IP Library › Granted Patent US 10,776,020
Granted Patent B2
US 10,776,020 · App. 16/102,374 · Granted Sep 15, 2020

Memory protection in virtualized computer systems using shadow page tables

Inventors: David Gilbert (Farnborough, GB); Paolo Bonzini (Milan, IT)
Assignee: Red Hat, Inc.
G06F3/062G06F3/0662G06F3/0673G06F9/45558G06F2009/45583
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,776,020
App. No.
16/102,374
Granted
Sep 15, 2020
Kind
B2
Abstract

Aspects of the disclosure provide for mechanisms for memory protection of virtual machines in a computer system. A method of the disclosure includes: obtaining, by a hypervisor, a guest page table associated with a virtual machine, wherein the guest page table comprises a first guest page table entry associated with a privilege flag indicating that a first virtual page of a guest memory of the virtual machine is accessible to unprivileged code; and in view of a determination that the virtual machine is running in a kernel mode, generating a first host page table in view of the guest page table, wherein the first host page table comprises a first host page table entry corresponding to the first guest page table entry, and wherein the first host page table entry is associated with a privilege flag indicating that the first virtual page is not accessible to the unprivileged code.

Claims (37)

1. A method comprising:

obtaining, by a processing device running a hypervisor, a guest page table associated with a virtual machine, wherein the guest page table comprises a first guest page table entry and a second guest page table entry, wherein the first guest page table entry is associated with a first privilege flag indicating that a first virtual page of a guest memory of the virtual machine is accessible to unprivileged code, and wherein the second guest page table entry is associated with a second privilege flag indicating that a second virtual page of the guest memory is accessible to privileged code;

determining whether the virtual machine is running in a kernel mode or a user mode; and

responsive to determining the virtual machine is running in the kernel mode, generating a first host page table based on the guest page table, wherein the first host page table comprises a first host page table entry corresponding to the first guest page table entry and a second host page table entry corresponding to the second guest page table entry, and wherein the first host page table entry is associated with a third privilege flag indicating that the first virtual page is not accessible to the unprivileged code.

2. The method of claim 1 , further comprising:

responsive to determining the virtual machine is running in the user mode, generating a second host page table based on the guest page table, wherein the second host page table comprises a third host page table entry corresponding to the first guest page table entry, and wherein the third host page table entry is associated with a fourth privilege flag indicating that the first virtual page is accessible to the unprivileged code.

3. The method of claim 2 , wherein the second host page table does not include a mapping of the second virtual page.

4. The method of claim 2 , further comprising:

associating, by the hypervisor, the second host page table with the virtual machine in view of an indication of a transition from the kernel mode to the user mode by the virtual machine.

5. The method of claim 4 , wherein the indication comprises a page fault caused by an attempt to access the first virtual page by the virtual machine.

6. The method of claim 1 , wherein the third privilege flag further indicates that the first virtual page is accessible to the privileged code.

7. The method of claim 1 , wherein the privileged code comprises kernel code, and wherein the unprivileged code comprises user code.

8. The method of claim 1 , wherein the second guest page table entry comprises a second virtual address of the second virtual page, and wherein the second host page table entry comprises a mapping of the second virtual address to a host physical address.

9. A system comprising:

a memory; and

a processing device operatively coupled to the memory, the processing device to:

obtain, via a hypervisor, a guest page table associated with a virtual machine, wherein the guest page table comprises a first guest page table entry and a second guest page table entry, wherein the first guest page table entry is associated with a first privilege flag indicating that a first virtual page of a guest memory of the virtual machine is accessible to unprivileged code, and wherein the second guest page table entry is associated with a second privilege flag indicating that a second virtual page of the guest memory is accessible to privileged code;

determine whether the virtual machine is running in a kernel mode or a user mode; and

responsive to determining the virtual machine is running in the kernel mode, generate a first host page table based on the guest page table, wherein the first host page table comprises a first host page table entry corresponding to the first guest page table entry and a second host page table entry corresponding to the second guest page table entry, and wherein the first host page table entry is associated with a third privilege flag indicating that the first virtual page is not accessible to the unprivileged code.

10. The system of claim 9 , wherein the processing device is further to:

responsive to determining the virtual machine is running in the user mode, generate a second host page table based on the guest page table, wherein the second host page table comprises a third host page table entry corresponding to the first guest page table entry, and wherein the third host page table entry is associated with a fourth privilege flag indicating that the first virtual page is accessible to the unprivileged code.

11. The system of claim 10 , wherein the second host page table does not include a mapping of the second virtual page.

12. The system of claim 10 , wherein the processing device is further to:

associate, via the hypervisor, the second host page table with the virtual machine in view of an indication of a transition from the kernel mode to the user mode by the virtual machine.

13. The system of claim 12 , wherein the indication comprises a page fault caused by an attempt to access the first virtual page by the virtual machine.

14. The system of claim 9 , wherein the third privilege flag further indicates that the first virtual page is accessible to the privileged code.

15. The system of claim 9 , wherein the privileged code comprises kernel code, and wherein the unprivileged code comprises user code.

16. The system of claim 9 , wherein the second guest page table entry comprises a second virtual address of the second virtual page, and wherein the second host page table entry comprises a mapping of the second virtual address to a host physical address.

17. A non-transitory machine-readable storage medium including instructions that, when accessed by a processing device, cause the processing device to:

obtain, via a hypervisor, a guest page table associated with a virtual machine, wherein the guest page table comprises a first guest page table entry and a second guest page table entry, wherein the first guest page table entry is associated with a first privilege flag indicating that a first virtual page of a guest memory of the virtual machine is accessible to unprivileged code, and wherein the second guest page table entry is associated with a second privilege flag indicating that a second virtual page of the guest memory is accessible to privileged code;

determine whether the virtual machine is running in a kernel mode or a user mode; and

responsive to determining the virtual machine is running in the kernel mode, generate a first host page table based on the guest page table, wherein the first host page table comprises a first host page table entry corresponding to the first guest page table entry and a second host page table entry corresponding to the second guest page table entry, and wherein the first host page table entry is associated with a third privilege flag indicating that the first virtual page is not accessible to the unprivileged code.

18. The non-transitory machine-readable storage medium of claim 17 , wherein the processing device is further to:

responsive to determining the virtual machine is running in the user mode, generate a second host page table based on the guest page table, wherein the second host page table comprises a third host page table entry corresponding to the first guest page table entry, and wherein the third host page table entry is associated with a fourth privilege flag indicating that the first virtual page is accessible to the unprivileged code.

19. The non-transitory machine-readable storage medium of claim 18 , wherein the second host page table does not include a mapping of the second virtual page.

20. The non-transitory machine-readable storage medium of claim 18 , wherein the processing device is further to:

associate, via the hypervisor, the second host page table with the virtual machine in view of an indication of a transition from the kernel mode to the user mode by the virtual machine.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2018
From: GILBERT, DAVID; BONZINI, PAOLO
To: RED HAT, INC.
Reel/Frame 046802/0278 →
Continuity (1)
Related Publication 20200050364A1 · Feb 13, 2020