From: Peter Fang <peter.fang@intel.com>
To: Dave Hansen <dave.hansen@intel.com>
Cc: Dave Hansen <dave.hansen@linux.intel.com>,
Kiryl Shutsemau <kas@kernel.org>,
Rick Edgecombe <rick.p.edgecombe@intel.com>,
"Kuppuswamy Sathyanarayanan"
<sathyanarayanan.kuppuswamy@linux.intel.com>,
Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>, <x86@kernel.org>,
"H. Peter Anvin" <hpa@zytor.com>, <linux-kernel@vger.kernel.org>,
<linux-coco@lists.linux.dev>, <kvm@vger.kernel.org>,
Xiaoyao Li <xiaoyao.li@intel.com>,
Binbin Wu <binbin.wu@linux.intel.com>,
Tony Lindgren <tony.lindgren@linux.intel.com>,
Sean Christopherson <seanjc@google.com>,
Artem Bityutskiy <artem.bityutskiy@intel.com>
Subject: Re: [PATCH v5 3/6] virt: tdx-guest: Calculate the Quote buffer size safely
Date: Mon, 28 Sep 2026 13:53:28 -0700 [thread overview]
Message-ID: <arrTyM42WnUUSgR7@intel.com> (raw)
In-Reply-To: <1753d73f-7464-4476-9fb7-c0a12157a6ab@intel.com>
On Mon, Sep 28, 2026 at 08:50:10AM -0700, Dave Hansen wrote:
> On 9/28/26 03:08, Peter Fang wrote:
> > -#define TDX_QUOTE_MAX_LEN (GET_QUOTE_BUF_SIZE - sizeof(struct tdx_quote_buf))
> > +#define TDX_QUOTE_TOTAL_SIZE(n) struct_size_t(struct tdx_quote_buf, data, n)
> >
> > /* struct tdx_quote_buf: Format of Quote request buffer.
> > * @version: Quote format version, filled by TD.
> > @@ -314,7 +314,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
> >
> > out_len = READ_ONCE(quote_buf->out_len);
> >
> > - if (out_len > TDX_QUOTE_MAX_LEN)
> > + if (TDX_QUOTE_TOTAL_SIZE(out_len) > GET_QUOTE_BUF_SIZE)
> > return -EFBIG;
>
> Gah, this is awful. There are two different literal "data" things:
>
> 1. The function argument: void *data
> 2. The flexible array member: tdx_quote_buf->data[]
>
> Worse, I think the function argument isn't even used, despite being
> passed through at least one level of static, file-local TDX calls.
>
> It becomes a *total* liability since there are so many "data" names
> being tossed around.
>
> I just committed this:
>
> > https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?h=x86/tdx&id=d48b2d347105436365280a3697a265aa4d37e96c
>
> Any reason not to keep it?
Thanks Dave! Your change makes perfect sense to me. I totally agree.
There are so many uses of "data" in this driver.
Dave actually suggested offline removing TDX_QUOTE_TOTAL_SIZE()
altogether because it really doesn't add much value, forces the reader
to look for the macro def, and doesn't even reduce LOC. So the next
version won't have this macro anymore. That also reduces one line of
code which is a small win.
next prev parent reply other threads:[~2026-09-28 20:53 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 10:08 [PATCH v5 0/6] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-09-28 10:08 ` [PATCH v5 1/6] x86/tdx: Take the Quote buffer as a generic pointer Peter Fang
2026-09-28 19:04 ` Edgecombe, Rick P
2026-09-28 20:37 ` Peter Fang
2026-09-28 20:10 ` Kuppuswamy Sathyanarayanan
2026-09-28 10:08 ` [PATCH v5 2/6] virt: tdx-guest: Give the Quote buffer an explicit type Peter Fang
2026-09-28 19:14 ` Edgecombe, Rick P
2026-09-28 20:16 ` Kuppuswamy Sathyanarayanan
2026-09-29 2:13 ` Binbin Wu
2026-09-29 7:41 ` Peter Fang
2026-09-29 7:43 ` Binbin Wu
2026-09-28 10:08 ` [PATCH v5 3/6] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-09-28 15:50 ` Dave Hansen
2026-09-28 20:53 ` Peter Fang [this message]
2026-09-28 10:08 ` [PATCH v5 4/6] virt: tdx-guest: Add a helper for the Quote buffer size Peter Fang
2026-09-28 16:13 ` Dave Hansen
2026-09-28 19:13 ` Edgecombe, Rick P
2026-09-29 10:32 ` Peter Fang
2026-09-29 10:08 ` Peter Fang
2026-09-28 18:23 ` Edgecombe, Rick P
2026-09-28 10:08 ` [PATCH v5 5/6] x86/tdx: Add a helper to query maximum Quote size Peter Fang
2026-09-28 18:35 ` Edgecombe, Rick P
2026-09-28 21:00 ` Peter Fang
2026-09-28 18:50 ` Edgecombe, Rick P
2026-09-28 21:13 ` Peter Fang
2026-09-28 21:25 ` Edgecombe, Rick P
2026-09-28 21:25 ` Edgecombe, Rick P
2026-09-28 22:47 ` Peter Fang
2026-09-28 23:01 ` Peter Fang
2026-09-29 10:40 ` Peter Fang
2026-09-28 20:32 ` Kuppuswamy Sathyanarayanan
2026-09-29 9:18 ` Peter Fang
2026-09-28 10:08 ` [PATCH v5 6/6] virt: tdx-guest: Make the Quote buffer size dynamic Peter Fang
2026-09-28 20:37 ` Kuppuswamy Sathyanarayanan
2026-09-29 7:23 ` Peter Fang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arrTyM42WnUUSgR7@intel.com \
--to=peter.fang@intel.com \
--cc=artem.bityutskiy@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=sathyanarayanan.kuppuswamy@linux.intel.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=tony.lindgren@linux.intel.com \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®