KVM: Disable SMAP for guests in EPT realmode and EPT unpaging mode
SMAP is disabled if CPU is in non-paging mode in hardware. However KVM always uses paging mode to emulate guest non-paging mode with TDP. To emulate this behavior, SMAP needs to be manually disabled when guest switches to non-paging mode. Signed-off-by: Feng Wu <feng.wu@intel.com> Signed-off-by: Marcelo Tosatti <mtosatti@redhat.com>
This commit is contained in:
parent
97ec8c067d
commit
e1e746b3c5
1 changed files with 6 additions and 5 deletions
|
@ -3484,13 +3484,14 @@ static int vmx_set_cr4(struct kvm_vcpu *vcpu, unsigned long cr4)
|
||||||
hw_cr4 &= ~X86_CR4_PAE;
|
hw_cr4 &= ~X86_CR4_PAE;
|
||||||
hw_cr4 |= X86_CR4_PSE;
|
hw_cr4 |= X86_CR4_PSE;
|
||||||
/*
|
/*
|
||||||
* SMEP is disabled if CPU is in non-paging mode in
|
* SMEP/SMAP is disabled if CPU is in non-paging mode
|
||||||
* hardware. However KVM always uses paging mode to
|
* in hardware. However KVM always uses paging mode to
|
||||||
* emulate guest non-paging mode with TDP.
|
* emulate guest non-paging mode with TDP.
|
||||||
* To emulate this behavior, SMEP needs to be manually
|
* To emulate this behavior, SMEP/SMAP needs to be
|
||||||
* disabled when guest switches to non-paging mode.
|
* manually disabled when guest switches to non-paging
|
||||||
|
* mode.
|
||||||
*/
|
*/
|
||||||
hw_cr4 &= ~X86_CR4_SMEP;
|
hw_cr4 &= ~(X86_CR4_SMEP | X86_CR4_SMAP);
|
||||||
} else if (!(cr4 & X86_CR4_PAE)) {
|
} else if (!(cr4 & X86_CR4_PAE)) {
|
||||||
hw_cr4 &= ~X86_CR4_PAE;
|
hw_cr4 &= ~X86_CR4_PAE;
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in a new issue