mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v3 00/10] TDX: Stop auto-generating the global metadata code
@ 2026-09-30  5:38 Chao Gao
  2026-09-30  5:38 ` [PATCH v3 01/10] x86/virt/tdx: Add a helper to read a table of metadata fields Chao Gao
                   ` (9 more replies)
  0 siblings, 10 replies; 11+ messages in thread
From: Chao Gao @ 2026-09-30  5:38 UTC (permalink / raw)
  To: x86, linux-coco, kvm, linux-kernel
  Cc: yilun.xu, chao.gao, binbin.wu, tony.lindgren, Kiryl Shutsemau,
	Rick Edgecombe, Dave Hansen, Thomas Gleixner, Ingo Molnar,
	Borislav Petkov, H. Peter Anvin

This series cleans up the TDX global metadata code. It has two goals:

1. Replace the generated code with a table-driven metadata reader.

2. Make the existing code easier to read and maintain, and simplify
   adding new metadata fields.

I dropped the RFC tag from this posting, as nobody seemed to disagree
with the approach in v2. Tony's suggestions, splitting the version
fields out so that tdx_sys_info can be __ro_after_init and not caching
init-only metadata, are left for a separate series.

Dave, please feel free to ignore this for now. Kirill, Rick, and other TDX
developers, please take a look. Reviews and tags are welcome.

Changes
=======

The biggest change is that the get_tdx_sys_info_foo() wrappers are
gone. Rick questioned whether a single-use wrapper around one
read_sys_metadata_table() call earns its keep, and Dave agreed it
is an unnecessary layer of abstraction.

Other changes:
  - Pass the field ID to TDX_SYSINFO_MAP() instead of pasting the
    TDX_MD_FIELD_ID_ prefix onto a suffix, and rename the
    defines to TDX_FIELD_*, so the names can be grepped (Rick)
  - Patch 8: Pick up Rick's Reviewed-by
  - Patch 9: Print the module version only after reading it succeeds.
    (Rick)
  - Patch 10: rewrite the changelog to add more background about the
    size bits in field IDs and also add an alternative discussion.
    [Rick]
  - Patch 10: Squash TDX_MD_FIELD_ELE_SIZE_CODE() and
    TDX_MD_FIELD_ELE_SIZE() into a single TDX_FIELD_SIZE() (Rick)
  - v2: https://lore.kernel.org/kvm/20260918132946.76533-1-chao.gao@intel.com/


Problem & Solution
==================

The TDX module reports its capabilities and limits through a set of global
metadata fields, each read using a 64-bit field ID via TDH.SYS.RD. The
fields are grouped into classes, and the kernel mirrors each class it
needs in a sub-structure of struct tdx_sys_info.

Both those structures and the code that fills them were generated by an
out-of-tree script from a JSON file.

The script was not the first approach.  Kai's first attempt paired each
field ID with its destination C member in a table and walked the table in a
loop to read every field.  Two pieces of feedback on it drove everything
that followed [1]:

  1. Compile-time type checking. Metadata fields have different sizes (u16
     and u64), so a common helper takes a void * and a size instead of
     a typed destination.

  2. The check that a field ID's encoded size matches its destination
     member ran at runtime, although both sizes are known at build time.

The discussion did not converge after several rounds of review. Dave noted
that, despite the void *, the size check provides the safety that matters:
it catches mismatched field and member widths [2]. That left one problem:
moving the size check from runtime to build time.

Before that was settled, the direction shifted to generating the code with a
script. At the time, the TDX ABI definitions were published as JSON, so
checking a field ID required consulting a machine-readable file by hand.
The script parsed the JSON and generated both the structures and their
readers [3]. Generation also made the size/type check unnecessary. The
field IDs and destination members came from the same input, so a mismatch
could only result from a bug in the script, which is less likely than a
mistake in hand-written code.

Dave concluded that the JSON experiment had failed [4] for two reasons:

  1. The JSON file is not stable. The CPUID config arrays here were once
     sized for a maximum of 32 entries, which has since increased to 128 [5].

  2. The JSON file is not authoritative enough to write code from by itself.

TDX ABI definitions are now available in human-readable PDF specifications
[6]. So, stop relying on the out-of-tree script and maintain the code by
hand.

Yilun later proposed a single table whose entries carry the offset and size
of each mapped member in struct tdx_sys_info [7]. That design does not
cover the new handoff metadata because it is not cached in
struct tdx_sys_info.

This series gives every class its own table: each entry pairs a field ID
with the member that holds it, and a loop walks the table. This also covers
handoff metadata, which is read into a local structure rather than into
struct tdx_sys_info.

The common reader still takes a void *, but each mapping verifies at build
time that the destination member size matches the size encoded in the field
ID. A field/member width mismatch therefore fails the build.

AI usage
========

I used LLM tools to review the patches and refine the wording of the cover
letter and changelogs from my drafts. I reviewed all suggestions and adopted
those I agreed with. For example, AI review suggested the
read_sys_metadata_table() macro, which avoids repeating the table name when
passing both the table and its size.


Testing
=======
Built each patch individually and successfully launched TDs.


Chao Gao (10):
  x86/virt/tdx: Add a helper to read a table of metadata fields
  x86/virt/tdx: Convert the version metadata reader
  x86/virt/tdx: Convert the features metadata reader
  x86/virt/tdx: Convert the tdmr metadata reader
  x86/virt/tdx: Convert the td_ctrl metadata reader
  x86/virt/tdx: Convert the handoff metadata reader
  x86/virt/tdx: Convert the td_conf metadata reader
  x86/virt/tdx: Remove tdx_global_metadata.c
  x86/virt/tdx: Use early returns in get_tdx_sys_info()
  x86/virt/tdx: Verify structure member sizes against metadata field IDs

 arch/x86/virt/vmx/tdx/tdx.c                 | 198 +++++++++++++++++++-
 arch/x86/virt/vmx/tdx/tdx.h                 |  46 +++++
 arch/x86/virt/vmx/tdx/tdx_global_metadata.c | 154 ---------------
 3 files changed, 241 insertions(+), 157 deletions(-)
 delete mode 100644 arch/x86/virt/vmx/tdx/tdx_global_metadata.c


base-commit: a49e2d257594931772ab8f0024708c3076f3aa1d
-- 
2.52.0


^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2026-09-30  5:41 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30  5:38 [PATCH v3 00/10] TDX: Stop auto-generating the global metadata code Chao Gao
2026-09-30  5:38 ` [PATCH v3 01/10] x86/virt/tdx: Add a helper to read a table of metadata fields Chao Gao
2026-09-30  5:38 ` [PATCH v3 02/10] x86/virt/tdx: Convert the version metadata reader Chao Gao
2026-09-30  5:38 ` [PATCH v3 03/10] x86/virt/tdx: Convert the features " Chao Gao
2026-09-30  5:38 ` [PATCH v3 04/10] x86/virt/tdx: Convert the tdmr " Chao Gao
2026-09-30  5:38 ` [PATCH v3 05/10] x86/virt/tdx: Convert the td_ctrl " Chao Gao
2026-09-30  5:38 ` [PATCH v3 06/10] x86/virt/tdx: Convert the handoff " Chao Gao
2026-09-30  5:38 ` [PATCH v3 07/10] x86/virt/tdx: Convert the td_conf " Chao Gao
2026-09-30  5:38 ` [PATCH v3 08/10] x86/virt/tdx: Remove tdx_global_metadata.c Chao Gao
2026-09-30  5:38 ` [PATCH v3 09/10] x86/virt/tdx: Use early returns in get_tdx_sys_info() Chao Gao
2026-09-30  5:38 ` [PATCH v3 10/10] x86/virt/tdx: Verify structure member sizes against metadata field IDs Chao Gao

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®