Re: [PATCH v2 4/4] KVM: selftests: Add coverage for the EFER_LMSLE_MBZ defeature

From: Sean Christopherson

Date: Mon Sep 28 2026 - 20:46:27 EST


On Wed, Sep 23, 2026, Jim Mattson wrote:
> + /*
> + * Per AMD APM vol. 2, if CPUID.80000008H:EBX[bit 20] is set, "64-bit

Please tell your LLM not to quote specific volumes/sections in code comments.
It's a-ok for changelogs to reference specific sections, because those are
naturally timestamped (and can even explicitly call out the APM/SDM version).
But code/comments are usually read without the context of when the code/comment
was added, i.e. are much more likely to become stale in practice.

> + /*
> + * EFER_LMSLE_MBZ, CPUID.80000008H:EBX[bit 20], is a "defeature" bit,
> + * i.e. is set when the CPU does *not* support long mode segment
> + * limits. KVM enumerates the defeature if and only if KVM refuses to
> + * set EFER.LMSLE, i.e. if the CPU doesn't support LMSLE, or if KVM
> + * doesn't support nested SVM. Derive the expectation from raw CPUID
> + * and kvm_amd's "nested" module param rather than from
> + * kvm_cpu_has(X86_FEATURE_SVM), so that the assertion doesn't simply
> + * compare KVM's enumeration to itself.
> + *
> + * Note, kvm_amd's "nested" is an "int" module param, i.e. reads back
> + * as '1'/'0' and not as 'Y'/'N'. Query the param if and only if the
> + * CPU supports SVM, i.e. if and only if kvm_amd is the module in
> + * play. Checking the vendor string wouldn't suffice, e.g. Zhaoxin
> + * and Centaur CPUs are "GenuineIntel"-adjacent at best, but run VMX
> + * and thus load kvm_intel.

Happily, that support is actually already in kvm-x86, i.e. there's now a
host_cpu_is_intel_compatible sitting in the "selftests" branch. That's mildly
annoying as I don't want to take this series through "selftests", but that's
easy enough to deal with, by deliberately touching the same code so I don't
forget to tell Paolo about a semantic-only conflict.

I also want to add a helper for "nested" so that we don't end up with similar
checks sprinkled here and there, but with a scary comment instructing developers
to use kvm_cpu_has(X86_FEATURE_{VMX,SVM}) (I want to avoid having two common ways
of doing one thing).

I'll send a v3 (assuming my code works) with this:

/*
* EFER_LMSLE_MBZ, CPUID.80000008H:EBX[bit 20], is a "defeature" bit,
* i.e. is set when the CPU does *not* support long mode segment
* limits. KVM enumerates the defeature if and only if KVM refuses to
* set EFER.LMSLE, i.e. if the CPU doesn't support LMSLE, or if KVM
* doesn't support nested SVM. Derive the expectation from raw CPUID
* and kvm_amd's "nested" module param rather than from
* kvm_cpu_has(X86_FEATURE_SVM), so that the assertion doesn't simply
* compare KVM's enumeration to itself.
*/
lmsle_mbz = this_cpu_has(X86_FEATURE_EFER_LMSLE_MBZ) ||
!this_cpu_has(X86_FEATURE_SVM) ||
!kvm_is_nested_virtualization_enabled();