[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v2] x86/svm: Intercept CR0 writes selectively


  • To: xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: Ross Lagerwall <ross.lagerwall@xxxxxxxxxx>
  • Date: Fri, 4 Sep 2026 13:23:30 +0100
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com; dkim=pass header.d=citrix.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=4y200znicxFhtMBf6+UXpmow9OhWujlHMUqpd7k5kz0=; b=D1oX7EYwjGOlUEeMNnX2yu8MpwkYkznWdRvwjjlJ2C4cbb9uWK52O/gOBw5q+pCREie9d7LqVml6ImfKxbFrCCNcb+bTQFptL1spSD0dFB3Rgc+b/H9BxBVaPLk2lTqTTuikuyALI1lHAV1gP8KmH9r2d+hXYcSrv1xhxV+84k/lK7zwNt37cfIri30G6kkcEyaXTkv869iLi6TTFRBkq7McGlQbF7BZIfxKR8AmHQjgTOA+rG7c2u46f4VjkVQZnlNImwedhFKCDlCZcfY5nQeeLSJqOmel/Zp06Q38vTzc26HIwS5ENsBykFCWUChAkOQy9X622HImptbsc1L9OQ==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=eAEyNIF36GAao7yiNM5UBaR9BNUlcS0+YrlkWpaE+2caj9pB10pG+1rxNKacvpCY7wy9pwsfkFLhk1BqLqD6ycdsfrWsMz9WS+qVjjd+k5dhxF7Hn6WUvt9sB9ohr+Ihx1UNwR5sMexc/jmoMpX2mOmV3jDd4+aiJ08LUs1cfN6XdbVEKAS+uaDnEFAWietCwLgB9Vq+TH4KZKK9nr3DNEW7/n8cFyOmS5h+kclNw6fWAYWyu1FCdrgqFowji1za1XjcyeX7jDbZTBaKidu/IqSe9gffFLQVbHnnNwlbl2NNIpCca56dVO4V9Drk74C502bofrzsS/Ju/Zi2+M6uFA==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=citrix.com header.i="@citrix.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=citrix.com;
  • Cc: Ross Lagerwall <ross.lagerwall@xxxxxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>, Jason Andryuk <jason.andryuk@xxxxxxx>, Teddy Astie <teddy.astie@xxxxxxxxxx>
  • Delivery-date: Fri, 04 Sep 2026 12:23:46 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

Since 3356d685dbda ("x86/svm: Remove lazy FPU support"), Xen does not
need to track when the TS or MP bits change so opt to intercept CR0
writes selectively. Aside from potentially reducing a few VMEXITs, this
fixes a nested virt bug where L1 intercepts CR0_SEL_WRITE and L0
intercepts CR0_WRITE. The hardware prioritizes CR0_WRITE and so L1 never
sees any CR0 writes.

Since CR0 may now change behind Xen's back, sync it on VMEXIT so that
the emulator sees the correct value.

Signed-off-by: Ross Lagerwall <ross.lagerwall@xxxxxxxxxx>
---

In v2:
* Keep case VMEXIT_CR0_WRITE for consistency with other not-intercepted
  CRx VMEXITs.
* Tweak commit message, comments, and formatting.

 xen/arch/x86/hvm/svm/svm.c  |  5 ++++-
 xen/arch/x86/hvm/svm/vmcb.c | 22 +++++++++++++---------
 2 files changed, 17 insertions(+), 10 deletions(-)

diff --git a/xen/arch/x86/hvm/svm/svm.c b/xen/arch/x86/hvm/svm/svm.c
index 5f5d903d872d..ddc35e31506e 100644
--- a/xen/arch/x86/hvm/svm/svm.c
+++ b/xen/arch/x86/hvm/svm/svm.c
@@ -1640,7 +1640,8 @@ static void svm_vmexit_do_cr_access(
 {
     int gp, cr, dir, rc;
 
-    cr = vmcb->exitcode - VMEXIT_CR0_READ;
+    cr = (vmcb->exitcode == VMEXIT_CR0_SEL_WRITE)
+         ? 16 : (vmcb->exitcode - VMEXIT_CR0_READ);
     dir = (cr > 15);
     cr &= 0xf;
     gp = vmcb->ei.mov_cr.gpr;
@@ -2517,6 +2518,7 @@ void asmlinkage svm_vmexit_handler(void)
     hvm_sanitize_regs_fields(
         regs, !(vmcb_get_efer(vmcb) & EFER_LMA) || !(vmcb->cs.l));
 
