From: Wei Hu <weh@linux.microsoft.com>
To: linux-hyperv@vger.kernel.org
Cc: linux-kernel@vger.kernel.org,
"K. Y. Srinivasan" <kys@microsoft.com>,
Haiyang Zhang <haiyangz@microsoft.com>,
Wei Liu <wei.liu@kernel.org>, Dexuan Cui <decui@microsoft.com>,
Long Li <longli@microsoft.com>
Subject: [PATCH v5 0/9] mshv: add SEV-SNP support for MSHV root partitions
Date: Tue, 8 Sep 2026 12:13:33 +0000 [thread overview]
Message-ID: <20260908121403.1160280-1-weh@linux.microsoft.com> (raw)
In-Reply-To: <20260831112704.2851147-1-weh@linux.microsoft.com>
This series adds support for creating and managing AMD SEV-SNP
confidential virtual machines through the Microsoft Hypervisor root
partition driver.
The series adds fixed-size MSHV UAPI definitions, the required Microsoft
Hypervisor ABI definitions and hypercall helpers, partition ioctls,
capability discovery, processor-feature handling, ordered encrypted-memory
teardown, and nested-root SynIC handling.
Two prerequisite fixes lead the series. The first makes memory-region
unmap ownership explicit and retains mappings, pinned pages, the partition,
and the module whenever checked hypervisor unmap cannot prove cleanup. The
second publishes and withdraws per-CPU SynIC pointers so interrupt readers
cannot observe mappings after initialization failure or CPU teardown.
Testing:
- Built all four affected x86 MSHV objects with W=1 at every commit.
- Built the complete x86_64 kernel and modules with W=1.
- Built the affected ARM64 objects with W=1.
- Ran scripts/checkpatch.pl --strict on every patch.
- Verified installed UAPI layouts in 64-bit and 32-bit userspace builds.
- Generated rust-vmm MSHV bindings from the installed kernel headers.
- Passed all 8 KUnit host-access tests on a separate test-only branch.
- Passed the corrected single-CVM runtime test.
- Booted a four-vCPU SEV-SNP guest to login.
The development host needs two additional local runtime patches to boot as
a nested MSHV root partition: EFI HvLoader root-partition boot enablement
and the non-upstreamable nested-VMBus interrupt-vector workaround. Neither
patch, the KUnit follow-up, nor any runtime-only commit is part of this
nine-patch series.
Changes since v4:
- Separate faults_blocked admission state from mapping_may_exist proof in
patch 1. The interval notifier no longer takes the fair rwsem, always
publishes its interval sequence after taking the region mutex, and a
movable fault drops all attempt-local locks before retry. This removes
the v4 ABBA cycle while preserving checked-unmap proof requirements.
- Correct patch 5's commit message to describe the isolated-page import
and import-completion wrappers actually added by that patch.
- Replace patch 6's region-wide host-access boolean with per-page READ,
WRITE, EXCLUSIVE, and UNCERTAIN state and exact completed-prefix updates.
Recovery restores only the known completed prefix; teardown restores
only nonbaseline state and retains uncertain pages.
- Make MAKE_EXCLUSIVE and MAKE_SHARED explicit ownership transitions.
Permission-only operations preserve ownership, and the child partition
ID is supplied only for MAKE_EXCLUSIVE. Support arbitrary cross-region
arrays, reject duplicate GPA/PFN entries and pinned aliases, and restore
PSP request pages to their exact original state.
- The first v5 runtime iteration exposed an incorrect forced MAKE_SHARED
and child partition_id model. The corrected wire/state matrix passed the
single-CVM runtime test and a four-vCPU guest boot to login.
- Leave two findings that predate this series unchanged and explicitly out
of scope: MMIO VMA/PFN validation and the blockable notifier remap-failure
contract. The reported L1VH local-SIRBP path is also pre-existing and is
unreachable for the hardware-CVM partition type exercised here.
