From: Binbin Wu <binbin.wu@linux.intel.com>
To: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>,
"seanjc@google.com" <seanjc@google.com>,
"Li, Xiaoyao" <xiaoyao.li@intel.com>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Cc: "kas@kernel.org" <kas@kernel.org>,
"pbonzini@redhat.com" <pbonzini@redhat.com>,
"nik.borisov@suse.com" <nik.borisov@suse.com>,
"Gao, Chao" <chao.gao@intel.com>,
"dave.hansen@linux.intel.com" <dave.hansen@linux.intel.com>,
"andrew.cooper3@citrix.com" <andrew.cooper3@citrix.com>
Subject: Re: [PATCH v3 1/4] KVM: TDX: Track configurable CPUID bits allowed by KVM
Date: Tue, 15 Sep 2026 15:49:19 +0800 [thread overview]
Message-ID: <8181bb5d-6081-4051-a083-24624d3bfdf3@linux.intel.com> (raw)
In-Reply-To: <a018a58f-76af-43a7-930b-943a9a5c0a9d@linux.intel.com>
On 9/3/2026 12:25 AM, Binbin Wu wrote:
> On 9/3/2026 12:22 AM, Edgecombe, Rick P wrote:
>> On Thu, 2026-09-03 at 00:19 +0800, Binbin Wu wrote:
>>>> I see. You added patch 2 because without it QEMU breaks. While for
>>>> EST/TM2/SDBG/XTPR/DCA, QEMU doesn't break after they are turned to
>>>> non-configurable. QEMU cannot represent all the userspace VMM. It still has
>>>> the potential to breaks other userspace VMMs.
>>>
>>> I think the risk is pretty low.
>>> I am not sure if Sean could provide some insight about this in google's
>>> userspace VMM.
>>
>> Can't we fix the issue if we are wrong?
>
> I think it could be fixed to add the missing bits (if any) as bug fix.
Directly configurable feature bits that KVM doesn't support for non-TDX VMs
fall into five categories:
1) Features that are forced to 0 when #VE is reduced, or they lack KVM's
support for associated MSRs:
EST, TM2, SDBG, DCA, ACPI, ACC (TM), RDT_A, RDT_M, TME, PCONFIG.
2) Features tied to MSR_IA32_MISC_ENABLE, whose corresponding
IA32_MISC_ENABLE bit can't be set from a TD's point of view when
TDCS.TD_CTLS.REDUCE_VE is set:
CID, PBE.
3) Host state clobbering features that KVM doesn't support for TDX:
HLE, RTM, WAITPKG, FRED.
Features in categories 1-3 should not be added to the allow list.
4) Features that are simply unsupported and thus don't need to be in the
allow list:
PREFETCHWT1 (Xeon Phi only), PSN (not implemented by TDX-capable
CPUs), AMX-TRANSPOSE (never implemented on any Intel platform), and
RAO_INT (defined only for "future processors").
5) Features that are added to the allow list via TDX_CFG_EXTRA_F():
MWAIT, XTPR, HT, CORE_CAPABILITIES.
XTPR can be exposed to a TD, but it never takes effect in the
underlying hardware when the guest changes IA32_MISC_ENABLE[23].
CORE_CAPABILITIES really belongs to category 1, but it's special
because older specs defined it as a fixed-1 bit, so userspace VMMs
may try to enable it based on stale knowledge. Add it to the allow
list to accommodate the legacy TDX module definition. Reporting
CORE_CAPABILITIES as directly configurable also lets userspace infer
that the bit is no longer fixed-1, and correct its stale knowledge.
Keep MSR_IA32_CORE_CAPS unsupported for TDX guests because existing
TDX users have no guest access to MSR_IA32_CORE_CAPS.
With the features in category 5 in the allow list, it shouldn't break
userspace.