+    v->arch.hvm.guest_cr[0] = vmcb_get_cr0(vmcb);
     v->arch.hvm.guest_cr[2] = vmcb_get_cr2(vmcb);
     if ( paging_mode_hap(v->domain) )
         v->arch.hvm.guest_cr[3] = v->arch.hvm.hw_cr[3] = vmcb_get_cr3(vmcb);
@@ -2883,6 +2885,7 @@ void asmlinkage svm_vmexit_handler(void)
 
     case VMEXIT_CR0_READ ... VMEXIT_CR15_READ:
     case VMEXIT_CR0_WRITE ... VMEXIT_CR15_WRITE:
+    case VMEXIT_CR0_SEL_WRITE:
         if ( cpu_has_svm_decode && vmcb->ei.mov_cr.mov_insn )
             svm_vmexit_do_cr_access(vmcb, regs);
         else if ( !hvm_emulate_one_insn(x86_insn_is_cr_access, "CR access") )
diff --git a/xen/arch/x86/hvm/svm/vmcb.c b/xen/arch/x86/hvm/svm/vmcb.c
index 975a1eaef806..f7e86c68b521 100644
--- a/xen/arch/x86/hvm/svm/vmcb.c
+++ b/xen/arch/x86/hvm/svm/vmcb.c
@@ -50,13 +50,13 @@ static int construct_vmcb(struct vcpu *v)
     struct vmcb_struct *vmcb = svm->vmcb;
 
     vmcb->_general1_intercepts =
-        GENERAL1_INTERCEPT_INTR        | GENERAL1_INTERCEPT_NMI         |
-        GENERAL1_INTERCEPT_SMI         | GENERAL1_INTERCEPT_INIT        |
-        GENERAL1_INTERCEPT_CPUID       | GENERAL1_INTERCEPT_INVD        |
-        GENERAL1_INTERCEPT_HLT         | GENERAL1_INTERCEPT_INVLPG      |
-        GENERAL1_INTERCEPT_INVLPGA     | GENERAL1_INTERCEPT_IOIO_PROT   |
-        GENERAL1_INTERCEPT_MSR_PROT    | GENERAL1_INTERCEPT_SHUTDOWN_EVT|
-        GENERAL1_INTERCEPT_TASK_SWITCH;
+        GENERAL1_INTERCEPT_INTR          | GENERAL1_INTERCEPT_NMI           |
+        GENERAL1_INTERCEPT_SMI           | GENERAL1_INTERCEPT_INIT          |
+        GENERAL1_INTERCEPT_CR0_SEL_WRITE | GENERAL1_INTERCEPT_CPUID         |
+        GENERAL1_INTERCEPT_INVD          | GENERAL1_INTERCEPT_HLT           |
+        GENERAL1_INTERCEPT_INVLPG        | GENERAL1_INTERCEPT_INVLPGA       |
+        GENERAL1_INTERCEPT_IOIO_PROT     | GENERAL1_INTERCEPT_MSR_PROT      |
+        GENERAL1_INTERCEPT_TASK_SWITCH   | GENERAL1_INTERCEPT_SHUTDOWN_EVT;
     vmcb->_general2_intercepts =
         GENERAL2_INTERCEPT_VMRUN       | GENERAL2_INTERCEPT_VMMCALL     |
         GENERAL2_INTERCEPT_VMLOAD      | GENERAL2_INTERCEPT_VMSAVE      |
@@ -76,8 +76,12 @@ static int construct_vmcb(struct vcpu *v)
     /* Intercept all debug-register writes. */
     vmcb->_dr_intercepts = ~0u;
 
-    /* Intercept all control-register accesses except for CR2 and CR8. */
-    vmcb->_cr_intercepts = ~(CR_INTERCEPT_CR2_READ |
+    /*
+     * Intercept all control-register accesses except for CR0 writes (use
+     * selective write instead), and CR2 and CR8 reads/writes.
+     */
+    vmcb->_cr_intercepts = ~(CR_INTERCEPT_CR0_WRITE |
+                             CR_INTERCEPT_CR2_READ |
                              CR_INTERCEPT_CR2_WRITE |
                              CR_INTERCEPT_CR8_READ |
                              CR_INTERCEPT_CR8_WRITE);
-- 
2.53.0




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.