From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5AE103ED3CA for ; Thu, 13 Aug 2026 19:32:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.42 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786649547; cv=none; b=d5Nxn03A1Z5BWh/5HMTCx2d1PgXYsrZLt/hUQbkEwtlrUPwCDbOSiPLQPqqTC1nKm31hcG9nEt2mqZXCTrmlYlzzKLY3++q4pD/BWq5VBjxQyChe5UJNctsUAm9Hn8w5gmSnrIZqSuS6I0RDtJD9qrMAKjrjtqeHzW6LmDsJyhE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786649547; c=relaxed/simple; bh=cQlaNRMDkTJMuIyxwsPvZ+cjUPtxFEg5mojh9WKY3uY=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=Fakk3NwXjeyX7AguVHund7u4RancaCfqIGzYlQNcHuJAewBsJYuAd9pFcohF7lkAg4D5UqpB8AZPk7UJRUetgQ+kQ/xppbGy+OuvCcc/Ki0YG57lfuRG2ClUv7JFxwmQWILpF9/cjk5kfVVoVTvu1uZKGWwA70Q9hYqa4hqW+0s= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=g4G65qkk; arc=none smtp.client-ip=209.85.128.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="g4G65qkk" Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-496bb7cdf51so3988275e9.2 for ; Thu, 13 Aug 2026 12:32:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786649545; x=1787254345; darn=vger.kernel.org; h=mime-version:user-agent:content-transfer-encoding:content-type :references:in-reply-to:date:cc:to:from:subject:message-id:from:to :cc:subject:date:message-id:reply-to:content-type; bh=7+51zd6tnkFNytI+UfVQUKOzVzDcWRHgwQiRbDmfdKw=; b=g4G65qkkn1WdT7X8iMuTtU15bsrkBTZtdcehSB1ZmJF9g1eIJpDjtMBGx84Bk7uo5E i0W9vSXs5fs6ryOObpthF+34ME873fPulZGg2HpTgxXZLe6Z7s9TuNfgfB7XR2/yEMo4 lS97B7HOpiGqLwrQ9MpcoVLBGeGo6sFiui6WZhp+C3axjtyM3ujxvpgZ6Mi8xRQCEn9f SOVsrcnII53RbLOr2W7d3PInEa+7V+f3ea3ASx6gJeuvh21dkiF/n0NysQeeGrjf+HQ7 dYPUB1wdk6GTU/vCtnM6pObkZSMMCtqBpWYezAHUQgYTTRhYaCxwgUJSe8K8rFJWWY1J +SCw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786649545; x=1787254345; h=mime-version:user-agent:content-transfer-encoding:content-type :references:in-reply-to:date:cc:to:from:subject:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=7+51zd6tnkFNytI+UfVQUKOzVzDcWRHgwQiRbDmfdKw=; b=QX3aEtR3s56GFtriNFFVDY0s9qBeQUS89l3x/DhxpV4xyeeEEcLOFMfUjr0ZlVXacb fD/2lYP637fScrFbOCxBkETqKLsjuXkX6LtTlAObf70hDQ6/q5ZlUI/mMguYPCBzHGi2 dlc2AMsDDKcJ7Jl2j/Zbh3d9ovZMBy9RFtcCOm6asYMZTWjavp1VM+gEooNdJ6mkOPQx 2Chhh//qegWZUWFbcJFlb9FnsoXeVhkm0Tw0k98l67GAyv5ItLniYOPcCMyuUNlBb8Vg RBBkuOg/VmZioKqP+KH/AuNMHVO3OH9mxrW51F0WoiwXBh/8MkBKK+pmgKpTHfKhaH0d TyMA== X-Forwarded-Encrypted: i=1; AHgh+RqAoKYra8aOJ/NJrZoSyUmdBb+51b4imn94QTw6WquiS5L0j8u0fWeMPotJsRwkqgt0NFo+eOYsxL7IiEQ=@vger.kernel.org X-Gm-Message-State: AOJu0YyptDsWVNVY+8abKlHVIen/+sIjBCGwfjgXbJYYVdKVfx4AhfE8 KmX+r9Fr3JSnODgvsSsbFPZGSdseBT/zj9yEOjNm2xbbt1zXwWIjZ4KN X-Gm-Gg: AR+sD11z7TPw9asoiZTMa+UCLXou+5J1W/l0D7Cck017lddLljLLJTO1GVuuOSKvEXi GA4m1JevsCnNQPESWjpaTzE8D9uOQsHDx3ukywez/tDt7PGDX7r9K4cj/pY+EAlxcXWaWb/W13I WjWZgdl5qPmOyQkc7EZJyp5n0x8hp/Uif7pS5Xbh5x+xpb+7KyLk+T7OM3iRVUYPMwUu41F1E+z PYnOMBslyOhdypVMJtTeltwyum2n+J93jBHavjVnqIm/6gx2OuztC5OwNfdVCmSBDN8/LijYSc7 hR9qpXFZQcq8NyNJ8mJc3RfEZAH7PRVuNNEqadVgEL24jTOwSJE5nOgTwI2UVDcfB9bpiJmu75m iwcnlrwN6SBHlNRj1Z4YvAjuWQdMovCs/6iUO52MCxSrBHE5QpdzUrZR6PMSI03x9FdGr+RnkDS aBp60DcVQvPW9piuWt9XgWk1guySbVbznX95Hu2PVMo5xsAPNurXSSNZF1lqBWog== X-Received: by 2002:a05:600c:1d0e:b0:495:4fd4:619b with SMTP id 5b1f17b1804b1-49987941a4amr8948855e9.1.1786649544454; Thu, 13 Aug 2026 12:32:24 -0700 (PDT) Received: from [10.245.244.3] ([134.191.227.48]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4815f20059asm1505239f8f.5.2026.08.13.12.32.