[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v1 5/5] x86/nestedsvm: fix up


  • To: xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: chunjie.zhu@xxxxxxxxxx
  • Date: Wed, 23 Sep 2026 17:20:45 +0800
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com; dkim=pass header.d=citrix.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=qQtCMr71u/dFmTTBykUGImfeS0Mu9gUyzujoZ62TAUA=; b=G7th76gRGCPrDB8N7wul0NfMb9oB+7EHcZg/hOcqN5dTJ70IF7EG1uNGs4pVmW3aO8QQiET/pWTfeSj3QGYEZhDGJeTYi8JKDd1SqqsYAIJ52a3Q8uVXkRzI4bNXxXnjqtIRJhJI/B/K/w2Az7M8M5JNsaPGeVLdVl9OmAAjwjD1H8neOYL4cqcPMqcSQu+C9zFfgOoFI52RkHnIBK7LiALTKX5DL5VJ/aNQp7vc3ZN0JQ49oFA+8JYMOmCS/LL3g2DxpwEPVsc8IeouHLXNN8o6mjmcSTi7b2x24VQ1A38q3anv/9FhdvFkt97xEaPnQwkwAhO8XCt+/PJPu+s7OA==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=HI5bySuzJHbhGWoESuQoIz6iLJP9PmdB0Y31zwgAtfInKoOY54Rs3kimHRW1Wb77kWHv4rabJGWZ7ZquhgK42Pnl9ouiJ8s/EqXhIXyyiNLt2zd3tPkpfP9JE1IsGAkdwGkzoKlGv7G+AfnjzTK+qFZymrOxsMUDU+Y0JlRfx/WwXS8UJsdyR0948/DPId0M1OcilS7huIQjmSMQthdRttUtTSWLvqIYx+kdHPswdWcnQlTj3HF8gIE/v/HOTmdhydOs1iBalQcpxmKcJgw23CAdh2sW1xdeEp16aM7rfZBxk/rl5BlEbXbKy57ftQ6MY1WyZevdN+yfG7DgxVFC7w==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=citrix.com header.i="@citrix.com" header.h="From:Date:Subject:Message-Id:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=citrix.com;
  • Cc: jbeulich@xxxxxxxx, andrew.cooper3@xxxxxxxxxx, roger@xxxxxxxxxxxxxx, jason.andryuk@xxxxxxx, teddy.astie@xxxxxxxxxx, Chunjie Zhu <chunjie.zhu@xxxxxxxxxx>
  • Delivery-date: Wed, 23 Sep 2026 09:21:48 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

From: Chunjie Zhu <chunjie.zhu@xxxxxxxxxx>

Signed-off-by: Chunjie Zhu <chunjie.zhu@xxxxxxxxxx>
---
 xen/arch/x86/hvm/svm/nestedsvm.c | 19 ++++++++++++++++---
 xen/arch/x86/hvm/svm/vmcb.c      |  9 +++++----
 xen/arch/x86/mm/p2m.c            |  5 +++++
 3 files changed, 26 insertions(+), 7 deletions(-)

diff --git a/xen/arch/x86/hvm/svm/nestedsvm.c b/xen/arch/x86/hvm/svm/nestedsvm.c
index 82e01e513e69..91872af8aa7b 100644
--- a/xen/arch/x86/hvm/svm/nestedsvm.c
+++ b/xen/arch/x86/hvm/svm/nestedsvm.c
@@ -355,7 +355,7 @@ static void nestedsvm_vmcb_set_nestedp2m(struct vcpu *v,
     vcpu_nestedsvm(v).ns_vmcb_hostcr3 = vvmcb->_h_cr3;
 
     p2m = p2m_get_nestedp2m(v);
-    n2vmcb->_h_cr3 = pagetable_get_paddr(p2m_get_pagetable(p2m));
+    vmcb_set_h_cr3(n2vmcb, pagetable_get_paddr(p2m_get_pagetable(p2m)));
 }
 
 void nsvm_vcpu_update_nestedp2m(struct vcpu *v)
@@ -373,6 +373,7 @@ void nsvm_vcpu_update_nestedp2m(struct vcpu *v)
         return;
 
     p2m = p2m_get_nestedp2m(v);
+    nv->stale_np2m = false;
 
