From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.19]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BBAB348663E; Fri, 11 Sep 2026 21:40:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.19 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789162809; cv=none; b=JVVJSDQVEOhpRIPJALezl1qACvYBWcctoSGYrZkprfvfj78jvJ6kzhwbdXUowXGi0ZBTYWbjozDJDxcbYFnpJ8rAn8AoUAoP1Y/eZ8Pe04JjU2U4ifev0RydfCIyTi4d/VAACjb3D07vB3rRGCYe6omgTbIvx2gC1b+lB1Evyi4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789162809; c=relaxed/simple; bh=3JG819fFRjeED+8qgUp8I6kuFeMoUUV2wMY/qZYu45g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=UMawVTthwK6aF1Gsr9BXPkYoFRlbBxP+AKpZqmftl7HNISvlCUyh/Em8II45CkySPc7WgQ+3n9QUoESKLx+s5yWSba/kbxLj0J/LPGDdgJJBrVYf/1oQyNT32sGDVkOgt0wa9HYIR1jLdN6sra6KgIUxWI/6RfuTDTnW6MQIhas= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=Jp5uWYGq; arc=none smtp.client-ip=192.198.163.19 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="Jp5uWYGq" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1789162808; x=1820698808; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=3JG819fFRjeED+8qgUp8I6kuFeMoUUV2wMY/qZYu45g=; b=Jp5uWYGqtyuKFQ1hD+ur7f+0cGMBPgEoHw2cQV5tqcpIWYlKRFu5kEVH Sy2Y+6i6KISx8pV4S7tk90zXFyNZBCFSIY/xLrxfDd0YEhjsEzX8cPCUX GAeE08+ozCThOsZFH48lbq7fy2Hx9uuCUilNQRLfBgUwlNvgIg3iiKvHH k54kgjMSoR6n4u1OPPt5aFPh49KgaZOdqYxKymtDjcw1VI2TyYJXNpm// 0wqa+3FmzgmuVN0+DgQDo7Oy6A4euvdziys10fjP5B8phH1aQj8nKSLFg 0erCMXqmV2G/DCC16EgF63VDSNQMgr32oV6uvO+N4A5/cKh/HlAYgpkmH Q==; X-CSE-ConnectionGUID: HbuFC2WMQFO+q6YCy+u6aQ== X-CSE-MsgGUID: tTwQxxhqQb2IF47s3DlNUg== X-IronPort-AV: E=McAfee;i="6800,10657,11902"; a="88572405" X-IronPort-AV: E=Sophos;i="6.27,98,1787036400"; d="scan'208";a="88572405" Received: from orviesa007.jf.intel.com ([10.64.159.147]) by fmvoesa113.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 11 Sep 2026 14:40:07 -0700 X-CSE-ConnectionGUID: sJ+j2DymQ2qU7iCXcpGo3w== X-CSE-MsgGUID: 6pR1esIKQCeV++gA7bWxiw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.27,98,1787036400"; d="scan'208";a="272003926" Received: from sohilmeh.sc.intel.com ([172.25.103.65]) by orviesa007.jf.intel.com with ESMTP; 11 Sep 2026 14:40:06 -0700 From: Sohil Mehta To: kvm@vger.kernel.org, x86@kernel.org Cc: Paolo Bonzini , Sean Christopherson , Jonathan Corbet , Shuah Khan , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , "H . Peter Anvin" , Xin Li , Andy Lutomirski , Peter Zijlstra , Andrew Cooper , Tom Lendacky , Nikunj A Dadhania , Shivansh Dhiman , David Woodhouse , Chao Gao , Binbin Wu , Sohil Mehta , Zhao Liu , Yosry Ahmed , David Matlack , linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org Subject: [PATCH v10 02/28] KVM: VMX: Initialize VM entry/exit FRED controls in vmcs_config Date: Fri, 11 Sep 2026 14:36:32 -0700 Message-ID: <20260911213659.2025974-3-sohil.mehta@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260911213659.2025974-1-sohil.mehta@intel.com> References: <20260911213659.2025974-1-sohil.mehta@intel.com> Precedence: bulk X-Mailing-List: linux-doc@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: "Xin Li (Intel)" Setup VM entry/exit FRED controls in the global vmcs_config for proper FRED VMCS fields management: 1) load guest FRED state upon VM entry. 2) save guest FRED state during VM exit. 3) load host FRED state during VM exit. Also add FRED control consistency checks to the existing VM entry/exit consistency check framework. Signed-off-by: Xin Li (Intel) Signed-off-by: Sohil Mehta Reviewed-by: Chao Gao Reviewed-by: Binbin Wu --- v10: - No change --- arch/x86/include/asm/vmx.h | 4 ++++ arch/x86/kvm/vmx/vmx.c | 2 ++ arch/x86/kvm/vmx/vmx.h | 7 +++++-- 3 files changed, 11 insertions(+), 2 deletions(-) diff --git a/arch/x86/include/asm/vmx.h b/arch/x86/include/asm/vmx.h index 1f7cffc118bf..682f09933612 100644 --- a/arch/x86/include/asm/vmx.h +++ b/arch/x86/include/asm/vmx.h @@ -121,6 +121,9 @@ struct vmcs { #define VM_EXIT_SAVE_IA32_PERF_GLOBAL_CTRL 0x40000000 #define VM_EXIT_ACTIVATE_SECONDARY_CONTROLS 0x80000000 +#define SECONDARY_VM_EXIT_SAVE_IA32_FRED BIT_ULL(0) +#define SECONDARY_VM_EXIT_LOAD_IA32_FRED BIT_ULL(1) + #define VM_EXIT_ALWAYSON_WITHOUT_TRUE_MSR 0x00036dff #define VM_ENTRY_LOAD_DEBUG_CONTROLS 0x00000004 @@ -134,6 +137,7 @@ struct vmcs { #define VM_ENTRY_PT_CONCEAL_PIP 0x00020000 #define VM_ENTRY_LOAD_IA32_RTIT_CTL 0x00040000 #define VM_ENTRY_LOAD_CET_STATE 0x00100000 +#define VM_ENTRY_LOAD_IA32_FRED 0x00800000 #define VM_ENTRY_ALWAYSON_WITHOUT_TRUE_MSR 0x000011ff diff --git a/arch/x86/kvm/vmx/vmx.c b/arch/x86/kvm/vmx/vmx.c index b4aec4218b7d..062631e2dd37 100644 --- a/arch/x86/kvm/vmx/vmx.c +++ b/arch/x86/kvm/vmx/vmx.c @@ -2778,6 +2778,8 @@ static int setup_vmcs_config(struct vmcs_config *vmcs_conf, u32 entry_control; u64 exit_control; } const vmcs_entry_exit2_pairs[] = { + { VM_ENTRY_LOAD_IA32_FRED, + SECONDARY_VM_EXIT_SAVE_IA32_FRED | SECONDARY_VM_EXIT_LOAD_IA32_FRED }, }; memset(vmcs_conf, 0, sizeof(*vmcs_conf)); diff --git a/arch/x86/kvm/vmx/vmx.h b/arch/x86/kvm/vmx/vmx.h index 6295f9302cd9..7a22e1b1a273 100644 --- a/arch/x86/kvm/vmx/vmx.h +++ b/arch/x86/kvm/vmx/vmx.h @@ -477,7 +477,8 @@ static inline u8 vmx_get_rvi(void) VM_ENTRY_LOAD_BNDCFGS | \ VM_ENTRY_PT_CONCEAL_PIP | \ VM_ENTRY_LOAD_IA32_RTIT_CTL | \ - VM_ENTRY_LOAD_CET_STATE) + VM_ENTRY_LOAD_CET_STATE | \ + VM_ENTRY_LOAD_IA32_FRED) #define __KVM_REQUIRED_VMX_VM_EXIT_CONTROLS \ (VM_EXIT_SAVE_DEBUG_CONTROLS | \ @@ -505,7 +506,9 @@ static inline u8 vmx_get_rvi(void) VM_EXIT_ACTIVATE_SECONDARY_CONTROLS) #define KVM_REQUIRED_VMX_SECONDARY_VM_EXIT_CONTROLS (0) -#define KVM_OPTIONAL_VMX_SECONDARY_VM_EXIT_CONTROLS (0) +#define KVM_OPTIONAL_VMX_SECONDARY_VM_EXIT_CONTROLS \ + (SECONDARY_VM_EXIT_SAVE_IA32_FRED | \ + SECONDARY_VM_EXIT_LOAD_IA32_FRED) #define KVM_REQUIRED_VMX_PIN_BASED_VM_EXEC_CONTROL \ (PIN_BASED_EXT_INTR_MASK | \ -- 2.43.0