[PATCH v1 7/8] x86/sev: Allow the guest to configure interrupt vectors for the hypervisor

From: Melody Wang

Date: Fri Aug 28 2026 - 23:42:59 EST


The SVSM APIC protocol supports 5 API calls. SVSM_APIC_CONFIGURE_VECTOR
(shortened to SVSM_APIC_CONFIG_VECTOR for brevity), call 4, provides for
the guest to configure an interrupt vector which the guest allows and
the hypervisor can use to signal interrupts for it.

Implement this call, and make the default interrupt setting permissive
to allow all interrupts when detecting an SVSM and Alternate Injection
is enabled.

Signed-off-by: Melody Wang <huibo.wang@xxxxxxx>
---
arch/x86/boot/compressed/sev.c | 12 +++++++++++-
arch/x86/boot/compressed/sev.h | 7 +++++++
2 files changed, 18 insertions(+), 1 deletion(-)

diff --git a/arch/x86/boot/compressed/sev.c b/arch/x86/boot/compressed/sev.c
index a8a175c90fa8..479b74c75b4b 100644
--- a/arch/x86/boot/compressed/sev.c
+++ b/arch/x86/boot/compressed/sev.c
@@ -520,7 +520,10 @@ bool sev_prepare(void)
return true;
}

- /* Register Alternate Injection */
+ /* When the guest is running at VMPL2 with Alternate Injection enabled,
+ * register Alternate Injection, and configure all of interrupts as
+ * permissive by default.
+ */
if (early_is_sevsnp_guest() && snp_vmpl) {
struct svsm_call call = {};
int ret;
@@ -535,6 +538,13 @@ bool sev_prepare(void)
ret = svsm_call_msr_protocol(&call);
if (ret)
sev_es_terminate(SEV_TERM_SET_LINUX, GHCB_TERM_ALT_INJ_FAIL);
+
+ call.rax = SVSM_APIC_CALL(SVSM_APIC_CONFIG_VECTOR);
+ call.rcx = SVSM_IRQ_ENABLE_ALL;
+
+ ret = svsm_call_msr_protocol(&call);
+ if (svsm_call_msr_protocol(&call))
+ sev_es_terminate(SEV_TERM_SET_LINUX, GHCB_TERM_ALT_INJ_FAIL);
}

return false;
diff --git a/arch/x86/boot/compressed/sev.h b/arch/x86/boot/compressed/sev.h
index dd058af2e7aa..035a7b46085b 100644
--- a/arch/x86/boot/compressed/sev.h
+++ b/arch/x86/boot/compressed/sev.h
@@ -18,6 +18,13 @@ enum svsm_ai_ctrl {
SVSM_AI_REGISTER,
};

+enum svsm_vec_enable {
+ SVSM_IRQ_DISABLE_SINGLE = (0u << 8),
+ SVSM_IRQ_ENABLE_SINGLE = (1u << 8),
+ SVSM_IRQ_DISABLE_ALL = (2u << 8),
+ SVSM_IRQ_ENABLE_ALL = (3u << 8),
+};
+
void snp_accept_memory(phys_addr_t start, phys_addr_t end);
u64 sev_get_status(void);
bool early_is_sevsnp_guest(void);
--
2.43.0