[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH] x86/nSVM: Save L2's CR4 on #VMEXIT, not Xen's


  • To: Jan Beulich <jbeulich@xxxxxxxx>, Lin Liu <lin.liu01@xxxxxxxxxx>
  • From: Ross Lagerwall <ross.lagerwall@xxxxxxxxxx>
  • Date: Thu, 24 Sep 2026 16:50:33 +0100
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com; dkim=pass header.d=citrix.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=bnzNbHNp3VyIXb7hkxTft/FfzXATib4lEj8daziz1rw=; b=hjVHE9Qkpui9bI3cajPD6oTQ7jDpC/bb+kxDh2XOhpR52YfKx6vzkLNVBxZ0Fy69PXQ8L+u3nnB6T7BRtwseKdDzxcEbsSZ3xzHUhWzzZeKLQ+jiFI+SmzCtOXY1ho4abmyZ1mrV2thWyH1Peu60l0SDgfMb3jS9mU20EJySn0HCUgfs4fUUOacP2ppg3jgu8rbwny8JzMfglXv020Qzrall5dNIsP775WEeQK39yTw7Q/6gNqEGXq60xOvTWhWNF1Ot9S7Jjd183aEzIbcAJ8+tEZsrNihref8uVUN+pzcdPVRv132GD5mCylpzXlMrbOrLD8Z/ylo2JNiVEmu+IA==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=yFVC4DQMltpsRL4PzN6oDDwsXU4OIeWyg8kYPPKA+ETbJyunoNpZjnPmkPC2pkVwa+8cuEcL6OgvM29axdkA7FBGV7YGyNU3rW13WX278of/LtLNiF/ETjXXUeYoR6B6mB0pTRE/uMlk1kG1Fh8YZ8Yff/8zoXDi550lbCT6XdIKjiYOrr0M5OfArHmZ2LTtkeTjtWfuGO2gwktYAt5ItURZ4rGYT5gB3tGEJAlPqjg0yLZsrdc077pcmMzOeCXngZ+Fr2gBG4hKsla6q3GhUziBKEUF+qIlAx/jo3H/KdsdEZBiS+Z0f0O9HM9Zh0RmERY2E7HrkgJrRRc/OP78aw==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=citrix.com header.i="@citrix.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=citrix.com;
  • Cc: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>, Jason Andryuk <jason.andryuk@xxxxxxx>, Teddy Astie <teddy.astie@xxxxxxxxxx>, xen-devel@xxxxxxxxxxxxxxxxxxxx
  • Delivery-date: Thu, 24 Sep 2026 15:50:47 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

On 9/24/26 4:01 PM, Jan Beulich wrote:
On 23.09.2026 13:16, Ross Lagerwall wrote:
On 9/23/26 10:51 AM, Lin Liu wrote:
Xen leaks the host's CR4 bits to L1.

nsvm_vmcb_prepare4vmrun() constructs the shadow VMCB's CR4 via
hvm_set_cr4(), and svm_update_guest_cr() ORs in HVM_CR4_HOST_MASK.
nsvm_vmcb_prepare4vmexit() then copies CR4 back out of the shadow VMCB
instead of the value kept in v->arch.hvm.guest_cr[4], so L1 reads back
Xen's bits - under HAP, CR4.MCE.

Fixes: 9a779e4fc161 ("Implement SVM specific part for Nested Virtualization")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Lin Liu <lin.liu01@xxxxxxxxxx>
---
   xen/arch/x86/hvm/svm/nestedsvm.c | 2 +-
   1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/xen/arch/x86/hvm/svm/nestedsvm.c b/xen/arch/x86/hvm/svm/nestedsvm.c
index a8b15d6eae..8d99b0affc 100644
--- a/xen/arch/x86/hvm/svm/nestedsvm.c
+++ b/xen/arch/x86/hvm/svm/nestedsvm.c
@@ -1082,7 +1082,7 @@ nsvm_vmcb_prepare4vmexit(struct vcpu *v, struct 
cpu_user_regs *regs)
       ns_vmcb->_efer = n2vmcb->_efer;
/* CRn */
-    ns_vmcb->_cr4 = n2vmcb->_cr4;
+    ns_vmcb->_cr4 = v->arch.hvm.guest_cr[4];
       ns_vmcb->_cr0 = n2vmcb->_cr0;
/* DRn */

Reviewed-by: Ross Lagerwall <ross.lagerwall@xxxxxxxxxx>

Did you consider addressing similar issues with the other state copied from
n2vmcb as well? i.e. I think something similar would apply to CR0, EFER, etc.

But (assuming the above code change is indeed correct) wouldn't we better deal
with CR0 then right away, rather that leaving things even visually inconsistent?

That's up to the maintainers to decide, though given the state of the Nested
SVM code at the moment IMO it is fine to take valid improvements and make some
forward progress even if they don't address all the related issues at once.

Ross



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.