On 09/07/20 19:00, Jim Mattson wrote: >> >> Mostly fine. Some edge cases, like different page fault errors for >> addresses above GUEST_MAXPHYADDR and below HOST_MAXPHYADDR. Which I >> think Mohammed fixed in the kernel recently. > Doesn't this require intercepting MOV-to-CR3 when the guest is in PAE > mode, so that the hypervisor can validate the high bits in the PDPTEs? In theory yes, but in practice it just means we'd use the AMD behavior of loading guest PDPT entries on demand during address translation (because the PDPT would point to nonexistent memory and cause an EPT violation on the PDE). Paolo