HypervisorVtl¶
- final class ntoseye.HypervisorVtl¶
One VTL of a virtual processor: the hypervisor’s context for it and, when found, its eVMCS and the guest state saved there.
- disassemble(address: int, count: int, physical: bool = False) list[DisassembledInstruction]¶
Disassemble
countinstructions of this VTL’s guest ataddress, as!hvudoes: read asreadreads it (guest virtual, or withphysical=Trueguest physical), and decoded in the mode the VTL left off in, 64-bit in IA-32e mode with a 64-bit code segment, else 32-bit. Branch and RIP-relative comments are addresses: there are no symbols for a guest. The listing stops at the first unreadable page, so it can hold fewer thancountinstructions. RaisesNtoseyeErrorwhen the first instruction is unreadable, without the VTL’s eVMCS state, for real-mode or 16-bit code, and for a virtual address unless the guest is in 4-level long-mode paging.
- property ept_pointer: int | None¶
The VTL’s EPT pointer, the root of its second-level address translation, or
Nonewithout the eVMCS.
- property exit_reason: int | None¶
The basic reason (Intel SDM Appendix C) the VTL last left for the hypervisor, or
Nonewithout the eVMCS.
- io_intercepts() IoIntercepts¶
Which I/O instructions of this VTL exit, as
!hvvmcs -ioshows them: the port ranges its I/O bitmaps intercept, or, when its controls use none, every port (every) or none. RaisesNtoseyeErrorwithout the VTL’s eVMCS, or when a bitmap is unreadable.
- msr_intercepts() MsrIntercepts¶
Which RDMSRs and WRMSRs of this VTL exit, as
!hvvmcs -msrshows them: through its MSR bitmap when its controls use one, else every one (every). Each intercepted range names the architectural MSRs in it, andread_without_exitandwrite_without_exitlist those the VTL accesses without an exit. MSRs outside the bitmap’s 0x0-0x1fff and 0xc0000000-0xc0001fff always exit. RaisesNtoseyeErrorwithout the VTL’s eVMCS, or when the bitmap is unreadable.
- read(address: int, size: int, physical: bool = False) bytes¶
Read
sizebytes of the memory of this VTL’s guest, as!hvddoes: guest virtual memory through the VTL’s page tables (its saved CR3), or withphysical=Trueguest physical memory, both through the VTL’s EPT. RaisesNtoseyeErrorwithout the VTL’s eVMCS state or when a page is not mapped, and for a virtual address unless the guest is in 4-level long-mode paging. The memory is read-only.
- to_dict() dict[str, Any]¶
Return the VTL as a plain
dict(level,context,vmcs,ept_pointer,rip,exit_reason).
- translate(gpa: int) EptMapping | None¶
Translate a guest physical address through this VTL’s EPT, as
!hveptdoes. ReturnsNonewhen no entry maps it, and raisesNtoseyeErrorwithout the VTL’s eVMCS state or when a table is unreadable.
- translate_virtual(address: int) tuple[int, int] | None¶
Translate a guest virtual address of this VTL’s guest through its page tables and its EPT:
(guest_physical, host_physical), orNonewhen the page tables do not map it. RaisesNtoseyeErrorunless the guest is in 4-level long-mode paging.