@samitouri / QOSamiQemu / commits / 99d50e32c7

i386/sev: free existing launch update data and kernel hashes data on init

If there is existing launch update data and kernel hashes data, they need to be freed when initialization code is executed. This is important for resettable confidential guests where the initialization happens once every reset. Signed-off-by: Ani Sinha <anisinha@redhat.com> Link: https://lore.kernel.org/r/20260225035000.385950-22-anisinha@redhat.com Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>

Ani Sinha committed Feb 25, 2026 at 09:19 UTC 99d50e32c7b5b318a561ead10dd4bf86528cab5e
1 file changed +12
target/i386/sev.c
+12
@@ -1773,6 +1773,7 @@ static int sev_common_kvm_init(ConfidentialGuestSupport *cgs, Error **errp)
1773 uint32_t ebx;
1774 uint32_t host_cbitpos;
1775 struct sev_user_data_status status = {};
1776 + SevLaunchUpdateData *data, *next_elm;
1777 SevCommonState *sev_common = SEV_COMMON(cgs);
1778 SevCommonStateClass *klass = SEV_COMMON_GET_CLASS(cgs);
1779 X86ConfidentialGuestClass *x86_klass =
@@ -1780,6 +1781,11 @@ static int sev_common_kvm_init(ConfidentialGuestSupport *cgs, Error **errp)
1781
1782 sev_common->state = SEV_STATE_UNINIT;
1783
1784 + /* free existing launch update data if any */
1785 + QTAILQ_FOREACH_SAFE(data, &launch_update, next, next_elm) {
1786 + g_free(data);
1787 + }
1788 +
1789 host_cpuid(0x8000001F, 0, NULL, &ebx, NULL, NULL);
1790 host_cbitpos = ebx & 0x3f;
1791
@@ -1968,6 +1974,8 @@ static int sev_snp_kvm_init(ConfidentialGuestSupport *cgs, Error **errp)
1974 {
1975 MachineState *ms = MACHINE(qdev_get_machine());
1976 X86MachineState *x86ms = X86_MACHINE(ms);
1977 + SevCommonState *sev_common = SEV_COMMON(cgs);
1978 + SevSnpGuestState *sev_snp_guest = SEV_SNP_GUEST(sev_common);
1979
1980 if (x86ms->smm == ON_OFF_AUTO_AUTO) {
1981 x86ms->smm = ON_OFF_AUTO_OFF;
@@ -1976,6 +1984,10 @@ static int sev_snp_kvm_init(ConfidentialGuestSupport *cgs, Error **errp)
1984 return -1;
1985 }
1986
1987 + /* free existing kernel hashes data if any */
1988 + g_free(sev_snp_guest->kernel_hashes_data);
1989 + sev_snp_guest->kernel_hashes_data = NULL;
1990 +
1991 return 0;
1992 }
1993