@samitouri / QOSamiQemu / commits / 7561c3247c

kvm/i386: reload firmware for confidential guest reset

When IGVM is not being used by the confidential guest, the guest firmware has to be reloaded explicitly again into memory. This is because, the memory into which the firmware was loaded before reset was encrypted and is thus lost upon reset. When IGVM is used, it is expected that the IGVM will contain the guest firmware and the execution of the IGVM directives will set up the guest firmware memory. Signed-off-by: Ani Sinha <anisinha@redhat.com> Link: https://lore.kernel.org/r/20260225035000.385950-15-anisinha@redhat.com Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>

Ani Sinha committed Feb 25, 2026 at 09:19 UTC 7561c3247c5646ce5d5d5da043df8e7903720420
1 file changed +8 -1
target/i386/kvm/kvm.c
+8 -1
@@ -3416,7 +3416,14 @@ int kvm_arch_on_vmfd_change(MachineState *ms, KVMState *s)
3416
3417 if (object_dynamic_cast(OBJECT(ms), TYPE_X86_MACHINE)) {
3418 X86MachineState *x86ms = X86_MACHINE(ms);
3419 -
3419 + /*
3420 + * For confidential guests, reload bios ROM if IGVM is not specified.
3421 + * If an IGVM file is specified then the firmware must be provided
3422 + * in the IGVM file.
3423 + */
3424 + if (ms->cgs && !x86ms->igvm) {
3425 + x86_bios_rom_reload(x86ms);
3426 + }
3427 if (x86_machine_is_smm_enabled(x86ms)) {
3428 memory_listener_register(&smram_listener.listener,
3429 &smram_address_space);