From: Jan Beulich Subject: x86: SHADOW_PAGING is deprecated Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly available, the decision was to deprecate the functionality, while still retaining it for people to use at their own (security) risk. Memory-wise small enough guests may still be okay to run. Some CI testing depends on SHADOW_PAGING. Explicitly enable it when needed. This is CVE-2026-42493 / XSA-495. Signed-off-by: Jan Beulich Reviewed-by: Juergen Gross diff --git a/SUPPORT.md b/SUPPORT.md index 67be5a5783d7..7db7ce9c3e37 100644 --- a/SUPPORT.md +++ b/SUPPORT.md @@ -353,6 +353,16 @@ This is typically done by a guest kernel agent known as a "balloon driver". Status: Supported +### Shadow paging + +Allows fully virtualized guests (HVM / PVH) to be run without (host side) page +translation support by hardware (AMD: NPT, Intel: EPT). + +It is also required to migrate PV guests, and to allow L1TF-vulnerable guests +to continue to run without compromising host security. + + Status: Supported, not security supported + ### Populate-on-demand memory This is a mechanism that allows normal operating systems with only a balloon driver @@ -485,7 +495,7 @@ This feature is independent of the ARM "page granularity" feature (see below). Status, x86 HVM/PVH, HAP: Supported - Status, x86 HVM/PVH, Shadow, 2MiB: Supported + Status, x86 HVM/PVH, Shadow, 2MiB: Supported, not security supported Status, ARM: Supported On x86 in shadow mode, only 2MiB (L2) superpages are available; diff --git a/automation/gitlab-ci/build.yaml b/automation/gitlab-ci/build.yaml index 5f0acda942ac..9309e10ebba0 100644 --- a/automation/gitlab-ci/build.yaml +++ b/automation/gitlab-ci/build.yaml @@ -312,11 +312,15 @@ debian-12-x86_64-gcc-debug: extends: .gcc-x86-64-build-debug variables: CONTAINER: debian:12-x86_64 + EXTRA_XEN_CONFIG: | + CONFIG_SHADOW_PAGING=y debian-12-x86_64-clang-debug: extends: .clang-x86-64-build-debug variables: CONTAINER: debian:12-x86_64 + EXTRA_XEN_CONFIG: | + CONFIG_SHADOW_PAGING=y debian-12-ppc64le-gcc-debug: extends: .gcc-ppc64le-cross-build-debug diff --git a/xen/arch/x86/Kconfig b/xen/arch/x86/Kconfig index 96fd1c3272d1..f63c55c783fc 100644 --- a/xen/arch/x86/Kconfig +++ b/xen/arch/x86/Kconfig @@ -177,7 +177,6 @@ config XEN_IBT config SHADOW_PAGING bool "Shadow Paging" - default !PV_SHIM_EXCLUSIVE depends on PV || HVM help @@ -193,7 +192,8 @@ config SHADOW_PAGING Under a small number of specific workloads, shadow paging may be deliberately used as a performance optimisation. - If unsure, say Y. + NOTE: This feature is now deprecated. It is in particular no longer + security supported. config BIGMEM bool "big memory support"