Link: https://lore.kernel.org/linux-hyperv/20260831112704.2851147-1-weh@linux.microsoft.com/
Wei Hu (3):
mshv: retain memory regions until unmap succeeds
mshv: clear SynIC mappings before freeing them
mshv: set up own SynIC registers on a nested root partition
Wei Liu (6):
mshv: add SEV-SNP UAPI definitions
mshv: add SEV-SNP PSP request hypercall
mshv: add SEV-SNP isolated page hypercalls
mshv: wire SEV-SNP partition ioctls
mshv: detect and report SEV-SNP support at init
mshv: use safe partition CPU feature defaults
drivers/hv/mshv_regions.c | 510 ++++++++++---
drivers/hv/mshv_root.h | 120 ++-
drivers/hv/mshv_root_hv_call.c | 369 ++++++++--
drivers/hv/mshv_root_main.c | 1267 ++++++++++++++++++++++++++++++--
drivers/hv/mshv_synic.c | 172 +++--
include/hyperv/hvgdk_mini.h | 31 +
include/hyperv/hvhdk.h | 124 +++-
include/hyperv/hvhdk_mini.h | 53 ++
include/uapi/linux/mshv.h | 111 ++-
9 files changed, 2452 insertions(+), 305 deletions(-)
base-commit: be0cfab740e58b70047ef6e7e3d578f00ed5d258
--
2.43.0
next prev parent reply other threads:[~2026-09-08 12:14 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 4:04 [PATCH v3 0/7] mshv: add SEV-SNP support for MSHV root partitions Wei Hu
2026-08-25 4:04 ` [PATCH v3 1/7] mshv: add SEV-SNP UAPI definitions Wei Hu
2026-08-25 4:04 ` [PATCH v3 2/7] mshv: add SEV-SNP PSP request hypercall Wei Hu
2026-08-25 4:17 ` sashiko-bot
2026-08-25 4:04 ` [PATCH v3 3/7] mshv: add SEV-SNP isolated page hypercalls Wei Hu
2026-08-25 4:04 ` [PATCH v3 4/7] mshv: wire SEV-SNP partition ioctls Wei Hu
2026-08-25 4:22 ` sashiko-bot
2026-08-25 4:04 ` [PATCH v3 5/7] mshv: detect and report SEV-SNP support at init Wei Hu
2026-08-25 4:19 ` sashiko-bot
2026-08-25 4:04 ` [PATCH v3 6/7] mshv: use safe partition CPU feature defaults Wei Hu
2026-08-25 4:04 ` [PATCH v3 7/7] mshv: set up own SynIC registers on a nested root partition Wei Hu
2026-08-25 4:20 ` sashiko-bot
2026-08-31 11:26 ` [PATCH v4 0/9] mshv: add SEV-SNP support for MSHV root partitions Wei Hu
2026-08-31 11:26 ` [PATCH v4 1/9] mshv: retain memory regions until unmap succeeds Wei Hu
2026-08-31 11:48 ` sashiko-bot
2026-09-01 12:04 ` [EXTERNAL] " Wei Hu
2026-08-31 11:26 ` [PATCH v4 2/9] mshv: clear SynIC mappings before freeing them Wei Hu
2026-08-31 11:26 ` [PATCH v4 3/9] mshv: add SEV-SNP UAPI definitions Wei Hu
2026-08-31 11:26 ` [PATCH v4 4/9] mshv: add SEV-SNP PSP request hypercall Wei Hu
2026-08-31 11:26 ` [PATCH v4 5/9] mshv: add SEV-SNP isolated page hypercalls Wei Hu
2026-08-31 11:53 ` sashiko-bot
2026-08-31 11:26 ` [PATCH v4 6/9] mshv: wire SEV-SNP partition ioctls Wei Hu
2026-08-31 12:07 ` sashiko-bot
2026-08-31 11:26 ` [PATCH v4 7/9] mshv: detect and report SEV-SNP support at init Wei Hu
2026-08-31 11:26 ` [PATCH v4 8/9] mshv: use safe partition CPU feature defaults Wei Hu
2026-08-31 11:26 ` [PATCH v4 9/9] mshv: set up own SynIC registers on a nested root partition Wei Hu
2026-08-31 12:09 ` sashiko-bot
2026-09-08 12:13 ` Wei Hu [this message]
2026-09-08 12:13 ` [PATCH v5 1/9] mshv: retain memory regions until unmap succeeds Wei Hu
2026-09-08 12:33 ` sashiko-bot
2026-09-08 12:13 ` [PATCH v5 2/9] mshv: clear SynIC mappings before freeing them Wei Hu
2026-09-08 12:13 ` [PATCH v5 3/9] mshv: add SEV-SNP UAPI definitions Wei Hu
2026-09-08 12:13 ` [PATCH v5 4/9] mshv: add SEV-SNP PSP request hypercall Wei Hu
2026-09-08 12:13 ` [PATCH v5 5/9] mshv: add SEV-SNP isolated page hypercalls Wei Hu
2026-09-08 12:13 ` [PATCH v5 6/9] mshv: wire SEV-SNP partition ioctls Wei Hu
2026-09-08 12:29 ` sashiko-bot
2026-09-08 12:13 ` [PATCH v5 7/9] mshv: detect and report SEV-SNP support at init Wei Hu
2026-09-08 12:28 ` sashiko-bot
2026-09-08 12:13 ` [PATCH v5 8/9] mshv: use safe partition CPU feature defaults Wei Hu
2026-09-08 12:13 ` [PATCH v5 9/9] mshv: set up own SynIC registers on a nested root partition Wei Hu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260908121403.1160280-1-weh@linux.microsoft.com \
--to=weh@linux.microsoft.com \
--cc=decui@microsoft.com \
--cc=haiyangz@microsoft.com \
--cc=kys@microsoft.com \
--cc=linux-hyperv@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=longli@microsoft.com \
--cc=wei.liu@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.