743844-015.pdf - 第38页

Intel ® APIC Virtualization Technology (Intel ® APICv) APIC virtualization is a collection of features that can be used to support the virtualization of interrupts and the Advanced Progr ammable Interrupt Controller (API…

100%1 / 224
For more information, refer to Intel
®
Virtualization Technology for Directed I/O
Architecture Specification http://www.intel.com/content/dam/www/public/us/en/
documents/product-specifications/vt-directed-io-spec.pdf
Intel
®
VT-d Key Features
The processor supports the following Intel
®
VT-d features:
Memory controller and processor graphics comply with the Intel
®
VT-d 2.1
Specification.
Two Intel
®
VT-d DMA remap engines.
iGFX DMA remap engine
Default DMA remap engine (covers all devices except iGFX)
Support for root entry, context entry, and the default context
46-bit guest physical address and host physical address widths
Support for 4K page sizes only
Support for register-based fault recording only (for single entry only) and support
for MSI interrupts for faults
Support for both leaf and non-leaf caching
Support for boot protection of default page table
Support for non-caching of invalid page table entries
Support for hardware-based flushing of translated but pending writes and pending
reads, on IOTLB invalidation
Support for Global, Domain-specific and Page specific IOTLB invalidation
MSI cycles (MemWr to address FEEx_xxxxh) not translated.
Interrupt Remapping is supported
Queued invalidation is supported
Intel
®
VT-d translation bypass address range is supported (Pass Through)
The processor supports the following added new Intel
®
VT-d features:
4-level Intel
®
VT-d Page walk – both default Intel
®
VT-d engine, as well as the
Processor Graphics VT-d engine are upgraded to support 4-level Intel
®
VT-d tables
(adjusted guest address width of 48 bits)
Intel
®
VT-d super-page – support of Intel
®
VT-d super-page (2 MB, 1 GB) for
default Intel
®
VT-d engine (that covers all devices except IGD)
IGD Intel
®
VT-d engine does not support super-page and BIOS should disable
super-page in default Intel
®
VT-d engine when iGfx is enabled.
NOTE
Intel
®
VT-d Technology may not be available on all SKUs.
R
Technologies—Intel
®
Core
, Xeon
6300 And Xeon
E 2400 Processors
13
th
Generation Intel
®
Core
, Intel
®
Core
14
th
Generation, Intel
®
Core
Processor (Series 1) and (Series 2), Intel
®
Xeon
E
2400 Processor and Intel
®
Xeon
6300 Processor
May 2025 Datasheet, Volume 1 of 2
Doc. No.: 743844, Rev.: 015 37
Intel
®
APIC Virtualization Technology (Intel
®
APICv)
APIC virtualization is a collection of features that can be used to support the
virtualization of interrupts and the Advanced Programmable Interrupt Controller
(APIC).
When APIC virtualization is enabled, the processor emulates many accesses to the
APIC, tracks the state of the virtual APIC, and delivers virtual interrupts — all in VMX
non-root operation without a VM exit.
The following are the VM-execution controls relevant to APIC virtualization and virtual
interrupts:
Virtual-interrupt Delivery. This controls enables the evaluation and delivery of
pending virtual interrupts. It also enables the emulation of writes (memory-
mapped or MSR-based, as enabled) to the APIC registers that control interrupt
prioritization.
Use TPR Shadow. This control enables emulation of accesses to the APIC’s task-
priority register (TPR) via CR8 and, if enabled, via the memory-mapped or MSR-
based interfaces.
Virtualize APIC Accesses. This control enables virtualization of memory-mapped
accesses to the APIC by causing VM exits on accesses to a VMM-specified APIC-
access page. Some of the other controls, if set, may cause some of these accesses
to be emulated rather than causing VM exits.
Virtualize x2APIC Mode. This control enables virtualization of MSR-based
accesses to the APIC.
APIC-register Virtualization. This control allows memory-mapped and MSR-
based reads of most APIC registers (as enabled) by satisfying them from the
virtual-APIC page. It directs memory-mapped writes to the APIC-access page to
the virtual-APIC page, following them by VM exits for VMM emulation.
