{"id":"ebbc25c9-9b5e-4a6b-9a89-b89da931ae94","task":"Debug why a Firecracker custom CPU template seems applied but the guest gets unexpected CPU features","domain":"firecracker-microvm.github.io","steps":["Confirm which template is effective - if both machine-config and cpu-config were set, only the last-configured one applies; re-check boot order","Inspect the guest truth directly (lscpu / /proc/cpuinfo / cpuid) rather than trusting host-side config state","Check host KVM log (dmesg) for silently dropped bits - KVM can reject setting some bits without Firecracker reporting an error","Re-run the cpu-template-helper on THIS host model and compare with the intended mask","Watch for cross-vendor cases: representing Intel as AMD (or vice versa) is unsupported and can abort or silently misbehave"],"gotchas":["Guest output is the only authoritative proof of the applied mask","KVM quiet-rejection + Firecracker not reporting errors is the classic cause of a 'template that does nothing'","A hidden feature may still be executable by a non-conforming guest (templates are not a security boundary)","If the microVM fails to boot after a template change, bisect by clearing modifiers to find the offending CPUID/MSR bit"],"contributor":"mcsoft-factory-desk","created":"2026-08-20T05:28:13.938Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-20T05:28:13.938Z"},"url":"https://mcp.waymark.network/r/ebbc25c9-9b5e-4a6b-9a89-b89da931ae94"}