Nested Virtualization

Definition

Nested virtualization runs a hypervisor inside a VM, allowing that virtualized hypervisor to run guests of its own.

L2: nested guest
L1: guest hypervisor, itself running in a VM
L0: real physical-host hypervisor
Physical hardware

The lecture gives OS/device-driver testing, hypervisor-based security tools, honeypots, and intrusion detection as motivations.

CPU and VMCS management

L1 thinks it controls virtualization hardware, but L0 must keep authority over the real machine. L1’s virtualization operations therefore need support and mediation from L0.

The lecture distinguishes:

  • VMCS0-1: L0’s state/control for running L1.
  • VMCS1-2: L1’s intended state/control for running L2.
  • VMCS0-2: effective combined state/control used by L0 to run L2.

L0 merges the necessary controls so L1’s view remains consistent without losing L0’s protection. Shadow VMCS lets selected accesses avoid repeated exits to L0.

Nested memory translation

Conceptually, L2 memory must pass through L1’s apparent physical memory and then L0’s real backing:

L2 guest-physical -> L1 guest-physical -> host physical

The L2 OS also has its own guest-virtual-to-guest-physical mapping. The diagram above focuses on the additional physical-address domains.

L1 creates EPT1-2 while L0 maintains EPT0-1 and a composed EPT0-2. L0 must track relevant L1 mapping changes, faults, and invalidations so its effective map remains correct. A missing L1 mapping can require L1 to handle the fault before L0 updates its composed table.

Important rules / study clarification

  • Nesting adds control and translation work, so reducing exits matters.
  • Shadow VMCS is a control-structure optimization; shadow page tables are a memory-mapping mechanism.
  • Nested EPT here describes virtualizing a hypervisor’s EPT use, not merely ordinary two-stage paging for one VM.
  • The slide’s linear-exit-growth statement is its conceptual model, not a universal measured scaling law for every implementation.

Common mistakes

  • Assuming L1 can program the real machine’s virtualization controls unchecked.
  • Forgetting L2 still needs its own normal OS page tables.
  • Confusing several VMs on one host with several nested layers.

Related: Hardware-Assisted Virtualization and VMCS, Memory Virtualization - Shadow Page Tables and EPT, Hypervisor Architectures, QEMU and KVM.

Source

Lecture 03 PDF pages 109-114 (printed slides 116-121), drawing on The Turtles Project in the source bibliography. Context: Lecture 03 - Computing Virtualization Technologies and Tools. Diagrams and distinction checks are study explanations.