SavedVtlState

final class ntoseye.SavedVtlState

Subclass of BaseRecord.

One VTL of a virtual processor, as the Windows hypervisor last saved it in the VTL’s Enlightened VMCS. A VMCS holds no general-purpose register other than rsp; general_registers has the others when they are known.

property cr0: int
property cr3: int

The page-table root of the VTL.

property cr4: int
property cs: int
property current: bool

Whether the VP assist page names this state’s eVMCS as current. The current VTL is the one that entered the hypervisor or that the hypervisor is about to enter.

property dr7: int
property ds: int
property es: int
property evmcs: int

The physical address of the eVMCS page that ntoseye read the state from.

property exit_instruction_length: int

The length of the instruction that caused the exit, for exits that an instruction caused.

property exit_interruption_info: int

The vector and type of the event behind an exception or interrupt exit (Intel SDM, VM-exit interruption information).

property exit_qualification: int

Reason-specific detail of the last exit, such as the access that caused an EPT violation (Intel SDM, exit qualification).

property exit_reason: int

The VM-exit reason of the last exit from the VTL. Bits 15:0 hold the basic reason, and bit 31 is set for a failed VM entry.

property exit_reason_name: str | None

The name of the exit reason (HLT, VMCALL, …), if it is a common reason.

property fs: int
property fs_base: int
property general_registers: Record | None

The guest’s general-purpose registers other than rsp at the last exit (rax to r15), read where the hypervisor’s VM-exit entry code saved them. Experimental: where that is, is read off the entry code. None when they are not known: for a VTL that is not the current one, while the vCPU is on host_rip (unless it stopped there on a breakpoint, when they are the vCPU’s own) or still saving them, or when the entry code does not save them in one block.

property gs: int
property gs_base: int
property host_rip: int

The hypervisor’s VM-exit entry point.

property host_rsp: int

The stack the hypervisor’s VM-exit entry point runs on.

property hypercall: DecodedHypercall | None

The hypercall of a VMCALL exit whose general-purpose registers are known, with its input decoded.

property may_be_stale: bool

The vCPU is stopped on host_rip, and not by a breakpoint there. KVM writes the eVMCS when it enters the hypervisor, and a stop from outside can fall between a VM exit and that entry, so this state may still describe the exit before the one in progress. The guest’s general-purpose registers are then still in the vCPU’s own registers. A breakpoint on host_rip fires after the write. Only the current state, the exiting VTL’s, can be behind; when no state of the VP is current, every state is marked.

property rflags: int
property rip: int
property rsp: int
property ss: int
property symbol: str | None

The symbol at rip in the VTL’s address space, if one resolves.

property vtl: int

0 or 1.