Repository navigation
Qualify the AMD CPU profiles on MSHV, WHP, and bare-metal hosts, and pin profiles for AMD client CPUs #409
Description
Activity
- added 2 commits that reference this issue
on Oct 6, 2026 ppenna commented
on Oct 8, 2026 ContributorAuthorMore actionsamd.genoa.v1fails on Genoa under nested MSHV on AzureAn Azure Dalsv6 VM (Standard_D64als_v6, EPYC 9V74, 25/17 stepping 1), whose Azure Linux 3.0 root partition (
6.6.148-200.mshv-b1f02da.azl3) runs on a nested Microsoft hypervisor (10.0.26100.9444), cannot cold-boot a microVM with--cpu-profile auto. Withv0.1.0-dev.f813dc76cd23, whose OpenVMM is the revision thatdevpins (3e1f5bd4), every cold boot fails before the guest runs:[E_PROFILE_UNSUPPORTED] the hypervisor's processor features cannot present CPU profile amd.genoa.v1: they lack tsa_l1_no_support, tsa_sq_no_supportCause
amd.genoa.v1pins what one GitHub-hosted runner's KVM offers on an Azure VM with the same CPU. The nested hypervisor's partitions, the root included, see less:CPUID amd.genoa.v1(the runner's KVM)This host's MSHV 0x0EAX, the maximum basic leaf0x1c0xd0x80000021EAX:LFENCEserialization (bit 2) and NoSmmCtlMsr (bit 9)0x20400x80000021ECX: TSA_SQ_NO (bit 1) and TSA_L1_NO (bit 2)0x60The TSA immunities are only the first check to fail. The host partition's processor features (
ProcessorFeatures10x50e00001ed) offer none of the bits that control0x80000021, so a cold boot stops there, but the support check that follows would also fail on the other two rows: a hypervisor that added only the TSA immunities would still failamd.genoa.v1.--cpu-fingerprintreports all three (surface digestsha256:0d4f63812ed2feae52196f88a16733f54b3822389ef062c8a0c31cdb31083585). The root's kernel reports TSA asVulnerable: Clear CPU buffers attempted, no microcode.amd.milan.v1, derived from nested WHP on Azure, has the same shape: maximum basic leaf0xdand nothing in0x80000021. The gap is therefore likely in what the Microsoft hypervisor presents to partitions on AMD CPUs, not in this VM.amd.turin.v1pins the same maximum basic leaf and0x80000021values asamd.genoa.v1, so Turin hosts on MSHV or WHP likely fail the same way; that is unverified.--cpu-profile hostboots on this host (amd.host.v1), butdoctornever qualifies a host profile.Fix in progress
The nanvix/openvmm branch
esaurez/cpu-profile-genoa-v2-20261007(d946e7a8, no pull request yet) pinsamd.genoa.v2, derived from the runner's KVM fingerprint and this host's MSHV fingerprint, which itstest_support::GENOA_MSHV_CPUIDandGENOA_MSHV_HOSTrecord. It isamd.genoa.v1with nothing in0x80000021and the maximum basic leaf0xd, so its Linux guests report TSA as vulnerable, as underamd.milan.v1.autoselects it on every Genoa host.amd.genoa.v1stays selectable by ID, so its snapshots still restore where it is supported.- Its author validated a build of it on this host, all on
auto: the fingerprint check passes, the time ABI preflight passes with 1 and 4 VPs, a 2-VP guest boots, and snapshot captures and restores pass. The host's surface digest has not changed since. - The commit applies cleanly to OpenVMM's
main(3e1f5bd4), wherecargo test -p cpu_profile(115 tests) andvirt_whp's time ABI tests (24, with 8 that need hardware ignored) pass on Windows.
