@samitouri / QOSamiQemu / commits / b6fde55342

hw/hyperv/vmbus: add support for confidential guest reset

On confidential guests when the KVM virtual machine file descriptor changes as a part of the reset process, event file descriptors needs to be reassociated with the new KVM VM file descriptor. This is achieved with the help of a callback handler that gets called when KVM VM file descriptor changes during the confidential guest reset process. This patch is tested on non-confidential platform only. Acked-by: Maciej S. Szmigiero <maciej.szmigiero@oracle.com> Signed-off-by: Ani Sinha <anisinha@redhat.com> Link: https://lore.kernel.org/r/20260225035000.385950-28-anisinha@redhat.com Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>

Ani Sinha committed Feb 25, 2026 at 09:19 UTC b6fde55342d16653ae48113a56792809d667e2e1
2 files changed +38
hw/hyperv/trace-events
+1
@@ -16,6 +16,7 @@ vmbus_gpadl_torndown(uint32_t gpadl_id) "gpadl #%d"
16 vmbus_open_channel(uint32_t chan_id, uint32_t gpadl_id, uint32_t target_vp) "channel #%d gpadl #%d target vp %d"
17 vmbus_channel_open(uint32_t chan_id, uint32_t status) "channel #%d status %d"
18 vmbus_close_channel(uint32_t chan_id) "channel #%d"
19 +vmbus_handle_vmfd_change(void) ""
20
21 # hv-balloon
22 hv_balloon_state_change(const char *tostr) "-> %s"
hw/hyperv/vmbus.c
+37
@@ -20,6 +20,7 @@
20 #include "hw/hyperv/vmbus-bridge.h"
21 #include "hw/core/sysbus.h"
22 #include "exec/cpu-common.h"
23 +#include "system/kvm.h"
24 #include "exec/target_page.h"
25 #include "trace.h"
26
@@ -248,6 +249,12 @@ struct VMBus {
249 * interrupt page
250 */
251 EventNotifier notifier;
252 +
253 + /*
254 + * Notifier to inform when vmfd is changed as a part of confidential guest
255 + * reset mechanism.
256 + */
257 + NotifierWithReturn vmbus_vmfd_change_notifier;
258 };
259
260 static bool gpadl_full(VMBusGpadl *gpadl)
@@ -2347,6 +2354,33 @@ static void vmbus_dev_unrealize(DeviceState *dev)
2354 free_channels(vdev);
2355 }
2356
2357 +/*
2358 + * If the KVM fd changes because of VM reset in confidential guests,
2359 + * reassociate event fd with the new KVM fd.
2360 + */
2361 +static int vmbus_handle_vmfd_change(NotifierWithReturn *notifier,
2362 + void *data, Error** errp)
2363 +{
2364 + VMBus *vmbus = container_of(notifier, VMBus,
2365 + vmbus_vmfd_change_notifier);
2366 + int ret = 0;
2367 +
2368 + /* we are not interested in pre vmfd change notification */
2369 + if (((VmfdChangeNotifier *)data)->pre) {
2370 + return 0;
2371 + }
2372 +
2373 + ret = hyperv_set_event_flag_handler(VMBUS_EVENT_CONNECTION_ID,
2374 + &vmbus->notifier);
2375 + /* if we are only using userland event handler, it may already exist */
2376 + if (ret != 0 && ret != -EEXIST) {
2377 + error_setg(errp, "hyperv set event handler failed with %d", ret);
2378 + }
2379 +
2380 + trace_vmbus_handle_vmfd_change();
2381 + return ret;
2382 +}
2383 +
2384 static const Property vmbus_dev_props[] = {
2385 DEFINE_PROP_UUID("instanceid", VMBusDevice, instanceid),
2386 };
@@ -2429,6 +2463,9 @@ static void vmbus_realize(BusState *bus, Error **errp)
2463 goto clear_event_notifier;
2464 }
2465
2466 + vmbus->vmbus_vmfd_change_notifier.notify = vmbus_handle_vmfd_change;
2467 + kvm_vmfd_add_change_notifier(&vmbus->vmbus_vmfd_change_notifier);
2468 +
2469 return;
2470
2471 clear_event_notifier: