Skip to content

feat(aarch64): add WHP backend for ARM64 Windows - #1638

Open
cshung wants to merge 16 commits into
hyperlight-dev:mainfrom
cshung:cshung/whp-aarch64
Open

cshung wants to merge 16 commits into
hyperlight-dev:mainfrom
cshung:cshung/whp-aarch64

Conversation

@cshung

@cshung cshung commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

Implements the WHP (Windows Hypervisor Platform) hypervisor backend for aarch64, enabling hyperlight to run micro-VMs on Windows ARM64 systems.

Resolves #1544

Changes

Structural

  • Restructure whp.rs into whp/ directory (mod.rs + x86_64.rs) to support per-architecture implementations, matching the existing kvm/ and mshv/ pattern
  • Fix super::x86_64::hw_interrupts module path after directory restructure

New: whp/aarch64.rs

  • Manual FFI bindings for ARM64 WHP register names, exit reasons, and exit context layout (extracted from Windows SDK WinHvPlatformDefs.h)
  • Full VirtualMachine trait implementation with:
    • MMIO-based I/O handling (ARM64 has no IO ports)
    • Register get/set via WHvGet/SetVirtualProcessorRegisters
    • Surrogate process support (same pattern as x86_64)

Integration

  • Wire WhpVm into hyperlight_vm/aarch64.rs for Windows platform
  • Add WindowsInterruptHandle for aarch64 Windows
  • Add CpuVendor::current() for aarch64 Windows target

Cross-compilation fix

  • Move vmm-sys-util to unix-only dependencies (it doesn't compile on Windows)

Verification

Verified compilation on three targets:

  • x86_64-pc-windows-msvc (native) — just clippy debug/release pass
  • aarch64-pc-windows-msvc (cross-compile) — cargo check passes
  • aarch64-unknown-linux-gnu (cross-compile) — cargo check --features kvm passes

Note: No runtime testing was possible — requires actual ARM64 Windows hardware with Hyper-V enabled. CI has no ARM64 Windows runners.

Why manual FFI bindings?

The windows crate (v0.62) does not expose ARM64 WHP types (register names, exit reasons, exit context structs). All definitions were extracted from the Windows SDK header WinHvPlatformDefs.h (SDK 10.0.26100.0) which has full ARM64 support behind #ifdef _ARM64_.

Copilot AI review requested due to automatic review settings July 12, 2026 15:02
@cshung cshung added kind/enhancement For PRs adding features, improving functionality, docs, tests, etc. ready-for-review PR is ready for (re-)review labels Jul 12, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a Windows Hypervisor Platform (WHP) backend for Windows/aarch64 so Hyperlight can run micro-VMs on ARM64 Windows systems, aligning WHP’s structure with existing per-arch hypervisor layouts.

Changes:

  • Introduces whp/aarch64.rs implementing the VirtualMachine trait for ARM64 WHP, including MMIO-based exit handling and register get/set via WHvGet/SetVirtualProcessorRegisters.
  • Restructures the WHP backend into whp/ with per-architecture modules and fixes x86_64 interrupt helper module paths.
  • Wires WHP into the aarch64 Hyperlight VM path on Windows and moves vmm-sys-util into unix-only dependencies to fix Windows builds.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 5 comments.

Show a summary per file
File Description
src/hyperlight_host/src/sandbox/snapshot/file/config.rs Adds Windows/aarch64 CPU vendor token for snapshot config.
src/hyperlight_host/src/hypervisor/virtual_machine/whp/x86_64.rs Updates hw_interrupts module paths after WHP directory restructure.
src/hyperlight_host/src/hypervisor/virtual_machine/whp/mod.rs New per-arch WHP module dispatcher (x86_64 vs aarch64).
src/hyperlight_host/src/hypervisor/virtual_machine/whp/aarch64.rs New ARM64 WHP backend implementation and manual ARM64 WHP FFI bindings.
src/hyperlight_host/src/hypervisor/hyperlight_vm/aarch64.rs Selects WHP on Windows/aarch64 and adds Windows interrupt handle wiring.
src/hyperlight_host/Cargo.toml Makes vmm-sys-util unix-only to avoid Windows compilation failures.

