[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v2 00/13] x86/nestedsvm: rework nested VMRUN/VMEXIT handling


  • To: xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: chunjie.zhu@xxxxxxxxxx
  • Date: Sat, 10 Oct 2026 18:13:13 +0800
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com; dkim=pass header.d=citrix.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=oqugbetrJdX8gVZTXaNh2smkuMQZeQG1KnruYZO7cYo=; b=zIERtxQIYpFVWc2BVVJqTLtaFn+lz0z/tkDnpbLtry1YXiFvxfjWz+jqbh62Um/b1MpYqqWJZuiC6rA1VfJ1/AxrcfxXDiYQ/idoXgCQ8UxQ37rvwXk1lgEHZssvzcFaWLPJlkQkJ8LBhQeYa75ent0V50NCRGylhwOaYAtOL6TlOC8lBJuuzyLigqMKA4sJmRXJz+BTknLvnQo7NMfmEn5FJtoMcPimSLL09I6jO/c8x+1d4N8hvuZ9bc5w/A9ujf5vUfEJ1UvLNtcZi+QYY8/ZahwYmgbF/Z6aXGoHMqyAqqk9kFpjL0RKPnoJ/De7yFwOb15aCiy0mdcT+t1utg==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=C8NNEPEDAuJCMq7RJO70uvbsHSC643tPpWropW2sS15ecVzKgt8PmliyX4kgoma/BRXSYfuylFwGunoxUhBjzULPG+noNOIT2YIjIp+bz5xonbxnmkeosDCwAR0k8Y7WrEUayE66x4ppkyC5es8qZa7HaTI3rp00IzmuZNz7h5r4kPIwxlN5g8aO2dvMZGjWiPXeuJ8k2tpS+z4RUjbqn4k5eYijZS/o/OcLSNrFmAxBUJjyGtJhoa6szKKDxLnrZDWJjfKjoDQuI1KxFOU88OLjFnmAxO0VF7MIMWpoMXpa/GJK1KRCQd+jwk5gwHLLQ09yYVbVnNYmQFpvLqe/VQ==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=citrix.com header.i="@citrix.com" header.h="From:Date:Subject:Message-Id:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=citrix.com;
  • Cc: ross.lagerwall@xxxxxxxxxx, jbeulich@xxxxxxxx, andrew.cooper3@xxxxxxxxxx, roger@xxxxxxxxxxxxxx, jason.andryuk@xxxxxxx, teddy.astie@xxxxxxxxxx, stephen.cheng@xxxxxxxxxx, lin.liu01@xxxxxxxxxx, Chunjie Zhu <chunjie.zhu@xxxxxxxxxx>
  • Delivery-date: Sat, 10 Oct 2026 10:14:14 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

From: Chunjie Zhu <chunjie.zhu@xxxxxxxxxx>

This series simplifies nested SVM execution by removing pending and
deferred state from the VMRUN and VMEXIT paths, and includes the nested
SVM / Viridian fixes the rework depends on.

Changes in v2 (following Ross Lagerwall's review of v1):
 - Dropped the v1 "x86/nestedsvm: update vmcb correctly" and
   "x86/nestedsvm: fix up" patches, which mixed in unrelated bug fixes
   from our internal patchqueue.
 - Those fixes are now submitted as separate patches (1-10) at the start
   of the series, with the original authorship preserved.  The p2m.c
   change from v1 5/5 is not included.
 - The three rework patches from v1 (1-3/5) are now patches 11-13.  The
   stale_np2m handling from v1 5/5 is folded into patch 11; the rest is
   rebased only.  See per-patch notes below the "---" line.

Contributions by author:
 Ross Lagerwall (patches 1-6, 8-9):
   - Fix CR3 MBZ check
   - Adjust L2's DR intercept when adjusting L1
   - Use the correct VMCB for vGIF
   - Set GIF during VMRUN if vGIF is enabled
   - Viridian stimer direct mode support in libxl
   - Clamp Viridian features to known set
   - Don't set VMCB(1-2)'s NP_ENABLE and N_CR3 during VMEXIT to L1
   - Fix VMLOAD/VMSAVE state handling when using nested virt
 Stephen Cheng (patch 7):
   - Require VMSAVEvirt for nested virt
 Lin Liu (patch 10):
   - Don't clear TLB_CONTROL on #VMEXIT
 Chunjie Zhu (patches 11-13):
   - Rework of nested VMRUN/VMEXIT without pending or deferred flags,
     and removal of nv_vmentry_pending

Chunjie Zhu (3):
  x86/nestedsvm: update vmrun without pending or deferred
  x86/nestedsvm: remove nv_vmentry_pending
  x86/nestedsvm: update vmexit without pending or deferred flag

Lin Liu (1):
  x86/nSVM: Don't clear TLB_CONTROL on #VMEXIT

Ross Lagerwall (8):
  nestedsvm: Fix CR3 MBZ check
  nestedsvm: Adjust L2's DR intercept when adjusting L1
  nestedsvm: Use the correct VMCB for vGIF
  nestedsvm: Set GIF during VMRUN if vGIF is enabled
  tools/libxl: Add support for Viridian stimer direct mode
  x86/hvm: Clamp Viridian features to known set
  nestedsvm: Don't set VMCB(1-2)'s NP_ENABLE and N_CR3 during VMEXIT to
    L1
  x86/svm: Fix VMLOAD/VMSAVE state handling when using nested virt

Stephen Cheng (1):
  x86/svm: require VMSAVEvirt for nested virt

 docs/designs/nested-svm-cpu-features.md  |  11 +
 docs/man/xl.cfg.5.pod.in                 |   5 +
 tools/include/libxl.h                    |   6 +
 tools/libs/light/libxl_types.idl         |   1 +
 tools/libs/light/libxl_x86.c             |   5 +
 xen/arch/x86/cpu-policy.c                |   3 +-
 xen/arch/x86/hvm/hvm.c                   |   4 +-
 xen/arch/x86/hvm/svm/entry.S             |  48 +++-
 xen/arch/x86/hvm/svm/intr.c              |  22 +-
 xen/arch/x86/hvm/svm/nestedhvm.h         |   6 +-
 xen/arch/x86/hvm/svm/nestedsvm.c         | 305 +++++++++--------------
 xen/arch/x86/hvm/svm/svm.c               | 226 +++++++----------
 xen/arch/x86/hvm/svm/svm.h               |   2 -
 xen/arch/x86/hvm/svm/vmcb.c              |  32 +--
 xen/arch/x86/hvm/svm/vmcb.h              |   3 +-
 xen/arch/x86/include/asm/hvm/svm-types.h |   7 -
 xen/arch/x86/x86_64/asm-offsets.c        |   1 +
 17 files changed, 302 insertions(+), 385 deletions(-)

-- 
2.34.1




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.