This series adds support for creating and managing AMD SEV-SNP
confidential virtual machines through the Microsoft Hypervisor root
partition driver.

The series adds fixed-size MSHV UAPI definitions, the required Microsoft
Hypervisor ABI definitions and hypercall helpers, partition ioctls,
capability discovery, processor-feature handling, ordered encrypted-memory
teardown, and nested-root SynIC handling.

Two prerequisite fixes lead the series. The first makes memory-region
unmap ownership explicit and retains mappings, pinned pages, the partition,
and the module whenever checked hypervisor unmap cannot prove cleanup. The
second publishes and withdraws per-CPU SynIC pointers so interrupt readers
cannot observe mappings after initialization failure or CPU teardown.

Testing:

  - Built the complete x86_64 kernel and modules with W=1.
  - Built the affected ARM64 objects with W=1.
  - Ran scripts/checkpatch.pl --strict on every production patch.
  - Passed all 9 KUnit host-access tests on a separate test-only branch.
  - Passed the Cloud Hypervisor single-CVM launch test on the exact
    userspace revision used for v6.

The development host needs two additional local runtime patches to boot as
a nested MSHV root partition: EFI HvLoader root-partition boot enablement
and the non-upstreamable nested-VMBus interrupt-vector workaround. Neither
patch, the KUnit follow-up, nor any runtime-only commit is part of this
nine-patch series.

Changes since v6:

  - In patch 6, periodically reschedule newly added region-sized scans,
    bitmap updates, duplicate-PFN validation, and host-access hypercall
    batching so large memory regions cannot monopolize a CPU.
  - In patch 6, allow a fatal signal to stop isolated-page import between
    completed batches. Return -EINTR with the exact completed prefix so
    userspace can resume safely without abandoning an in-flight async
    hypercall.
  - Patches 1-5 and 7-9 are unchanged from v6.

Link: 
https://lore.kernel.org/linux-hyperv/[email protected]/

Wei Hu (3):
  mshv: retain memory regions until unmap succeeds
  mshv: clear SynIC mappings before freeing them
  mshv: set up own SynIC registers on a nested root partition

Wei Liu (6):
  mshv: add SEV-SNP UAPI definitions
  mshv: add SEV-SNP PSP request hypercall
  mshv: add SEV-SNP isolated page hypercalls
  mshv: wire SEV-SNP partition ioctls
  mshv: detect and report SEV-SNP support at init
  mshv: use safe partition CPU feature defaults

 drivers/hv/mshv_regions.c      |  522 ++++++++++---
 drivers/hv/mshv_root.h         |  128 ++-
 drivers/hv/mshv_root_hv_call.c |  370 +++++++--
 drivers/hv/mshv_root_main.c    | 1325 ++++++++++++++++++++++++++++++--
 drivers/hv/mshv_synic.c        |  172 +++--
 include/hyperv/hvgdk_mini.h    |   31 +
 include/hyperv/hvhdk.h         |  124 ++-
 include/hyperv/hvhdk_mini.h    |   53 ++
 include/uapi/linux/mshv.h      |  117 ++-
 9 files changed, 2538 insertions(+), 304 deletions(-)

-- 
2.43.0


Reply via email to