From: Xu Yilun <yilun.xu@linux.intel.com>
To: Peter Fang <peter.fang@intel.com>
Cc: Zhenzhong Duan <zhenzhong.duan@intel.com>,
x86@kernel.org, linux-coco@lists.linux.dev,
linux-kernel@vger.kernel.org, dave.hansen@linux.intel.com,
tglx@kernel.org, mingo@redhat.com, bp@alien8.de, hpa@zytor.com,
dave.hansen@intel.com, kas@kernel.org,
rick.p.edgecombe@intel.com, jgg@nvidia.com, nicolinc@nvidia.com,
aik@amd.com, aneesh.kumar@kernel.org, seanjc@google.com,
pbonzini@redhat.com, chao.gao@intel.com,
vishal.l.verma@intel.com, xiaoyao.li@intel.com,
kevin.tian@intel.com, chao.p.peng@intel.com
Subject: Re: [RFC PATCH 01/15] x86/tdx: Export tdg_vm_rd() for tdx-guest module
Date: Thu, 1 Oct 2026 20:38:26 +0800 [thread overview]
Message-ID: <ar5UQg/Q4zePFSzb@yilunxu-OptiPlex-7050> (raw)
In-Reply-To: <ar2JlI0ApPCb_C2G@intel.com>
On Wed, Sep 30, 2026 at 03:13:40PM -0700, Peter Fang wrote:
> On Thu, Sep 24, 2026 at 12:10:18PM +0800, Zhenzhong Duan wrote:
> > Export tdg_vm_rd() to allow the tdx-guest driver module to directly
> > read TD-scoped metadata fields from the Trust Domain Control Structure
> > (TDCS) via TDG.VM.RD TDCALL.
> >
> > Since tdg_vm_rd() is read-only and cannot cause harm, exporting it
> > directly is simpler and more flexible. This allows the tdx-guest driver
> > to read any TDCS field it needs.
> >
> > In a following patch, the tdx-guest driver will use tdg_vm_rd() to read
> > TDCS_CONFIG_FLAGS field directly.
>
> Can this be a separate helper? I'm adding another helper for
> TDCS_QUOTE_MAX_SIZE [1]. I think maybe their patterns should stay consistent.
>
> Yilun, any thoughts on this?
There was a helper in the series before this public RFC, but was then
dropped, something like:
int tdx_get_config_flags(u64 *flags)
{
u64 sret;
sret = tdg_vm_rd(TDCS_CONFIG_FLAGS, flags);
if (sret)
return -EIO;
return 0;
}
EXPORT_SYMBOL_FOR_MODULES(tdx_get_config_flags, "tdx-guest");
The concern is how risky is the tdg_vm_rd() export, and how it impacts
the existing tdg_vm_rd() usage, and the tdh_mng_rd() export which reads
the same data set on host.
My initial concern about the cons of tdg_vm_rd() export are, the
SEAMCALL reads any TDCS fields, some of them are writable by tdg_vm_wr()
and there is no synchronization between them, so seems not a good kAPI.
Reducing the scope to read-only fields (e.g. TDCS_CONFIG_FLAGS) may be a
good start.
Now there are 2 cases in flight: tdx_get_max_quote_size() helper in DICE
and tdg_vm_rd() export here. Maybe we need more cases to see which is
better but anyway I agree we'd better stay consistent now.
>
> Thanks,
> Peter
>
> [1] https://lore.kernel.org/kvm/20260930103739.2851980-6-peter.fang@intel.com/
>
> >
> > Signed-off-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
next prev parent reply other threads:[~2026-10-01 12:40 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 4:10 [RFC PATCH 00/15] PCI/TSM: coco/tdx-guest: Implement TDX-Connect PCIe TDISP (phase2) Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 01/15] x86/tdx: Export tdg_vm_rd() for tdx-guest module Zhenzhong Duan
2026-09-30 22:13 ` Peter Fang
2026-10-01 12:38 ` Xu Yilun [this message]
2026-10-08 6:45 ` Duan, Zhenzhong
2026-10-08 16:30 ` Edgecombe, Rick P
2026-09-24 4:10 ` [RFC PATCH 02/15] x86/tdx: Add TDCM hypercall wrapper for TDX Connect Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 03/15] x86/tdx: Add TDG.TDI.RD module call " Zhenzhong Duan
2026-09-25 0:06 ` Edgecombe, Rick P
2026-10-08 6:27 ` Duan, Zhenzhong
2026-10-08 16:42 ` Edgecombe, Rick P
2026-10-09 2:28 ` Duan, Zhenzhong
2026-09-24 4:10 ` [RFC PATCH 04/15] virt: tdx-guest: Support devsec TSM for secure devices Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 05/15] virt: tdx-guest: Add TDCM helpers and TEE-IO support check Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 06/15] virt: tdx-guest: Support TDI bind and unbind operations Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 07/15] PCI/TSM: Track Device Interface Report MMIO range index Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 08/15] x86/tdx: Add TDG.MMIO.ACCEPT module call wrapper for TDX Connect Zhenzhong Duan
2026-09-24 23:41 ` Edgecombe, Rick P
2026-09-25 0:02 ` Edgecombe, Rick P
2026-10-08 6:01 ` Duan, Zhenzhong
2026-10-08 16:47 ` Edgecombe, Rick P
2026-10-08 5:49 ` Duan, Zhenzhong
2026-10-08 16:44 ` Edgecombe, Rick P
2026-10-09 2:16 ` Duan, Zhenzhong
2026-09-24 4:10 ` [RFC PATCH 09/15] virt: tdx-guest: Capture the TDI report during device lock Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 10/15] virt: tdx-guest: Set up and accept private MMIO ranges Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 11/15] x86/tdx: Add TDG.TDI.START module call wrapper for TDX Connect Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 12/15] virt: tdx-guest: Support Trust Device Interface (TDI) activation Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 13/15] x86/tdx: Add __tdcall_saved() helper Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 14/15] x86/tdx: Add TDG.DMAR.ACCEPT module call wrapper for TDX Connect Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 15/15] virt: tdx-guest: Accept default DMAR entry during PCI driver attach Zhenzhong Duan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ar5UQg/Q4zePFSzb@yilunxu-OptiPlex-7050 \
--to=yilun.xu@linux.intel.com \
--cc=aik@amd.com \
--cc=aneesh.kumar@kernel.org \
--cc=bp@alien8.de \
--cc=chao.gao@intel.com \
--cc=chao.p.peng@intel.com \
--cc=dave.hansen@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=jgg@nvidia.com \
--cc=kas@kernel.org \
--cc=kevin.tian@intel.com \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=nicolinc@nvidia.com \
--cc=pbonzini@redhat.com \
--cc=peter.fang@intel.com \
--cc=rick.p.edgecombe@intel.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=vishal.l.verma@intel.com \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
--cc=zhenzhong.duan@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®