* [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
@ 2026-07-29 12:29 Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
` (3 more replies)
0 siblings, 4 replies; 7+ messages in thread
From: Peter Fang @ 2026-07-29 12:29 UTC (permalink / raw)
To: Dave Hansen, Kiryl Shutsemau, Rick Edgecombe,
Kuppuswamy Sathyanarayanan
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu, Peter Fang
Hi,
A new TDX module ABI provides the maximum attestation report size. This
series changes the TDX guest driver's report buffer size from a fixed
constant to that queried value. So effectively:
s/FIXED_BUF_SIZE/queried_buf_size/g
...in the TDX guest driver.
Terminology
===========
A "TD Quote" is an attestation structure signed with a platform key. It
contains information about a TDX guest and the platform it's running on.
The "Quote buffer" in the TDX guest driver is a memory buffer shared
between the TDX guest and the host VMM to retrieve TD Quotes. It has a
header defined in the GHCI spec [1].
Device Identifier Composition Engine ("DICE") provides a framework for
layering attestation evidence. This replaces the SGX model of contacting
an Intel server to obtain a certificate.
Problem
=======
The fixed-size Quote buffer approach is not sustainable. As
cryptographic algorithms evolve, TD Quote sizes also grow. A previous
commit [2] increased the guest driver's fixed-size Quote buffer to 128
KB to accommodate DICE Quotes, but it may still be insufficient when
those Quotes use post-quantum cryptography (PQC). PQC certificate chains
are roughly 10x-15x larger than conventional ones, which can increase
Quote sizes significantly.
What's in this series
=====================
To avoid changing the driver whenever the Quote buffer becomes too
small, newer TDX modules report their maximum Quote size via a metadata
field. The guest driver uses this value for its Quote buffer when
available. Older TDX modules continue to use the 128 KB buffer.
Patches 2 and 3 refactor the existing fixed buffer handling. Patch 4
then makes the buffer size dynamic.
The "outblob" file in configfs-tsm no longer has a fixed maximum size.
The limit can now come from this new TDX module ABI.
Patch 1/4: Add a helper to read the QUOTE_MAX_SIZE metadata field.
Patch 2/4: Calculate the Quote buffer size with struct_size_t().
Patch 3/4: Store the Quote buffer size in a variable instead of a
constant.
Patch 4/4: Allocate the Quote buffer using the queried size, when
available.
AI use
======
I used Claude:claude-opus-4-8 to help edit this cover letter and the
changelogs, and to collect the review feedback on lore. The series also
underwent AI code review (Claude:claude-opus-4-7), but its comments were
limited to style suggestions.
v2: https://lore.kernel.org/all/20260717214349.4075994-1-peter.fang@intel.com/
Changes in v3:
- Split the v2 "Allocate Quote buffer dynamically" patch to do the
refactoring first, then make the buffer size dynamic. [Dave]
- Improve patterns for readability. [Dave]
- Drop __GFP_NOWARN so an allocation failure warns. [Dave, Rick, Kiryl]
- Add Binbin's Reviewed-by to patch 1.
- Drop the Reviewed-by tags (Kiryl, Binbin) as the patch was reworked.
v1: https://lore.kernel.org/all/20260612110853.3188196-1-peter.fang@intel.com/
Changes in v2:
- Collect Reviewed-by tags. [Kiryl, Xiaoyao, Binbin, Sathya]
- Keep the explicit (u32) cast in tdx_get_max_quote_size(). [Binbin]
- Calculate the Quote buffer size with struct_size_t(). [Kiryl, Binbin]
- Add __GFP_NOWARN to the allocation since its size comes from the
host. [sashiko]
- Rename quote_data_size to quote_data_len. [Sathya]
- Drop the Assisted-by tags, as AI was not used to write the code.
