[PATCH v3 1/9] KVM: SVM: Initialize FRED VMCB fields
From: Shivansh Dhiman
Date: Fri Sep 25 2026 - 07:46:44 EST
The AMD FRED (Flexible Return and Event Delivery) feature introduces
several new fields to the VMCB save area. These fields include
FRED-specific stack pointers (fred_rsp[1-3], fred_ssp[1-3]), stack level
tracking (fred_stklvls), and configuration (fred_config), and the
control-area fields exit_int_data and event_inj_data. Note that
fred_rsp0 is only saved/restored for SEV-ES guests.
All FRED MSRs are zeroed on RESET. Reproduce the HW behavior here to
ensure that vCPU starts with a valid FRED state. Also update the size
of save areas of VMCB.
Co-developed-by: Neeraj Upadhyay <Neeraj.Upadhyay@xxxxxxx>
Signed-off-by: Neeraj Upadhyay <Neeraj.Upadhyay@xxxxxxx>
Signed-off-by: Shivansh Dhiman <shivansh.dhiman@xxxxxxx>
Reviewed-by: Nikunj A Dadhania <nikunj@xxxxxxx>
---
Changes in v3:
* Update the fields and offsets of FRED MSRs according to the latest APM.
* Dropped fred_rsp0 from vmcb_save_area. Hardware doesn't save/restore
it for non-SEV-ES guests. Move its handling to patch 3.
* Updated the commit message.
Changes in v2:
* Modified the zeroing of FRED MSRs from INIT to RESET and updated the commit
message (Sean Christopherson).
---
arch/x86/include/asm/svm.h | 31 ++++++++++++++++++++++++++++---
arch/x86/kvm/svm/svm.c | 11 +++++++++++
2 files changed, 39 insertions(+), 3 deletions(-)
diff --git a/arch/x86/include/asm/svm.h b/arch/x86/include/asm/svm.h
index aa63431ba92c..0570581e251a 100644
--- a/arch/x86/include/asm/svm.h
+++ b/arch/x86/include/asm/svm.h
@@ -165,7 +165,10 @@ struct __attribute__ ((__packed__)) vmcb_control_area {
u8 reserved_9[22];
u64 allowed_sev_features; /* Offset 0x138 */
u64 guest_sev_features; /* Offset 0x140 */
- u8 reserved_10[664];
+ u8 reserved_10[40];
+ u64 exit_int_data; /* Offset 0x170 */
+ u64 event_inj_data;
+ u8 reserved_11[608];
/*
* Offset 0x3e0, 32 bytes reserved
* for use by hypervisor/software.
@@ -370,6 +373,15 @@ struct vmcb_save_area {
u64 last_excp_to;
u8 reserved_0x298[72];
u64 spec_ctrl; /* Guest version of SPEC_CTRL at 0x2E0 */
+ u8 reserved_0x2e8[1496];
+ u64 fred_rsp1;
+ u64 fred_rsp2;
+ u64 fred_rsp3;
+ u64 fred_stklvls;
+ u64 fred_ssp1;
+ u64 fred_ssp2;
+ u64 fred_ssp3;
+ u64 fred_config;
} __packed;
/* Save area definition for SEV-ES and SEV-SNP guests */
@@ -482,6 +494,18 @@ struct sev_es_save_area {
u8 fpreg_x87[80];
u8 fpreg_xmm[256];
u8 fpreg_ymm[256];
+ u8 reserved_0x670[568];
+ u64 guest_exit_int_data;
+ u64 guest_event_inj_data;
+ u64 fred_rsp0;
+ u64 fred_rsp1;
+ u64 fred_rsp2;
+ u64 fred_rsp3;
+ u64 fred_stklvls;
+ u64 fred_ssp1;
+ u64 fred_ssp2;
+ u64 fred_ssp3;
+ u64 fred_config;
} __packed;
struct ghcb_save_area {
@@ -552,9 +576,9 @@ struct vmcb {
};
} __packed;
-#define EXPECTED_VMCB_SAVE_AREA_SIZE 744
+#define EXPECTED_VMCB_SAVE_AREA_SIZE 2304
#define EXPECTED_GHCB_SAVE_AREA_SIZE 1032
-#define EXPECTED_SEV_ES_SAVE_AREA_SIZE 1648
+#define EXPECTED_SEV_ES_SAVE_AREA_SIZE 2304
#define EXPECTED_VMCB_CONTROL_AREA_SIZE 1024
#define EXPECTED_GHCB_SIZE PAGE_SIZE
@@ -578,6 +602,7 @@ static inline void __unused_size_checks(void)
BUILD_BUG_RESERVED_OFFSET(vmcb_save_area, 0x180);
BUILD_BUG_RESERVED_OFFSET(vmcb_save_area, 0x248);
BUILD_BUG_RESERVED_OFFSET(vmcb_save_area, 0x298);
+ BUILD_BUG_RESERVED_OFFSET(vmcb_save_area, 0x2e8);
BUILD_BUG_RESERVED_OFFSET(sev_es_save_area, 0xc8);
BUILD_BUG_RESERVED_OFFSET(sev_es_save_area, 0xcc);
diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c
index dd19c7b4e904..6d55b0a576d9 100644
--- a/arch/x86/kvm/svm/svm.c
+++ b/arch/x86/kvm/svm/svm.c
@@ -1217,6 +1217,17 @@ static void init_vmcb(struct kvm_vcpu *vcpu, bool init_event)
save->idtr.base = 0;
save->idtr.limit = 0xffff;
+ if (!init_event) {
+ save->fred_rsp1 = 0;
+ save->fred_rsp2 = 0;
+ save->fred_rsp3 = 0;
+ save->fred_stklvls = 0;
+ save->fred_ssp1 = 0;
+ save->fred_ssp2 = 0;
+ save->fred_ssp3 = 0;
+ save->fred_config = 0;
+ }
+
init_sys_seg(&save->ldtr, SEG_TYPE_LDT);
init_sys_seg(&save->tr, SEG_TYPE_BUSY_TSS16);
--
2.43.0