On Tue, Sep 01, 2026 at 09:55:18AM -0700, Thara Gopinath wrote:
> Set bit 0 of the Hyper-V private OsLoaderIndications EFI variable
> during exit_boot() so the bootloader/firmware knows the OS intends
> to enable VTL1. Without this, VTL1 cannot be brought up from the
> Linux kernel.
> 
> The support bit is first checked in OsLoaderIndicationsSupported,
> and the variable is only written when the VSM bit is not already
> set.
> 
> Signed-off-by: Thara Gopinath <[email protected]>
> ---
>  drivers/firmware/efi/libstub/x86-stub.c | 57 +++++++++++++++++++++++++
>  1 file changed, 57 insertions(+)
> 
[...]
> +#ifdef CONFIG_HYPERV_VSM
> +static void efi_set_hv_os_indications(void)
> +{
> +     efi_guid_t guid = HYPERV_PRIVATE_EFI_NAMESPACE_GUID;
> +     efi_status_t status;
> +     unsigned long size;
> +     u32 attr, val;
> +
> +     size = sizeof(val);
> +     status = get_efi_var(efi_HvPrivOsloaderIndicationsSupported_name,
> +                          &guid, &attr, &size, &val);
> +     if (status != EFI_SUCCESS) {
> +             efi_err("Could not read Hyper-V 
> OsloaderIndicationsSupported\n");
> +             return;
> +     }
> +
> +     if (!(val & HV_OSLOADER_INDICATION_VSM)) {
> +             efi_info("Hyper-V does not support VSM in 
> OsloaderIndicationsSupported\n");
> +             return;
> +     }
> +
> +     size = sizeof(val);
> +     status = get_efi_var(efi_HvPrivOsloaderIndications_name, &guid, &attr, 
> &size, &val);
> +     if (status != EFI_SUCCESS) {
> +             efi_err("Could not read Hyper-V OsLoaderIndications\n");
> +             return;
> +     }
> +
> +     if (val & HV_OSLOADER_INDICATION_VSM) {
> +             efi_info("VSM is already supported in OsLoaderIndications.");
> +             return;
> +     }
> +
> +     val |= HV_OSLOADER_INDICATION_VSM;
> +     size = sizeof(val);
> +     status = set_efi_var(efi_HvPrivOsloaderIndications_name, &guid, attr, 
> size, &val);

I'm not familiar with the security model, so bear with me.

What happens if the VTL0 kernel doesn't use VTL1 at all? Does that
become a security issue, that malware can use the VTL1 to hide itself?

Asking this because I think you will want to enable this in the generic
kernel(s). Not all users have or want to package a secure kernel.

Wei

> +     if (status != EFI_SUCCESS)
> +             efi_err("Could not set Hyper-V OsLoaderIndications to indicate 
> VSM support\n");
> +}
> +#endif
> +
>  static efi_status_t exit_boot(struct boot_params *boot_params, void *handle)
>  {
>       struct setup_data *e820ext = NULL;
> @@ -768,6 +820,11 @@ static efi_status_t exit_boot(struct boot_params 
> *boot_params, void *handle)
>       if (status != EFI_SUCCESS)
>               return status;
>  
> +#ifdef CONFIG_HYPERV_VSM
> +     /* Indicate to bootloader that we will be enabling VTL1 before exiting 
> boot services */
> +     efi_set_hv_os_indications();
> +#endif
> +
>       /* Might as well exit boot services now */
>       status = efi_exit_boot_services(handle, &priv, exit_boot_func);
>       if (status != EFI_SUCCESS)
> -- 
> 2.34.1
> 

Reply via email to