[PATCH v5 0/9] mshv: add SEV-SNP support for MSHV root partitions

From: Wei Hu

Date: Tue Sep 08 2026 - 08:36:45 EST


This series adds support for creating and managing AMD SEV-SNP
confidential virtual machines through the Microsoft Hypervisor root
partition driver.

The series adds fixed-size MSHV UAPI definitions, the required Microsoft
Hypervisor ABI definitions and hypercall helpers, partition ioctls,
capability discovery, processor-feature handling, ordered encrypted-memory
teardown, and nested-root SynIC handling.

Two prerequisite fixes lead the series. The first makes memory-region
unmap ownership explicit and retains mappings, pinned pages, the partition,
and the module whenever checked hypervisor unmap cannot prove cleanup. The
second publishes and withdraws per-CPU SynIC pointers so interrupt readers
cannot observe mappings after initialization failure or CPU teardown.

Testing:

- Built all four affected x86 MSHV objects with W=1 at every commit.
- Built the complete x86_64 kernel and modules with W=1.
- Built the affected ARM64 objects with W=1.
- Ran scripts/checkpatch.pl --strict on every patch.
- Verified installed UAPI layouts in 64-bit and 32-bit userspace builds.
- Generated rust-vmm MSHV bindings from the installed kernel headers.
- Passed all 8 KUnit host-access tests on a separate test-only branch.
- Passed the corrected single-CVM runtime test.
- Booted a four-vCPU SEV-SNP guest to login.

The development host needs two additional local runtime patches to boot as
a nested MSHV root partition: EFI HvLoader root-partition boot enablement
and the non-upstreamable nested-VMBus interrupt-vector workaround. Neither
patch, the KUnit follow-up, nor any runtime-only commit is part of this
nine-patch series.

Changes since v4:

- Separate faults_blocked admission state from mapping_may_exist proof in
patch 1. The interval notifier no longer takes the fair rwsem, always
publishes its interval sequence after taking the region mutex, and a
movable fault drops all attempt-local locks before retry. This removes
the v4 ABBA cycle while preserving checked-unmap proof requirements.
- Correct patch 5's commit message to describe the isolated-page import
and import-completion wrappers actually added by that patch.
- Replace patch 6's region-wide host-access boolean with per-page READ,
WRITE, EXCLUSIVE, and UNCERTAIN state and exact completed-prefix updates.
Recovery restores only the known completed prefix; teardown restores
only nonbaseline state and retains uncertain pages.
- Make MAKE_EXCLUSIVE and MAKE_SHARED explicit ownership transitions.
Permission-only operations preserve ownership, and the child partition
ID is supplied only for MAKE_EXCLUSIVE. Support arbitrary cross-region
arrays, reject duplicate GPA/PFN entries and pinned aliases, and restore
PSP request pages to their exact original state.
- The first v5 runtime iteration exposed an incorrect forced MAKE_SHARED
and child partition_id model. The corrected wire/state matrix passed the
single-CVM runtime test and a four-vCPU guest boot to login.
- Leave two findings that predate this series unchanged and explicitly out
of scope: MMIO VMA/PFN validation and the blockable notifier remap-failure
contract. The reported L1VH local-SIRBP path is also pre-existing and is
unreachable for the hardware-CVM partition type exercised here.

Link: https://lore.kernel.org/linux-hyperv/20260831112704.2851147-1-weh@xxxxxxxxxxxxxxxxxxx/

Wei Hu (3):
mshv: retain memory regions until unmap succeeds
mshv: clear SynIC mappings before freeing them
mshv: set up own SynIC registers on a nested root partition

Wei Liu (6):
mshv: add SEV-SNP UAPI definitions
mshv: add SEV-SNP PSP request hypercall
mshv: add SEV-SNP isolated page hypercalls
mshv: wire SEV-SNP partition ioctls
mshv: detect and report SEV-SNP support at init
mshv: use safe partition CPU feature defaults

drivers/hv/mshv_regions.c | 510 ++++++++++---
drivers/hv/mshv_root.h | 120 ++-
drivers/hv/mshv_root_hv_call.c | 369 ++++++++--
drivers/hv/mshv_root_main.c | 1267 ++++++++++++++++++++++++++++++--
drivers/hv/mshv_synic.c | 172 +++--
include/hyperv/hvgdk_mini.h | 31 +
include/hyperv/hvhdk.h | 124 +++-
include/hyperv/hvhdk_mini.h | 53 ++
include/uapi/linux/mshv.h | 111 ++-
9 files changed, 2452 insertions(+), 305 deletions(-)


base-commit: be0cfab740e58b70047ef6e7e3d578f00ed5d258
--
2.43.0