All of lore.kernel.org
 help / color / mirror / Atom feed
From: Dave Hansen <dave.hansen@intel.com>
To: Peter Fang <peter.fang@intel.com>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	Kiryl Shutsemau <kas@kernel.org>,
	Rick Edgecombe <rick.p.edgecombe@intel.com>,
	Kuppuswamy Sathyanarayanan
	<sathyanarayanan.kuppuswamy@linux.intel.com>
Cc: Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
	Borislav Petkov <bp@alien8.de>,
	x86@kernel.org, "H. Peter Anvin" <hpa@zytor.com>,
	linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev,
	kvm@vger.kernel.org, Xiaoyao Li <xiaoyao.li@intel.com>,
	Binbin Wu <binbin.wu@linux.intel.com>,
	Tony Lindgren <tony.lindgren@linux.intel.com>,
	Sean Christopherson <seanjc@google.com>,
	Artem Bityutskiy <artem.bityutskiy@intel.com>
Subject: Re: [PATCH v5 3/6] virt: tdx-guest: Calculate the Quote buffer size safely
Date: Mon, 28 Sep 2026 08:50:10 -0700	[thread overview]
Message-ID: <1753d73f-7464-4476-9fb7-c0a12157a6ab@intel.com> (raw)
In-Reply-To: <20260928100913.2265687-4-peter.fang@intel.com>

On 9/28/26 03:08, Peter Fang wrote:
> -#define TDX_QUOTE_MAX_LEN		(GET_QUOTE_BUF_SIZE - sizeof(struct tdx_quote_buf))
> +#define TDX_QUOTE_TOTAL_SIZE(n)		struct_size_t(struct tdx_quote_buf, data, n)
>  
>  /* struct tdx_quote_buf: Format of Quote request buffer.
>   * @version: Quote format version, filled by TD.
> @@ -314,7 +314,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
>  
>  	out_len = READ_ONCE(quote_buf->out_len);
>  
> -	if (out_len > TDX_QUOTE_MAX_LEN)
> +	if (TDX_QUOTE_TOTAL_SIZE(out_len) > GET_QUOTE_BUF_SIZE)
>  		return -EFBIG;

Gah, this is awful. There are two different literal "data" things:

	1. The function argument: void *data
	2. The flexible array member: tdx_quote_buf->data[]

Worse, I think the function argument isn't even used, despite being
passed through at least one level of static, file-local TDX calls.

It becomes a *total* liability since there are so many "data" names
being tossed around.

I just committed this:

> https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?h=x86/tdx&id=d48b2d347105436365280a3697a265aa4d37e96c

Any reason not to keep it?

  reply	other threads:[~2026-09-28 15:50 UTC|newest]

Thread overview: 40+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 10:08 [PATCH v5 0/6] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-09-28 10:08 ` [PATCH v5 1/6] x86/tdx: Take the Quote buffer as a generic pointer Peter Fang
2026-09-28 19:04   ` Edgecombe, Rick P
2026-09-28 20:37     ` Peter Fang
2026-09-28 20:10   ` Kuppuswamy Sathyanarayanan
2026-09-28 10:08 ` [PATCH v5 2/6] virt: tdx-guest: Give the Quote buffer an explicit type Peter Fang
2026-09-28 19:14   ` Edgecombe, Rick P
2026-09-28 20:16   ` Kuppuswamy Sathyanarayanan
2026-09-29  2:13   ` Binbin Wu
2026-09-29  7:41     ` Peter Fang
2026-09-29  7:43       ` Binbin Wu
2026-09-28 10:08 ` [PATCH v5 3/6] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-09-28 15:50   ` Dave Hansen [this message]
2026-09-28 20:53     ` Peter Fang
2026-09-28 10:08 ` [PATCH v5 4/6] virt: tdx-guest: Add a helper for the Quote buffer size Peter Fang
2026-09-28 16:13   ` Dave Hansen
2026-09-28 19:13     ` Edgecombe, Rick P
2026-09-29 10:32       ` Peter Fang
2026-09-29 15:45         ` Edgecombe, Rick P
2026-09-29 16:03           ` Peter Fang
2026-09-29 10:08     ` Peter Fang
2026-09-28 18:23   ` Edgecombe, Rick P
2026-09-29 16:38     ` Peter Fang
2026-09-28 10:08 ` [PATCH v5 5/6] x86/tdx: Add a helper to query maximum Quote size Peter Fang
2026-09-28 18:35   ` Edgecombe, Rick P
2026-09-28 21:00     ` Peter Fang
2026-09-28 18:50   ` Edgecombe, Rick P
2026-09-28 21:13     ` Peter Fang
2026-09-28 21:25       ` Edgecombe, Rick P
2026-09-28 21:25         ` Edgecombe, Rick P
2026-09-28 22:47           ` Peter Fang
2026-09-28 23:01         ` Peter Fang
2026-09-29 10:40       ` Peter Fang
2026-09-28 20:32   ` Kuppuswamy Sathyanarayanan
2026-09-29  9:18     ` Peter Fang
2026-09-29 14:18       ` Dave Hansen
2026-09-29 15:38         ` Peter Fang
2026-09-28 10:08 ` [PATCH v5 6/6] virt: tdx-guest: Make the Quote buffer size dynamic Peter Fang
2026-09-28 20:37   ` Kuppuswamy Sathyanarayanan
2026-09-29  7:23     ` Peter Fang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1753d73f-7464-4476-9fb7-c0a12157a6ab@intel.com \
    --to=dave.hansen@intel.com \
    --cc=artem.bityutskiy@intel.com \
    --cc=binbin.wu@linux.intel.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=kas@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=peter.fang@intel.com \
    --cc=rick.p.edgecombe@intel.com \
    --cc=sathyanarayanan.kuppuswamy@linux.intel.com \
    --cc=seanjc@google.com \
    --cc=tglx@kernel.org \
    --cc=tony.lindgren@linux.intel.com \
    --cc=x86@kernel.org \
    --cc=xiaoyao.li@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.