From: Peter Fang <peter.fang@intel.com>
To: Dave Hansen <dave.hansen@linux.intel.com>,
Kiryl Shutsemau <kas@kernel.org>,
Rick Edgecombe <rick.p.edgecombe@intel.com>,
"Kuppuswamy Sathyanarayanan"
<sathyanarayanan.kuppuswamy@linux.intel.com>
Cc: Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>, <x86@kernel.org>,
"H. Peter Anvin" <hpa@zytor.com>, <linux-kernel@vger.kernel.org>,
<linux-coco@lists.linux.dev>, <kvm@vger.kernel.org>,
Xiaoyao Li <xiaoyao.li@intel.com>,
Binbin Wu <binbin.wu@linux.intel.com>,
Tony Lindgren <tony.lindgren@linux.intel.com>,
Sean Christopherson <seanjc@google.com>,
Artem Bityutskiy <artem.bityutskiy@intel.com>,
Peter Fang <peter.fang@intel.com>
Subject: [PATCH v6 4/6] virt: tdx-guest: Add a helper for the Quote buffer size
Date: Wed, 30 Sep 2026 03:30:53 -0700 [thread overview]
Message-ID: <20260930103739.2851980-5-peter.fang@intel.com> (raw)
In-Reply-To: <20260930103739.2851980-1-peter.fang@intel.com>
The Quote buffer size is a constant sprinkled across several places.
Read it from a helper instead. And rename the constant to avoid using a
verb.
This sets up the plumbing for a later change that makes the size
dynamic.
There are several "sizes" at play here: the raw Quote data, the Quote
buffer (the header metadata plus the raw data), and the allocation (the
page-padded Quote buffer). The helper returns the Quote buffer size and
leaves page alignment to callers that need it.
AI was used under supervision to collect/apply feedback, review code and
workshop logs.
Signed-off-by: Peter Fang <peter.fang@intel.com>
---
v6:
- Don't cache the size in the helper. [Rick]
- Let the callers page-align the buffer size. [Rick]
- Add a comment for the helper. [Dave]
v5:
- Reworked v4 3/4 to use a helper instead of a global. [Dave, Xiaoyao]
- Use TDX_DEFAULT_QUOTE_SIZE instead of GET_QUOTE_DEFAULT_BUF_SIZE.
[Dave]
- Use "size" instead of "len" for buffer size variables. [Dave]
- Drop the RB tags, as the code changed substantially.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 31 +++++++++++++++++--------
1 file changed, 21 insertions(+), 10 deletions(-)
diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index 77c63c3f820f..0cf078f09a73 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -162,7 +162,7 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
* DICE-based attestation uses layered evidence that requires
* larger Quote size (~100K).
*/
-#define GET_QUOTE_BUF_SIZE SZ_128K
+#define TDX_DEFAULT_QUOTE_SIZE SZ_128K
#define GET_QUOTE_CMD_VER 1
@@ -206,26 +206,36 @@ static long tdx_get_report0(struct tdx_report_req __user *req)
USER_SOCKPTR(req->tdreport));
}
+/* Size of the header metadata plus the largest possible raw Quote. */
+static size_t get_quote_buf_size(void)
+{
+ return TDX_DEFAULT_QUOTE_SIZE;
+}
+
static void free_quote_buf(struct tdx_quote_buf *buf)
{
- size_t len = PAGE_ALIGN(GET_QUOTE_BUF_SIZE);
- unsigned int count = len >> PAGE_SHIFT;
+ size_t alloc_size = PAGE_ALIGN(get_quote_buf_size());
+ unsigned int count;
+
+ count = alloc_size >> PAGE_SHIFT;
if (set_memory_encrypted((unsigned long)buf, count)) {
pr_err("Failed to restore encryption mask for Quote buffer, leak it\n");
return;
}
- free_pages_exact(buf, len);
+ free_pages_exact(buf, alloc_size);
}
static struct tdx_quote_buf *alloc_quote_buf(void)
{
- size_t len = PAGE_ALIGN(GET_QUOTE_BUF_SIZE);
- unsigned int count = len >> PAGE_SHIFT;
+ size_t alloc_size = PAGE_ALIGN(get_quote_buf_size());
struct tdx_quote_buf *buf;
+ unsigned int count;
- buf = alloc_pages_exact(len, GFP_KERNEL | __GFP_ZERO);
+ count = alloc_size >> PAGE_SHIFT;
+
+ buf = alloc_pages_exact(alloc_size, GFP_KERNEL | __GFP_ZERO);
if (!buf)
return NULL;
@@ -266,6 +276,7 @@ static int tdx_report_new_locked(struct tsm_report *report)
{
u8 *buf;
struct tsm_report_desc *desc = &report->desc;
+ size_t quote_buf_size = get_quote_buf_size();
u32 out_len;
int ret;
u64 err;
@@ -281,7 +292,7 @@ static int tdx_report_new_locked(struct tsm_report *report)
if (desc->inblob_len != TDX_REPORTDATA_LEN)
return -EINVAL;
- memset(quote_buf, 0, GET_QUOTE_BUF_SIZE);
+ memset(quote_buf, 0, quote_buf_size);
/* Update Quote buffer header */
quote_buf->version = GET_QUOTE_CMD_VER;
@@ -292,7 +303,7 @@ static int tdx_report_new_locked(struct tsm_report *report)
if (ret)
return ret;
- err = tdx_hcall_get_quote(quote_buf, GET_QUOTE_BUF_SIZE);
+ err = tdx_hcall_get_quote(quote_buf, PAGE_ALIGN(quote_buf_size));
if (err) {
pr_err("GetQuote hypercall failed, status:%llx\n", err);
return -EIO;
@@ -311,7 +322,7 @@ static int tdx_report_new_locked(struct tsm_report *report)
out_len = READ_ONCE(quote_buf->out_len);
- if (struct_size(quote_buf, data, out_len) > GET_QUOTE_BUF_SIZE)
+ if (struct_size(quote_buf, data, out_len) > quote_buf_size)
return -EFBIG;
buf = kvmemdup(quote_buf->data, out_len, GFP_KERNEL);
--
2.53.0
next prev parent reply other threads:[~2026-09-30 10:38 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 10:30 [PATCH v6 0/6] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-09-30 10:30 ` [PATCH v6 1/6] x86/tdx: Take the Quote buffer as a generic pointer Peter Fang
2026-09-30 10:30 ` [PATCH v6 2/6] virt: tdx-guest: Give the Quote buffer an explicit type Peter Fang
2026-09-30 10:30 ` [PATCH v6 3/6] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-09-30 10:30 ` Peter Fang [this message]
2026-09-30 10:30 ` [PATCH v6 5/6] x86/tdx: Add a helper to query maximum Quote size Peter Fang
2026-09-30 10:30 ` [PATCH v6 6/6] virt: tdx-guest: Make the Quote buffer size dynamic Peter Fang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930103739.2851980-5-peter.fang@intel.com \
--to=peter.fang@intel.com \
--cc=artem.bityutskiy@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=sathyanarayanan.kuppuswamy@linux.intel.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=tony.lindgren@linux.intel.com \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®