From: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>
To: "Li, Xiaoyao" <xiaoyao.li@intel.com>,
"binbin.wu@linux.intel.com" <binbin.wu@linux.intel.com>
Cc: "Gao, Chao" <chao.gao@intel.com>,
"dedekind1@gmail.com" <dedekind1@gmail.com>,
"seanjc@google.com" <seanjc@google.com>,
"dave.hansen@linux.intel.com" <dave.hansen@linux.intel.com>,
"kas@kernel.org" <kas@kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"Maloor, Kishen" <kishen.maloor@intel.com>,
"tony.lindgren@linux.intel.com" <tony.lindgren@linux.intel.com>,
"andrew.cooper3@citrix.com" <andrew.cooper3@citrix.com>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
"nik.borisov@suse.com" <nik.borisov@suse.com>,
"pbonzini@redhat.com" <pbonzini@redhat.com>
Subject: Re: [PATCH v4 1/4] KVM: TDX: Track configurable CPUID bits allowed by KVM
Date: Mon, 28 Sep 2026 23:58:51 +0000 [thread overview]
Message-ID: <c2b669f099174c5d67593d5446a02abc43eff40c.camel@intel.com> (raw)
In-Reply-To: <c612e6cd-ca84-4c37-af72-9c13eeb1f3ce@linux.intel.com>
On Mon, 2026-09-28 at 16:08 +0800, Binbin Wu wrote:
> > > I don't know why the CPUID is disconnected with the MSR.
> > > But this bit is present on the host, I think we can add it to the
> > > allowlist.
> >
> > I have opposite opinion. Since 1) this feature is related to hardware
> > processor PIN, 2) KVM never advertise it to normal VMs, and 3) no usage in
> > kernel for this feature. I think no TD relies on it and don't allow it
> > should be OK.
Yea, I lean towards educated guesses that userspace/guests are not relying on
these kind of features. If we guess wrong, we can revert the change. If we allow
it for years, then we have another line in the allow list forever that maybe
nobody is using.
>
> My consideration was maybe some userspace could set this bit.
>
> But userspace is expected to consult KVM_TDX_CAPABILITIES for the configurable
> bits before invoking KVM_TDX_INIT_VM
If a guest is already using it, then even if the bit disappears from
KVM_TDX_CAPABILITIES it could cause a regression when it doesn't get configured
in the guest.
> , regardless of this patch series, there is no risk to break userspace, except
> for CORE_CAPABILITIES, which is the only
> special case as it was defined as fixed-1.
>
> I think there is no need to add XTPR to the allow list either.
next prev parent reply other threads:[~2026-09-28 23:58 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 7:25 [PATCH v4 0/4] KVM: TDX: Validate directly configurable CPUID bits Binbin Wu
2026-09-17 7:25 ` [PATCH v4 1/4] KVM: TDX: Track configurable CPUID bits allowed by KVM Binbin Wu
2026-09-23 0:01 ` Edgecombe, Rick P
2026-09-23 0:14 ` Binbin Wu
2026-09-23 0:45 ` Edgecombe, Rick P
2026-09-23 0:57 ` Binbin Wu
2026-09-23 1:09 ` Edgecombe, Rick P
2026-09-23 1:17 ` Binbin Wu
2026-09-23 11:21 ` Xiaoyao Li
2026-09-23 14:25 ` Edgecombe, Rick P
2026-09-24 2:05 ` Xiaoyao Li
2026-09-24 6:36 ` Xiaoyao Li
2026-09-24 7:49 ` Binbin Wu
2026-09-24 9:30 ` Xiaoyao Li
2026-09-24 11:41 ` Binbin Wu
2026-09-24 13:55 ` Xiaoyao Li
2026-09-24 15:10 ` Binbin Wu
2026-09-24 14:33 ` Xiaoyao Li
2026-09-28 8:08 ` Binbin Wu
2026-09-28 23:58 ` Edgecombe, Rick P [this message]
2026-09-29 0:19 ` Binbin Wu
2026-09-17 7:25 ` [PATCH v4 2/4] KVM: TDX: Report CORE_CAPABILITIES as configurable Binbin Wu
2026-09-22 21:11 ` Edgecombe, Rick P
2026-09-23 0:03 ` Binbin Wu
2026-09-24 6:44 ` Xiaoyao Li
2026-09-17 7:25 ` [PATCH v4 3/4] KVM: TDX: Filter configurable CPUID bits Binbin Wu
2026-09-23 0:16 ` Edgecombe, Rick P
2026-09-23 0:28 ` Binbin Wu
2026-09-23 0:34 ` Edgecombe, Rick P
2026-09-17 7:25 ` [PATCH v4 4/4] KVM: TDX: Validate userspace CPUID input for KVM_TDX_INIT_VM Binbin Wu
2026-09-23 0:16 ` Edgecombe, Rick P
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c2b669f099174c5d67593d5446a02abc43eff40c.camel@intel.com \
--to=rick.p.edgecombe@intel.com \
--cc=andrew.cooper3@citrix.com \
--cc=binbin.wu@linux.intel.com \
--cc=chao.gao@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=dedekind1@gmail.com \
--cc=kas@kernel.org \
--cc=kishen.maloor@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nik.borisov@suse.com \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=tony.lindgren@linux.intel.com \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®