|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [PATCH] nestedsvm: Don't set VMCB(1-2)'s NP_ENABLE and N_CR3 during VMEXIT to L1
Le 18/09/2026 à 14:54, Ross Lagerwall a écrit : As per the VMRUN pseudocode in APM Vol 3 3.38, the VMCB's NP_ENABLE and N_CR3 fields are not set during a VMEXIT so don't do this when updating VMCB(1-2). At the same time, cleanup the somewhat bogus and irrelevant comments. Not clearing N_CR3 does not introduce a security hole as stated since L1 can set it regardless and it is never used directly when running L2. Signed-off-by: Ross Lagerwall <ross.lagerwall@xxxxxxxxxx> --- xen/arch/x86/hvm/svm/nestedsvm.c | 32 +------------------------------- 1 file changed, 1 insertion(+), 31 deletions(-) diff --git a/xen/arch/x86/hvm/svm/nestedsvm.c b/xen/arch/x86/hvm/svm/nestedsvm.c index a8b15d6eae05..c62fca571d75 100644 --- a/xen/arch/x86/hvm/svm/nestedsvm.c +++ b/xen/arch/x86/hvm/svm/nestedsvm.c @@ -1023,37 +1023,6 @@ nsvm_vmcb_prepare4vmexit(struct vcpu *v, struct cpu_user_regs *regs)ns_vmcb->event_inj.raw = 0; - /* Nested paging mode */ I would suggest to group all the CRn (the CR2 part is currently separated). That can be done separately. Reviewed-by: Teddy Astie <teddy.astie@xxxxxxxxxx> Teddy Attachment:
OpenPGP_signature.asc
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |