Skip to content

Enable paravirt guest support, AMD CPUs, haltpoll and hardening in the x86_64 kernel config - #950

Merged
crosbymichael merged 1 commit into
apple:mainfrom
vincepri:kernel-x86-paravirt
Oct 8, 2026
Merged

crosbymichael merged 1 commit into
apple:mainfrom
vincepri:kernel-x86-paravirt

Conversation

@vincepri

@vincepri vincepri commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Paravirt guest support (HYPERVISOR_GUEST, PARAVIRT, PARAVIRT_SPINLOCKS, KVM_GUEST, PARAVIRT_CLOCK, PVH, X86_X2APIC). X86_X2APIC needs HYPERVISOR_GUEST (or IRQ_REMAP), so the config could not enable it. cloud-hypervisor describes vCPUs only with x2APIC MADT entries, so an x86_64 guest booted with 1 usable CPU, whatever the VM's vCPU count. KVM_GUEST adds kvm-clock, paravirt spinlocks and paravirt TLB flush.

CPU_SUP_AMD. Without it, a guest on an AMD host logs CPU: vendor_id 'AuthenticAMD' unknown, using generic init. and skips the AMD CPU init. That init detects the AMD speculation issues (for example SRSO and Retbleed) and selects their mitigations, so the guest reported them as "Not affected" without a check.

Haltpoll cpuidle (ARCH_CPUIDLE_HALTPOLL, HALTPOLL_CPUIDLE, CPU_IDLE_GOV_HALTPOLL): the guest polls briefly before an idle vCPU halts. The driver loads only when the host sets the KVM realtime hint or the kernel command line has cpuidle_haltpoll.force=1, so the default does not change.

Hardening: X86_UMIP, HARDENED_USERCOPY, BPF_UNPRIV_DEFAULT_OFF (the Kconfig default; the kernel.unprivileged_bpf_disabled sysctl can still change it) and X86_INTEL_MEMORY_PROTECTION_KEYS (the Kconfig default; pkey_* system calls for guest processes, on Intel and AMD).

Edited in place, as for earlier config changes.

Tests

  • linux-6.18.5 x86_64 build with kernel/build.sh: every option above is set after olddefconfig.
  • Boot under cloud-hypervisor v52.0 on an Intel KVM host, bzImage and vmlinux (PVH): 8 of 8 and 16 of 16 vCPUs online. The kernel from the current config: 1 of 8.
  • Not booted on an AMD host.

…e x86_64 kernel config

Paravirt guest support (HYPERVISOR_GUEST, PARAVIRT, PARAVIRT_SPINLOCKS,
KVM_GUEST, PARAVIRT_CLOCK, PVH, X86_X2APIC). X86_X2APIC needs
HYPERVISOR_GUEST (or IRQ_REMAP), so the config could not enable it.
cloud-hypervisor describes vCPUs only with x2APIC MADT entries, so an
x86_64 guest booted with 1 usable CPU, whatever the VM's vCPU count.
KVM_GUEST adds kvm-clock, paravirt spinlocks and paravirt TLB flush.

CPU_SUP_AMD. Without it, a guest on an AMD host logs "CPU: vendor_id
'AuthenticAMD' unknown, using generic init." and skips the AMD CPU init.
That init detects the AMD speculation issues (for example SRSO and
Retbleed) and selects their mitigations, so the guest reported them as
"Not affected" without a check, and ran the Intel BHI sequences instead.

Haltpoll cpuidle (ARCH_CPUIDLE_HALTPOLL, HALTPOLL_CPUIDLE,
CPU_IDLE_GOV_HALTPOLL): the guest polls briefly before an idle vCPU halts.
The driver loads only when the host sets the KVM realtime hint or the
kernel command line has cpuidle_haltpoll.force=1, so the default does not
change.

Hardening: X86_UMIP, HARDENED_USERCOPY, BPF_UNPRIV_DEFAULT_OFF (the
Kconfig default; the kernel.unprivileged_bpf_disabled sysctl can still
change it) and X86_INTEL_MEMORY_PROTECTION_KEYS (the Kconfig default;
pkey_* system calls for guest processes, on Intel and AMD).

Edited in place, as for earlier config changes.
@crosbymichael
crosbymichael merged commit c0a6f76 into apple:main Oct 8, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants