tests: enable KVM SEV-SNP confidential VM integration tests

Bring the confidential VM (CVM) integration tests up on the KVM SEV-SNP
backend in addition to MSHV. On KVM the IGVM is an Oak stage0 firmware
image and the guest kernel is supplied separately: stage0 reads the
kernel, cmdline and E820 over fw_cfg. The test harness selects this
model when a guest kernel is present at /igvm_files/bzImage, mirroring
how the stage0 IGVM is discovered; MSHV keeps using the monolithic IGVM
with the kernel baked in.

  - test_infra: stage0 + direct-kernel + fw_cfg boot wiring (both the
    command line and the HTTP/D-Bus API path) plus an on_kvm_sev_snp()
    helper for tests to branch on.
  - tests: the CVM tests that don't work on the KVM SEV-SNP path yet are
    gated with #[cfg(not(feature = "kvm"))] inside the common_cvm module.
    The MSHV build enables mshv,igvm,sev_snp (no kvm feature) while the
    KVM build enables kvm,igvm,sev_snp,fw_cfg, so the cfg compiles these
    tests into the MSHV binary only and drops them on KVM; both
    hypervisors run the single common_cvm nextest profile. They all still
    run on MSHV:
      * test_pci_multiple_segments - stage0 places all 64-bit BARs in a
        single global window, so a BAR allocated in a different
        per-segment window is relocated cross-window and wedges boot.
      * test_dmi_uuid / test_dmi_oem_strings /
        test_dmi_system_and_chassis - SMBIOS is not delivered to SEV-SNP
        guests on the KVM stage0 boot path, so the guest's DMI tables
        read empty. VMM follow-up.
      * test_vdpa_block - needs host vdpa_sim_blk setup, and vDPA DMA
        into SEV-SNP-encrypted memory is unsupported (the guest hangs).

Assisted-by: Claude:Opus-4.8
Signed-off-by: Ruben Hakobyan <hruben@meta.com>
This commit is contained in:
Ruben Hakobyan
2026-06-08 08:30:22 -07:00
committed by Rob Bradford
parent b1d33ec9aa
commit 2fc37a3235
6 changed files with 80 additions and 5 deletions

View File

@@ -354,6 +354,33 @@ mshv,igvm,sev_snp` and requires IGVM files to be present at
**Test group:** `common_cvm` (`nproc / 4` threads, retries 3).
#### KVM SEV-SNP
```shell
scripts/dev_cli.sh tests --integration-cvm --hypervisor kvm
```
With `--hypervisor kvm` the script builds with `--features
kvm,igvm,sev_snp,fw_cfg`. On KVM the IGVM is an Oak stage0 firmware image
and the guest kernel is supplied separately (read by stage0 over fw_cfg);
the harness selects this boot model when a guest kernel is present at
`/igvm_files/bzImage`. When no `--test-filter`
is given it runs the full `common_cvm` set.
Prerequisites:
- An AMD SEV-SNP-capable KVM host with `/dev/kvm` and `/dev/sev` present
and SNP enabled.
- A KVM-bootable stage0 IGVM file at `/usr/share/cloud-hypervisor/cvm` and
a guest kernel at `/igvm_files/bzImage`.
To scope the run to a single test explicitly:
```shell
scripts/dev_cli.sh tests --integration-cvm --hypervisor kvm \
-- --test-filter test_jammy_simple_launch
```
## Performance metrics
```shell