[1] Guest Hypervisor Communication Interface (GHCI) Specification,
Version 1.5, Section "TDG.VP.VMCALL<GetQuote>"
[2] 43185067c6fd ("configfs-tsm-report: tdx_guest: Increase Quote buffer
size to 128KB")
Kuppuswamy Sathyanarayanan (1):
virt: tdx-guest: Allocate Quote buffer dynamically
Peter Fang (3):
x86/tdx: Add helper to query maximum TD Quote size
virt: tdx-guest: Calculate the Quote buffer size safely
virt: tdx-guest: Use a variable to store the Quote buffer size
arch/x86/coco/tdx/tdx.c | 19 ++++++++++
arch/x86/include/asm/shared/tdx.h | 1 +
arch/x86/include/asm/tdx.h | 2 ++
drivers/virt/coco/tdx-guest/tdx-guest.c | 46 ++++++++++++++++++-------
4 files changed, 55 insertions(+), 13 deletions(-)
base-commit: f5098b6bae761e346ebcd9da7f95622c04733cff
--
2.53.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
@ 2026-07-29 12:29 ` Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
` (2 subsequent siblings)
3 siblings, 0 replies; 7+ messages in thread
From: Peter Fang @ 2026-07-29 12:29 UTC (permalink / raw)
To: Dave Hansen, Kiryl Shutsemau, Rick Edgecombe,
Kuppuswamy Sathyanarayanan
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu, Peter Fang
TDX attestation report ("Quote") sizes can grow with newer cryptographic
schemes, so guests can no longer rely on a fixed-size buffer for the
Quote.
Newer TDX modules report the maximum Quote size via a TD-scope metadata
field. Add a helper to query the size instead of exposing tdg_vm_rd()
directly, as it can read arbitrary metadata fields.
Thanks to Xu Yilun for suggesting this in an off-list discussion.
Reviewed-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
Reviewed-by: Xiaoyao Li <xiaoyao.li@intel.com>
Reviewed-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
Signed-off-by: Peter Fang <peter.fang@intel.com>
---
v3:
- No code changes. Add Binbin's Reviewed-by.
v2:
- Keep the explicit (u32) cast to document the metadata field width.
[Binbin]
- Note that Xu Yilun's suggestion was made in an off-list discussion.
[Sathya]
- Drop the Assisted-by tags, as the code was not written by AI.
---
arch/x86/coco/tdx/tdx.c | 19 +++++++++++++++++++
arch/x86/include/asm/shared/tdx.h | 1 +
arch/x86/include/asm/tdx.h | 2 ++
3 files changed, 22 insertions(+)
diff --git a/arch/x86/coco/tdx/tdx.c b/arch/x86/coco/tdx/tdx.c
index 29b6f1ed59ec..fa2ed012e736 100644
--- a/arch/x86/coco/tdx/tdx.c
+++ b/arch/x86/coco/tdx/tdx.c
@@ -198,6 +198,25 @@ u64 tdx_hcall_get_quote(u8 *buf, size_t size)
}
EXPORT_SYMBOL_GPL(tdx_hcall_get_quote);
+/**
+ * tdx_get_max_quote_size() - Get the maximum TD Quote size
+ *
+ * Read the maximum size of a TD Quote from a 4-byte TD metadata field. The TDX
+ * guest driver uses it to size the buffer for Quote retrieval. Older TDX
+ * modules do not support this field and return an error.
+ *
+ * Return: Maximum Quote size in bytes on success, or 0 on failure.
+ */
+u32 tdx_get_max_quote_size(void)
+{
+ u64 val, ret;
+
+ ret = tdg_vm_rd(TDCS_QUOTE_MAX_SIZE, &val);
+
+ return ret ? 0 : (u32)val;
+}
+EXPORT_SYMBOL_GPL(tdx_get_max_quote_size);
+
static void __noreturn tdx_panic(const char *msg)
{
struct tdx_module_args args = {
diff --git a/arch/x86/include/asm/shared/tdx.h b/arch/x86/include/asm/shared/tdx.h
index f20e91d7ac35..a58751321613 100644
--- a/arch/x86/include/asm/shared/tdx.h
+++ b/arch/x86/include/asm/shared/tdx.h
@@ -50,6 +50,7 @@
/* TDX TD-Scope Metadata. To be used by TDG.VM.WR and TDG.VM.RD */
#define TDCS_CONFIG_FLAGS 0x1110000300000016
#define TDCS_TD_CTLS 0x1110000300000017
+#define TDCS_QUOTE_MAX_SIZE 0x9010000200000008
#define TDCS_NOTIFY_ENABLES 0x9100000000000010
#define TDCS_TOPOLOGY_ENUM_CONFIGURED 0x9100000000000019
diff --git a/arch/x86/include/asm/tdx.h b/arch/x86/include/asm/tdx.h
index 89e97d5761d8..a75dbbe004bd 100644
--- a/arch/x86/include/asm/tdx.h
+++ b/arch/x86/include/asm/tdx.h
@@ -83,6 +83,8 @@ int tdx_mcall_extend_rtmr(u8 index, u8 *data);
u64 tdx_hcall_get_quote(u8 *buf, size_t size);
+u32 tdx_get_max_quote_size(void);
+
void __init tdx_dump_attributes(u64 td_attr);
void __init tdx_dump_td_ctls(u64 td_ctls);
--
2.53.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
@ 2026-07-29 12:29 ` Peter Fang
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
3 siblings, 0 replies; 7+ messages in thread
From: Peter Fang @ 2026-07-29 12:29 UTC (permalink / raw)
To: Dave Hansen, Kiryl Shutsemau, Rick Edgecombe,
Kuppuswamy Sathyanarayanan
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu, Peter Fang
struct tdx_quote_buf has a trailing flexible array member.
struct_size_t() calculates the size of this kind of struct safely. It
handles overflow, which is an important property since the Quote size
comes from the host.
Use it in place of the fixed length limit.
Signed-off-by: Peter Fang <peter.fang@intel.com>
---
v3:
- Split out the use of struct_size_t() for buffer length from the v2
"Allocate Quote buffer dynamically" patch to refactor first. [Dave]
- Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
reworked.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index d0303e31e816..f47c5429d002 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -170,7 +170,7 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
#define GET_QUOTE_SUCCESS 0
#define GET_QUOTE_IN_FLIGHT 0xffffffffffffffff
-#define TDX_QUOTE_MAX_LEN (GET_QUOTE_BUF_SIZE - sizeof(struct tdx_quote_buf))
+#define TDX_QUOTE_BUF_LEN(n) struct_size_t(struct tdx_quote_buf, data, n)
/* struct tdx_quote_buf: Format of Quote request buffer.
* @version: Quote format version, filled by TD.
@@ -315,7 +315,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
out_len = READ_ONCE(quote_buf->out_len);
- if (out_len > TDX_QUOTE_MAX_LEN)
+ if (TDX_QUOTE_BUF_LEN(out_len) > GET_QUOTE_BUF_SIZE)
return -EFBIG;
buf = kvmemdup(quote_buf->data, out_len, GFP_KERNEL);
--
2.53.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
@ 2026-07-29 12:29 ` Peter Fang
2026-07-29 12:58 ` sashiko-bot
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
3 siblings, 1 reply; 7+ messages in thread
From: Peter Fang @ 2026-07-29 12:29 UTC (permalink / raw)
To: Dave Hansen, Kiryl Shutsemau, Rick Edgecombe,
Kuppuswamy Sathyanarayanan
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu, Peter Fang
In preparation for dynamic Quote buffer sizes, replace the fixed size
constant with a variable.
The size is currently a constant sprinkled across several places. Store
it in a variable and have all the users read it from there.