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 13 Aug 2026 12:32:24 -0700 (PDT) Message-ID: <98dcc8a12f117745a1cb9981dc8f0f1548e9c96f.camel@gmail.com> Subject: Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic From: Artem Bityutskiy To: "Edgecombe, Rick P" , "seanjc@google.com" Cc: "kvm@vger.kernel.org" , "linux-kernel@vger.kernel.org" , "dave.hansen@linux.intel.com" , "bp@alien8.de" , "kas@kernel.org" , "binbin.wu@linux.intel.com" , "Li, Xiaoyao" , "sathyanarayanan.kuppuswamy@linux.intel.com" , "mingo@redhat.com" , "hpa@zytor.com" , "tglx@kernel.org" , "Fang, Peter" , "linux-coco@lists.linux.dev" , "x86@kernel.org" Date: Thu, 13 Aug 2026 22:32:20 +0300 In-Reply-To: References: <20260729122939.1340412-1-peter.fang@intel.com> <80b4ea89ebf17398c3bee21d157c7f97ea32aadf.camel@intel.com> <86d532f33816cd4fa3e29c40079a6003abf89324.camel@intel.com> <20260812223707.GD1013044@pedri> <6191a69559e58e04c8e3f1efa776e9639796af3d.camel@intel.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.60.2 (3.60.2-1.fc44) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 On Wed, 2026-08-12 at 23:30 +0000, Edgecombe, Rick P wrote: > Hmm, let me flag Artem to see if he can add anymore weight one way or the= other > from the migration POV. Hi, I will just assume the question is: "Is a TD-scoped quote seamcall fundamentally wrong or acceptable?" Short answer: I would say acceptable. I see it as a practical tradeoff. Let me lay out my mental model, which should explain how I came to this conclusion. Mental model =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D 1. SGX-based attestation The original SGX-style flow is two steps: 1. The TD gets TD report. 2. A quoting agent signs that report and produces the quote. What is quoting agent: a process using a special SGX enclave. Why 2-step: the key limitation is that the quoting agent cannot fetch TD evidence such as FW hash or other per-TD data. So the quote is conceptually: - TD report body - signature over the report body - trust material such as the public attestation key and certificate chain 2. DICE-based attestation The DICE-based model keeps the same two-step flow for compatibility, but the quoting service runs in the TDX module and can read TD evidence directly. As a result, the quote can include: - TD report body - extra per-TD evidence - signature over the report body and the extra evidence - trust material IOW: in the SGX-based design, it is impossible to add TD evidence to the quote. In the DICE-based design, it is possible. But the question is - OK, it is possible, but why should it be done? 3. Why freezing TD report size Linux supports 1024-byte TD reports via the `TDX_CMD_GET_REPORT0` ioctl. It is already full, no more TD evidence fits, and changing TD report size would require a new ioctl. Also, as I understand it, based on TDX feature requests from customers, there may be a need to increase TD report size more often and more significantly than one would expect. Therefore, for DICE-based attestation the TDX module adds new TD evidence in the quote instead of expanding the TD report. Is this the cleanest approach? Maybe not. A clear separation of concern, with TD evidence in the report and the quote only adding signature and trust material, does feel cleaner. But on the other hand: - The quote itself is already a per-TD data structure - The it is inherently variable size because it contains cryptographic=C2=A0material and trust data - A fixed-size TD report means that at least one of them is fixed size, not both. 4. Migration-specific case For the normal user attestation path, the TD report is TD-scoped. For migration, the report is effectively platform-scoped, just because the migration flow does not need TD-specific evidence. I would say that clean design is when Linux does not need to know this and care about this specific case: be able to treat all TD reports as per-TD. Thanks, Artem.