If no objection, the next version will still limit the allow list to the
capabilities KVM supported for non-TDX VMs, with a few exceptions listed
in category 5.
next prev parent reply other threads:[~2026-09-15 7:49 UTC|newest]
Thread overview: 66+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 3:18 [PATCH v3 0/4] KVM: TDX: Validate directly configurable CPUID bits Binbin Wu
2026-08-27 3:18 ` [PATCH v3 1/4] KVM: TDX: Track configurable CPUID bits allowed by KVM Binbin Wu
2026-09-01 6:29 ` Tony Lindgren
2026-09-01 8:23 ` Binbin Wu
2026-09-01 8:27 ` Tony Lindgren
2026-09-01 14:35 ` Xiaoyao Li
2026-09-02 0:33 ` Binbin Wu
2026-09-02 15:09 ` Xiaoyao Li
2026-09-02 16:19 ` Binbin Wu
2026-09-02 16:22 ` Edgecombe, Rick P
2026-09-02 16:25 ` Binbin Wu
2026-09-15 7:49 ` Binbin Wu [this message]
2026-09-03 7:28 ` Xiaoyao Li
2026-09-03 8:57 ` Binbin Wu
2026-09-08 21:13 ` Edgecombe, Rick P
2026-09-09 16:39 ` Xiaoyao Li
2026-09-09 22:29 ` Sean Christopherson
2026-09-09 23:18 ` Edgecombe, Rick P
2026-09-10 2:39 ` Binbin Wu
2026-09-10 21:29 ` Edgecombe, Rick P
2026-09-11 0:55 ` Binbin Wu
2026-09-11 1:30 ` Edgecombe, Rick P
2026-09-10 2:53 ` Xiaoyao Li
2026-09-16 5:17 ` Binbin Wu
2026-09-08 21:15 ` Edgecombe, Rick P
2026-08-27 3:18 ` [PATCH v3 2/4] KVM: TDX: Report CORE_CAPABILITIES as configurable Binbin Wu
2026-09-01 6:45 ` Tony Lindgren
2026-09-02 17:43 ` Kishen Maloor
2026-09-03 2:22 ` Binbin Wu
2026-09-03 6:10 ` Kishen Maloor
2026-09-03 8:12 ` Binbin Wu
2026-08-27 3:18 ` [PATCH v3 3/4] KVM: TDX: Filter configurable CPUID bits Binbin Wu
2026-09-01 6:44 ` Tony Lindgren
2026-09-01 8:42 ` Binbin Wu
2026-09-01 9:09 ` Tony Lindgren
2026-09-03 8:04 ` Xiaoyao Li
2026-09-03 8:23 ` Binbin Wu
2026-08-27 3:18 ` [PATCH v3 4/4] KVM: TDX: Validate userspace CPUID input for KVM_TDX_INIT_VM Binbin Wu
2026-09-01 6:47 ` Tony Lindgren
2026-08-27 19:33 ` [PATCH v3 0/4] KVM: TDX: Validate directly configurable CPUID bits Edgecombe, Rick P
2026-08-28 3:19 ` Binbin Wu
2026-08-28 16:58 ` Edgecombe, Rick P
2026-08-31 5:01 ` Binbin Wu
2026-09-01 9:42 ` Xiaoyao Li
2026-09-01 10:21 ` Xiaoyao Li
2026-09-02 16:09 ` Edgecombe, Rick P
2026-09-02 16:21 ` Binbin Wu
2026-09-09 1:46 ` Binbin Wu
2026-09-01 9:38 ` Xiaoyao Li
2026-09-01 17:41 ` Edgecombe, Rick P
2026-09-02 10:29 ` Xiaoyao Li
2026-09-02 13:13 ` Edgecombe, Rick P
2026-09-02 13:39 ` Xiaoyao Li
2026-09-02 13:53 ` Edgecombe, Rick P
2026-09-02 14:21 ` Xiaoyao Li
2026-09-02 16:26 ` Binbin Wu
2026-09-08 9:42 ` Artem Bityutskiy
2026-09-09 0:04 ` Binbin Wu
2026-09-08 20:30 ` Artem Bityutskiy
2026-09-08 22:31 ` Edgecombe, Rick P
2026-09-09 6:52 ` Artem Bityutskiy
2026-09-09 8:48 ` Binbin Wu
2026-09-09 11:20 ` Artem Bityutskiy
2026-09-10 2:54 ` Binbin Wu
2026-09-08 23:54 ` Binbin Wu
2026-09-09 5:37 ` Binbin Wu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8181bb5d-6081-4051-a083-24624d3bfdf3@linux.intel.com \
--to=binbin.wu@linux.intel.com \
--cc=andrew.cooper3@citrix.com \
--cc=chao.gao@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nik.borisov@suse.com \
--cc=pbonzini@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=seanjc@google.com \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®