|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [PATCH v2 08/13] nestedsvm: Don't set VMCB(1-2)'s NP_ENABLE and N_CR3 during VMEXIT to L1
From: Ross Lagerwall <ross.lagerwall@xxxxxxxxxx>
As per the VMRUN pseudocode in APM Vol 3 3.38, the VMCB's NP_ENABLE and
N_CR3 fields are not set during a VMEXIT so don't do this when updating
VMCB(1-2). At the same time, cleanup the somewhat bogus and irrelevant
comments. Not clearing N_CR3 does not introduce a security hole as
stated since L1 can set it regardless and it is never used directly when
running L2.
Signed-off-by: Ross Lagerwall <ross.lagerwall@xxxxxxxxxx>
---
xen/arch/x86/hvm/svm/nestedsvm.c | 36 +++-----------------------------
1 file changed, 3 insertions(+), 33 deletions(-)
diff --git a/xen/arch/x86/hvm/svm/nestedsvm.c b/xen/arch/x86/hvm/svm/nestedsvm.c
index 79242bdd9117..d47e57c8a1d7 100644
--- a/xen/arch/x86/hvm/svm/nestedsvm.c
+++ b/xen/arch/x86/hvm/svm/nestedsvm.c
@@ -1031,37 +1031,6 @@ nsvm_vmcb_prepare4vmexit(struct vcpu *v, struct
cpu_user_regs *regs)
ns_vmcb->event_inj.raw = 0;
- /* Nested paging mode */
- if ( nestedhvm_paging_mode_hap(v) )
- {
- /* host nested paging + guest nested paging. */
- vmcb_set_np(ns_vmcb, vmcb_get_np(n2vmcb));
- ns_vmcb->_cr3 = n2vmcb->_cr3;
- /* The vmcb->h_cr3 is the shadowed h_cr3. The original
- * unshadowed guest h_cr3 is kept in ns_vmcb->h_cr3,
- * hence we keep the ns_vmcb->h_cr3 value. */
- }
- else if ( !paging_mode_shadow(v->domain) )
- {
- /* host nested paging + guest shadow paging. */
- vmcb_set_np(ns_vmcb, false);
- /* Throw h_cr3 away. Guest is not allowed to set it or
- * it can break out, otherwise (security hole!) */
- ns_vmcb->_h_cr3 = 0x0;
- /* Stop intercepting #PF (already done above
- * by restoring cached intercepts). */
- ns_vmcb->_cr3 = n2vmcb->_cr3;
- }
- else
- {
- /* host shadow paging + guest shadow paging. */
- vmcb_set_np(ns_vmcb, false);
- ns_vmcb->_h_cr3 = 0x0;
- /* The vmcb->_cr3 is the shadowed cr3. The original
- * unshadowed guest cr3 is kept in ns_vmcb->_cr3,
- * hence we keep the ns_vmcb->_cr3 value. */
- }
-
/* LBR virtualization - keep lbr control as is */
/* NextRIP */
@@ -1090,8 +1059,9 @@ nsvm_vmcb_prepare4vmexit(struct vcpu *v, struct
cpu_user_regs *regs)
ns_vmcb->_efer = v->arch.hvm.guest_efer;
/* CRn */
- ns_vmcb->_cr4 = v->arch.hvm.guest_cr[4];
- ns_vmcb->_cr0 = v->arch.hvm.guest_cr[0];
+ ns_vmcb->_cr4 = n2vmcb->_cr4;
+ ns_vmcb->_cr3 = n2vmcb->_cr3;
+ ns_vmcb->_cr0 = n2vmcb->_cr0;
/* DRn */
ns_vmcb->_dr7 = n2vmcb->_dr7;
--
2.34.1
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |