mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Xu Yilun <yilun.xu@linux.intel.com>
To: x86@kernel.org, linux-coco@lists.linux.dev,
	 linux-kernel@vger.kernel.org
Cc: Kiryl Shutsemau <kas@kernel.org>,
	 Rick Edgecombe <rick.p.edgecombe@intel.com>,
	 Dave Hansen <dave.hansen@linux.intel.com>,
	dave.hansen@intel.com,  kvm@vger.kernel.org, yilun.xu@intel.com,
	yilun.xu@linux.intel.com,  xiaoyao.li@intel.com,
	sohil.mehta@intel.com, adrian.hunter@intel.com,
	 kishen.maloor@intel.com, tony.lindgren@linux.intel.com,
	 peter.fang@intel.com, baolu.lu@linux.intel.com,
	zhenzhong.duan@intel.com,  chao.gao@intel.com,
	artem.bityutskiy@linux.intel.com, nik.borisov@suse.com
Subject: [PATCH v3 0/6] Enable TDX module extensions
Date: Tue, 06 Oct 2026 01:41:44 +0800	[thread overview]
Message-ID: <20261006-tdx-module-ext-v3-0-db52cb05b918@linux.intel.com> (raw)

Hi,

This is another respin of the TDX module extensions series. Thank you
all for the design discussion and architectural review. During the last
version, some architecture discussions lead to changes. And the need to
support DPAMT creates more touch points. But the all the design issues
are settled, we don't have any major opens.

So Kiryl, Rick and TDX developers, please help review. If there is no
major change, I hope to get your RBs and then ask Dave to look at this
version.

== Changes ==

One change is that the extensions re-initialization patch is picked back
into this series. In v2, the extensions re-initialization operation
(TDH.EXT.INIT) was expected to be integrated in TDH.SYS.UPDATE. Host
didn't have to explicitly invoke it on update anymore. But later an
off-list discussion concludes that the separation of TDH.SYS.UPDATE &
TDH.EXT.INIT brings more flexibility for needs from different types of
VMMs, such as reducing the black-out time of update, allowing for new
feature enabling... So now the host needs to call TDH.EXT.INIT right
after TDH.SYS.UPDATE to restore the extensions functionalities.

However the add-on feature re-configuration is orthogonal to the
update flow change. We should still start with the basic update
functionality that restores the previous settings. Re-configuring new
feature is a separate functionality and the use case is unclear now.
So I still expect that a TDH.SYS.UPDATE v0 would restore add-on features
that was configured during boot.

Rick pointed out that if TDH.EXT.INIT could always return a reasonable
return code, we don't have to query ext_required metadata. A fix for the
ABI is: TDH.EXT.INIT should return success if no extensions are
required. We reached agreement with TDX module team and removed
ext_required. After ext_required removal, the v2:Patch 3 became too
trivial so merge it into v2:Patch 4.

Rick raised a question that a single 4K allocation per iteration on
boot may not cause much fragmentation. Kiryl answered
CONFIG_SHUFFLE_PAGE_ALLOCATOR may affect the actual behavior but we'd
better verify this in practice. The test result shows the allocation is
affected by several aspects, e.g. MPOL_INTERLEAVED, per-CPU page cache.
The allocated pages were scattered across many more page blocks than
expected.

The DPAMT is now queued in tip x86/tdx and will be default on in next
rc1. Adding memory to the extensions without first installing DPAMT will
trigger SEAMCALL failure and in turn fail the whole TDX module
initialization. Add a new patch to support DPAMT.

Other changes:
  - Patch 1: sizeof(tdmr_pa_array->phys[0]) instead of sizeof(u64)
    (Rick)

  - Patch 1: Re-phrase the code comments for struct tdmr_info_pa_array
    (Tony)

  - Patch 2: Update the stale changlog for bitmap arg of the wrapper
    (Chao)

  - Patch 2: s/get_tdx_addon_features0()/get_tdx_usable_addon_features0()
    (Tony)

  - Patch 3: Don't save the metadata in tdx_sysinfo (Rick)

  - Patch 3: Tweak the code comment for memory_pool_required_pages == 0
    (Chao)

  - Patch 3: Re-phrase the code comment for struct tdx_hpa_list (Tony)

  - Patch 5: Rename the reinit function as reinit_tdx_module_extensions()
    (Tony)

  - Patch 5: Move the extensions re-init under TDH.SYS.UPDATE (Rick)

v2: https://lore.kernel.org/all/20260915102658.713079-1-yilun.xu@linux.intel.com/

v1: https://lore.kernel.org/all/20260821032920.256225-1-yilun.xu@linux.intel.com/

Quoting v2: https://lore.kernel.org/lkml/20260618081355.3253581-1-yilun.xu@linux.intel.com/

Quoting v1: https://lore.kernel.org/all/20260522034128.3144354-1-yilun.xu@linux.intel.com/

== Overview ==

To date, SEAMCALL execution must either complete quickly to avoid
stalling the host, or yield quickly at pre-defined interrupt
checkpoints. This is acceptable for the existing SEAMCALL leafs,
which perform simple, bounded operations.

However, some new features such as attestation and TD migration require
higher level security protocols inside the TDX module, which cannot fit
within that constraint. TDX solves this by making those operations
inherently preemptible and resumable like OS tasks. TDX provides a
separate SEAMCALL execution environment - the TDX module extensions -
for those operations.

This capability allows for higher-level SEAMCALL ABI design - like
"create a DICE-based attestation quote". Several new features, such as
DICE-based attestation, TDISP and TD migration, use SEAMCALL leafs
backed by the TDX module extensions.

The TDX module extensions need memory for their execution environment
to serve these SEAMCALL leafs, so they need extra setup steps during TDX
module initialization. The bulk of this series implements these setup
steps.

At runtime, the host invokes these SEAMCALL leafs just as normal ones -
if interrupted, simply re-invoke the leaf to resume.

For more information on TDX module extensions, please refer to [1].

[1] https://lore.kernel.org/lkml/20260618081355.3253581-1-yilun.xu@linux.intel.com/

== Branch stack ==

This is based on tip x86/tdx. You can find the full branch stack at [2].
The DICE part is in the full branch as an example for extensions. But it
does not include the other DICE feedbacks.

The full branch contains:

  This series: Patch 1~7: This series, including this cover-letter.
  Use case:    Patch 8~N: The old DICE part as an example.

[2] https://github.com/intel-staging/tdx/tree/tdx-module-ext

---
Xu Yilun (6):
      x86/virt/tdx: Move TDH.SYS.CONFIG operations into a wrapper
      x86/virt/tdx: Configure add-on features on TDX module init
      x86/virt/tdx: Add extra memory to TDX module for the extensions
      x86/virt/tdx: Make TDX module initialize the extensions
      x86/virt/tdx: Re-initialize the extensions on runtime TDX module update
      x86/virt/tdx: Support DPAMT when adding memory for the extensions

 arch/x86/include/asm/tdx.h                  |   1 +
 arch/x86/include/asm/tdx_global_metadata.h  |   4 +
 arch/x86/virt/vmx/tdx/tdx.h                 |   2 +
 arch/x86/virt/vmx/tdx/tdx.c                 | 252 ++++++++++++++++++++++++++--
 arch/x86/virt/vmx/tdx/tdx_global_metadata.c |  14 ++
 5 files changed, 259 insertions(+), 14 deletions(-)
---
base-commit: 5b8212d45d99b77c84e3ad305a295e9e65d5ef20
change-id: 20260916-tdx-module-ext-da1930f33c04

Best regards,
-- 
Xu Yilun <yilun.xu@linux.intel.com>


             reply	other threads:[~2026-10-05 17:45 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 17:41 Xu Yilun [this message]
2026-10-05 17:41 ` [PATCH v3 1/6] x86/virt/tdx: Move TDH.SYS.CONFIG operations into a wrapper Xu Yilun
2026-10-05 17:41 ` [PATCH v3 2/6] x86/virt/tdx: Configure add-on features on TDX module init Xu Yilun
2026-10-05 17:41 ` [PATCH v3 3/6] x86/virt/tdx: Add extra memory to TDX module for the extensions Xu Yilun
2026-10-05 17:41 ` [PATCH v3 4/6] x86/virt/tdx: Make TDX module initialize " Xu Yilun
2026-10-05 17:41 ` [PATCH v3 5/6] x86/virt/tdx: Re-initialize the extensions on runtime TDX module update Xu Yilun
2026-10-06  4:32   ` Tony Lindgren
2026-10-05 17:41 ` [PATCH v3 6/6] x86/virt/tdx: Support DPAMT when adding memory for the extensions Xu Yilun
2026-10-06  4:36   ` Tony Lindgren

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261006-tdx-module-ext-v3-0-db52cb05b918@linux.intel.com \
    --to=yilun.xu@linux.intel.com \
    --cc=adrian.hunter@intel.com \
    --cc=artem.bityutskiy@linux.intel.com \
    --cc=baolu.lu@linux.intel.com \
    --cc=chao.gao@intel.com \
    --cc=dave.hansen@intel.com \
    --cc=dave.hansen@linux.intel.com \
    --cc=kas@kernel.org \
    --cc=kishen.maloor@intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=nik.borisov@suse.com \
    --cc=peter.fang@intel.com \
    --cc=rick.p.edgecombe@intel.com \
    --cc=sohil.mehta@intel.com \
    --cc=tony.lindgren@linux.intel.com \
    --cc=x86@kernel.org \
    --cc=xiaoyao.li@intel.com \
    --cc=yilun.xu@intel.com \
    --cc=zhenzhong.duan@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®