@samitouri / QOSamiQemu / commits / 13395029b5

i386/sev: add migration blockers only once

sev_launch_finish() and sev_snp_launch_finish() could be called multiple times when the confidential guest is being reset/rebooted. The migration blockers should not be added multiple times, once per invocation. This change makes sure that the migration blockers are added only one time by adding the migration blockers to the vm state change handler when the vm transitions to the running state. Subsequent reboots do not change the state of the vm. Reviewed-by: Prasad Pandit <pjp@fedoraproject.org> Signed-off-by: Ani Sinha <anisinha@redhat.com> Link: https://lore.kernel.org/r/20260225035000.385950-20-anisinha@redhat.com Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>

Ani Sinha committed Feb 25, 2026 at 09:19 UTC 13395029b567a49609ac05c9bfefad3d4a3eddb1
1 file changed +5 -15
target/i386/sev.c
+5 -15
@@ -1421,11 +1421,6 @@ sev_launch_finish(SevCommonState *sev_common)
1421 }
1422
1423 sev_set_guest_state(sev_common, SEV_STATE_RUNNING);
1424 -
1425 - /* add migration blocker */
1426 - error_setg(&sev_mig_blocker,
1427 - "SEV: Migration is not implemented");
1428 - migrate_add_blocker(&sev_mig_blocker, &error_fatal);
1424 }
1425
1426 static int snp_launch_update_data(uint64_t gpa, void *hva, size_t len,
@@ -1608,7 +1603,6 @@ static void
1603 sev_snp_launch_finish(SevCommonState *sev_common)
1604 {
1605 int ret, error;
1611 - Error *local_err = NULL;
1606 OvmfSevMetadata *metadata;
1607 SevLaunchUpdateData *data;
1608 SevSnpGuestState *sev_snp = SEV_SNP_GUEST(sev_common);
@@ -1655,15 +1649,6 @@ sev_snp_launch_finish(SevCommonState *sev_common)
1649
1650 kvm_mark_guest_state_protected();
1651 sev_set_guest_state(sev_common, SEV_STATE_RUNNING);
1658 -
1659 - /* add migration blocker */
1660 - error_setg(&sev_mig_blocker,
1661 - "SEV-SNP: Migration is not implemented");
1662 - ret = migrate_add_blocker(&sev_mig_blocker, &local_err);
1663 - if (local_err) {
1664 - error_report_err(local_err);
1665 - exit(1);
1666 - }
1652 }
1653
1654
@@ -1676,6 +1661,11 @@ sev_vm_state_change(void *opaque, bool running, RunState state)
1661 if (running) {
1662 if (!sev_check_state(sev_common, SEV_STATE_RUNNING)) {
1663 klass->launch_finish(sev_common);
1664 +
1665 + /* add migration blocker */
1666 + error_setg(&sev_mig_blocker,
1667 + "SEV: Migration is not implemented");
1668 + migrate_add_blocker(&sev_mig_blocker, &error_fatal);
1669 }
1670 }
1671 }