A new functional test is added that exercises the code changes related to
closing of the old KVM VM file descriptor and opening a new one upon VM reset.
This normally happens when confidential guests are resetted but for
non-confidential guests, we use a special machine specific debug/test parameter
'x-change-vmfd-on-reset' to enable this behavior.
Only specific code changes related to re-initialization of SEV-ES, SEV-SNP and
TDX platforms are not exercized in this test as they require hardware that
supports running confidential guests.
Signed-off-by: Ani Sinha <anisinha@redhat.com>
---
MAINTAINERS | 6 ++
tests/functional/x86_64/meson.build | 1 +
.../x86_64/test_vmfd_change_reboot.py | 96 +++++++++++++++++++
3 files changed, 103 insertions(+)
create mode 100755 tests/functional/x86_64/test_vmfd_change_reboot.py
diff --git a/MAINTAINERS b/MAINTAINERS
index c1e586c58f..f3367d4251 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS
@@ -151,6 +151,12 @@ F: tools/i386/
F: tests/functional/i386/
F: tests/functional/x86_64/
+X86 VM file descriptor change on reset test
+M: Ani Sinha <anisinha@redhat.com>
+M: Paolo Bonzini <pbonzini@redhat.com>
+S: Maintained
+F: tests/functional/x86_64/test_vmfd_change_reboot.py
+
Guest CPU cores (TCG)
---------------------
Overall TCG CPUs
diff --git a/tests/functional/x86_64/meson.build b/tests/functional/x86_64/meson.build
index f78eec5e6c..784d9791cb 100644
--- a/tests/functional/x86_64/meson.build
+++ b/tests/functional/x86_64/meson.build
@@ -36,4 +36,5 @@ tests_x86_64_system_thorough = [
'vfio_user_client',
'virtio_balloon',
'virtio_gpu',
+ 'vmfd_change_reboot',
]
diff --git a/tests/functional/x86_64/test_vmfd_change_reboot.py b/tests/functional/x86_64/test_vmfd_change_reboot.py
new file mode 100755
index 0000000000..b9e099aae1
--- /dev/null
+++ b/tests/functional/x86_64/test_vmfd_change_reboot.py
@@ -0,0 +1,96 @@
+#!/usr/bin/env python3
+#
+# KVM VM file descriptor change on reset test
+#
+# Copyright © 2026 Red Hat, Inc.
+#
+# Author:
+# Ani Sinha <anisinha@redhat.com>
+#
+# SPDX-License-Identifier: GPL-2.0-or-later
+
+import os
+from qemu.machine import machine
+
+from qemu_test import QemuSystemTest, Asset, exec_command_and_wait_for_pattern
+from qemu_test import wait_for_console_pattern
+
+class KVMGuest(QemuSystemTest):
+
+ # ASSET UKI was generated using
+ # https://gitlab.com/kraxel/edk2-tests/-/blob/unittest/tools/make-supermin.sh
+ ASSET_UKI = Asset('https://gitlab.com/anisinha/misc-artifacts/'
+ '-/raw/main/uki.x86-64.efi?ref_type=heads',
+ 'e0f806bd1fa24111312e1fe849d2ee69808d4343930a5'
+ 'dc8c1688da17c65f576')
+ # ASSET_OVMF comes from /usr/share/edk2/ovmf/OVMF.stateless.fd of a fc43
+ # distro which in turn comes from the edk2-ovmf-20251119-3.fc43.noarch rpm.
+ ASSET_OVMF = Asset('https://gitlab.com/anisinha/misc-artifacts/'
+ '-/raw/main/OVMF.stateless.fd?ref_type=heads',
+ '58a4275aafa8774bd6b1540adceae4ea434b8db75b476'
+ '11839ff47be88cfcf22')
+
+ def common_vm_setup(self, kvm_args=None, cpu_args=None):
+ self.require_accelerator("kvm")
+
+ self.vm.set_console()
+ if kvm_args:
+ self.vm.add_args("-accel", "kvm,%s" %kvm_args)
+ else:
+ self.vm.add_args("-accel", "kvm")
+ self.vm.add_args("-smp", "2")
+ if cpu_args:
+ self.vm.add_args("-cpu", "host,%s" %cpu_args)
+ else:
+ self.vm.add_args("-cpu", "host")
+ self.vm.add_args("-m", "2G")
+ self.vm.add_args("-nographic", "-nodefaults")
+
+ self.uki_path = self.ASSET_UKI.fetch()
+ self.ovmf_path = self.ASSET_OVMF.fetch()
+
+ def run_and_check(self):
+ self.vm.add_args('-kernel', self.uki_path)
+ self.vm.add_args("-bios", self.ovmf_path)
+ # enable KVM VMFD change on reset for a non-coco VM
+ self.vm.add_args("-machine", "q35,x-change-vmfd-on-reset=on")
+ # enable tracing
+ self.vm.add_args("-d", "trace:kvm_reset_vmfd")
+
+ try:
+ self.vm.launch()
+ except machine.VMLaunchFailure as e:
+ if "Xen HVM guest support not present" in e.output:
+ self.skipTest("KVM Xen support is not present "
+ "(need v5.12+ kernel with CONFIG_KVM_XEN)")
+ elif "Property 'kvm-accel.xen-version' not found" in e.output:
+ self.skipTest("QEMU not built with CONFIG_XEN_EMU support")
+ else:
+ raise e
+
+ self.log.info('VM launched')
+ console_pattern = 'bash-5.1#'
+ wait_for_console_pattern(self, console_pattern)
+ self.log.info('VM ready with a bash prompt')
+
+ exec_command_and_wait_for_pattern(self, '/usr/sbin/reboot -f',
+ 'reboot: machine restart')
+ console_pattern = '# --- Hello world ---'
+ wait_for_console_pattern(self, console_pattern)
+ self.vm.shutdown()
+ self.assertRegex(self.vm.get_log(),
+ r'kvm_reset_vmfd')
+ self.assertRegex(self.vm.get_log(),
+ r'virtual machine accel file descriptor has changed')
+
+ def test_vmfd_change_on_reset(self):
+ self.common_vm_setup()
+ self.run_and_check()
+
+ def test_xen_emulation(self):
+ self.common_vm_setup("xen-version=0x4000a,kernel-irqchip=split")
+ self.run_and_check()
+
+
+if __name__ == '__main__':
+ QemuSystemTest.main()
--
2.42.0