[PATCH v6 0/9] mshv: add SEV-SNP support for MSHV root partitions
From: Wei Hu
Date: Fri Sep 18 2026 - 08:34:39 EST
This series adds support for creating and managing AMD SEV-SNP
confidential virtual machines through the Microsoft Hypervisor root
partition driver.
The series adds fixed-size MSHV UAPI definitions, the required Microsoft
Hypervisor ABI definitions and hypercall helpers, partition ioctls,
capability discovery, processor-feature handling, ordered encrypted-memory
teardown, and nested-root SynIC handling.
Two prerequisite fixes lead the series. The first makes memory-region
unmap ownership explicit and retains mappings, pinned pages, the partition,
and the module whenever checked hypervisor unmap cannot prove cleanup. The
second publishes and withdraws per-CPU SynIC pointers so interrupt readers
cannot observe mappings after initialization failure or CPU teardown.
Testing:
- Built all four affected x86 MSHV objects with W=1 at every commit (9/9).
- Built the complete x86_64 kernel and modules with W=1.
- Built the affected ARM64 objects with W=1.
- Ran scripts/checkpatch.pl --strict on every production patch.
- Verified installed UAPI layouts in 64-bit and 32-bit userspace builds.
- Generated rust-vmm MSHV bindings for x86_64 and arm64.
- Passed all 9 KUnit host-access tests on a separate test-only branch.
- Passed the Cloud Hypervisor single-CVM launch test.
- Booted a four-vCPU SEV-SNP guest to login; Cloud Hypervisor exited cleanly.
The development host needs two additional local runtime patches to boot as
a nested MSHV root partition: EFI HvLoader root-partition boot enablement
and the non-upstreamable nested-VMBus interrupt-vector workaround. Neither
patch, the KUnit follow-up, nor any runtime-only commit is part of this
nine-patch series.
Changes since v5:
- In patch 1, keep the existing failed-chunk rollback, then attempt checked
full-region cleanup for any earlier mapped chunks before quarantining an
unpublished region. Preserve the original map error and serialize the
initial movable NO_ACCESS map with mreg_mutex.
- In patch 6, cap MODIFY_GPA_HOST_ACCESS at 65536 4K array entries. Reject a
larger request with -E2BIG and completed set to zero before variable
allocation or side effects. Use sort_nonatomic() and bounded scheduling
points in long user-controlled loops.
- Document in patch 6 that a successful PSP request intentionally leaves
request and response pages host-none for encrypted guest consumption;
explicit access changes or teardown restore them.
- In patch 7, use CONFIG_X86_64 for the in-kernel SNP reporting block. Keep
__x86_64__ in exported UAPI because headers_install rejects CONFIG_* leaks;
x86_64 and arm64 bindgen output and UAPI layouts remain correct.
- Classify the reported PSP-success restoration issue as a false positive.
Findings identified as pre-existing remain unchanged and out of scope.
Link: https://lore.kernel.org/linux-hyperv/20260908121403.1160280-1-weh@xxxxxxxxxxxxxxxxxxx/
Wei Hu (3):
mshv: retain memory regions until unmap succeeds
mshv: clear SynIC mappings before freeing them
mshv: set up own SynIC registers on a nested root partition
Wei Liu (6):
mshv: add SEV-SNP UAPI definitions
mshv: add SEV-SNP PSP request hypercall
mshv: add SEV-SNP isolated page hypercalls
mshv: wire SEV-SNP partition ioctls
mshv: detect and report SEV-SNP support at init
mshv: use safe partition CPU feature defaults
drivers/hv/mshv_regions.c | 510 +++++++++---
drivers/hv/mshv_root.h | 122 ++-
drivers/hv/mshv_root_hv_call.c | 369 +++++++--
drivers/hv/mshv_root_main.c | 1324 ++++++++++++++++++++++++++++++--
drivers/hv/mshv_synic.c | 172 +++--
include/hyperv/hvgdk_mini.h | 31 +
include/hyperv/hvhdk.h | 124 ++-
include/hyperv/hvhdk_mini.h | 53 ++
include/uapi/linux/mshv.h | 117 ++-
9 files changed, 2518 insertions(+), 304 deletions(-)
base-commit: be0cfab740e58b70047ef6e7e3d578f00ed5d258
--
2.43.0