KVM: VMX: Print out "bad" offsets+value on VMCS config mismatch

JIRA: https://issues.redhat.com/browse/RHEL-151869

commit c0d6b8bbbced660e9c2efe079e2b2cb34b27d97f
Author: Sean Christopherson <seanjc@google.com>
Date:   Tue Jan 27 17:43:10 2026 -0800

    KVM: VMX: Print out "bad" offsets+value on VMCS config mismatch

    When kvm-intel.ko refuses to load due to a mismatched VMCS config, print
    all mismatching offsets+values to make it easier to debug goofs during
    development, and to make it at least feasible to triage failures that
    occur during production.  E.g. if a physical core is flaky or is running
    with the "wrong" microcode patch loaded, then a CPU can get a legitimate
    mismatch even without KVM bugs.

    Print the mismatches as 32-bit values as a compromise between hand coding
    every field (to provide precise information) and printing individual bytes
    (requires more effort to deduce the mismatch bit(s)).  All fields in the
    VMCS config are either 32-bit or 64-bit values, i.e. in many cases,
    printing 32-bit values will be 100% precise, and in the others it's close
    enough, especially when considering that MSR values are split into EDX:EAX
    anyways.

    E.g. on mismatch CET entry/exit controls, KVM will print:

      kvm_intel: VMCS config on CPU 0 doesn't match reference config:
        Offset 76 REF = 0x107fffff, CPU0 = 0x007fffff, mismatch = 0x10000000
        Offset 84 REF = 0x0010f3ff, CPU0 = 0x0000f3ff, mismatch = 0x00100000

    Opportunistically tweak the wording on the initial error message to say
    "mismatch" instead of "inconsistent", as the VMCS config itself isn't
    inconsistent, and the wording conflates the cross-CPU compatibility check
    with the error_on_inconsistent_vmcs_config knob that treats inconsistent
    VMCS configurations as errors (e.g. if a CPU supports CET entry controls
    but no CET exit controls).

    Cc: Jim Mattson <jmattson@google.com>
    Reviewed-by: Xiaoyao Li <xiaoyao.li@intel.com>
    Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
    Link: https://patch.msgid.link/20260128014310.3255561-4-seanjc@google.com
    Signed-off-by: Sean Christopherson <seanjc@google.com>

Signed-off-by: Maxim Levitsky <mlevitsk@redhat.com>
This commit is contained in:
Maxim Levitsky
2026-07-21 14:12:04 -04:00
parent f0989110e0
commit 9d9face9fe
+16 -1
View File
@@ -2961,8 +2961,23 @@ int vmx_check_processor_compat(void)
}
if (nested)
nested_vmx_setup_ctls_msrs(&vmcs_conf, vmx_cap.ept);
if (memcmp(&vmcs_config, &vmcs_conf, sizeof(struct vmcs_config))) {
pr_err("Inconsistent VMCS config on CPU %d\n", cpu);
u32 *gold = (void *)&vmcs_config;
u32 *mine = (void *)&vmcs_conf;
int i;
BUILD_BUG_ON(sizeof(struct vmcs_config) % sizeof(u32));
pr_err("VMCS config on CPU %d doesn't match reference config:", cpu);
for (i = 0; i < sizeof(struct vmcs_config) / sizeof(u32); i++) {
if (gold[i] == mine[i])
continue;
pr_cont("\n Offset %u REF = 0x%08x, CPU%u = 0x%08x, mismatch = 0x%08x",
i * (int)sizeof(u32), gold[i], cpu, mine[i], gold[i] ^ mine[i]);
}
pr_cont("\n");
return -EIO;
}
return 0;