From: Tharit Tangkijwanichakul <tharitt97@gmail.com>
To: seanjc@google.com, pbonzini@redhat.com, shuah@kernel.org
Cc: kvm@vger.kernel.org, linux-kselftest@vger.kernel.org,
linux-kernel@vger.kernel.org,
linux-kernel-mentees@lists.linux.dev, skhan@linuxfoundation.org,
me@brighamcampbell.com, jkoolstra@xs4all.nl,
Tharit Tangkijwanichakul <tharitt97@gmail.com>
Subject: [PATCH v2] KVM: selftests: Verify KVM_MSR_EXIT_REASON_INVAL on non-canonical FS_BASE write
Date: Tue, 29 Sep 2026 23:29:40 +0700 [thread overview]
Message-ID: <20260929162940.14610-1-tharitt97@gmail.com> (raw)
The msr_filter_deny test covers the FILTER and UNKNOWN MSR exit
reasons, but nothing exercises KVM_MSR_EXIT_REASON_INVAL.
Have the guest write a non-canonical value to FS_BASE and verify
that the write exits to userspace with KVM_MSR_EXIT_REASON_INVAL along
with the attempted value.
FS_BASE writes are passed through to hardware, i.e. a plain WRMSR
takes #GP directly without exiting, so use forced emulation to route
the write through KVM.
Signed-off-by: Tharit Tangkijwanichakul <tharitt97@gmail.com>
---
v2:
- Use a write of non-canonical to FS_BASE value instead of
reserved EFER bit 63 because writing non-canonical can't
become valid without massive architectural changes unlike EFER reserved bit
(suggested by Sean).
Tested on Intel Core i5-10210U (VMX). Not tested on AMD.
---
.../kvm/x86/userspace_msr_exit_test.c | 19 ++++++++++++++++++-
1 file changed, 18 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/kvm/x86/userspace_msr_exit_test.c b/tools/testing/selftests/kvm/x86/userspace_msr_exit_test.c
index 2808ce727e5f..40b084cba2c0 100644
--- a/tools/testing/selftests/kvm/x86/userspace_msr_exit_test.c
+++ b/tools/testing/selftests/kvm/x86/userspace_msr_exit_test.c
@@ -309,6 +309,14 @@ static void guest_msr_calls(bool trapped)
/* Invalid MSR, should always be handled by user space exit */
GUEST_ASSERT(rdmsr(0xdeadbeef) == 0xdeadbeef);
wrmsr(0xdeadbeef, 0x1234);
+
+ /*
+ * Writing a non-canonical value to FS_BASE is rejected by KVM, but
+ * FS_BASE writes are passed through to hardware, so force emulation
+ * to route the write through KVM and get an INVAL exit.
+ */
+ if (is_forced_emulation_enabled)
+ test_em_wrmsr(MSR_FS_BASE, NONCANONICAL);
}
static void guest_code_filter_deny(void)
@@ -627,6 +635,13 @@ static void handle_wrmsr(struct kvm_run *run)
TEST_ASSERT(run->msr.reason == KVM_MSR_EXIT_REASON_UNKNOWN,
"deadbeef trap w/o inval fault");
}
+
+ if (run->msr.index == MSR_FS_BASE) {
+ TEST_ASSERT(run->msr.data == NONCANONICAL,
+ "MSR_FS_BASE data is not NONCANONICAL");
+ TEST_ASSERT(run->msr.reason == KVM_MSR_EXIT_REASON_INVAL,
+ "MSR_FS_BASE trap w/o inval fault");
+ }
}
KVM_ONE_VCPU_TEST(user_msr, msr_filter_deny, guest_code_filter_deny)
@@ -667,7 +682,9 @@ KVM_ONE_VCPU_TEST(user_msr, msr_filter_deny, guest_code_filter_deny)
done:
TEST_ASSERT(msr_reads == 4, "Handled 4 rdmsr in user space");
- TEST_ASSERT(msr_writes == 3, "Handled 3 wrmsr in user space");
+ TEST_ASSERT(msr_writes == (is_forced_emulation_enabled ? 5 : 3),
+ "Handled %u wrmsr in user space, expected %u",
+ msr_writes, is_forced_emulation_enabled ? 5 : 3);
}
KVM_ONE_VCPU_TEST(user_msr, msr_permission_bitmap, guest_code_permission_bitmap)
--
2.53.0
reply other threads:[~2026-09-29 16:29 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929162940.14610-1-tharitt97@gmail.com \
--to=tharitt97@gmail.com \
--cc=jkoolstra@xs4all.nl \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel-mentees@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=me@brighamcampbell.com \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=shuah@kernel.org \
--cc=skhan@linuxfoundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®