[MODERATED] Re: ***UNCHECKED*** Re: NX, nested virtualization and arch caps

Joerg Roedel <[email protected]>
Newsgroups org.kernel.lore.historical-speck
Message-ID <[email protected]>
On Wed, Oct 16, 2019 at 10:15:07AM +0200, speck for Joerg Roedel wrote:
> I also think that any nested hypervisor can ignore the ITLB_MULTIHIT
> bug, but for a different reason: The host also builds the nested EPT
> table as a shadow of the guests EPT table, so it does the mitigation on
> behalf of the nested hypervisor.

Left out the case where host mitigation is disabled: I agree in this
case too with your reasoning, one should only disable the host
mitigation when the guests are trusted. And the guests are only trusted
when they only run trusted guests themselves.

By passing through the issue to the nested hypervisor we could support
untrusted nested guests on trusted guests with host mitigation disabled.
But this is probably not faster than enabling the mitigation on the host
because then KVM will trap/emulate all the guest EPT updates for
splitting/promoting hugepages.

Regards,

	Joerg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.