From: Jon Kohler <jon@nutanix.com>
To: seanjc@google.com, pbonzini@redhat.com, tglx@linutronix.de,
mingo@redhat.com, bp@alien8.de, dave.hansen@linux.intel.com,
x86@kernel.org, hpa@zytor.com, kvm@vger.kernel.org,
linux-kernel@vger.kernel.org
Cc: ken@codelabs.ch, Alexander.Grest@microsoft.com,
chao.gao@intel.com, madvenka@linux.microsoft.com,
mic@digikod.net, nsaenz@amazon.es, tao1.su@linux.intel.com,
xiaoyao.li@intel.com, zhao1.liu@intel.com,
Jon Kohler <jon@nutanix.com>
Subject: [PATCH 7/8] KVM: VMX: allow MBEC with EVMCS
Date: Mon, 22 Dec 2025 22:48:00 -0700 [thread overview]
Message-ID: <20251223054806.1611168-8-jon@nutanix.com> (raw)
In-Reply-To: <20251223054806.1611168-1-jon@nutanix.com>
Extend EVMCS1_SUPPORTED_2NDEXEC to allow MBEC and EVMCS to coexist.
Presenting both EVMCS and MBEC simultaneously causes KVM to filter out
MBEC and not present it as a supported control to the guest, preventing
performance gains from MBEC when Windows HVCI is enabled.
The guest may choose not to use MBEC (e.g., if the admin does not enable
Windows HVCI / Memory Integrity), but if they use traditional nested
virt (Hyper-V, WSL2, etc.), having EVMCS exposed is important for
improving nested guest performance. IOW allowing MBEC and EVMCS to
coexist provides maximum optionality to Windows users without
overcomplicating VM administration.
Signed-off-by: Jon Kohler <jon@nutanix.com>
---
arch/x86/kvm/vmx/hyperv_evmcs.h | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/x86/kvm/vmx/hyperv_evmcs.h b/arch/x86/kvm/vmx/hyperv_evmcs.h
index 6536290f4274..0568f76aafc1 100644
--- a/arch/x86/kvm/vmx/hyperv_evmcs.h
+++ b/arch/x86/kvm/vmx/hyperv_evmcs.h
@@ -87,6 +87,7 @@
SECONDARY_EXEC_PT_CONCEAL_VMX | \
SECONDARY_EXEC_BUS_LOCK_DETECTION | \
SECONDARY_EXEC_NOTIFY_VM_EXITING | \
+ SECONDARY_EXEC_MODE_BASED_EPT_EXEC | \
SECONDARY_EXEC_ENCLS_EXITING)
#define EVMCS1_SUPPORTED_3RDEXEC (0ULL)
--
2.43.0
next prev parent reply other threads:[~2025-12-23 5:05 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-12-23 5:47 [PATCH 0/8] KVM: VMX: Introduce Intel Mode-Based Execute Control (MBEC) Jon Kohler
2025-12-23 5:47 ` [PATCH 1/8] KVM: TDX/VMX: rework EPT_VIOLATION_EXEC_FOR_RING3_LIN into PROT_MASK Jon Kohler
2025-12-23 5:47 ` [PATCH 2/8] KVM: x86/mmu: remove SPTE_PERM_MASK Jon Kohler
2025-12-23 5:47 ` [PATCH 3/8] KVM: x86/mmu: adjust MMIO generation bit allocation and allowed mask Jon Kohler
2025-12-23 5:47 ` [PATCH 4/8] KVM: x86/mmu: update access permissions from ACC_ALL to ACC_RWX Jon Kohler
2025-12-23 5:47 ` [PATCH 5/8] KVM: x86/mmu: bootstrap support for Intel MBEC Jon Kohler
2026-03-03 17:54 ` Paolo Bonzini
2026-03-03 19:04 ` Jon Kohler
2025-12-23 5:47 ` [PATCH 6/8] KVM: VMX: enhance EPT violation handler for MBEC Jon Kohler
2025-12-23 5:48 ` Jon Kohler [this message]
2025-12-23 5:48 ` [PATCH 8/8] KVM: nVMX: advertise MBEC and setup mmu has_mbec Jon Kohler
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20251223054806.1611168-8-jon@nutanix.com \
--to=jon@nutanix.com \
--cc=Alexander.Grest@microsoft.com \
--cc=bp@alien8.de \
--cc=chao.gao@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=ken@codelabs.ch \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=madvenka@linux.microsoft.com \
--cc=mic@digikod.net \
--cc=mingo@redhat.com \
--cc=nsaenz@amazon.es \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=tao1.su@linux.intel.com \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
--cc=zhao1.liu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®