On Tue, Sep 01, 2026 at 09:55:18AM -0700, Thara Gopinath wrote:
> Set bit 0 of the Hyper-V private OsLoaderIndications EFI variable
> during exit_boot() so the bootloader/firmware knows the OS intends
> to enable VTL1. Without this, VTL1 cannot be brought up from the
> Linux kernel.
>
> The support bit is first checked in OsLoaderIndicationsSupported,
> and the variable is only written when the VSM bit is not already
> set.
>
> Signed-off-by: Thara Gopinath <[email protected]>
> ---
> drivers/firmware/efi/libstub/x86-stub.c | 57 +++++++++++++++++++++++++
> 1 file changed, 57 insertions(+)
>
[...]
> +#ifdef CONFIG_HYPERV_VSM
> +static void efi_set_hv_os_indications(void)
> +{
> + efi_guid_t guid = HYPERV_PRIVATE_EFI_NAMESPACE_GUID;
> + efi_status_t status;
> + unsigned long size;
> + u32 attr, val;
> +
> + size = sizeof(val);
> + status = get_efi_var(efi_HvPrivOsloaderIndicationsSupported_name,
> + &guid, &attr, &size, &val);
> + if (status != EFI_SUCCESS) {
> + efi_err("Could not read Hyper-V
> OsloaderIndicationsSupported\n");
> + return;
> + }
> +
> + if (!(val & HV_OSLOADER_INDICATION_VSM)) {
> + efi_info("Hyper-V does not support VSM in
> OsloaderIndicationsSupported\n");
> + return;
> + }
> +
> + size = sizeof(val);
> + status = get_efi_var(efi_HvPrivOsloaderIndications_name, &guid, &attr,
> &size, &val);
> + if (status != EFI_SUCCESS) {
> + efi_err("Could not read Hyper-V OsLoaderIndications\n");
> + return;
> + }
> +
> + if (val & HV_OSLOADER_INDICATION_VSM) {
> + efi_info("VSM is already supported in OsLoaderIndications.");
> + return;
> + }
> +
> + val |= HV_OSLOADER_INDICATION_VSM;
> + size = sizeof(val);
> + status = set_efi_var(efi_HvPrivOsloaderIndications_name, &guid, attr,
> size, &val);
I'm not familiar with the security model, so bear with me.
What happens if the VTL0 kernel doesn't use VTL1 at all? Does that
become a security issue, that malware can use the VTL1 to hide itself?
Asking this because I think you will want to enable this in the generic
kernel(s). Not all users have or want to package a secure kernel.
Wei
> + if (status != EFI_SUCCESS)
> + efi_err("Could not set Hyper-V OsLoaderIndications to indicate
> VSM support\n");
> +}
> +#endif
> +
> static efi_status_t exit_boot(struct boot_params *boot_params, void *handle)
> {
> struct setup_data *e820ext = NULL;
> @@ -768,6 +820,11 @@ static efi_status_t exit_boot(struct boot_params
> *boot_params, void *handle)
> if (status != EFI_SUCCESS)
> return status;
>
> +#ifdef CONFIG_HYPERV_VSM
> + /* Indicate to bootloader that we will be enabling VTL1 before exiting
> boot services */
> + efi_set_hv_os_indications();
> +#endif
> +
> /* Might as well exit boot services now */
> status = efi_exit_boot_services(handle, &priv, exit_boot_func);
> if (status != EFI_SUCCESS)
> --
> 2.34.1
>