kvm/i386: reload firmware for confidential guest reset
When IGVM is not being used by the confidential guest, the guest firmware has to be reloaded explicitly again into memory. This is because, the memory into which the firmware was loaded before reset was encrypted and is thus lost upon reset. When IGVM is used, it is expected that the IGVM will contain the guest firmware and the execution of the IGVM directives will set up the guest firmware memory. Signed-off-by: Ani Sinha <anisinha@redhat.com> Link: https://lore.kernel.org/r/20260225035000.385950-15-anisinha@redhat.com Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Ani Sinha committed
Feb 25, 2026 at 09:19 UTC
7561c3247c5646ce5d5d5da043df8e7903720420
1 file changed
+8
-1
target/i386/kvm/kvm.c
+8
-1
@@ -3416,7 +3416,14 @@ int kvm_arch_on_vmfd_change(MachineState *ms, KVMState *s)
3416
3417
if (object_dynamic_cast(OBJECT(ms), TYPE_X86_MACHINE)) {
3418
X86MachineState *x86ms = X86_MACHINE(ms);
3419
-
3419
+ /*
3420
+ * For confidential guests, reload bios ROM if IGVM is not specified.
3421
+ * If an IGVM file is specified then the firmware must be provided
3422
+ * in the IGVM file.
3423
+ */
3424
+ if (ms->cgs && !x86ms->igvm) {
3425
+ x86_bios_rom_reload(x86ms);
3426
+ }
3427
if (x86_machine_is_smm_enabled(x86ms)) {
3428
memory_listener_register(&smram_listener.listener,
3429
&smram_address_space);