Re: [PATCH v6 42/44] KVM: VMX: Dedup code for adding MSR to VMCS's auto list

From: Namhyung Kim

Date: Fri Feb 20 2026 - 14:15:11 EST


On Fri, Feb 20, 2026 at 08:46:07AM -0800, Sean Christopherson wrote:
> On Thu, Feb 19, 2026, Namhyung Kim wrote:
> > Hello,
> >
> > On Fri, Dec 05, 2025 at 04:17:18PM -0800, Sean Christopherson wrote:
> > > Add a helper to add an MSR to a VMCS's "auto" list to deduplicate the code
> > > in add_atomic_switch_msr(), and so that the functionality can be used in
> > > the future for managing the MSR auto-store list.
> > >
> > > No functional change intended.
> > >
> > > Signed-off-by: Sean Christopherson <seanjc@xxxxxxxxxx>
> > > ---
> > > arch/x86/kvm/vmx/vmx.c | 41 +++++++++++++++++++----------------------
> > > 1 file changed, 19 insertions(+), 22 deletions(-)
> > >
> > > diff --git a/arch/x86/kvm/vmx/vmx.c b/arch/x86/kvm/vmx/vmx.c
> > > index 018e01daab68..3f64d4b1b19c 100644
> > > --- a/arch/x86/kvm/vmx/vmx.c
> > > +++ b/arch/x86/kvm/vmx/vmx.c
> > > @@ -1093,12 +1093,28 @@ static __always_inline void add_atomic_switch_msr_special(struct vcpu_vmx *vmx,
> > > vm_exit_controls_setbit(vmx, exit);
> > > }
> > >
> > > +static void vmx_add_auto_msr(struct vmx_msrs *m, u32 msr, u64 value,
> > > + unsigned long vmcs_count_field, struct kvm *kvm)
> > > +{
> > > + int i;
> > > +
> > > + i = vmx_find_loadstore_msr_slot(m, msr);
> > > + if (i < 0) {
> > > + if (KVM_BUG_ON(m->nr == MAX_NR_LOADSTORE_MSRS, kvm))
> > > + return;
> > > +
> > > + i = m->nr++;
> > > + m->val[i].index = msr;
> > > + vmcs_write32(vmcs_count_field, m->nr);
> > > + }
> > > + m->val[i].value = value;
> > > +}
> > > +
> > > static void add_atomic_switch_msr(struct vcpu_vmx *vmx, unsigned msr,
> > > u64 guest_val, u64 host_val)
> > > {
> > > struct msr_autoload *m = &vmx->msr_autoload;
> > > struct kvm *kvm = vmx->vcpu.kvm;
> > > - int i;
> > >
> > > switch (msr) {
> > > case MSR_EFER:
> > > @@ -1132,27 +1148,8 @@ static void add_atomic_switch_msr(struct vcpu_vmx *vmx, unsigned msr,
> > > wrmsrq(MSR_IA32_PEBS_ENABLE, 0);
> > > }
> > >
> > > - i = vmx_find_loadstore_msr_slot(&m->guest, msr);
> > > - if (i < 0) {
> > > - if (KVM_BUG_ON(m->guest.nr == MAX_NR_LOADSTORE_MSRS, kvm))
> > > - return;
> > > -
> > > - i = m->guest.nr++;
> > > - m->guest.val[i].index = msr;
> > > - vmcs_write32(VM_ENTRY_MSR_LOAD_COUNT, m->guest.nr);
> > > - }
> > > - m->guest.val[i].value = guest_val;
> > > -
> > > - i = vmx_find_loadstore_msr_slot(&m->host, msr);
> > > - if (i < 0) {
> > > - if (KVM_BUG_ON(m->host.nr == MAX_NR_LOADSTORE_MSRS, kvm))
> > > - return;
> > > -
> > > - i = m->host.nr++;
> > > - m->host.val[i].index = msr;
> > > - vmcs_write32(VM_EXIT_MSR_LOAD_COUNT, m->host.nr);
> > > - }
> > > - m->host.val[i].value = host_val;
> > > + vmx_add_auto_msr(&m->guest, msr, guest_val, VM_ENTRY_MSR_LOAD_COUNT, kvm);
> > > + vmx_add_auto_msr(&m->guest, msr, host_val, VM_EXIT_MSR_LOAD_COUNT, kvm);
> >
> > Shouldn't it be &m->host for the host_val?
>
> Ouch. Yes. How on earth did this escape testing... Ah, because in practice
> only MSR_IA32_PEBS_ENABLE goes through the load lists, and the VM-Entry load list
> will use the guest's value due to VM_ENTRY_MSR_LOAD_COUNT not covering the bad
> host value.
>
> Did you happen to run into problems when using PEBS events in the host?

No, I just found it by reading the patch.

>
> Regardless, do you want to send a patch? Either way, I'll figure out a way to
> verify the bug and the fix.

Sure, will do.

Thanks,
Namhyung