Comment thread src/hyperlight_host/src/hypervisor/virtual_machine/whp/aarch64.rs Outdated
Comment thread src/hyperlight_host/src/hypervisor/virtual_machine/whp/aarch64.rs Outdated
Comment thread src/hyperlight_host/src/hypervisor/virtual_machine/whp/aarch64.rs Outdated
Comment thread src/hyperlight_host/src/hypervisor/virtual_machine/whp/aarch64.rs Outdated
Comment thread src/hyperlight_host/src/sandbox/snapshot/file/config.rs Outdated
@cshung
cshung marked this pull request as draft July 13, 2026 02:13
@github-actions github-actions Bot removed the ready-for-review PR is ready for (re-)review label Jul 13, 2026
Comment thread src/hyperlight_host/src/sandbox/snapshot/file/config.rs Outdated
@cshung
cshung force-pushed the cshung/whp-aarch64 branch from 5f992dc to 1d3a299 Compare July 30, 2026 22:14
@jsturtevant jsturtevant mentioned this pull request Aug 5, 2026
2 tasks
@cshung

cshung commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

End-to-end cargo-hyperlight validation completed on the ARM64 WHP hardware.

Using this PR's 0.16 crates, a freshly scaffolded sample successfully built aarch64-hyperlight-none guests and ran through WHP in debug and release. Host callbacks, typed calls, persistent state, snapshot, and restore passed. I also ran the release workflow 10 times with surrogate mappings and 10 times with surrogates disabled. All runs produced the expected output.

The backend works. The published scaffold is the remaining user-experience gap: cargo-hyperlight pins Hyperlight 0.15 and hardcodes the generated host's x64 guest path. Filed hyperlight-dev/cargo-hyperlight#70 with the reproduction and results.

@syntactically syntactically left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks great! I have a bunch of little nits, and also I (more majorly) think that the addition of reset_vcpu to InteruptHandle seems wrong.

Comment thread src/hyperlight_host/src/hypervisor/hyperlight_vm/aarch64.rs Outdated
Comment thread src/hyperlight_host/src/hypervisor/hyperlight_vm/aarch64.rs Outdated
Comment thread src/hyperlight_host/src/hypervisor/hyperlight_vm/aarch64.rs Outdated
Comment thread src/hyperlight_host/src/hypervisor/virtual_machine/whp/aarch64.rs
Comment thread src/hyperlight_host/src/hypervisor/virtual_machine/whp/aarch64.rs
Comment thread src/hyperlight_host/src/hypervisor/virtual_machine/whp/aarch64.rs
Comment thread src/hyperlight_host/src/hypervisor/virtual_machine/whp/x86_64.rs Outdated
Comment thread src/hyperlight_host/src/hypervisor/mod.rs Outdated
Comment thread src/hyperlight_host/tests/integration_test.rs
Comment thread src/hyperlight_host/tests/integration_test.rs
@cshung
cshung force-pushed the cshung/whp-aarch64 branch 5 times, most recently from 7e93813 to 4c2f4e4 Compare August 18, 2026 23:59
@cshung
cshung force-pushed the cshung/whp-aarch64 branch 3 times, most recently from 404a655 to 189317a Compare August 19, 2026 15:45
cshung and others added 11 commits September 28, 2026 21:32
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 6f20a05d-6bee-4e2e-b320-12f8d9759bbc
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Use WHvResetPartition so snapshots preserve partition mappings while resetting virtual processor state. Keep reset ownership in the virtual machine abstraction.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Wait for process-wide partition capacity before allocating GIC-backed ARM64 partitions. Release capacity only after WHP teardown completes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Match WHV_RUN_VP_EXIT_CONTEXT's 16-byte ABI alignment.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 6f20a05d-6bee-4e2e-b320-12f8d9759bbc
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
Fall back to generic MMIO for undecodable ARM64 writes and share file-mapping cleanup across WHP backends.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 6f20a05d-6bee-4e2e-b320-12f8d9759bbc
Signed-off-by: cshung <3410332+cshung@users.noreply.github.com>
@hyperlight-gh-bot

This comment has been minimized.

14 similar comments
@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

This comment has been minimized.

@hyperlight-gh-bot

Copy link
Copy Markdown

Benchmark Results

Measured commit: 4ad16d1bd69c
Baseline commit: 5131e8332f88

kvm / amd (Linux) (➖ stable)

No benchmark improved or regressed.

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 752.93 ns (➖ 1.12x faster)
vec_bytes 582.74 ns (➖ 1.02x slower)
374.36 µs (➖ 1.00x slower)

payload_allocation

slot_pool_segmented
262144 537.05 ns (➖ 1.01x slower)
65536 144.34 ns (➖ 1.01x slower)

sandboxes

create_initialized_and_drop
medium 80.25 ms (➖ 1.06x slower)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
7.76 ns (➖ 1.00x slower) 7.72 ns (➖ 1.00x faster) 7.95 ns (➖ 1.05x faster)

snapshot_files

load_snapshot_unverified
small 89.66 µs (➖ 1.04x faster)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 7.53 µs (➖ 1.07x faster) 6.77 µs (➖ 1.07x faster)
65536 1.93 µs (➖ 1.00x slower) 2.06 µs (➖ 1.06x slower)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 6.43 µs (➖ 1.07x faster) 6.30 µs (➖ 1.04x faster)
8192 1.06 µs (➖ 1.00x slower) 1.07 µs (➖ 1.00x faster)
262144 26.92 µs (➖ 1.05x faster)
kvm / intel (Linux) (➖ stable)

No benchmark improved or regressed.

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 677.16 ns (➖ 1.39x faster)
vec_bytes 510.21 ns (➖ 1.17x faster)
675.09 µs (➖ 1.20x faster)

payload_allocation

slot_pool_segmented
262144 499.45 ns (➖ 1.12x faster)
65536 136.76 ns (➖ 1.11x faster)

sandboxes

create_initialized_and_drop
medium 81.08 ms (➖ 1.28x slower)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
7.11 ns (➖ 1.08x faster) 6.93 ns (➖ 1.20x faster) 7.04 ns (➖ 1.10x faster)

snapshot_files

load_snapshot_unverified
small 45.29 µs (➖ 1.08x faster)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 7.60 µs (➖ 1.11x faster) 7.56 µs (➖ 1.10x faster)
65536 2.13 µs (➖ 1.09x faster) 2.13 µs (➖ 1.10x faster)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 7.14 µs (➖ 1.22x faster) 7.13 µs (➖ 1.24x faster)
8192 749.74 ns (➖ 1.19x faster) 728.88 ns (➖ 1.18x faster)
262144 29.41 µs (➖ 1.20x faster)
mshv3 / amd (Linux) (❌ 1.83x)

Top regressions

  • sandboxes/create_initialized_and_drop/medium — ❌ 1.83x slower

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 957.07 ns (➖ 1.04x faster)
vec_bytes 728.02 ns (➖ 1.08x slower)
269.47 µs (➖ 1.29x faster)

payload_allocation

slot_pool_segmented
262144 720.19 ns (➖ 1.01x slower)
65536 192.87 ns (➖ 1.01x slower)

sandboxes

create_initialized_and_drop
medium 55.68 ms (❌ 1.83x slower)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
9.72 ns (➖ 1.00x faster) 10.02 ns (➖ 1.04x slower) 9.73 ns (➖ 1.00x faster)

snapshot_files

load_snapshot_unverified
small 84.90 µs (➖ 1.09x faster)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 9.16 µs (➖ 1.04x faster) 9.03 µs (➖ 1.00x faster)
65536 2.24 µs (➖ 1.06x faster) 2.24 µs (➖ 1.05x faster)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 8.19 µs (➖ 1.10x faster) 8.14 µs (➖ 1.05x faster)
8192 1.29 µs (➖ 1.02x slower) 1.36 µs (➖ 1.09x slower)
262144 36.98 µs (➖ 1.05x faster)
mshv3 / intel (Linux) (❌ 1.57x)

Top regressions

  • sandboxes/create_initialized_and_drop/medium — ❌ 1.57x slower

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 823.49 ns (➖ 1.18x faster)
vec_bytes 595.75 ns (➖ 1.03x faster)
770.42 µs (➖ 1.07x slower)

payload_allocation

slot_pool_segmented
262144 603.91 ns (➖ 1.01x slower)
65536 162.65 ns (➖ 1.04x slower)

sandboxes

create_initialized_and_drop
medium 61.28 ms (❌ 1.57x slower)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
8.25 ns (➖ 1.03x slower) 8.23 ns (➖ 1.02x slower) 8.25 ns (➖ 1.03x slower)

snapshot_files

load_snapshot_unverified
small 45.74 µs (➖ 1.01x slower)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 8.92 µs (➖ 1.03x slower) 8.97 µs (➖ 1.03x slower)
65536 2.52 µs (➖ 1.04x slower) 2.51 µs (➖ 1.02x slower)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 8.50 µs (➖ 1.06x faster) 8.50 µs (➖ 1.05x faster)
8192 882.12 ns (➖ 1.01x slower) 880.96 ns (➖ 1.05x faster)
262144 34.63 µs (➖ 1.05x faster)
hyperv-ws2025 / amd (Windows) (❌ 1.76x)

Top regressions

  • sandboxes/create_initialized_and_drop/medium — ❌ 1.76x slower

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 1.12 µs (➖ 1.03x faster)
vec_bytes 799.56 ns (➖ 1.00x faster)
2.15 ms (➖ 1.18x slower)

payload_allocation

slot_pool_segmented
262144 780.81 ns (➖ 1.03x faster)
65536 242.46 ns (➖ 1.10x slower)

sandboxes

create_initialized_and_drop
medium 113.51 ms (❌ 1.76x slower)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
10.56 ns (➖ 1.05x slower) 10.56 ns (➖ 1.04x slower) 10.57 ns (➖ 1.04x slower)

snapshot_files

load_snapshot_unverified
small 725.07 µs (➖ 1.11x slower)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 8.83 µs (➖ 1.09x faster) 10.14 µs (➖ 1.05x slower)
65536 2.57 µs (➖ 1.07x slower) 2.57 µs (➖ 1.08x slower)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 8.76 µs (➖ 1.02x faster) 9.10 µs (➖ 1.02x slower)
8192 1.45 µs (➖ 1.12x slower) 1.44 µs (➖ 1.12x slower)
262144 39.45 µs (➖ 1.01x faster)
hyperv-ws2025 / intel (Windows) (❌ 1.51x)

Top regressions

  • virtq_readwrite/slot_pool_segmented/262144 — ❌ 1.51x slower

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 1.21 µs (➖ 1.04x slower)
vec_bytes 801.52 ns (➖ 1.04x slower)
2.96 ms (➖ 1.01x slower)

payload_allocation

slot_pool_segmented
262144 755.80 ns (➖ 1.05x faster)
65536 212.12 ns (➖ 1.11x faster)

sandboxes

create_initialized_and_drop
medium 106.77 ms (➖ 1.18x slower)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
10.48 ns (➖ 1.04x slower) 9.97 ns (➖ 1.07x faster) 9.97 ns (➖ 1.01x faster)

snapshot_files

load_snapshot_unverified
small 608.08 µs (➖ 1.26x slower)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 7.81 µs (➖ 1.00x faster) 7.64 µs (➖ 1.02x faster)
65536 2.38 µs (➖ 1.02x slower) 2.31 µs (➖ 1.00x faster)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 8.49 µs (➖ 1.01x faster) 8.30 µs (➖ 1.00x slower)
8192 1.15 µs (➖ 1.05x slower) 1.11 µs (➖ 1.04x faster)
262144 58.49 µs (❌ 1.51x slower)

Reported by cargo ci bench-report --candidate run:36597233968 --baseline run:36361996946 --config-file bench_report.toml.

@cshung
cshung marked this pull request as ready for review September 29, 2026 17:37

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/enhancement For PRs adding features, improving functionality, docs, tests, etc.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support AArch64 on Windows

3 participants