On 06/03/2016 10:28, Xiao Guangrong wrote: >> This patch disables CPUID:PKU without ept, because pkeys is not yet >> implemented for shadow paging. > > Does the PKRU is loaded/saved during vm-enter/vm-exit? Yes, through XSAVE/XRSTOR (which uses eager mode when PKE is active). > BTW, I just very quickly go through the spec, it seems VMX lacks the > ability to intercept the access to PKRU. Right? Indeed RDPKRU/WRPKRU cannot be intercepted. Paolo -- To unsubscribe from this list: send the line "unsubscribe kvm" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html