[PATCH v6 42/44] KVM: VMX: Dedup code for adding MSR to VMCS's auto list

Namhyung Kim namhyung at kernel.org
Fri Feb 20 11:14:49 PST 2026


On Fri, Feb 20, 2026 at 08:46:07AM -0800, Sean Christopherson wrote:
> On Thu, Feb 19, 2026, Namhyung Kim wrote:
> > Hello,
> > 
> > On Fri, Dec 05, 2025 at 04:17:18PM -0800, Sean Christopherson wrote:
> > > Add a helper to add an MSR to a VMCS's "auto" list to deduplicate the code
> > > in add_atomic_switch_msr(), and so that the functionality can be used in
> > > the future for managing the MSR auto-store list.
> > > 
> > > No functional change intended.
> > > 
> > > Signed-off-by: Sean Christopherson <seanjc at google.com>
> > > ---
> > >  arch/x86/kvm/vmx/vmx.c | 41 +++++++++++++++++++----------------------
> > >  1 file changed, 19 insertions(+), 22 deletions(-)
> > > 
> > > diff --git a/arch/x86/kvm/vmx/vmx.c b/arch/x86/kvm/vmx/vmx.c
> > > index 018e01daab68..3f64d4b1b19c 100644
> > > --- a/arch/x86/kvm/vmx/vmx.c
> > > +++ b/arch/x86/kvm/vmx/vmx.c
> > > @@ -1093,12 +1093,28 @@ static __always_inline void add_atomic_switch_msr_special(struct vcpu_vmx *vmx,
> > >  	vm_exit_controls_setbit(vmx, exit);
> > >  }
> > >  
> > > +static void vmx_add_auto_msr(struct vmx_msrs *m, u32 msr, u64 value,
> > > +			     unsigned long vmcs_count_field, struct kvm *kvm)
> > > +{
> > > +	int i;
> > > +
> > > +	i = vmx_find_loadstore_msr_slot(m, msr);
> > > +	if (i < 0) {
> > > +		if (KVM_BUG_ON(m->nr == MAX_NR_LOADSTORE_MSRS, kvm))
> > > +			return;
> > > +
> > > +		i = m->nr++;
> > > +		m->val[i].index = msr;
> > > +		vmcs_write32(vmcs_count_field, m->nr);
> > > +	}
> > > +	m->val[i].value = value;
> > > +}
> > > +
> > >  static void add_atomic_switch_msr(struct vcpu_vmx *vmx, unsigned msr,
> > >  				  u64 guest_val, u64 host_val)
> > >  {
> > >  	struct msr_autoload *m = &vmx->msr_autoload;
> > >  	struct kvm *kvm = vmx->vcpu.kvm;
> > > -	int i;
> > >  
> > >  	switch (msr) {
> > >  	case MSR_EFER:
> > > @@ -1132,27 +1148,8 @@ static void add_atomic_switch_msr(struct vcpu_vmx *vmx, unsigned msr,
> > >  		wrmsrq(MSR_IA32_PEBS_ENABLE, 0);
> > >  	}
> > >  
> > > -	i = vmx_find_loadstore_msr_slot(&m->guest, msr);
> > > -	if (i < 0) {
> > > -		if (KVM_BUG_ON(m->guest.nr == MAX_NR_LOADSTORE_MSRS, kvm))
> > > -			return;
> > > -
> > > -		i = m->guest.nr++;
> > > -		m->guest.val[i].index = msr;
> > > -		vmcs_write32(VM_ENTRY_MSR_LOAD_COUNT, m->guest.nr);
> > > -	}
> > > -	m->guest.val[i].value = guest_val;
> > > -
> > > -	i = vmx_find_loadstore_msr_slot(&m->host, msr);
> > > -	if (i < 0) {
> > > -		if (KVM_BUG_ON(m->host.nr == MAX_NR_LOADSTORE_MSRS, kvm))
> > > -			return;
> > > -
> > > -		i = m->host.nr++;
> > > -		m->host.val[i].index = msr;
> > > -		vmcs_write32(VM_EXIT_MSR_LOAD_COUNT, m->host.nr);
> > > -	}
> > > -	m->host.val[i].value = host_val;
> > > +	vmx_add_auto_msr(&m->guest, msr, guest_val, VM_ENTRY_MSR_LOAD_COUNT, kvm);
> > > +	vmx_add_auto_msr(&m->guest, msr, host_val, VM_EXIT_MSR_LOAD_COUNT, kvm);
> > 
> > Shouldn't it be &m->host for the host_val?
> 
> Ouch.  Yes.  How on earth did this escape testing...  Ah, because in practice
> only MSR_IA32_PEBS_ENABLE goes through the load lists, and the VM-Entry load list
> will use the guest's value due to VM_ENTRY_MSR_LOAD_COUNT not covering the bad
> host value.
> 
> Did you happen to run into problems when using PEBS events in the host?

No, I just found it by reading the patch.

> 
> Regardless, do you want to send a patch?  Either way, I'll figure out a way to
> verify the bug and the fix.

Sure, will do.

Thanks,
Namhyung




More information about the linux-arm-kernel mailing list