@samitouri / QOSamiQemu / commits / bfff4b2ae5

target/i386: Add VMX_SECONDARY_EXEC_MODE_BASED_EPT_EXEC

Enumerate ability to enable Intel Mode-Based Execute Control (MBEC) on secondary execution control bit 22. Intel MBEC is a hardware feature, introduced in the Kabylake generation, that allows for more granular control over execution permissions. MBEC enables the separation and tracking of execution permissions for supervisor (kernel) and user-mode code. It is used as an accelerator for Microsoft's Memory Integrity [1] (also known as hypervisor-protected code integrity or HVCI). [1] https://learn.microsoft.com/en-us/windows/security/hardware-security/enable-virtualization-based-protection-of-code-integrity Code is mirrored here: https://github.com/JonKohler/linux/tree/mbec-v1-6.18 https://github.com/JonKohler/kvm-unit-tests/tree/mbec-v1 LKML thread(s) are here: Original RFC: https://lore.kernel.org/all/20250313203702.575156-1-jon@nutanix.com/ V1 code: https://lore.kernel.org/all/20251223054806.1611168-1-jon@nutanix.com/ KVM unit test changes: https://lore.kernel.org/all/20251223054850.1611618-1-jon@nutanix.com/ Cc: Xiaoyao Li <xiaoyao.li@intel.com> Cc: Zhao Liu <zhao1.liu@intel.com> Co-authored-by: Jon Kohler <jon@nutanix.com> Co-authored-by: Aditya Desai <aditya.desai@nutanix.com> Signed-off-by: Jon Kohler <jon@nutanix.com> Link: https://lore.kernel.org/r/20251223060834.1618428-1-jon@nutanix.com Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>

Jon Kohler committed Dec 22, 2025 at 23:08 UTC bfff4b2ae5452463ab8c14b4a8a020288b5ff5d8
2 files changed +6 -1
target/i386/cpu.c
+5 -1
@@ -1656,7 +1656,7 @@ FeatureWordInfo feature_word_info[FEATURE_WORDS] = {
1656 "vmx-apicv-register", "vmx-apicv-vid", "vmx-ple", "vmx-rdrand-exit",
1657 "vmx-invpcid-exit", "vmx-vmfunc", "vmx-shadow-vmcs", "vmx-encls-exit",
1658 "vmx-rdseed-exit", "vmx-pml", NULL, NULL,
1659 - "vmx-xsaves", NULL, NULL, NULL,
1659 + "vmx-xsaves", NULL, "vmx-mbec", NULL,
1660 NULL, "vmx-tsc-scaling", "vmx-enable-user-wait-pause", NULL,
1661 NULL, NULL, NULL, NULL,
1662 },
@@ -1971,6 +1971,10 @@ static FeatureDep feature_dependencies[] = {
1971 .from = { FEAT_VMX_SECONDARY_CTLS, VMX_SECONDARY_EXEC_ENABLE_EPT },
1972 .to = { FEAT_VMX_SECONDARY_CTLS, VMX_SECONDARY_EXEC_UNRESTRICTED_GUEST },
1973 },
1974 + {
1975 + .from = { FEAT_VMX_SECONDARY_CTLS, VMX_SECONDARY_EXEC_ENABLE_EPT },
1976 + .to = { FEAT_VMX_SECONDARY_CTLS, VMX_SECONDARY_EXEC_MODE_BASED_EPT_EXEC },
1977 + },
1978 {
1979 .from = { FEAT_VMX_SECONDARY_CTLS, VMX_SECONDARY_EXEC_ENABLE_VPID },
1980 .to = { FEAT_VMX_EPT_VPID_CAPS, 0xffffffffull << 32 },
target/i386/cpu.h
+1
@@ -1414,6 +1414,7 @@ uint64_t x86_cpu_get_supported_feature_word(X86CPU *cpu, FeatureWord w);
1414 #define VMX_SECONDARY_EXEC_RDSEED_EXITING 0x00010000
1415 #define VMX_SECONDARY_EXEC_ENABLE_PML 0x00020000
1416 #define VMX_SECONDARY_EXEC_XSAVES 0x00100000
1417 +#define VMX_SECONDARY_EXEC_MODE_BASED_EPT_EXEC 0x00400000
1418 #define VMX_SECONDARY_EXEC_TSC_SCALING 0x02000000
1419 #define VMX_SECONDARY_EXEC_ENABLE_USER_WAIT_PAUSE 0x04000000
1420