mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Peter Fang <peter.fang@intel.com>
To: Dave Hansen <dave.hansen@linux.intel.com>,
	Kiryl Shutsemau <kas@kernel.org>,
	Rick Edgecombe <rick.p.edgecombe@intel.com>,
	"Kuppuswamy Sathyanarayanan"
	<sathyanarayanan.kuppuswamy@linux.intel.com>
Cc: Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
	Borislav Petkov <bp@alien8.de>, <x86@kernel.org>,
	"H. Peter Anvin" <hpa@zytor.com>, <linux-kernel@vger.kernel.org>,
	<linux-coco@lists.linux.dev>, <kvm@vger.kernel.org>,
	Xiaoyao Li <xiaoyao.li@intel.com>,
	Binbin Wu <binbin.wu@linux.intel.com>,
	Tony Lindgren <tony.lindgren@linux.intel.com>,
	Sean Christopherson <seanjc@google.com>,
	Artem Bityutskiy <artem.bityutskiy@intel.com>,
	Peter Fang <peter.fang@intel.com>
Subject: [PATCH v5 0/6] tdx-guest: Make Quote buffer size dynamic
Date: Mon, 28 Sep 2026 03:08:11 -0700	[thread overview]
Message-ID: <20260928100913.2265687-1-peter.fang@intel.com> (raw)

Hi,

This is v5 of the series to make the TDX guest driver's Quote buffer
size dynamic. There is more refactoring in this version, which added 2
more patches. I also reordered the patches so that cleanups/refactoring
come first, and the last patch focuses on the dynamic size feature
itself. This means they're no longer grouped by subsystem first, in
favor of the logical order of the changes.

One thing worth mentioning is that I used EXPORT_SYMBOL_FOR_MODULES() to
export the symbol to the driver, even though I argued in the past [1]
that this is a new pattern for guest-side TDX code. This is because a
separate patch on the list [2] is adding this pattern to
arch/x86/coco/tdx/tdx.c, so hopefully everything will eventually come
together nicely.

Newer TDX modules have an ABI that tells the guest how big a Quote can
get. The Quote buffer no longer has to be a fixed size. So effectively:

  s/FIXED_BUF_SIZE/queried_buf_size/

... in the TDX guest driver.

Terminology
===========

A "TD Quote" is an attestation structure signed with a platform key. It
contains information about a TDX guest and the platform it's running on.

The "Quote buffer" in the TDX guest driver is a memory buffer shared
between the TDX guest and the host VMM to retrieve TD Quotes. It has a
header defined in the GHCI spec [3].

Device Identifier Composition Engine ("DICE") provides a framework for
layering attestation evidence. This replaces the SGX model of contacting
an Intel server to obtain a certificate.

Problem
=======

The fixed-size Quote buffer approach is not sustainable. As
cryptographic algorithms evolve, TD Quote sizes also grow. A previous
commit [4] increased the guest driver's fixed-size Quote buffer to 128KB
to accommodate DICE Quotes, but it may still be insufficient when those
Quotes use post-quantum cryptography (PQC). PQC certificate chains are
roughly 10x-15x larger than conventional ones, which can increase Quote
sizes significantly.

What's in this series
=====================

To avoid changing the driver whenever the Quote buffer becomes too
small, newer TDX modules report their largest possible Quote size via a
metadata field [5]. The guest driver uses this value, plus room for the
header, for its Quote buffer when available. Older TDX modules continue
to use the 128KB buffer.

Patches 1-4 refactor the existing fixed buffer handling. Patch 5 adds a
helper to query the new metadata field, and patch 6 then makes the
buffer size dynamic.

Patch 1/6: Take the Quote buffer as a generic pointer.
Patch 2/6: Give the Quote buffer an explicit type.
Patch 3/6: Calculate the Quote buffer size with struct_size_t().
Patch 4/6: Read the Quote buffer size from a helper.
Patch 5/6: Add a helper to read the QUOTE_MAX_SIZE metadata field.
Patch 6/6: The final s/FIXED_BUF_SIZE/queried_buf_size/, when available.

Base
====

This is based on v7.3-rc5.

AI use
======

I used AI to help edit this cover letter and the changelogs, and to
collect and apply the review feedback on lore under my supervision. The
series also underwent AI code review, but its comments were limited to
style suggestions and existing issues. Sashiko's __GFP_NOWARN suggestion
was adopted in v2, but it was dropped in v3.

v4: https://lore.kernel.org/all/20260915092632.2822169-1-peter.fang@intel.com/

Changes in v5:
 - Give the Quote buffer an explicit type. [Dave]
 - Replace the quote_data_len global with a helper. [Dave, Xiaoyao]
 - Simplify tdx_get_max_quote_size(). [Dave]
 - Use EXPORT_SYMBOL_FOR_MODULES() instead of EXPORT_SYMBOL_GPL().
   [Xiaoyao, Dave]
 - Rename GET_QUOTE_DEFAULT_BUF_SIZE to TDX_DEFAULT_QUOTE_SIZE. [Dave]
 - Rename TDX_QUOTE_BUF_LEN() to TDX_QUOTE_TOTAL_SIZE(). [Dave]
 - Drop the comment about the buddy allocator. [Dave]
 - Reorder the patches so that cleanups/refactoring come before the
   feature.
 - Add Kiryl's Reviewed-by to patch 3.
 - Drop the Reviewed-by tags from patches 4-6 as they were reworked.
 - Change the author of patch 6 to me, and credit Sathya in the log.

v3: https://lore.kernel.org/all/20260729122939.1340412-1-peter.fang@intel.com/

Changes in v4:
 - Update the TDCS_QUOTE_MAX_SIZE encoding to 0x9010000200000007.
 - Provide documentation for the metadata field. [Rick, Kiryl]
 - Document the reported size's properties. [Xiaoyao, Tony]
 - Page align quote_data_len unconditionally. [Xiaoyao]
 - Collect Reviewed-by tags. [Sathya, Tony, Xiaoyao, Binbin]

v2: https://lore.kernel.org/all/20260717214349.4075994-1-peter.fang@intel.com/

Changes in v3:
 - Split the v2 "Allocate Quote buffer dynamically" patch to do the
   refactoring first, then make the buffer size dynamic. [Dave]
 - Improve patterns for readability. [Dave]
 - Drop __GFP_NOWARN so an allocation failure warns. [Dave, Rick, Kiryl]
 - Add Binbin's Reviewed-by to patch 1.
 - Drop the Reviewed-by tags (Kiryl, Binbin) as the patch was reworked.

v1: https://lore.kernel.org/all/20260612110853.3188196-1-peter.fang@intel.com/

Changes in v2:
 - Collect Reviewed-by tags. [Kiryl, Xiaoyao, Binbin, Sathya]
 - Keep the explicit (u32) cast in tdx_get_max_quote_size(). [Binbin]
 - Calculate the Quote buffer size with struct_size_t(). [Kiryl, Binbin]
 - Add __GFP_NOWARN to the allocation since its size comes from the
   host. [sashiko]
 - Rename quote_data_size to quote_data_len. [Sathya]
 - Drop the Assisted-by tags, as AI was not used to write the code.

[1] https://lore.kernel.org/all/20260623044411.GB923079@pedri/
[2] https://lore.kernel.org/all/20260925131808.2415177-1-nik.borisov@suse.com/
[3] Guest Hypervisor Communication Interface (GHCI) Specification,
    Version 1.5, Section "TDG.VP.VMCALL<GetQuote>"
[4] 43185067c6fd ("configfs-tsm-report: tdx_guest: Increase Quote buffer
    size to 128KB")
[5] Intel TDX Module ABI Definitions, August 2026, TD-scope metadata
    field "TD_QUOTE_MAX_SIZE"

Peter Fang (6):
  x86/tdx: Take the Quote buffer as a generic pointer
  virt: tdx-guest: Give the Quote buffer an explicit type
  virt: tdx-guest: Calculate the Quote buffer size safely
  virt: tdx-guest: Add a helper for the Quote buffer size
  x86/tdx: Add a helper to query maximum Quote size
  virt: tdx-guest: Make the Quote buffer size dynamic

 arch/x86/coco/tdx/tdx.c                 | 19 +++++-
 arch/x86/include/asm/shared/tdx.h       |  1 +
 arch/x86/include/asm/tdx.h              |  4 +-
 drivers/virt/coco/tdx-guest/tdx-guest.c | 79 +++++++++++++++++--------
 4 files changed, 75 insertions(+), 28 deletions(-)


base-commit: 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
-- 
2.53.0


             reply	other threads:[~2026-09-28 10:10 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 10:08 Peter Fang [this message]
2026-09-28 10:08 ` [PATCH v5 1/6] x86/tdx: Take the Quote buffer as a generic pointer Peter Fang
2026-09-28 19:04   ` Edgecombe, Rick P
2026-09-28 20:37     ` Peter Fang
2026-09-28 20:10   ` Kuppuswamy Sathyanarayanan
2026-09-28 10:08 ` [PATCH v5 2/6] virt: tdx-guest: Give the Quote buffer an explicit type Peter Fang
2026-09-28 19:14   ` Edgecombe, Rick P
2026-09-28 20:16   ` Kuppuswamy Sathyanarayanan
2026-09-28 10:08 ` [PATCH v5 3/6] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-09-28 15:50   ` Dave Hansen
2026-09-28 10:08 ` [PATCH v5 4/6] virt: tdx-guest: Add a helper for the Quote buffer size Peter Fang
2026-09-28 16:13   ` Dave Hansen
2026-09-28 19:13     ` Edgecombe, Rick P
2026-09-28 18:23   ` Edgecombe, Rick P
2026-09-28 10:08 ` [PATCH v5 5/6] x86/tdx: Add a helper to query maximum Quote size Peter Fang
2026-09-28 18:35   ` Edgecombe, Rick P
2026-09-28 18:50   ` Edgecombe, Rick P
2026-09-28 20:32   ` Kuppuswamy Sathyanarayanan
2026-09-28 10:08 ` [PATCH v5 6/6] virt: tdx-guest: Make the Quote buffer size dynamic Peter Fang
2026-09-28 20:37   ` Kuppuswamy Sathyanarayanan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928100913.2265687-1-peter.fang@intel.com \
    --to=peter.fang@intel.com \
    --cc=artem.bityutskiy@intel.com \
    --cc=binbin.wu@linux.intel.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=kas@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=rick.p.edgecombe@intel.com \
    --cc=sathyanarayanan.kuppuswamy@linux.intel.com \
    --cc=seanjc@google.com \
    --cc=tglx@kernel.org \
    --cc=tony.lindgren@linux.intel.com \
    --cc=x86@kernel.org \
    --cc=xiaoyao.li@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®