     /*
      * This may happen if we've handled VMEXIT_NPF at the same time as a
@@ -383,8 +384,6 @@ void nsvm_vcpu_update_nestedp2m(struct vcpu *v)
          vmcb_get_h_cr3(nv->nv_n2vmcx) !=
          pagetable_get_paddr(p2m_get_pagetable(p2m)) )
         nestedsvm_vmcb_set_nestedp2m(v, nv->nv_vvmcx, nv->nv_n2vmcx);
-
-    nv->stale_np2m = false;
 }
 
 static int nsvm_vmcb_prepare4vmrun(struct vcpu *v, struct cpu_user_regs *regs)
@@ -1024,6 +1023,20 @@ nsvm_vmcb_prepare4vmexit(struct vcpu *v, struct 
cpu_user_regs *regs)
     struct vmcb_struct *ns_vmcb = nv->nv_vvmcx;
     struct vmcb_struct *n2vmcb = nv->nv_n2vmcx;
 
+    ASSERT(v == current);
+
+    /*
+     * The physical VMCB fields covered by VMSAVE/VMLOAD may not be in sync
+     * with v's vmcb if a context switch happened since the last VMLOAD.
+     * VMSAVE below would otherwise capture stale/foreign register state
+     * into the L1 shadow VMCB.
+     */
+    if ( v->arch.hvm.svm.vmcb_sync_state == vmcb_needs_vmload )
+    {
+        svm_vmload_pa(v->arch.hvm.svm.vmcb_pa);
+        v->arch.hvm.svm.vmcb_sync_state = vmcb_in_sync;
+    }
+
     svm_vmsave_pa(nv->nv_n1vmcx_pa);
 
     /* Cache guest physical address of virtual vmcb
diff --git a/xen/arch/x86/hvm/svm/vmcb.c b/xen/arch/x86/hvm/svm/vmcb.c
index 5354c4f1b85f..2f7053ed7eec 100644
--- a/xen/arch/x86/hvm/svm/vmcb.c
+++ b/xen/arch/x86/hvm/svm/vmcb.c
@@ -357,10 +357,11 @@ bool svm_vmcb_isvalid(
         PRINTF("CR0: bits [63:32] are not zero (%#"PRIx64")\n", cr0);
 
     if ( (cr0 & X86_CR0_PG) &&
-         ((cr3 & 7) ||
-          ((!(cr4 & X86_CR4_PAE) || (efer & EFER_LMA)) && (cr3 & 0xfe0)) ||
-          ((efer & EFER_LMA) &&
-           (cr3 >> v->domain->arch.cpuid->extd.maxphysaddr))) )
+         ((!(cr4 & X86_CR4_PCIDE) &&
+           ((cr3 & 7) ||
+            ((!(cr4 & X86_CR4_PAE) || (efer & EFER_LMA)) &&
+             (cr3 & 0xfe0)))) ||
+          (cr3 >> v->domain->arch.cpuid->extd.maxphysaddr)) )
         PRINTF("CR3: MBZ bits are set (%#"PRIx64")\n", cr3);
 
     valid = hvm_cr4_guest_valid_bits(v->domain);
diff --git a/xen/arch/x86/mm/p2m.c b/xen/arch/x86/mm/p2m.c
index 027b9ae69be3..d1fafc479c78 100644
--- a/xen/arch/x86/mm/p2m.c
+++ b/xen/arch/x86/mm/p2m.c
@@ -1517,7 +1517,12 @@ p2m_get_nestedp2m_locked(struct vcpu *v)
     np2m_base &= ~(0xfffULL);
 
     if ( nv->nv_flushp2m && nv->nv_p2m )
+    {
+        p2m = nv->nv_p2m;
+        if ( p2m )
+            p2m_flush_table(p2m);
         nv->nv_p2m = NULL;
+    }
 
     nestedp2m_lock(d);
     p2m = nv->nv_p2m;
-- 
2.34.1




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.