvm/kvm.c  | 10 ++++++\n 7 files changed, 120 insertions(+), 3 deletions(-)\n create mode 100644 stubs/kvm.c","diff":"diff --git a/MAINTAINERS b/MAINTAINERS\nindex d3aa6d6732..b0eb77c08f 100644\n--- a/MAINTAINERS\n+++ b/MAINTAINERS\n@@ -152,6 +152,12 @@ F: tools/i386/\n F: tests/functional/i386/\n F: tests/functional/x86_64/\n \n+X86 VM file descriptor change on reset test\n+M: Ani Sinha <anisinha@redhat.com>\n+M: Paolo Bonzini <pbonzini@redhat.com>\n+S: Maintained\n+F: stubs/kvm.c\n+\n Guest CPU cores (TCG)\n ---------------------\n Overall TCG CPUs\ndiff --git a/accel/kvm/kvm-all.c b/accel/kvm/kvm-all.c\nindex 0d8b0c4347..14729666a0 100644\n--- a/accel/kvm/kvm-all.c\n+++ b/accel/kvm/kvm-all.c\n@@ -2415,11 +2415,9 @@ void kvm_irqchip_set_qemuirq_gsi(KVMState *s, qemu_irq irq, int gsi)\n     g_hash_table_insert(s->gsimap, irq, GINT_TO_POINTER(gsi));\n }\n \n-static void kvm_irqchip_create(KVMState *s)\n+static void do_kvm_irqchip_create(KVMState *s)\n {\n     int ret;\n-\n-    assert(s->kernel_irqchip_split != ON_OFF_AUTO_AUTO);\n     if (kvm_check_extension(s, KVM_CAP_IRQCHIP)) {\n         ;\n     } else if (kvm_check_extension(s, KVM_CAP_S390_IRQCHIP)) {\n@@ -2452,7 +2450,13 @@ static void kvm_irqchip_create(KVMState *s)\n         fprintf(stderr, \"Create kernel irqchip failed: %s\\n\", strerror(-ret));\n         exit(1);\n     }\n+}\n \n+static void kvm_irqchip_create(KVMState *s)\n+{\n+    assert(s->kernel_irqchip_split != ON_OFF_AUTO_AUTO);\n+\n+    do_kvm_irqchip_create(s);\n     kvm_kernel_irqchip = true;\n     /* If we have an in-kernel IRQ chip then we must have asynchronous\n      * interrupt delivery (though the reverse is not necessarily true)\n@@ -2607,6 +2611,75 @@ static int kvm_setup_dirty_ring(KVMState *s)\n     return 0;\n }\n \n+static int kvm_reset_vmfd(MachineState *ms)\n+{\n+    KVMState *s;\n+    KVMMemoryListener *kml;\n+    int ret = 0, type;\n+    Error *err = NULL;\n+\n+    /*\n+     * bail if the current architecture does not support VM file\n+     * descriptor change.\n+     */\n+    if (!kvm_arch_supports_vmfd_change()) {\n+        error_report(\"This target architecture does not support KVM VM \"\n+                     \"file descriptor change.\");\n+        return -EOPNOTSUPP;\n+    }\n+\n+    s = KVM_STATE(ms->accelerator);\n+    kml = &s->memory_listener;\n+\n+    memory_listener_unregister(&kml->listener);\n+    memory_listener_unregister(&kvm_io_listener);\n+\n+    if (s->vmfd >= 0) {\n+        close(s->vmfd);\n+    }\n+\n+    type = find_kvm_machine_type(ms);\n+    if (type < 0) {\n+        return -EINVAL;\n+    }\n+\n+    ret = do_kvm_create_vm(s, type);\n+    if (ret < 0) {\n+        return ret;\n+    }\n+\n+    s->vmfd = ret;\n+\n+    kvm_setup_dirty_ring(s);\n+\n+    /* rebind memory to new vm fd */\n+    ret = ram_block_rebind(&err);\n+    if (ret < 0) {\n+        return ret;\n+    }\n+    assert(!err);\n+\n+    ret = kvm_arch_on_vmfd_change(ms, s);\n+    if (ret < 0) {\n+        return ret;\n+    }\n+\n+    if (s->kernel_irqchip_allowed) {\n+        do_kvm_irqchip_create(s);\n+    }\n+\n+    /* these can be only called after ram_block_rebind() */\n+    memory_listener_register(&kml->listener, &address_space_memory);\n+    memory_listener_register(&kvm_io_listener, &address_space_io);\n+\n+    /*\n+     * kvm fd has changed. Commit the irq routes to KVM once more.\n+     */\n+    kvm_irqchip_commit_routes(s);\n+    trace_kvm_reset_vmfd();\n+    return ret;\n+}\n+\n static int kvm_init(AccelState *as, MachineState *ms)\n {\n     MachineClass *mc = MACHINE_GET_CLASS(ms);\n@@ -4015,6 +4088,7 @@ static void kvm_accel_class_init(ObjectClass *oc, const void *data)\n     AccelClass *ac = ACCEL_CLASS(oc);\n     ac->name = \"KVM\";\n     ac->init_machine = kvm_init;\n+    ac->rebuild_guest = kvm_reset_vmfd;\n     ac->has_memory = kvm_accel_has_memory;\n     ac->allowed = &kvm_allowed;\n     ac->gdbstub_supported_sstep_flags = kvm_gdbstub_sstep_flags;\ndiff --git a/accel/kvm/trace-events b/accel/kvm/trace-events\nindex e43d18a869..e4beda0148 100644\n--- a/accel/kvm/trace-events\n+++ b/accel/kvm/trace-events\n@@ -14,6 +14,7 @@ kvm_destroy_vcpu(int cpu_index, unsigned long arch_cpu_id) \"index: %d id: %lu\"\n kvm_park_vcpu(int cpu_index, unsigned long arch_cpu_id) \"index: %d id: %lu\"\n kvm_unpark_vcpu(unsigned long arch_cpu_id, const char *msg) \"id: %lu %s\"\n kvm_irqchip_commit_routes(void) \"\"\n+kvm_reset_vmfd(void) \"\"\n kvm_irqchip_add_msi_route(char *name, int vector, int virq) \"dev %s vector %d virq %d\"\n kvm_irqchip_update_msi_route(int virq) \"Updating MSI route virq=%d\"\n kvm_irqchip_release_virq(int virq) \"virq %d\"\ndiff --git a/include/system/kvm.h b/include/system/kvm.h\nindex 8f9eecf044..5fc7251fd9 100644\n--- a/include/system/kvm.h\n+++ b/include/system/kvm.h\n@@ -456,6 +456,9 @@ int kvm_physical_memory_addr_from_host(KVMState *s, void *ram_addr,\n \n #endif /* COMPILING_PER_TARGET */\n \n+bool kvm_arch_supports_vmfd_change(void);\n+int kvm_arch_on_vmfd_change(MachineState *ms, KVMState *s);\n+\n void kvm_cpu_synchronize_state(CPUState *cpu);\n \n void kvm_init_cpu_signals(CPUState *cpu);\ndiff --git a/stubs/kvm.c b/stubs/kvm.c\nnew file mode 100644\nindex 0000000000..2db61d89a7\n--- /dev/null\n+++ b/stubs/kvm.c\n@@ -0,0 +1,22 @@\n+/*\n+ * kvm target arch specific stubs\n+ *\n+ * Copyright (c) 2026 Red Hat, Inc.\n+ *\n+ * Author:\n+ *   Ani Sinha <anisinha@redhat.com>\n+ *\n+ * SPDX-License-Identifier: GPL-2.0-or-later\n+ */\n+#include \"qemu/osdep.h\"\n+#include \"system/kvm.h\"\n+\n+int kvm_arch_on_vmfd_change(MachineState *ms, KVMState *s)\n+{\n+    abort();\n+}\n+\n+bool kvm_arch_supports_vmfd_change(void)\n+{\n+    return false;\n+}\ndiff --git a/stubs/meson.build b/stubs/meson.build\nindex 8a07059500..6ae478bacc 100644\n--- a/stubs/meson.build\n+++ b/stubs/meson.build\n@@ -74,6 +74,7 @@ if have_system\n   if igvm.found()\n     stub_ss.add(files('igvm.c'))\n   endif\n+  stub_ss.add(files('kvm.c'))\n   stub_ss.add(files('target-get-monitor-def.c'))\n   stub_ss.add(files('target-monitor-defs.c'))\n   stub_ss.add(files('win32-kbd-hook.c'))\ndiff --git a/target/i386/kvm/kvm.c b/target/i386/kvm/kvm.c\nindex 6d823a7991..a4e18734b1 100644\n--- a/target/i386/kvm/kvm.c\n+++ b/target/i386/kvm/kvm.c\n@@ -3389,6 +3389,16 @@ static int kvm_vm_enable_energy_msrs(KVMState *s)\n     return 0;\n }\n \n+int kvm_arch_on_vmfd_change(MachineState *ms, KVMState *s)\n+{\n+    abort();\n+}\n+\n+bool kvm_arch_supports_vmfd_change(void)\n+{\n+    return false;\n+}\n+\n int kvm_arch_init(MachineState *ms, KVMState *s)\n {\n     int ret;\n","prefixes":["v5","05/34"]}