Process Posted Interrupts. This control allows software to post virtual
interrupts in a data structure and send a notification to another logical processor;
upon receipt of the notification, the target processor will process the posted
interrupts by copying them into the virtual-APIC page.
NOTE
Intel
®
APIC Virtualization Technology may not be available on all SKUs.
Intel
®
APIC Virtualization specifications and functional descriptions are included in the
Intel
®
64 Architectures Software Developer’s Manual, Volume 3. Available at:
http://www.intel.com/products/processor/manuals
Hypervisor-Managed Linear Address Translation
Hypervisor-Managed Linear Address Translation (HLAT) is active when the “enable
HLAT” VM-execution control is 1. The processor looks up the HLAT if, during a guest
linear address translation, the guest linear address matches the Protected Linear
Range. The lookup from guest linear addresses to the guest physical address and
attributes is determined by a set of HLAT paging structures.
2.2.3
2.2.4
R
Intel
®
Core
, Xeon
6300 And Xeon
E 2400 Processors—Technologies
13
th
Generation Intel
®
Core
, Intel
®
Core
14
th
Generation, Intel
®
Core
Processor (Series 1) and (Series 2), Intel
®
Xeon
E
2400 Processor and Intel
®
Xeon
6300 Processor
Datasheet, Volume 1 of 2 May 2025
38 Doc. No.: 743844, Rev.: 015
The guest paging structure managed by the guest OS specifies the ordinary
translation of a guest linear address to the guest physical address and attributes that
the guest ring-0 software has programmed, whereas HLAT specifies the alternate
translation of the guest linear address to guest physical address and attributes that
the Secure Kernel and VMM seek to enforce. A logical processor uses HLAT to translate
guest linear addresses only when those guest linear addresses are used to access
memory (both for code fetch and data load/store) and the guest linear addresses
match the PLR programmed by the VMM/Secure Kernel.
HLAT specifications and functional descriptions are included in the Intel
®
Architecture
Instruction Set Extensions Programming Reference. Available at:
https://software.intel.com/en-us/download/intel-architecture-instruction-set-
extensions-programming-reference
Security Technologies
Intel
®
Trusted Execution Technology
Intel
®
Trusted Execution Technology (Intel
®
TXT) defines platform-level
enhancements that provide the building blocks for creating trusted platforms.
The Intel
®
TXT platform helps to provide the authenticity of the controlling
environment such that those wishing to rely on the platform can make an appropriate
trust decision. The Intel
®
TXT platform determines the identity of the controlling
environment by accurately measuring and verifying the controlling software.
Another aspect of the trust decision is the ability of the platform to resist attempts to
change the controlling environment. The Intel
®
TXT platform will resist attempts by
software processes to change the controlling environment or bypass the bounds set by
the controlling environment.
Intel
®
TXT is a set of extensions designed to provide a measured and controlled
launch of system software that will then establish a protected environment for itself
and any additional software that it may execute.
These extensions enhance two areas:
The launching of the Measured Launched Environment (MLE).
The protection of the MLE from potential corruption.
The enhanced platform provides these launch and control interfaces using Safer Mode
Extensions (SMX).
The SMX interface includes the following functions:
Measured/Verified launch of the MLE.
Mechanisms to ensure the above measurement is protected and stored in a secure
location.
Protection mechanisms that allow the MLE to control attempts to modify itself.
The processor also offers additional enhancements to System Management Mode
(SMM) architecture for enhanced security and performance. The processor provides
new MSRs to:
Enable a second SMM range
2.3
2.3.1
R
Technologies—Intel
®
Core
, Xeon
6300 And Xeon
E 2400 Processors
13
th
Generation Intel
®
Core
, Intel
®
Core
14
th
Generation, Intel
®
Core
Processor (Series 1) and (Series 2), Intel
®
Xeon
E
2400 Processor and Intel
®
Xeon
6300 Processor
May 2025 Datasheet, Volume 1 of 2
Doc. No.: 743844, Rev.: 015 39