Commit 4bc9b982 authored by Sheng Yang's avatar Sheng Yang Committed by Avi Kivity

KVM: VMX: Enforce EPT pagetable level checking

We only support 4 levels EPT pagetable now.
Signed-off-by: default avatarSheng Yang <sheng@linux.intel.com>
Signed-off-by: default avatarMarcelo Tosatti <mtosatti@redhat.com>
parent d2d7a611
...@@ -340,6 +340,11 @@ static inline bool cpu_has_vmx_ept_1g_page(void) ...@@ -340,6 +340,11 @@ static inline bool cpu_has_vmx_ept_1g_page(void)
return vmx_capability.ept & VMX_EPT_1GB_PAGE_BIT; return vmx_capability.ept & VMX_EPT_1GB_PAGE_BIT;
} }
static inline bool cpu_has_vmx_ept_4levels(void)
{
return vmx_capability.ept & VMX_EPT_PAGE_WALK_4_BIT;
}
static inline bool cpu_has_vmx_invept_individual_addr(void) static inline bool cpu_has_vmx_invept_individual_addr(void)
{ {
return vmx_capability.ept & VMX_EPT_EXTENT_INDIVIDUAL_BIT; return vmx_capability.ept & VMX_EPT_EXTENT_INDIVIDUAL_BIT;
...@@ -1568,7 +1573,8 @@ static __init int hardware_setup(void) ...@@ -1568,7 +1573,8 @@ static __init int hardware_setup(void)
if (!cpu_has_vmx_vpid()) if (!cpu_has_vmx_vpid())
enable_vpid = 0; enable_vpid = 0;
if (!cpu_has_vmx_ept()) { if (!cpu_has_vmx_ept() ||
!cpu_has_vmx_ept_4levels()) {
enable_ept = 0; enable_ept = 0;
enable_unrestricted_guest = 0; enable_unrestricted_guest = 0;
} }
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment