KVM: TDX: Save and restore IA32_DEBUGCTL
authorAdrian Hunter <adrian.hunter@intel.com>
Wed, 29 Jan 2025 09:59:00 +0000 (11:59 +0200)
committerPaolo Bonzini <pbonzini@redhat.com>
Fri, 14 Mar 2025 18:20:54 +0000 (14:20 -0400)
Save the IA32_DEBUGCTL MSR before entering a TDX VCPU and restore it
afterwards.  The TDX Module preserves bits 1, 12, and 14, so if no
other bits are set, no restore is done.

Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Message-ID: <20250129095902.16391-12-adrian.hunter@intel.com>
Reviewed-by: Xiayao Li <xiaoyao.li@intel.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
arch/x86/kvm/vmx/tdx.c

index 06decfe9eb5e4f02b22e9c9ab5d54f8a256ec6df..7ad680b5f771aff237ee8cd67ed6900f365594ec 100644 (file)
@@ -688,6 +688,8 @@ void tdx_prepare_switch_to_guest(struct kvm_vcpu *vcpu)
        else
                vt->msr_host_kernel_gs_base = read_msr(MSR_KERNEL_GS_BASE);
 
+       vt->host_debugctlmsr = get_debugctlmsr();
+
        vt->guest_state_loaded = true;
 }
 
@@ -831,11 +833,15 @@ static void tdx_load_host_xsave_state(struct kvm_vcpu *vcpu)
        if (kvm_host.xss != (kvm_tdx->xfam & kvm_caps.supported_xss))
                wrmsrl(MSR_IA32_XSS, kvm_host.xss);
 }
-EXPORT_SYMBOL_GPL(kvm_load_host_xsave_state);
+
+#define TDX_DEBUGCTL_PRESERVED (DEBUGCTLMSR_BTF | \
+                               DEBUGCTLMSR_FREEZE_PERFMON_ON_PMI | \
+                               DEBUGCTLMSR_FREEZE_IN_SMM)
 
 fastpath_t tdx_vcpu_run(struct kvm_vcpu *vcpu, bool force_immediate_exit)
 {
        struct vcpu_tdx *tdx = to_tdx(vcpu);
+       struct vcpu_vt *vt = to_vt(vcpu);
 
        /*
         * force_immediate_exit requires vCPU entering for events injection with
@@ -851,6 +857,9 @@ fastpath_t tdx_vcpu_run(struct kvm_vcpu *vcpu, bool force_immediate_exit)
 
        tdx_vcpu_enter_exit(vcpu);
 
+       if (vt->host_debugctlmsr & ~TDX_DEBUGCTL_PRESERVED)
+               update_debugctlmsr(vt->host_debugctlmsr);
+
        tdx_load_host_xsave_state(vcpu);
        tdx->guest_entered = true;