On 03/05/2018 03:27, Wanpeng Li wrote: > So for 1) guest->guest attacks 2) guest/ring3->host/ring3 attacks 3) > guest/ring0->host/ring0 attacks, if IBPB is enough to protect these > three scenarios and retpoline is not needed? In theory yes, in practice if you want to do that IBPB is much more expensive than retpolines, because you'd need an IBPB on vmexit or a cache flush on vmentry. Paolo