On Wed, Aug 06, 2025 at 08:45:06PM +0000, John Allen wrote: >Set up interception of shadow stack MSRs. In the event that shadow stack >is unsupported on the host or the MSRs are otherwise inaccessible, the >interception code will return an error. In certain circumstances such as >host initiated MSR reads or writes, the interception code will get or >set the requested MSR value. The changelog does not match the code. This patch does not set up interception for shadow stack MSRs; instead, it emulates shadow stack MSR read/write by accessing the corresponding fields in the VMCB. > >Signed-off-by: John Allen <john.allen@xxxxxxx> >--- > arch/x86/kvm/svm/svm.c | 18 ++++++++++++++++++ > 1 file changed, 18 insertions(+) > >diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c >index 6375695ce285..d4e27e70b926 100644 >--- a/arch/x86/kvm/svm/svm.c >+++ b/arch/x86/kvm/svm/svm.c >@@ -2776,6 +2776,15 @@ static int svm_get_msr(struct kvm_vcpu *vcpu, struct msr_data *msr_info) > if (guest_cpuid_is_intel_compatible(vcpu)) > msr_info->data |= (u64)svm->sysenter_esp_hi << 32; > break; >+ case MSR_IA32_S_CET: >+ msr_info->data = svm->vmcb->save.s_cet; >+ break; >+ case MSR_IA32_INT_SSP_TAB: >+ msr_info->data = svm->vmcb->save.isst_addr; >+ break; >+ case MSR_KVM_INTERNAL_GUEST_SSP: >+ msr_info->data = svm->vmcb->save.ssp; >+ break; > case MSR_TSC_AUX: > msr_info->data = svm->tsc_aux; > break; >@@ -3008,6 +3017,15 @@ static int svm_set_msr(struct kvm_vcpu *vcpu, struct msr_data *msr) > svm->vmcb01.ptr->save.sysenter_esp = (u32)data; > svm->sysenter_esp_hi = guest_cpuid_is_intel_compatible(vcpu) ? (data >> 32) : 0; > break; >+ case MSR_IA32_S_CET: >+ svm->vmcb->save.s_cet = data; >+ break; >+ case MSR_IA32_INT_SSP_TAB: >+ svm->vmcb->save.isst_addr = data; >+ break; >+ case MSR_KVM_INTERNAL_GUEST_SSP: >+ svm->vmcb->save.ssp = data; >+ break; > case MSR_TSC_AUX: > /* > * TSC_AUX is always virtualized for SEV-ES guests when the >-- >2.34.1 >