Promoting it into NVX takes more than the gitlink. With
amd.genoa.v2pinned,test_the_catalog_copy_matches_openvmm_pinned_profilesfails, as it should on a second revision: NVX's copy of the catalog (CPU_GENERATIONSinscripts/nvx_tools/time_abi.py) names one profile per generation, alwaysv1(CpuGeneration.profile_id), whichdoctor --no-openvmmreports.doc/usage.md,doc/design/time-abi.md, anddoc/ci.mdalso nameamd.genoa.v1as Genoa's profile.This host can also serve the plan's qualification of the MSHV backend's AMD paths (per-VP
0x8000001E,HWCR, andDE_CFG).Reproduction
$RELis the extractednvx-0.1.0-linux-mshvpackage ofv0.1.0-dev.f813dc76cd23.$ $REL/bin/openvmm --machine microvm --hypervisor mshv --processors 1 --memory 256M \ --kernel $REL/guest/vmlinux --initrd $REL/guest/initramfs.cpio.gz --x-time-abi-verify NVX-TIME-ABI-VERIFY: v=1 status=fail backend=mshv code=E_PROFILE_UNSUPPORTED detail="failed to launch vm worker: ... [E_PROFILE_UNSUPPORTED] the hypervisor's processor features cannot present CPU profile amd.genoa.v1: they lack tsa_l1_no_support, tsa_sq_no_suppo..." $ $REL/bin/openvmm --hypervisor mshv --cpu-fingerprint fingerprint.json NVX-CPU-PROFILE: status=fail backend=mshv generation=genoa profile=amd.genoa.v1 profile_digest=sha256:894ac647... surface_digest=sha256:0d4f6381... host_invariant_tsc=no code=E_PROFILE_UNSUPPORTED detail="the backend does not support CPU profile amd.genoa.v1: CPUID 0x0 EAX[31:0] is 0x1c, above the supported 0xd; CPUID 0x80000021 EAX bits 2, 9 are not supported; CPUID 0x80000021 ECX bits 1, 2 are not supported; ..." $ $REL/bin/openvmm --machine microvm --hypervisor mshv --processors 1 --memory 256M \ --kernel $REL/guest/vmlinux --initrd $REL/guest/initramfs.cpio.gz --x-time-abi-verify \ --cpu-profile host NVX-TIME-ABI-VERIFY: v=1 status=ok backend=mshv cpu_profile=amd.host.v1 tsc_hz=2596150073 native_tsc_hz=2596150073 lapic_hz=200000000 msr_route=ExitToVmm sync=FrozenWrite
The fingerprint check's elided entries, which lie outside the profile, come from the fingerprint's probe partition, which enables every feature: the check reads them there because
amd.genoa.v1already failed. Onamd.genoa.v2, it reads them on a partition configured from the profile, and passes.- Its author validated a build of it on this host, all on
- added 7 commits that reference this issue
on Oct 8, 2026
Summary
#396 added AMD support to the time ABI's CPU profiles. #404 pinned
amd.milan.v1from one nested-WHP fingerprint. #412 pinnedamd.genoa.v1andamd.turin.v1from KVM fingerprints of GitHub-hosted Actions runners, and qualified all three profiles on KVM on those runners. What remains needs AMD hosts that neither the configured development hosts nor the CI runners provide:0x8000001Eresults and theHWCRandDE_CFGinterceptsE_PROFILE_UNSUPPORTED, which names--cpu-profile host, until a later revision intersects its fingerprint. Genoa and Turin are unverified on MSHV and WHP, and Milan on MSHVIBRS,STIBP, orSSBD, so no AMD profile has them, and their Linux guests mitigate Spectre v2 with retpolines. On Genoa, Azure presents the TSA immunities of0x80000021ECX.amd.genoa.v1pins them, so it fails on a bare-metal Genoa host whose KVM, under a host kernel that applies theVERWmitigation, does not report themautofails withE_PROFILE_HOST_UNKNOWN, and--cpu-profile hostserves them. Client CPUs: the Ryzen models of Zen 3, Zen 4, and Zen 5. Other server models: Bergamo, Siena, and Turin DensePlan
nvx.py doctorandnvx.py test-microvm, and derivev2revisions that intersect the fingerprints of every backend.amd.genoa.v1on the TSA immunities, the maximum basic leaf, and0x80000021EAX (Qualify the AMD CPU profiles on MSHV, WHP, and bare-metal hosts, and pin profiles for AMD client CPUs #409 (comment)).amd.genoa.v2, which intersects that fingerprint with the runner's KVM fingerprint (nanvix/openvmm branchesaurez/cpu-profile-genoa-v2-20261007), and promote it into NVX with the catalog copy inscripts/nvx_tools/time_abi.py, its test, and the docs that nameamd.genoa.v1.amd.genoa.v2withnvx.py doctorandnvx.py test-microvm --backend mshv.amd.turin.v1pins the same maximum basic leaf and0x80000021values asamd.genoa.v1.0x8000001Eresults and itsHWCRandDE_CFGintercepts on an AMD MSHV host.openvmm --hypervisor whp --cpu-fingerprint fingerprint.jsonwrites the fingerprint before it fails withE_PROFILE_HOST_UNKNOWN.Until then,
run --cpu-profile hostboots the hosts that no built-in profile serves.