From: Peter Fang <peter.fang@intel.com>
To: Dave Hansen <dave.hansen@linux.intel.com>,
Kiryl Shutsemau <kas@kernel.org>,
Rick Edgecombe <rick.p.edgecombe@intel.com>,
"Kuppuswamy Sathyanarayanan"
<sathyanarayanan.kuppuswamy@linux.intel.com>
Cc: Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>, <x86@kernel.org>,
"H. Peter Anvin" <hpa@zytor.com>, <linux-kernel@vger.kernel.org>,
<linux-coco@lists.linux.dev>, <kvm@vger.kernel.org>,
Xiaoyao Li <xiaoyao.li@intel.com>,
Binbin Wu <binbin.wu@linux.intel.com>,
Tony Lindgren <tony.lindgren@linux.intel.com>,
Sean Christopherson <seanjc@google.com>,
Artem Bityutskiy <artem.bityutskiy@intel.com>,
Peter Fang <peter.fang@intel.com>
Subject: [PATCH v4 2/4] virt: tdx-guest: Calculate the Quote buffer size safely
Date: Tue, 15 Sep 2026 02:26:01 -0700 [thread overview]
Message-ID: <20260915092632.2822169-3-peter.fang@intel.com> (raw)
In-Reply-To: <20260915092632.2822169-1-peter.fang@intel.com>
struct tdx_quote_buf has a trailing flexible array member.
struct_size_t() calculates the size of this kind of struct safely. It
handles overflow, which helps since the Quote size comes from the host.
Use it to rewrite the bounds check logic, since
"header_size + data_len > buf_size"
...is more readable than "data_len > buf_size - header_size".
Signed-off-by: Peter Fang <peter.fang@intel.com>
Reviewed-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
Reviewed-by: Tony Lindgren <tony.lindgren@linux.intel.com>
Reviewed-by: Xiaoyao Li <xiaoyao.li@intel.com>
Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
---
v4:
- No code changes.
- Add Reviewed-by tags. [Sathya, Tony, Xiaoyao, Binbin]
v3:
- Split out the use of struct_size_t() for buffer length from the v2
"Allocate Quote buffer dynamically" patch to refactor first. [Dave]
- Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
reworked.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index d0303e31e816..f47c5429d002 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -170,7 +170,7 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
#define GET_QUOTE_SUCCESS 0
#define GET_QUOTE_IN_FLIGHT 0xffffffffffffffff
-#define TDX_QUOTE_MAX_LEN (GET_QUOTE_BUF_SIZE - sizeof(struct tdx_quote_buf))
+#define TDX_QUOTE_BUF_LEN(n) struct_size_t(struct tdx_quote_buf, data, n)
/* struct tdx_quote_buf: Format of Quote request buffer.
* @version: Quote format version, filled by TD.
@@ -315,7 +315,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
out_len = READ_ONCE(quote_buf->out_len);
- if (out_len > TDX_QUOTE_MAX_LEN)
+ if (TDX_QUOTE_BUF_LEN(out_len) > GET_QUOTE_BUF_SIZE)
return -EFBIG;
buf = kvmemdup(quote_buf->data, out_len, GFP_KERNEL);
--
2.53.0
next prev parent reply other threads:[~2026-09-15 9:27 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 9:25 [PATCH v4 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-09-15 9:26 ` [PATCH v4 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-09-15 9:26 ` Peter Fang [this message]
2026-09-16 12:26 ` [PATCH v4 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Kiryl Shutsemau
2026-09-15 9:26 ` [PATCH v4 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-09-16 12:30 ` Kiryl Shutsemau
2026-09-15 9:26 ` [PATCH v4 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
2026-09-16 12:31 ` Kiryl Shutsemau
2026-09-15 14:07 ` [PATCH v4 0/4] tdx-guest: Make Quote buffer size dynamic Sean Christopherson
2026-09-15 16:11 ` Edgecombe, Rick P
2026-09-15 23:04 ` Peter Fang
2026-09-16 0:06 ` Edgecombe, Rick P
2026-09-16 0:34 ` Peter Fang
2026-09-16 0:36 ` Edgecombe, Rick P
2026-09-16 0:50 ` Peter Fang
2026-09-16 1:20 ` Edgecombe, Rick P
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260915092632.2822169-3-peter.fang@intel.com \
--to=peter.fang@intel.com \
--cc=artem.bityutskiy@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=sathyanarayanan.kuppuswamy@linux.intel.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=tony.lindgren@linux.intel.com \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®