[PATCH v3 2/9] KVM: SVM: Disable interception of FRED MSRs for FRED supported guests

From: Shivansh Dhiman

Date: Fri Sep 25 2026 - 07:48:19 EST


The FRED (Flexible Return and Event Delivery) feature introduces a new set
of MSRs for managing its state, such as MSR_IA32_FRED_CONFIG and the
various stack pointer MSRs.

For a guest that has FRED enabled via its CPUID bits, the guest OS
expects to be able to directly read and write these MSRs. Intercepting
these accesses would cause unnecessary VM-Exits and performance overhead.
In addition, the state of the MSRs at any point should always correspond
to the context (host or guest) which is running. Otherwise, the event
delivery could refer to wrong MSR values.

Co-developed-by: Neeraj Upadhyay <Neeraj.Upadhyay@xxxxxxx>
Signed-off-by: Neeraj Upadhyay <Neeraj.Upadhyay@xxxxxxx>
Signed-off-by: Shivansh Dhiman <shivansh.dhiman@xxxxxxx>
---

Changes in v3:
* Rebased, no functional changes.

Changes in v2:
* Used guest_cpu_cap_has() instead of checking VMCB bit (Sean Christopherson).
* Variable rename from 'fred_enable' to 'intercept' (Sean Christopherson).

---
arch/x86/kvm/svm/svm.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)

diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c
index 6d55b0a576d9..e212f53d262a 100644
--- a/arch/x86/kvm/svm/svm.c
+++ b/arch/x86/kvm/svm/svm.c
@@ -788,6 +788,21 @@ static void svm_recalc_pmu_msr_intercepts(struct kvm_vcpu *vcpu)
MSR_TYPE_RW, intercept);
}

+static void svm_recalc_fred_msr_intercepts(struct kvm_vcpu *vcpu)
+{
+ bool intercept = guest_cpu_cap_has(vcpu, X86_FEATURE_FRED);
+
+ svm_set_intercept_for_msr(vcpu, MSR_IA32_FRED_RSP0, MSR_TYPE_RW, !intercept);
+ svm_set_intercept_for_msr(vcpu, MSR_IA32_FRED_RSP1, MSR_TYPE_RW, !intercept);
+ svm_set_intercept_for_msr(vcpu, MSR_IA32_FRED_RSP2, MSR_TYPE_RW, !intercept);
+ svm_set_intercept_for_msr(vcpu, MSR_IA32_FRED_RSP3, MSR_TYPE_RW, !intercept);
+ svm_set_intercept_for_msr(vcpu, MSR_IA32_FRED_STKLVLS, MSR_TYPE_RW, !intercept);
+ svm_set_intercept_for_msr(vcpu, MSR_IA32_FRED_SSP1, MSR_TYPE_RW, !intercept);
+ svm_set_intercept_for_msr(vcpu, MSR_IA32_FRED_SSP2, MSR_TYPE_RW, !intercept);
+ svm_set_intercept_for_msr(vcpu, MSR_IA32_FRED_SSP3, MSR_TYPE_RW, !intercept);
+ svm_set_intercept_for_msr(vcpu, MSR_IA32_FRED_CONFIG, MSR_TYPE_RW, !intercept);
+}
+
static void svm_recalc_msr_intercepts(struct kvm_vcpu *vcpu)
{
struct vcpu_svm *svm = to_svm(vcpu);
@@ -857,6 +872,7 @@ static void svm_recalc_msr_intercepts(struct kvm_vcpu *vcpu)
sev_es_recalc_msr_intercepts(vcpu);

svm_recalc_pmu_msr_intercepts(vcpu);
+ svm_recalc_fred_msr_intercepts(vcpu);

/*
* x2APIC intercepts are modified on-demand and cannot be filtered by
--
2.43.0