[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v2 08/13] nestedsvm: Don't set VMCB(1-2)'s NP_ENABLE and N_CR3 during VMEXIT to L1


  • To: xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: chunjie.zhu@xxxxxxxxxx
  • Date: Sat, 10 Oct 2026 18:13:21 +0800
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com; dkim=pass header.d=citrix.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=oexZirZAMZNzftk6MpNV1/OYjX520+aEwGhwJ24lOgU=; b=mh1xm3/VzX2QCemhXNqWCv8ZBX8ar11CxpTbp/Xn88tbvV02sMMMpH85Je3gmr5qr1RzsRCkCIlKeuHn+BjiadCYWHPnFm6juzaiqgVGjVagJ/5STcZBO9UKHCpG3mIkrXgvfAFYsx205FXIxcsNQZJCDTcNCdpGDzwBwgHLsGyxQFVx/p5Vo0JQNu9QaWqDnQE/ibxRdm4t8Hi339EDTOaa4LnKfSxwT0UmiFJzB+C2r+PBX8V5dZL+2YKjJLD4hxFNR9WAa5KrbkEFbbdmvPk2H37enxClvJ1DNOOon7TfVkKdylRsgLU2k9uWLXu7HNQpnniJC+fWL8nEH3CDng==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=rikAVu81sc8AypQ/GgomOr8zPltWuy0Nx9J0dDCULqFTcagxleBO3BMVNa0qYOmd7TWdRhl+xhEQphkt81cSgFR0s/If5X3oCPzvWQ0uloerqG/IhetJU3diS7VVUcQAmHagZhnhptXJye5qBdqte4He0SalNosncQNH7Xmf2R18jK3oRieHnNLIt+tcL6ryX0w5wDSLqX4lHZ1J6tXLqkIDgrUoYetKyOl/YAcbeWfFm/RPfxpjWGl/yDo4lKH/tFvNnzuNr4u17vssrRKJ2F5AVUIo1ffitr21qZm1NmqzsihpV0WgcZOryreJH179El0B/Kln4FXVl81Cn54GXA==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=citrix.com header.i="@citrix.com" header.h="From:Date:Subject:Message-Id:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=citrix.com;
  • Cc: ross.lagerwall@xxxxxxxxxx, jbeulich@xxxxxxxx, andrew.cooper3@xxxxxxxxxx, roger@xxxxxxxxxxxxxx, jason.andryuk@xxxxxxx, teddy.astie@xxxxxxxxxx, stephen.cheng@xxxxxxxxxx, lin.liu01@xxxxxxxxxx
  • Delivery-date: Sat, 10 Oct 2026 10:15:50 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

From: Ross Lagerwall <ross.lagerwall@xxxxxxxxxx>

As per the VMRUN pseudocode in APM Vol 3 3.38, the VMCB's NP_ENABLE and
N_CR3 fields are not set during a VMEXIT so don't do this when updating
VMCB(1-2). At the same time, cleanup the somewhat bogus and irrelevant
comments. Not clearing N_CR3 does not introduce a security hole as
stated since L1 can set it regardless and it is never used directly when
running L2.

Signed-off-by: Ross Lagerwall <ross.lagerwall@xxxxxxxxxx>
---
 xen/arch/x86/hvm/svm/nestedsvm.c | 36 +++-----------------------------
 1 file changed, 3 insertions(+), 33 deletions(-)

diff --git a/xen/arch/x86/hvm/svm/nestedsvm.c b/xen/arch/x86/hvm/svm/nestedsvm.c
index 79242bdd9117..d47e57c8a1d7 100644
--- a/xen/arch/x86/hvm/svm/nestedsvm.c
+++ b/xen/arch/x86/hvm/svm/nestedsvm.c
@@ -1031,37 +1031,6 @@ nsvm_vmcb_prepare4vmexit(struct vcpu *v, struct 
cpu_user_regs *regs)
 
     ns_vmcb->event_inj.raw = 0;
 
-    /* Nested paging mode */
-    if ( nestedhvm_paging_mode_hap(v) )
-    {
-        /* host nested paging + guest nested paging. */
-        vmcb_set_np(ns_vmcb, vmcb_get_np(n2vmcb));
-        ns_vmcb->_cr3 = n2vmcb->_cr3;
-        /* The vmcb->h_cr3 is the shadowed h_cr3. The original
-         * unshadowed guest h_cr3 is kept in ns_vmcb->h_cr3,
-         * hence we keep the ns_vmcb->h_cr3 value. */
-    }
-    else if ( !paging_mode_shadow(v->domain) )
-    {
-        /* host nested paging + guest shadow paging. */
-        vmcb_set_np(ns_vmcb, false);
-        /* Throw h_cr3 away. Guest is not allowed to set it or
-         * it can break out, otherwise (security hole!) */
-        ns_vmcb->_h_cr3 = 0x0;
-        /* Stop intercepting #PF (already done above
-         * by restoring cached intercepts). */
-        ns_vmcb->_cr3 = n2vmcb->_cr3;
-    }
-    else
-    {
-        /* host shadow paging + guest shadow paging. */
-        vmcb_set_np(ns_vmcb, false);
-        ns_vmcb->_h_cr3 = 0x0;
-        /* The vmcb->_cr3 is the shadowed cr3. The original
-         * unshadowed guest cr3 is kept in ns_vmcb->_cr3,
-         * hence we keep the ns_vmcb->_cr3 value. */
-    }
-
     /* LBR virtualization - keep lbr control as is */
 
     /* NextRIP */
@@ -1090,8 +1059,9 @@ nsvm_vmcb_prepare4vmexit(struct vcpu *v, struct 
cpu_user_regs *regs)
     ns_vmcb->_efer = v->arch.hvm.guest_efer;
 
     /* CRn */
-    ns_vmcb->_cr4 = v->arch.hvm.guest_cr[4];
-    ns_vmcb->_cr0 = v->arch.hvm.guest_cr[0];
+    ns_vmcb->_cr4 = n2vmcb->_cr4;
+    ns_vmcb->_cr3 = n2vmcb->_cr3;
+    ns_vmcb->_cr0 = n2vmcb->_cr0;
 
     /* DRn */
     ns_vmcb->_dr7 = n2vmcb->_dr7;
-- 
2.34.1




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.