From: Rick Edgecombe <rick.p.edgecombe@intel.com>
To: bp@alien8.de, dave.hansen@intel.com, hpa@zytor.com,
kas@kernel.org, kvm@vger.kernel.org, linux-coco@lists.linux.dev,
linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org,
mingo@redhat.com, nik.borisov@suse.com, pbonzini@redhat.com,
seanjc@google.com, tglx@kernel.org, vannapurve@google.com,
x86@kernel.org, chao.gao@intel.com, yan.y.zhao@intel.com,
kai.huang@intel.com
Cc: rick.p.edgecombe@intel.com,
"Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
Subject: [PATCH v6 10/11] x86/virt/tdx: Enable Dynamic PAMT
Date: Mon, 25 May 2026 19:35:14 -0700 [thread overview]
Message-ID: <20260526023515.288829-11-rick.p.edgecombe@intel.com> (raw)
In-Reply-To: <20260526023515.288829-1-rick.p.edgecombe@intel.com>
From: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
The Physical Address Metadata Table (PAMT) holds TDX metadata for
physical memory and must be allocated by the kernel during TDX module
initialization. Dynamic PAMT is a TDX module feature that can reduce this
memory use by allocating part of the PAMT dynamically.
All pieces are in place to Enable Dynamic PAMT if it is supported.
Determine if the TDX module supports it by checking the 'features0' bit
exposed by the TDX module.
The TDX module also exposes information about whether the *system* (and
not the module) supports Dynamic PAMT.
The TDX module documentation describes how PAMT works internally. To allow
the last level to be dynamically allocated, it uses a 3 level tree
structure, not unlike page tables. Like page tables, it has a maximum
address space that it can cover. This address space can be covered in 48
bits. If the host physical address space is higher than this, than the
TDX module can't guarantee the tree will be able to cover the TDX memory.
The TDX module exposes this system support via metadata stating the
minimum number of HKIDs that need to be available in order for Dynamic
PAMT to be usable. The reasoning appears to be that more HKIDs can shrink
the "real" addressable physical address bits enough to make the 48 bit
Dynamic PAMT limit workable on high physical address width HW. However,
the docs also clearly explain the 48 bit limit and how this fits into the
Dymamic PAMT tree constraints.
The handy x86_phys_bits value is already read and adjusted for keyid bits.
So just compare that against 48 instead of reading more metadata and
burdening the code with the more tenuous connection to minimum HKID bits.
Signed-off-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Co-developed-by: Rick Edgecombe <rick.p.edgecombe@intel.com>
Signed-off-by: Rick Edgecombe <rick.p.edgecombe@intel.com>
---
v6:
- After Nikolai pointed out that the TDX docs actually have the Dynamic
PAMT pages-per-2MB region fixed at 2 instead of variable sized, I
checked over the docs more closely looking for anything else that might
have been missed. Spotted this 48 bit physical address bit check in the
docs, so added it.
---
arch/x86/include/asm/tdx.h | 11 ++++++++++-
arch/x86/virt/vmx/tdx/tdx.c | 11 +++++++++--
arch/x86/virt/vmx/tdx/tdx.h | 3 ---
3 files changed, 19 insertions(+), 6 deletions(-)
diff --git a/arch/x86/include/asm/tdx.h b/arch/x86/include/asm/tdx.h
index 191da84bbf2a1..187014686df3e 100644
--- a/arch/x86/include/asm/tdx.h
+++ b/arch/x86/include/asm/tdx.h
@@ -33,6 +33,10 @@
#define TDX_SUCCESS 0ULL
#define TDX_RND_NO_ENTROPY 0x8000020300000000ULL
+/* Bit definitions of TDX_FEATURES0 metadata field */
+#define TDX_FEATURES0_NO_RBP_MOD BIT_ULL(18)
+#define TDX_FEATURES0_DYNAMIC_PAMT BIT_ULL(36)
+
#ifndef __ASSEMBLER__
#include <uapi/asm/mce.h>
@@ -152,7 +156,12 @@ const struct tdx_sys_info *tdx_get_sysinfo(void);
static inline bool tdx_supports_dynamic_pamt(const struct tdx_sys_info *sysinfo)
{
- return false; /* To be enabled when kernel is ready */
+ /*
+ * The TDX Module's internal Dynamic PAMT tree structure can't
+ * handle physical addresses with more than 48 bits.
