• G
    KVM: nVMX: fix shadow on EPT · d0d538b9
    Gleb Natapov 提交于
    72f85795 broke shadow on EPT. This patch reverts it and fixes PAE
    on nEPT (which reverted commit fixed) in other way.
    
    Shadow on EPT is now broken because while L1 builds shadow page table
    for L2 (which is PAE while L2 is in real mode) it never loads L2's
    GUEST_PDPTR[0-3].  They do not need to be loaded because without nested
    virtualization HW does this during guest entry if EPT is disabled,
    but in our case L0 emulates L2's vmentry while EPT is enables, so we
    cannot rely on vmcs12->guest_pdptr[0-3] to contain up-to-date values
    and need to re-read PDPTEs from L2 memory. This is what kvm_set_cr3()
    is doing, but by clearing cache bits during L2 vmentry we drop values
    that kvm_set_cr3() read from memory.
    
    So why the same code does not work for PAE on nEPT? kvm_set_cr3()
    reads pdptes into vcpu->arch.walk_mmu->pdptrs[]. walk_mmu points to
    vcpu->arch.nested_mmu while nested guest is running, but ept_load_pdptrs()
    uses vcpu->arch.mmu which contain incorrect values. Fix that by using
    walk_mmu in ept_(load|save)_pdptrs.
    Signed-off-by: NGleb Natapov <gleb@redhat.com>
    Reviewed-by: NPaolo Bonzini <pbonzini@redhat.com>
    Tested-by: NPaolo Bonzini <pbonzini@redhat.com>
    Signed-off-by: NPaolo Bonzini <pbonzini@redhat.com>
    d0d538b9
vmx.c 243.8 KB