Memory Virtualization - Shadow Page Tables and EPT

Address domains

Guest virtual address (GVA)
  -> Guest physical address (GPA)
  -> Machine / host physical address (HPA)

The guest OS maps its process addresses to its apparent physical memory. The host controls where that memory resides on the real machine. These are different mappings.

Shadow page tables

The VMM composes a direct GVA -> HPA mapping used by the CPU. The guest cannot see the shadow table as its own page table.

The cost is synchronization: guest page-table changes must be reflected in the effective mapping. The lecture’s brute-force approach intercepts CR3 writes and protects guest page-table memory; a lazy approach tolerates some stale state and updates on selected invalidations or faults.

Study clarification: protecting page-table pages does not mean every ordinary access to guest RAM must cause an exit. The important intercepted writes affect translation metadata.

EPT / NPT

Intel Extended Page Tables and AMD Nested Page Tables provide hardware support for the second mapping:

MappingMaintained by
GVA -> GPAGuest OS page tables
GPA -> HPAHost-controlled EPT/NPT

This avoids much software shadow-table synchronization. It does not eliminate address-translation cost, faults, or every memory-related VM exit.

Study calculation: an uncached four-level walk

PDF page 48 / slide 51 counts (4 + 1) × 4 = 20 additional EPT table accesses: each of four guest-table reads and the final data access needs a four-level GPA-to-HPA walk.

In that simplified, fully uncached case:

4 guest page-table reads + 20 EPT reads = 24 translation reads
24 translation reads + 1 final data access = 25 memory accesses

This explains the slide’s counting. It is not the cost of every load: TLB and page-walk caches, page sizes, and paging depth change the actual work.

TLB, tagged entries, and huge pages

  • A TLB caches translations and avoids repeated walks on hits.
  • Virtual-processor identifiers distinguish cached contexts, reducing the need to flush all entries at each VM entry/exit.
  • Huge pages increase the memory covered by a limited number of entries, potentially improving TLB reach.
  • Tags do not remove the need for invalidation when mappings change.

Common mistakes

  • Calling GPA a real machine address.
  • Treating EPT as the guest’s replacement page table.
  • Reporting 20 as the total cost of every x64 memory access.
  • Reading the slides’ “without any overhead” wording as a zero-cost guarantee.

Related: Hardware-Assisted Virtualization and VMCS, Memory Ballooning, I-O Virtualization - Emulation PV and Passthrough, Nested Virtualization.

Source

Lecture 03 PDF pages 38-50 (printed slides 41-53). Context: Lecture 03 - Computing Virtualization Technologies and Tools. The address labels, total-access calculation, and qualifications are study explanations. Benchmark gains cited from 2009 are historical and workload-specific.