Can you check following scenario:
* on host that has IA32_TSX_CTRL and TSX enabled (RTM/HLE cpuid bits present)
* boot 2 vcpus VM with TSX enabled on VMM side but with tsx=off on kernel CLI
that should cause kernel to set MSR_IA32_TSX_CTRL to 3H from initial 0H
and clear RTM+HLE bits in CPUID, check that RTM/HLE cpuid it cleared
* hotunplug a VCPU and then replug it again
if IA32_TSX_CTRL is reset to initial state, that should re-enable
RTM/HLE cpuid bits and KVM_SET_CPUID2 might fail due to difference
and as Sean pointed out there might be other non constant leafs,
where exact match check could leave userspace broken.