The task switch emulation loaded RFLAGS with the EFLAGS image of the
new task's TSS as it was. A processor does not load the reserved bits:
bit 1 stays set and bits 3, 5, 15 and 22-31 stay clear.
Windows XP stops the other processors with an NMI when it restarts or
shuts down. Its NMI handler is a task gate and the EFLAGS image in that
task's TSS is 0, so the vCPU got RFLAGS 0x4000 (NT). The next VM entry
failed (invalid guest state, bit 1 of RFLAGS must be set) and bhyve
aborted, at every restart of a Windows XP guest with two vCPUs.
Other hypervisors force bit 1 at the same place: KVM's
load_state_from_tss32() has "ctxt->eflags = tss->eflags | 2" and Xen's
hvm_task_switch() has "regs->rflags = tss.eflags | X86_EFLAGS_MBS".
Signed-off-by: Wanpeng Qian <wanpengqian@gmail.com>
Sponsored by: keelos.dev