From: Jan Beulich <jbeulich@suse.com>
To: Ross Lagerwall <ross.lagerwall@citrix.com>
Cc: "Andrew Cooper" <andrew.cooper3@citrix.com>,
"Roger Pau Monné" <roger@xenproject.org>,
"Jason Andryuk" <jason.andryuk@amd.com>,
"Teddy Astie" <teddy.astie@vates.tech>,
xen-devel@lists.xenproject.org
Subject: Re: [PATCH v2] x86/svm: Intercept CR0 writes selectively
Date: Mon, 7 Sep 2026 14:24:50 +0200 [thread overview]
Message-ID: <c7c19c6e-e9d9-4941-868c-ad74815f1e6e@suse.com> (raw)
In-Reply-To: <20260904122330.306936-1-ross.lagerwall@citrix.com>
On 04.09.2026 14:23, Ross Lagerwall wrote:
> Since 3356d685dbda ("x86/svm: Remove lazy FPU support"), Xen does not
> need to track when the TS or MP bits change so opt to intercept CR0
> writes selectively. Aside from potentially reducing a few VMEXITs, this
> fixes a nested virt bug where L1 intercepts CR0_SEL_WRITE and L0
> intercepts CR0_WRITE. The hardware prioritizes CR0_WRITE and so L1 never
> sees any CR0 writes.
>
> Since CR0 may now change behind Xen's back, sync it on VMEXIT so that
> the emulator sees the correct value.
>
> Signed-off-by: Ross Lagerwall <ross.lagerwall@citrix.com>
Reviewed-by: Jan Beulich <jbeulich@suse.com>
with two remarks (which I may take the liberty of carrying out while
committing):
> --- a/xen/arch/x86/hvm/svm/vmcb.c
> +++ b/xen/arch/x86/hvm/svm/vmcb.c
> @@ -50,13 +50,13 @@ static int construct_vmcb(struct vcpu *v)
> struct vmcb_struct *vmcb = svm->vmcb;
>
> vmcb->_general1_intercepts =
> - GENERAL1_INTERCEPT_INTR | GENERAL1_INTERCEPT_NMI |
> - GENERAL1_INTERCEPT_SMI | GENERAL1_INTERCEPT_INIT |
> - GENERAL1_INTERCEPT_CPUID | GENERAL1_INTERCEPT_INVD |
> - GENERAL1_INTERCEPT_HLT | GENERAL1_INTERCEPT_INVLPG |
> - GENERAL1_INTERCEPT_INVLPGA | GENERAL1_INTERCEPT_IOIO_PROT |
> - GENERAL1_INTERCEPT_MSR_PROT | GENERAL1_INTERCEPT_SHUTDOWN_EVT|
> - GENERAL1_INTERCEPT_TASK_SWITCH;
> + GENERAL1_INTERCEPT_INTR | GENERAL1_INTERCEPT_NMI |
> + GENERAL1_INTERCEPT_SMI | GENERAL1_INTERCEPT_INIT |
> + GENERAL1_INTERCEPT_CR0_SEL_WRITE | GENERAL1_INTERCEPT_CPUID |
> + GENERAL1_INTERCEPT_INVD | GENERAL1_INTERCEPT_HLT |
> + GENERAL1_INTERCEPT_INVLPG | GENERAL1_INTERCEPT_INVLPGA |
> + GENERAL1_INTERCEPT_IOIO_PROT | GENERAL1_INTERCEPT_MSR_PROT |
> + GENERAL1_INTERCEPT_TASK_SWITCH | GENERAL1_INTERCEPT_SHUTDOWN_EVT;
I think it would be nice to avoid moving the |-s out, to keep ...
> vmcb->_general2_intercepts =
> GENERAL2_INTERCEPT_VMRUN | GENERAL2_INTERCEPT_VMMCALL |
> GENERAL2_INTERCEPT_VMLOAD | GENERAL2_INTERCEPT_VMSAVE |
... aligning with the ones here.
> @@ -76,8 +76,12 @@ static int construct_vmcb(struct vcpu *v)
> /* Intercept all debug-register writes. */
> vmcb->_dr_intercepts = ~0u;
>
> - /* Intercept all control-register accesses except for CR2 and CR8. */
> - vmcb->_cr_intercepts = ~(CR_INTERCEPT_CR2_READ |
> + /*
> + * Intercept all control-register accesses except for CR0 writes (use
> + * selective write instead), and CR2 and CR8 reads/writes.
> + */
Imo slightly more precise as "... (using selective write intercept instead) ..."
Jan
> + vmcb->_cr_intercepts = ~(CR_INTERCEPT_CR0_WRITE |
> + CR_INTERCEPT_CR2_READ |
> CR_INTERCEPT_CR2_WRITE |
> CR_INTERCEPT_CR8_READ |
> CR_INTERCEPT_CR8_WRITE);
next prev parent reply other threads:[~2026-09-07 12:25 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 12:23 [PATCH v2] x86/svm: Intercept CR0 writes selectively Ross Lagerwall
2026-09-07 12:24 ` Jan Beulich [this message]
2026-09-08 8:44 ` Jan Beulich
2026-09-08 13:57 ` Andrew Cooper
2026-09-08 14:09 ` Ross Lagerwall
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c7c19c6e-e9d9-4941-868c-ad74815f1e6e@suse.com \
--to=jbeulich@suse.com \
--cc=andrew.cooper3@citrix.com \
--cc=jason.andryuk@amd.com \
--cc=roger@xenproject.org \
--cc=ross.lagerwall@citrix.com \
--cc=teddy.astie@vates.tech \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.