CPU Virtualization and Trap and Emulate

Definition

CPU virtualization provides controlled guest execution while retaining VMM authority over the physical processor. Trap and emulate (T&E) lets ordinary instructions execute and transfers control to the VMM for operations requiring mediation.

The lecture’s requirements

The Popek-Goldberg framing combines equivalent execution behavior, efficient direct execution of a dominant portion of instructions, and VMM control of resources. Full virtualization aims to support an unmodified guest OS.

Privileged versus sensitive

  • Privileged: traps when executed without required processor privilege.
  • Sensitive: reveals or affects state that matters to virtualization; the slide emphasizes observing physical processor state.

Classical de-privileging works cleanly when sensitive operations are also privileged. Traditional x86 contains sensitive behavior that does not trap reliably, so simply moving the guest kernel to a lower ring is insufficient.

Lecture execution model

Ordinary guest work executes
Guest attempts an intercepted operation
  -> trap to VMM
  -> VMM emulates the virtual effect
  -> resume guest

Ring 0 normally hosts a kernel; ring 3 hosts applications. Older designs place the VMM in ring 0 and guest kernel in ring 1, or compress the guest kernel/apps into ring 3. The lecture uses these to show protection difficulties.

Study clarification: syscall versus hypervisor transition

A syscall asks the guest OS for a service. A VM exit transfers execution to the host virtualization layer. They are different transitions. Older de-privileged models need extra handling for certain syscall mechanisms; hardware assistance lets the guest’s application-to-kernel transition stay in non-root mode.

Common mistakes

  • Assuming every sensitive instruction traps automatically.
  • Assuming every guest instruction is software-emulated.
  • Treating the slide’s possible 10× syscall penalty as universal.
  • Confusing the guest’s kernel privilege with authority over physical host resources.

Related: Hardware-Assisted Virtualization and VMCS, Dynamic Binary Translation, Paravirtualization and Hypercalls, Virtual Machines and Hypervisors.

Source

Lecture 03 PDF pages 8-21 (printed slides 9-23, with gaps), plus page 35 / slide 38 for the hardware-assisted syscall contrast. Context: Lecture 03 - Computing Virtualization Technologies and Tools. The transition distinction and common mistakes are study explanations.