[PATCH v3 0/9] KVM: SVM: Enable FRED support

From: Shivansh Dhiman

Date: Fri Sep 25 2026 - 07:47:39 EST


This series adds SVM support for FRED (Flexible Return and Event Delivery)
virtualization in KVM.

Background
----------
FRED introduces simplified privilege level transitions to replace IDT-based
event delivery and IRET returns, providing lower latency event handling while
ensuring complete supervisor context on delivery and full user context on
return. FRED defines event delivery for both ring 3->0 and ring 0->0
transitions, and introduces ERETU for returning to ring 3 and ERETS for
remaining in ring 0.

AMD hardware extends the VMCB to support FRED virtualization [1] with
dedicated save area fields for FRED MSRs (RSP1-3, SSP1-3, STKLVLS, CONFIG;
RSP0 only in the SEV-ES VMSA) and control fields for event injection data
(EXITINTDATA, EVENTINJDATA).

The implementation spans nine patches. The important changes are:

1) Extend VMCB structures with the FRED fields mentioned above, disable MSR
interception for FRED-enabled guests to avoid unnecessary VM exits, and
context switch FRED_RSP0, which hardware doesn't save/restore for
non-SEV-ES guests.

2) Support for nested exceptions, where we populate event injection data
when delivering exceptions like page faults and debug traps.

3) Let userspace save/restore the FRED MSRs, and don't intercept ICEBP
while the guest has FRED enabled.

Major changes in v3
-------------------
* Rebased on v10 of the FRED VMX series [2].
* New patch to save/restore the FRED MSRs for live migration.
* New patch to disable interception of ICEBP when the guest enables FRED.
* Update the FRED fields and their offsets in the VMCB to match the latest
APM.
* Clear FRED from the KVM capabilities when vNMI is unavailable.

The full changelog is at the end of this letter.

Dependencies
------------
This series applies on top of:
* v10 of the FRED VMX series [2], which adds the common x86 FRED support
(CR4.FRED, the FRED MSRs, exception event data and nested exception
tracking).
* "KVM: SVM: Clear VMCB save area instead of entire VMCB on shutdown
intercept" [3]. It keeps FRED_VIRT_ENABLE set across an intercepted
shutdown.

Testing
-------
Testing was done on a Zen 6 machine in the following scenarios:
* Booting FRED-enabled guests and checking that FRED is exposed
* Running SEV, SEV-ES and SEV-SNP guests with FRED enabled
* Live migration of a guest with FRED enabled
* KVM selftests

The msrs_test modified in the VMX series is passing, however, fred_test
doesn't pass on SVM yet. A fix, if needed, will be posted in upcoming
versions.

Opens
-----
* INT1 event type: As I understand it, SVM intercepts ICEBP only because
an ICEBP-induced #DB delivered through a task gate otherwise ends up
with the wrong RIP [4]. FRED has no task gates, so patch 9 drops the
intercept for FRED-enabled guests. The CPU then delivers INT1 itself,
and the guest sees the correct event type 5. David, does this look
like a reasonable approach to you?

However, when KVM itself injects an INT1, the guest still sees event
type 3 instead of 5, even though the hardware supports it. I think a
generic fix in KVM may be required. Any thoughts would be appreciated.

* Nested FRED: FRED for L2 under nested SVM isn't part of this series
and will be posted in upcoming versions.

Links
-----
[1]: https://docs.amd.com/v/u/en-US/69191-PUB
[2]: https://lore.kernel.org/all/20260911213659.2025974-1-sohil.mehta@xxxxxxxxx/
[3]: https://lore.kernel.org/all/20260824131824.6040-1-shivansh.dhiman@xxxxxxx/
[4]: https://lore.kernel.org/kvm/e03f092dfbb7d391a6bf2797ba01e122ba080bcd.camel@xxxxxxxxxxxxx/

Previous versions
-----------------
v2: https://lore.kernel.org/all/20260402184240.1939480-1-shivansh.dhiman@xxxxxxx/
v1: https://lore.kernel.org/kvm/20260129063653.3553076-1-shivansh.dhiman@xxxxxxx/

Regards,
Shivansh

---
Changelog:

v2 -> v3:
* Rebased on v10 of the FRED VMX series.
* New patch to save/restore FRED MSRs via KVM_{GET,SET}_MSRS (patch 4).
* New patch to stop intercepting ICEBP for FRED guests (patch 9).
* Keep the guest's FRED_RSP0 in vcpu_svm for non-SEV-ES guests.
* Updated the FRED fields and offsets in the VMCB per the latest APM.
* Clear the FRED capability when vNMI is unavailable (Andrew Cooper).
* Renamed FRED_VIRT_ENABLE_MASK to SVM_MISC2_ENABLE_V_FRED.
* Use ex->is_nested to check for nested exceptions.
* Updated the FRED prints in dump_vmcb().
* Updated the commit messages.

v1 -> v2:
* Modified the zeroing of FRED MSRs from INIT to RESET and updated the
commit message (Sean Christopherson).
* Moved FRED MSRs save/restore logic from svm_vcpu_enter_exit() to
svm_prepare_[host_switch/switch_to_guest]() to reduce some MSR
accesses.
* Confined the enabling of vFRED to svm_vcpu_after_set_cpuid() only
(Sean Christopherson).
* Removed the need for a new function parameter 'reinject_on_vmexit' in
svm_complete_interrupts() (Paolo Bonzini).
* Used guest_cpu_cap_has() instead of checking VMCB bit in recalc
intercepts (Sean Christopherson).
* Gate all the FRED MSRs through guest_cpu_cap_has() while dumping VMCB
(Sean Christopherson).
* While switching to host, added a safety check on guest_state_loaded.
* Variable rename from 'fred_enable' to 'intercept' (Sean Christopherson).
* Replace variable 'nested' with 'is_nested' (Sean Christopherson).
* Formatted variables in reverse fir-tree order (Sean Christopherson).

---
Neeraj Upadhyay (2):
KVM: SVM: Populate FRED event data on event injection
KVM: SVM: Support FRED nested exception injection

Shivansh Dhiman (7):
KVM: SVM: Initialize FRED VMCB fields
KVM: SVM: Disable interception of FRED MSRs for FRED supported guests
KVM: SVM: Save/restore FRED_RSP0 for FRED supported guests
KVM: SVM: Add support for saving and restoring FRED MSRs
KVM: SVM: Dump FRED context in dump_vmcb()
KVM: SVM: Enable FRED virtualization
KVM: SVM: Don't intercept ICEBP while the guest has FRED enabled

arch/x86/include/asm/svm.h | 33 ++++++-
arch/x86/kvm/svm/svm.c | 180 +++++++++++++++++++++++++++++++++++--
arch/x86/kvm/svm/svm.h | 2 +
3 files changed, 207 insertions(+), 8 deletions(-)

--
2.43.0