I have 2 questions. 1. In nested VMs that use multi-dimensional page tables( EPT on EPT) where exactly in the code are EPT ( 0 -> 2) entries constructed? I can know from the Turtles paper that these entries are created by combining EPT 1->2 and EPT 0->1. But I can find that in KVM code. 2. Are there rmap entries for EPT 0->2 pages maintained? I am trying to write protect nested guest GFN's directly in L0 ( without letting L1 do it) but I don't know how to find the EPT 0->2 entry for a given L2 guest GFN. regards, Rohith -- To unsubscribe from this list: send the line "unsubscribe kvm" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html