i386/tdx: add a pre-vmfd change notifier to reset tdx state
During reset, when the VM file descriptor is changed, the TDX state needs to be re-initialized. A notifier callback is implemented to reset the old state and free memory before the new state is initialized post VM file descriptor change. Signed-off-by: Ani Sinha <anisinha@redhat.com> Link: https://lore.kernel.org/r/20260225035000.385950-19-anisinha@redhat.com Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Ani Sinha committed
Feb 25, 2026 at 09:19 UTC
154f1bcd64869471198d501ffaf928fe6c72e6b9
1 file changed
+31
target/i386/kvm/tdx.c
+31
@@ -405,6 +405,36 @@ static void tdx_handle_reset(Object *obj, ResetType type)
405
trace_tdx_handle_reset();
406
}
407
408
+/* TDX guest reset will require us to reinitialize some of tdx guest state. */
409
+static int set_tdx_vm_uninitialized(NotifierWithReturn *notifier,
410
+ void *data, Error** errp)
411
+{
412
+ TdxFirmware *fw = &tdx_guest->tdvf;
413
+
414
+ if (!((VmfdChangeNotifier *)data)->pre) {
415
+ return 0;
416
+ }
417
+
418
+ if (tdx_guest->initialized) {
419
+ tdx_guest->initialized = false;
420
+ }
421
+
422
+ g_free(tdx_guest->ram_entries);
423
+
424
+ /*
425
+ * the firmware entries will be parsed again, see
426
+ * x86_firmware_configure() -> tdx_parse_tdvf()
427
+ */
428
+ fw->entries = 0;
429
+ g_free(fw->entries);
430
+
431
+ return 0;
432
+}
433
+
434
+static NotifierWithReturn tdx_vmfd_change_notifier = {
435
+ .notify = set_tdx_vm_uninitialized,
436
+};
437
+
438
/*
439
* Some CPUID bits change from fixed1 to configurable bits when TDX module
440
* supports TDX_FEATURES0.VE_REDUCTION. e.g., MCA/MCE/MTRR/CORE_CAPABILITY.
@@ -1549,6 +1579,7 @@ static void tdx_guest_init(Object *obj)
1579
1580
tdx->event_notify_vector = -1;
1581
tdx->event_notify_apicid = -1;
1582
+ kvm_vmfd_add_change_notifier(&tdx_vmfd_change_notifier);
1583
qemu_register_resettable(obj);
1584
}
1585