Commit 93de2a6a4b91 for kernel

commit 93de2a6a4b91b72607136dd656edf03fb399d27f
Author: Sean Christopherson <seanjc@google.com>
Date:   Wed Sep 23 09:37:21 2026 -0700

    KVM: SEV: Do cache maintenance on the source VM during intra-host migration

    Manually perform cache maintenance on the source VM during intra-host
    migration to ensure no stale data is left in CPU caches after the VM is
    destroyed.  Because the source VM is "converted" to a non-SEV VM, KVM's
    memory reclaim flows won't trigger cache maintenance, e.g. when all guest
    memory is reclaimed in response to detaching from the mmu_notifier.

    Note, relying on the destination VM to do cache maintenance isn't an option
    as KVM doesn't require identical guest memory configurations, i.e. the
    source VM may have access to memory that the destination VM does not.
    Enforcing equivalent memory configurations is infeasible, as it would
    require a *deep* comparison of memslots, e.g. to verify that not only are
    the memslot identical, but what the memslots point at is also identical.

    Fixes: b56639318bb2 ("KVM: SEV: Add support for SEV intra host migration")
    Cc: stable@vger.kernel.org
    Reported-by: Stefan Teodorescu <fane@google.com>
    Signed-off-by: Sean Christopherson <seanjc@google.com>
    Message-ID: <20260923163721.1584779-3-seanjc@google.com>
    Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>

diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c
index cdc1c04f60da..63eb2155a774 100644
--- a/arch/x86/kvm/svm/sev.c
+++ b/arch/x86/kvm/svm/sev.c
@@ -2048,6 +2048,12 @@ static void sev_migrate_from(struct kvm *dst_kvm, struct kvm *src_kvm)
 	src->pages_locked = 0;
 	src->es_active = false;

+	/*
+	 * Do cache maintenance on the source VM as it is no longer an SEV VM,
+	 * i.e. memory reclaim flows won't trigger cache maintenance on the VM.
+	 */
+	sev_writeback_caches(src_kvm);
+
 	list_cut_before(&dst->regions_list, &src->regions_list, &src->regions_list);

 	mutex_lock(&sev_mirror_lock);
@@ -2187,6 +2193,10 @@ int sev_vm_move_enc_context_from(struct kvm *kvm, unsigned int source_fd)
 	 * the set of CPUs from the source.  If a CPU was used to run a vCPU in
 	 * the source VM but is never used for the destination VM, then the CPU
 	 * can only have cached memory that was accessible to the source VM.
+	 * Furthermore, KVM *must* perform cache maintenance on the source VM,
+	 * as the source VM may have access to memory that the destination VM
+	 * does not, i.e. KVM could skip flushes if memory is reclaimed from
+	 * the old VM but not the new VM.
 	 */
 	if (!zalloc_cpumask_var(&dst_sev->have_run_cpus, GFP_KERNEL_ACCOUNT)) {
 		ret = -ENOMEM;