From: Kishen Maloor <kishen.maloor@intel.com>
To: Binbin Wu <binbin.wu@linux.intel.com>,
<linux-kernel@vger.kernel.org>, <kvm@vger.kernel.org>
Cc: <seanjc@google.com>, <pbonzini@redhat.com>,
<dave.hansen@linux.intel.com>, <andrew.cooper3@citrix.com>,
<nik.borisov@suse.com>, <kas@kernel.org>,
<rick.p.edgecombe@intel.com>, <xiaoyao.li@intel.com>,
<chao.gao@intel.com>
Subject: Re: [PATCH v3 2/4] KVM: TDX: Report CORE_CAPABILITIES as configurable
Date: Wed, 2 Sep 2026 10:43:09 -0700 [thread overview]
Message-ID: <73beeef9-3ecf-49fc-87e3-6fa30f8f56d3@intel.com> (raw)
In-Reply-To: <20260827031837.2863609-3-binbin.wu@linux.intel.com>
On 8/26/26 8:18 PM, Binbin Wu wrote:
> Reporting CORE_CAPABILITIES as configurable keeps userspace able to enable
> the bit across the fixed-1 => configurable transition, and lets userspace
> infer that the bit is no longer fixed-1 so it can adjust its expectations.
> ...
> @@ -147,6 +147,12 @@ static void __init tdx_initialize_cpu_cfg_caps(void)
> + /*
> + * KVM does not support MSR_IA32_CORE_CAPS, but older TDX specs
> + * define this bit as fixed-1. Report it as configurable so
> + * userspace can know the feature is no longer a fixed-1 bit.
> + */
> + TDX_CFG_EXTRA_F(CORE_CAPABILITIES),
Would a mask of the bits that are fixed-1 across the modules KVM supports today
be worth carrying, or adding to the allowed set?
I assume it would be hardcoded, just as the allowed list is.
If a module update later made one of them configurable, userspace would keep the
ability to set it -- something it has today with the denylist. And since such
bits are already enabled in every TD running now, continuing to accept them
can't turn on anything that isn't already on.
A bit that becomes fixed-1 in the future and configurable after a subsequent
module update would still need a patch to the mask, just as this patch does.
Is CORE_CAPABILITIES the only fixed-1 case so far?
next prev parent reply other threads:[~2026-09-02 17:43 UTC|newest]
Thread overview: 43+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 3:18 [PATCH v3 0/4] KVM: TDX: Validate directly configurable CPUID bits Binbin Wu
2026-08-27 3:18 ` [PATCH v3 1/4] KVM: TDX: Track configurable CPUID bits allowed by KVM Binbin Wu
2026-09-01 6:29 ` Tony Lindgren
2026-09-01 8:23 ` Binbin Wu
2026-09-01 8:27 ` Tony Lindgren
2026-09-01 14:35 ` Xiaoyao Li
2026-09-02 0:33 ` Binbin Wu
2026-09-02 15:09 ` Xiaoyao Li
2026-09-02 16:19 ` Binbin Wu
2026-09-02 16:22 ` Edgecombe, Rick P
2026-09-02 16:25 ` Binbin Wu
2026-09-03 7:28 ` Xiaoyao Li
2026-09-03 8:57 ` Binbin Wu
2026-08-27 3:18 ` [PATCH v3 2/4] KVM: TDX: Report CORE_CAPABILITIES as configurable Binbin Wu
2026-09-01 6:45 ` Tony Lindgren
2026-09-02 17:43 ` Kishen Maloor [this message]
2026-09-03 2:22 ` Binbin Wu
2026-09-03 6:10 ` Kishen Maloor
2026-09-03 8:12 ` Binbin Wu
2026-08-27 3:18 ` [PATCH v3 3/4] KVM: TDX: Filter configurable CPUID bits Binbin Wu
2026-09-01 6:44 ` Tony Lindgren
2026-09-01 8:42 ` Binbin Wu
2026-09-01 9:09 ` Tony Lindgren
2026-09-03 8:04 ` Xiaoyao Li
2026-09-03 8:23 ` Binbin Wu
2026-08-27 3:18 ` [PATCH v3 4/4] KVM: TDX: Validate userspace CPUID input for KVM_TDX_INIT_VM Binbin Wu
2026-09-01 6:47 ` Tony Lindgren
2026-08-27 19:33 ` [PATCH v3 0/4] KVM: TDX: Validate directly configurable CPUID bits Edgecombe, Rick P
2026-08-28 3:19 ` Binbin Wu
2026-08-28 16:58 ` Edgecombe, Rick P
2026-08-31 5:01 ` Binbin Wu
2026-09-01 9:42 ` Xiaoyao Li
2026-09-01 10:21 ` Xiaoyao Li
2026-09-02 16:09 ` Edgecombe, Rick P
2026-09-02 16:21 ` Binbin Wu
2026-09-01 9:38 ` Xiaoyao Li
2026-09-01 17:41 ` Edgecombe, Rick P
2026-09-02 10:29 ` Xiaoyao Li
2026-09-02 13:13 ` Edgecombe, Rick P
2026-09-02 13:39 ` Xiaoyao Li
2026-09-02 13:53 ` Edgecombe, Rick P
2026-09-02 14:21 ` Xiaoyao Li
2026-09-02 16:26 ` Binbin Wu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=73beeef9-3ecf-49fc-87e3-6fa30f8f56d3@intel.com \
--to=kishen.maloor@intel.com \
--cc=andrew.cooper3@citrix.com \
--cc=binbin.wu@linux.intel.com \
--cc=chao.gao@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nik.borisov@suse.com \
--cc=pbonzini@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=seanjc@google.com \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®