CPU Virtualization and Trap and Emulate
Definition
CPU virtualization provides controlled guest execution while retaining VMM authority over the physical processor. Trap and emulate (T&E) lets ordinary instructions execute and transfers control to the VMM for operations requiring mediation.
The lecture’s requirements
The Popek-Goldberg framing combines equivalent execution behavior, efficient direct execution of a dominant portion of instructions, and VMM control of resources. Full virtualization aims to support an unmodified guest OS.
Privileged versus sensitive
- Privileged: traps when executed without required processor privilege.
- Sensitive: reveals or affects state that matters to virtualization; the slide emphasizes observing physical processor state.
Classical de-privileging works cleanly when sensitive operations are also privileged. Traditional x86 contains sensitive behavior that does not trap reliably, so simply moving the guest kernel to a lower ring is insufficient.
Lecture execution model
Ordinary guest work executes
Guest attempts an intercepted operation
-> trap to VMM
-> VMM emulates the virtual effect
-> resume guestRing 0 normally hosts a kernel; ring 3 hosts applications. Older designs place the VMM in ring 0 and guest kernel in ring 1, or compress the guest kernel/apps into ring 3. The lecture uses these to show protection difficulties.
Study clarification: syscall versus hypervisor transition
A syscall asks the guest OS for a service. A VM exit transfers execution to the host virtualization layer. They are different transitions. Older de-privileged models need extra handling for certain syscall mechanisms; hardware assistance lets the guest’s application-to-kernel transition stay in non-root mode.
Common mistakes
- Assuming every sensitive instruction traps automatically.
- Assuming every guest instruction is software-emulated.
- Treating the slide’s possible 10× syscall penalty as universal.
- Confusing the guest’s kernel privilege with authority over physical host resources.
Related: Hardware-Assisted Virtualization and VMCS, Dynamic Binary Translation, Paravirtualization and Hypercalls, Virtual Machines and Hypervisors.
Source
Lecture 03 PDF pages 8-21 (printed slides 9-23, with gaps), plus page 35 / slide 38 for the hardware-assisted syscall contrast. Context: Lecture 03 - Computing Virtualization Technologies and Tools. The transition distinction and common mistakes are study explanations.