From: Peter Fang <peter.fang@intel.com>
To: Dave Hansen <dave.hansen@linux.intel.com>,
Kiryl Shutsemau <kas@kernel.org>,
Rick Edgecombe <rick.p.edgecombe@intel.com>,
"Kuppuswamy Sathyanarayanan"
<sathyanarayanan.kuppuswamy@linux.intel.com>
Cc: Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>, <x86@kernel.org>,
"H. Peter Anvin" <hpa@zytor.com>, <linux-kernel@vger.kernel.org>,
<linux-coco@lists.linux.dev>, <kvm@vger.kernel.org>,
Xiaoyao Li <xiaoyao.li@intel.com>,
Binbin Wu <binbin.wu@linux.intel.com>,
Tony Lindgren <tony.lindgren@linux.intel.com>,
Sean Christopherson <seanjc@google.com>,
Artem Bityutskiy <artem.bityutskiy@intel.com>,
Peter Fang <peter.fang@intel.com>
Subject: [PATCH v4 4/4] virt: tdx-guest: Allocate Quote buffer dynamically
Date: Tue, 15 Sep 2026 02:26:03 -0700 [thread overview]
Message-ID: <20260915092632.2822169-5-peter.fang@intel.com> (raw)
In-Reply-To: <20260915092632.2822169-1-peter.fang@intel.com>
From: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
A new TDX module ABI reports the Quote size limit in a metadata field.
Prior to this, the guest driver uses a fixed 128KB buffer. Intel derived
this number from current Quote types, but that is not sustainable as
Quotes evolve. 128KB may be too small for Quotes using schemes such as
post-quantum cryptography (PQC), where larger certificate chains can
increase the Quote size significantly. With this ABI, the guest no
longer has to rely on some empirical number.
Allocate the Quote buffer based on the reported limit. This avoids
wasting memory on platforms that do not need larger Quotes. Older
platforms fall back to the default 128KB buffer.
As a result, the maximum size of the "outblob" file in configfs-tsm now
depends on the TDX module.
Because the Quote buffer must be physically contiguous, its size is
bound by the buddy allocator's maximum page order (4MB), which should be
sufficient for current attestation needs.
Signed-off-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
Signed-off-by: Peter Fang <peter.fang@intel.com>
Reviewed-by: Tony Lindgren <tony.lindgren@linux.intel.com>
---
v4:
- Move the PAGE_ALIGN() out of get_quote_buf_size(). [Xiaoyao]
- Improve the get_quote_buf_size() pattern again.
- Document that the reported size covers every Quote type. [Xiaoyao]
- Document that a module update does not change the reported size.
[Tony]
- Add Tony's Reviewed-by.
v3:
- Split out from the v2 "Allocate Quote buffer dynamically" patch. Add
the dynamic buffer feature on top of the refactoring. [Dave]
- Improve the get_quote_buf_size() pattern for better readability.
[Dave]
- Drop __GFP_NOWARN so an allocation failure warns. [Dave, Rick, Kiryl]
- Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
reworked.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 31 +++++++++++++++++++++++--
1 file changed, 29 insertions(+), 2 deletions(-)
diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index ec886c401fcb..7224a66b65d1 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -162,7 +162,7 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
* DICE-based attestation uses layered evidence that requires
* larger Quote size (~100K).
*/
-#define GET_QUOTE_BUF_SIZE SZ_128K
+#define GET_QUOTE_DEFAULT_BUF_SIZE SZ_128K
#define GET_QUOTE_CMD_VER 1
@@ -222,11 +222,34 @@ static void free_quote_buf(void *buf, size_t len)
free_pages_exact(buf, len);
}
+/*
+ * Return a buffer size large enough for a Quote. This covers all Quote
+ * types supported by the platform.
+ */
+static size_t get_quote_buf_size(void)
+{
+ u32 quote_size = tdx_get_max_quote_size();
+ size_t len;
+
+ if (quote_size)
+ /* The reported size does not include the buffer header */
+ len = TDX_QUOTE_BUF_LEN(quote_size);
+ else
+ /* Older TDX modules don't report the size, use the default */
+ len = GET_QUOTE_DEFAULT_BUF_SIZE;
+
+ return len;
+}
+
static void *alloc_quote_buf(size_t len)
{
unsigned int count = len >> PAGE_SHIFT;
void *addr;
+ /*
+ * This fails if the requested size exceeds the buddy allocator's
+ * maximum order (order-10, 4MB).
+ */
addr = alloc_pages_exact(len, GFP_KERNEL | __GFP_ZERO);
if (!addr)
return NULL;
@@ -416,7 +439,11 @@ static int __init tdx_guest_init(void)
if (ret)
goto deinit_mr;
- quote_data_len = PAGE_ALIGN(GET_QUOTE_BUF_SIZE);
+ /*
+ * The buffer size remains the same throughout the lifecycle of the TD,
+ * even after a runtime TDX module update.
+ */
+ quote_data_len = PAGE_ALIGN(get_quote_buf_size());
quote_data = alloc_quote_buf(quote_data_len);
if (!quote_data) {
pr_err("Failed to allocate Quote buffer\n");
--
2.53.0
next prev parent reply other threads:[~2026-09-15 9:27 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 9:25 [PATCH v4 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-09-15 9:26 ` [PATCH v4 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-09-15 9:26 ` [PATCH v4 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-09-16 12:26 ` Kiryl Shutsemau
2026-09-15 9:26 ` [PATCH v4 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-09-16 12:30 ` Kiryl Shutsemau
2026-09-15 9:26 ` Peter Fang [this message]
2026-09-16 12:31 ` [PATCH v4 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Kiryl Shutsemau
2026-09-15 14:07 ` [PATCH v4 0/4] tdx-guest: Make Quote buffer size dynamic Sean Christopherson
2026-09-15 16:11 ` Edgecombe, Rick P
2026-09-15 23:04 ` Peter Fang
2026-09-16 0:06 ` Edgecombe, Rick P
2026-09-16 0:34 ` Peter Fang
2026-09-16 0:36 ` Edgecombe, Rick P
2026-09-16 0:50 ` Peter Fang
2026-09-16 1:20 ` Edgecombe, Rick P
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260915092632.2822169-5-peter.fang@intel.com \
--to=peter.fang@intel.com \
--cc=artem.bityutskiy@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=sathyanarayanan.kuppuswamy@linux.intel.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=tony.lindgren@linux.intel.com \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®