+ */
+ return sysinfo->features.tdx_features0 & TDX_FEATURES0_DYNAMIC_PAMT &&
+ boot_cpu_data.x86_phys_bits <= 48;
}
/* Simple structure for pre-allocating Dynamic PAMT pages outside of locks. */
diff --git a/arch/x86/virt/vmx/tdx/tdx.c b/arch/x86/virt/vmx/tdx/tdx.c
index 3544794fb092a..75140511571bf 100644
--- a/arch/x86/virt/vmx/tdx/tdx.c
+++ b/arch/x86/virt/vmx/tdx/tdx.c
@@ -1028,8 +1028,9 @@ static __init int construct_tdmrs(struct list_head *tmb_list,
return ret;
}
-static __init int config_tdx_module(struct tdmr_info_list *tdmr_list,
- u64 global_keyid)
+#define TDX_SYS_CONFIG_DYNAMIC_PAMT BIT(16)
+
+static __init int config_tdx_module(struct tdmr_info_list *tdmr_list, u64 global_keyid)
{
struct tdx_module_args args = {};
u64 *tdmr_pa_array;
@@ -1056,6 +1057,12 @@ static __init int config_tdx_module(struct tdmr_info_list *tdmr_list,
args.rcx = __pa(tdmr_pa_array);
args.rdx = tdmr_list->nr_consumed_tdmrs;
args.r8 = global_keyid;
+
+ if (tdx_supports_dynamic_pamt(&tdx_sysinfo)) {
+ pr_info("Enable Dynamic PAMT\n");
+ args.r8 |= TDX_SYS_CONFIG_DYNAMIC_PAMT;
+ }
+
ret = seamcall_prerr(TDH_SYS_CONFIG, &args);
/* Free the array as it is not required anymore. */
diff --git a/arch/x86/virt/vmx/tdx/tdx.h b/arch/x86/virt/vmx/tdx/tdx.h
index 8c39dde347cc2..68a68468fbeb6 100644
--- a/arch/x86/virt/vmx/tdx/tdx.h
+++ b/arch/x86/virt/vmx/tdx/tdx.h
@@ -86,9 +86,6 @@ struct tdmr_info {
DECLARE_FLEX_ARRAY(struct tdmr_reserved_area, reserved_areas);
} __packed __aligned(TDMR_INFO_ALIGNMENT);
-/* Bit definitions of TDX_FEATURES0 metadata field */
-#define TDX_FEATURES0_NO_RBP_MOD BIT(18)
-
/*
* Do not put any hardware-defined TDX structure representations below
* this comment!
--
2.54.0
next prev parent reply other threads:[~2026-05-26 2:35 UTC|newest]
Thread overview: 107+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-26 2:35 [PATCH v6 00/11] " Rick Edgecombe
2026-05-26 2:35 ` [PATCH v6 01/11] x86/virt/tdx: Simplify tdmr_get_pamt_sz() Rick Edgecombe
2026-06-04 16:05 ` Kiryl Shutsemau
2026-07-01 0:08 ` Edgecombe, Rick P
2026-06-11 18:25 ` Vishal Annapurve
2026-07-03 5:48 ` Chao Gao
2026-07-06 20:18 ` Edgecombe, Rick P
2026-07-07 3:24 ` Yan Zhao
2026-07-07 19:08 ` Edgecombe, Rick P
2026-07-07 23:22 ` Sohil Mehta
2026-07-08 1:23 ` Edgecombe, Rick P
2026-05-26 2:35 ` [PATCH v6 02/11] x86/virt/tdx: Allocate page bitmap for Dynamic PAMT Rick Edgecombe
2026-06-04 16:14 ` Kiryl Shutsemau
2026-07-01 0:14 ` Edgecombe, Rick P
2026-06-11 18:47 ` Vishal Annapurve
2026-07-03 8:26 ` Chao Gao
2026-07-07 3:59 ` Yan Zhao
2026-07-07 21:25 ` Edgecombe, Rick P
2026-07-08 0:49 ` Sohil Mehta
2026-07-08 2:07 ` Edgecombe, Rick P
2026-07-08 2:10 ` Edgecombe, Rick P
2026-07-08 3:35 ` Sohil Mehta
2026-07-08 20:50 ` Edgecombe, Rick P
2026-07-08 21:20 ` Sohil Mehta
2026-05-26 2:35 ` [PATCH v6 03/11] x86/virt/tdx: Add tdx_alloc/free_control_page() helpers Rick Edgecombe
2026-06-08 2:11 ` Binbin Wu
2026-06-08 2:18 ` Yan Zhao
2026-07-01 0:15 ` Edgecombe, Rick P
2026-07-06 12:31 ` Chao Gao
2026-07-06 20:23 ` Edgecombe, Rick P
2026-07-08 3:50 ` Sohil Mehta
2026-07-08 22:54 ` Edgecombe, Rick P
2026-05-26 2:35 ` [PATCH v6 04/11] x86/virt/tdx: Allocate ref counts for Dynamic PAMT memory Rick Edgecombe
2026-07-02 7:20 ` Binbin Wu
2026-07-06 20:26 ` Edgecombe, Rick P
2026-07-06 13:22 ` Chao Gao
2026-07-06 20:26 ` Edgecombe, Rick P
2026-07-07 4:53 ` Yan Zhao
2026-07-07 22:32 ` Edgecombe, Rick P
2026-07-08 20:49 ` Sohil Mehta
2026-07-08 23:21 ` Edgecombe, Rick P
2026-05-26 2:35 ` [PATCH v6 05/11] x86/virt/tdx: Handle concurrent callers in tdx_pamt_get/put() Rick Edgecombe
2026-07-02 7:39 ` Binbin Wu
2026-07-06 20:27 ` Edgecombe, Rick P
2026-07-07 5:54 ` Chao Gao
2026-07-08 6:46 ` Yan Zhao
2026-07-09 0:33 ` Edgecombe, Rick P
2026-07-09 2:50 ` Yan Zhao
2026-07-09 23:09 ` Edgecombe, Rick P
2026-07-10 2:24 ` Yan Zhao
2026-07-08 19:01 ` Dave Hansen
2026-07-08 21:03 ` Edgecombe, Rick P
2026-07-08 21:11 ` Sohil Mehta
2026-07-08 21:13 ` Dave Hansen
2026-05-26 2:35 ` [PATCH v6 06/11] x86/virt/tdx: Optimize tdx_pamt_get/put() Rick Edgecombe
2026-05-26 8:57 ` Chao Gao
2026-05-26 16:42 ` Edgecombe, Rick P
2026-06-04 16:59 ` Kiryl Shutsemau
2026-06-05 5:40 ` Chao Gao
2026-06-05 11:42 ` Kiryl Shutsemau
2026-06-05 16:23 ` Dave Hansen
2026-06-08 9:14 ` Kiryl Shutsemau
2026-06-08 9:50 ` Yan Zhao
2026-07-01 1:45 ` Edgecombe, Rick P
2026-07-01 5:37 ` Yan Zhao
2026-07-01 1:05 ` Edgecombe, Rick P
2026-07-07 6:45 ` Chao Gao
2026-07-08 8:46 ` Yan Zhao
2026-07-09 0:44 ` Edgecombe, Rick P
2026-05-26 2:35 ` [PATCH v6 07/11] KVM: TDX: Allocate PAMT memory for TD and vCPU control structures Rick Edgecombe
2026-07-02 8:55 ` Binbin Wu
2026-07-06 23:47 ` Sean Christopherson
2026-07-06 23:54 ` Edgecombe, Rick P
2026-07-07 0:25 ` Sean Christopherson
2026-07-08 18:30 ` Dave Hansen
2026-07-07 6:54 ` Chao Gao
2026-07-08 9:13 ` Yan Zhao
2026-07-09 1:12 ` Edgecombe, Rick P
2026-07-09 3:18 ` Yan Zhao
2026-07-10 1:04 ` Edgecombe, Rick P
2026-07-10 2:43 ` Yan Zhao
2026-05-26 2:35 ` [PATCH v6 08/11] x86/tdx: Add APIs to support Dynamic PAMT ops from KVM's fault path Rick Edgecombe
2026-06-04 17:11 ` Kiryl Shutsemau
2026-07-02 9:32 ` Binbin Wu
2026-07-07 7:25 ` Chao Gao
2026-07-09 7:17 ` Yan Zhao
2026-07-10 1:34 ` Edgecombe, Rick P
2026-07-10 2:47 ` Yan Zhao
2026-05-26 2:35 ` [PATCH v6 09/11] KVM: TDX: Get/put PAMT pages when (un)mapping private memory Rick Edgecombe
2026-07-03 3:15 ` Binbin Wu
2026-07-06 20:47 ` Edgecombe, Rick P
2026-07-06 21:02 ` Sean Christopherson
2026-07-06 21:52 ` Edgecombe, Rick P
2026-07-08 8:35 ` Chao Gao
2026-07-09 1:22 ` Edgecombe, Rick P
2026-05-26 2:35 ` Rick Edgecombe [this message]
2026-06-04 17:14 ` [PATCH v6 10/11] x86/virt/tdx: Enable Dynamic PAMT Kiryl Shutsemau
2026-06-05 5:25 ` Chao Gao
2026-07-01 1:20 ` Edgecombe, Rick P
2026-07-06 20:48 ` Edgecombe, Rick P
2026-07-03 4:35 ` Binbin Wu
2026-05-26 2:35 ` [PATCH v6 11/11] Documentation/x86: Add documentation for TDX's " Rick Edgecombe
2026-07-03 4:54 ` Binbin Wu
2026-06-08 5:45 ` [PATCH v6 00/11] " Tony Lindgren
2026-07-06 21:01 ` Edgecombe, Rick P
2026-07-07 16:17 ` Sean Christopherson
2026-07-07 17:25 ` Edgecombe, Rick P
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260526023515.288829-11-rick.p.edgecombe@intel.com \
--to=rick.p.edgecombe@intel.com \
--cc=bp@alien8.de \
--cc=chao.gao@intel.com \
--cc=dave.hansen@intel.com \
--cc=hpa@zytor.com \
--cc=kai.huang@intel.com \
--cc=kas@kernel.org \
--cc=kirill.shutemov@linux.intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=nik.borisov@suse.com \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=vannapurve@google.com \
--cc=x86@kernel.org \
--cc=yan.y.zhao@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome