From: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>
To: "seanjc@google.com" <seanjc@google.com>
Cc: "mikko.ylinen@linux.intel.com" <mikko.ylinen@linux.intel.com>,
"Huang, Kai" <kai.huang@intel.com>,
"binbin.wu@linux.intel.com" <binbin.wu@linux.intel.com>,
"Yao, Jiewen" <jiewen.yao@intel.com>,
"Lindgren, Tony" <tony.lindgren@intel.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"Hunter, Adrian" <adrian.hunter@intel.com>,
"Li, Xiaoyao" <xiaoyao.li@intel.com>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
"Zhao, Yan Y" <yan.y.zhao@intel.com>,
"Chatre, Reinette" <reinette.chatre@intel.com>,
"Yamahata, Isaku" <isaku.yamahata@intel.com>,
"Shutemov, Kirill" <kirill.shutemov@intel.com>,
"pbonzini@redhat.com" <pbonzini@redhat.com>
Subject: Re: [RFC PATCH 3/4] KVM: TDX: Exit to userspace for GetTdVmCallInfo
Date: Wed, 11 Jun 2025 18:52:01 +0000 [thread overview]
Message-ID: <a746dbb0ffd130996058af92c54e91c4880a1337.camel@intel.com> (raw)
In-Reply-To: <aEnHYjTGofgGiDTH@google.com>
On Wed, 2025-06-11 at 11:13 -0700, Sean Christopherson wrote:
> > I don't know if that was a consideration for why it got added to the
> > optional
> > category. The inputs were gathered from more than just Linux.
>
> If there's an actual use case for TDX without attestation, then by all means,
> make it optional. I'm genuinely curious if there's a hypervisor that plans on
> productizing TDX without supporting attestation. It's entirely possible
> (likely?)
> I'm missing or forgetting something.
Ok, will check back in with the story.
The only things I could think of are:
1. TDX usage as a hardening thing, similar to unmapping guest memory for all
page tables in the host.
2. Some highly coupled guest/VMM has an alternate attestation scheme.
More likely it was to retroactively bring the initial KVM PR into spec. We got
some pretty specific direction from Paolo to explore GetTdVmCallInfo exiting, so
it didn't make much of a difference one way or the other until now.
next prev parent reply other threads:[~2025-06-11 18:52 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-06-10 2:14 [RFC PATCH 0/4] TDX attestation support and GHCI fixup Binbin Wu
2025-06-10 2:14 ` [RFC PATCH 1/4] KVM: TDX: Add new TDVMCALL status code for unsupported subfuncs Binbin Wu
2025-06-10 2:14 ` [RFC PATCH 2/4] KVM: TDX: Handle TDG.VP.VMCALL<GetQuote> Binbin Wu
2025-06-10 2:14 ` [RFC PATCH 3/4] KVM: TDX: Exit to userspace for GetTdVmCallInfo Binbin Wu
2025-06-10 9:16 ` Xiaoyao Li
2025-06-10 16:50 ` Edgecombe, Rick P
2025-06-10 16:54 ` Edgecombe, Rick P
2025-06-11 2:04 ` Binbin Wu
2025-06-11 2:37 ` Xiaoyao Li
2025-06-11 14:17 ` Edgecombe, Rick P
2025-06-11 14:34 ` Xiaoyao Li
2025-06-11 14:41 ` Edgecombe, Rick P
2025-06-11 1:37 ` Binbin Wu
2025-06-11 2:17 ` Xiaoyao Li
2025-06-11 14:54 ` Sean Christopherson
2025-06-11 14:58 ` Edgecombe, Rick P
2025-06-11 16:26 ` Sean Christopherson
2025-06-11 16:53 ` Edgecombe, Rick P
2025-06-11 18:13 ` Sean Christopherson
2025-06-11 18:52 ` Edgecombe, Rick P [this message]
2025-06-12 8:27 ` Huang, Kai
2025-06-12 15:26 ` Edgecombe, Rick P
2025-06-20 18:27 ` Edgecombe, Rick P
2025-06-10 2:14 ` [RFC PATCH 4/4] KVM: TDX: Check KVM exit on KVM_HC_MAP_GPA_RANGE when TD finalize Binbin Wu
2025-06-10 17:01 ` Edgecombe, Rick P
2025-06-10 19:58 ` Sean Christopherson
2025-06-11 1:22 ` Binbin Wu
2025-06-11 13:36 ` Sean Christopherson
2025-06-11 14:01 ` Xiaoyao Li
2025-06-11 14:04 ` Edgecombe, Rick P
2025-06-11 14:26 ` Xiaoyao Li
2025-06-11 16:00 ` Binbin Wu
2025-06-11 15:33 ` Binbin Wu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a746dbb0ffd130996058af92c54e91c4880a1337.camel@intel.com \
--to=rick.p.edgecombe@intel.com \
--cc=adrian.hunter@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=isaku.yamahata@intel.com \
--cc=jiewen.yao@intel.com \
--cc=kai.huang@intel.com \
--cc=kirill.shutemov@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mikko.ylinen@linux.intel.com \
--cc=pbonzini@redhat.com \
--cc=reinette.chatre@intel.com \
--cc=seanjc@google.com \
--cc=tony.lindgren@intel.com \
--cc=xiaoyao.li@intel.com \
--cc=yan.y.zhao@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®