[PATCH v3 9/9] KVM: SVM: Don't intercept ICEBP while the guest has FRED enabled
From: Shivansh Dhiman
Date: Fri Sep 25 2026 - 07:54:22 EST
Commit ec9a16c6aeba ("KVM: SVM: Always intercept ICEBP to workaround AMD
ICEBP+TASK_SWITCH flaws") makes KVM intercept ICEBP and inject the
resulting #DB as a hardware exception. A FRED guest therefore sees INT1
as event type 3 instead of 5. FRED has no task gates, so the workaround
isn't needed while CR4.FRED is set.
Stop intercepting ICEBP while CR4.FRED is set, and recalculate the
intercepts whenever svm_set_cr4() changes CR4.FRED.
Signed-off-by: Shivansh Dhiman <shivansh.dhiman@xxxxxxx>
---
Changes in v3:
* New patch.
---
arch/x86/kvm/svm/svm.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c
index 25dd379725d4..9b2cab844823 100644
--- a/arch/x86/kvm/svm/svm.c
+++ b/arch/x86/kvm/svm/svm.c
@@ -1137,6 +1137,11 @@ static void svm_recalc_instruction_intercepts(struct kvm_vcpu *vcpu)
svm_set_intercept(svm, INTERCEPT_RDPMC);
else
svm_clr_intercept(svm, INTERCEPT_RDPMC);
+
+ if (is_fred_enabled(vcpu))
+ svm_clr_intercept(svm, INTERCEPT_ICEBP);
+ else
+ svm_set_intercept(svm, INTERCEPT_ICEBP);
}
static void svm_recalc_intercepts(struct kvm_vcpu *vcpu)
@@ -1911,6 +1916,9 @@ void svm_set_cr4(struct kvm_vcpu *vcpu, unsigned long cr4)
if ((cr4 ^ old_cr4) & (X86_CR4_OSXSAVE | X86_CR4_PKE))
vcpu->arch.cpuid_dynamic_bits_dirty = true;
+
+ if ((cr4 ^ old_cr4) & X86_CR4_FRED)
+ kvm_make_request(KVM_REQ_RECALC_INTERCEPTS, vcpu);
}
static void svm_set_segment(struct kvm_vcpu *vcpu,
--
2.43.0