x86emul: MOVNTI does not allow REP prefixes Just like 66, prefixes F3 and F2 cause #UD. Also adjust a related comment, which in its previous wording was misleading (as in 16-bit mode there would nothing be undone when adjusting operand size from 2 to 4). Signed-off-by: Jan Beulich --- a/xen/arch/x86/x86_emulate/x86_emulate.c +++ b/xen/arch/x86/x86_emulate/x86_emulate.c @@ -1954,8 +1954,7 @@ x86_decode_twobyte( case 0x50 ... 0x77: case 0x79 ... 0x7f: case 0xae: - case 0xc2: - case 0xc4 ... 0xc6: + case 0xc2 ... 0xc6: case 0xd0 ... 0xfe: ctxt->opcode |= MASK_INSR(vex.pfx, X86EMUL_OPC_PFX_MASK); break; @@ -2461,8 +2460,8 @@ x86_decode( } /* - * Undo the operand-size override effect of prefix 66 when it was - * determined to have another meaning. + * When prefix 66 has a meaning different from operand-size override, + * operand size defaults to 4 and can't be overridden to 2. */ if ( op_bytes == 2 && (ctxt->opcode & X86EMUL_OPC_PFX_MASK) == X86EMUL_OPC_66(0, 0) ) @@ -5291,7 +5290,6 @@ x86_emulate( case X86EMUL_OPC(0x0f, 0xc3): /* movnti */ /* Ignore the non-temporal hint for now. */ vcpu_must_have(sse2); - generate_exception_if(dst.bytes <= 2, EXC_UD); dst.val = src.val; break;