According to section "Checks on Guest Control Registers, Debug Registers, and and MSRs" in Intel SDM vol 3C, the following checks are performed on vmentry of nested guests: "The IA32_SYSENTER_ESP field and the IA32_SYSENTER_EIP field must each contain a canonical address." Patch# 1: Adds the required KVM checks. Patch# 2: Modifies an existing kvm-unit-test function to suit the new test being added as part of this KVM check. Patch# 3: Removes a redundant function from the test suite. Patch# 4: Adds a kvm-unit-test to validate this new KVM check. [PATCH 1/4] KVM: nVMX: Check GUEST_SYSENTER_ESP and GUEST_SYSENTER_EIP on [PATCH 2/4] kvm-unit-test: nVMX: Modify test_canonical() to process guest fields [PATCH 3/4] kvm-unit-test: nVMX: Remove test_sysenter_field() and use [PATCH 4/4] kvm-unit-test: nVMX: Test GUEST_SYSENTER_ESP and GUEST_SYSENTER_EIP on arch/x86/kvm/vmx/nested.c | 4 ++++ 1 file changed, 4 insertions(+) Krish Sadhukhan (1): nVMX: Check GUEST_SYSENTER_ESP and GUEST_SYSENTER_EIP on vmentry of nested guests x86/vmx_tests.c | 85 ++++++++++++++++++++++++++++++-------------------------- 1 file changed, 46 insertions(+), 39 deletions(-) Krish Sadhukhan (3): nVMX: Modify test_canonical() to process guest fields also nVMX: Remove test_sysenter_field() and use test_canonical() instead nVMX: Test GUEST_SYSENTER_ESP and GUEST_SYSENTER_EIP on vmentry of nested guests