Signed-off-by: Peter Fang <peter.fang@intel.com>
---
v3:
- Split out using a variable for the buffer size from the v2 "Allocate
Quote buffer dynamically" patch to refactor first. [Dave]
- Pass the buffer size into alloc_quote_buf() by value. [Dave]
- Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
reworked.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 22 +++++++++++-----------
1 file changed, 11 insertions(+), 11 deletions(-)
diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index f47c5429d002..3d3f79ab45af 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -191,8 +191,9 @@ struct tdx_quote_buf {
u8 data[];
};
-/* Quote data buffer */
+/* Quote data buffer and length */
static void *quote_data;
+static size_t quote_data_len;
/* Lock to streamline quote requests */
static DEFINE_MUTEX(quote_lock);
@@ -209,9 +210,8 @@ static long tdx_get_report0(struct tdx_report_req __user *req)
USER_SOCKPTR(req->tdreport));
}
-static void free_quote_buf(void *buf)
+static void free_quote_buf(void *buf, size_t len)
{
- size_t len = PAGE_ALIGN(GET_QUOTE_BUF_SIZE);
unsigned int count = len >> PAGE_SHIFT;
if (set_memory_encrypted((unsigned long)buf, count)) {
@@ -222,9 +222,8 @@ static void free_quote_buf(void *buf)
free_pages_exact(buf, len);
}
-static void *alloc_quote_buf(void)
+static void *alloc_quote_buf(size_t len)
{
- size_t len = PAGE_ALIGN(GET_QUOTE_BUF_SIZE);
unsigned int count = len >> PAGE_SHIFT;
void *addr;
@@ -285,7 +284,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
if (desc->inblob_len != TDX_REPORTDATA_LEN)
return -EINVAL;
- memset(quote_data, 0, GET_QUOTE_BUF_SIZE);
+ memset(quote_data, 0, quote_data_len);
/* Update Quote buffer header */
quote_buf->version = GET_QUOTE_CMD_VER;
@@ -296,7 +295,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
if (ret)
return ret;
- err = tdx_hcall_get_quote(quote_data, GET_QUOTE_BUF_SIZE);
+ err = tdx_hcall_get_quote(quote_data, quote_data_len);
if (err) {
pr_err("GetQuote hypercall failed, status:%llx\n", err);
return -EIO;
@@ -315,7 +314,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
out_len = READ_ONCE(quote_buf->out_len);
- if (TDX_QUOTE_BUF_LEN(out_len) > GET_QUOTE_BUF_SIZE)
+ if (TDX_QUOTE_BUF_LEN(out_len) > quote_data_len)
return -EFBIG;
buf = kvmemdup(quote_buf->data, out_len, GFP_KERNEL);
@@ -417,7 +416,8 @@ static int __init tdx_guest_init(void)
if (ret)
goto deinit_mr;
- quote_data = alloc_quote_buf();
+ quote_data_len = GET_QUOTE_BUF_SIZE;
+ quote_data = alloc_quote_buf(quote_data_len);
if (!quote_data) {
pr_err("Failed to allocate Quote buffer\n");
ret = -ENOMEM;
@@ -431,7 +431,7 @@ static int __init tdx_guest_init(void)
return 0;
free_quote:
- free_quote_buf(quote_data);
+ free_quote_buf(quote_data, quote_data_len);
free_misc:
misc_deregister(&tdx_misc_dev);
deinit_mr:
@@ -444,7 +444,7 @@ module_init(tdx_guest_init);
static void __exit tdx_guest_exit(void)
{
tsm_report_unregister(&tdx_tsm_ops);
- free_quote_buf(quote_data);
+ free_quote_buf(quote_data, quote_data_len);
misc_deregister(&tdx_misc_dev);
tdx_mr_deinit(tdx_attr_groups[0]);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
` (2 preceding siblings ...)
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
@ 2026-07-29 12:29 ` Peter Fang
2026-07-29 12:55 ` sashiko-bot
3 siblings, 1 reply; 7+ messages in thread
From: Peter Fang @ 2026-07-29 12:29 UTC (permalink / raw)
To: Dave Hansen, Kiryl Shutsemau, Rick Edgecombe,
Kuppuswamy Sathyanarayanan
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu, Peter Fang
From: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
A new TDX module ABI reports the TD Quote size limit in a metadata
field. This size used to be fixed at 128 KB.
The guest driver's Quote buffer is shared with the host VMM. The current
fixed size may be too small for Quotes using schemes such as
post-quantum cryptography (PQC), where larger certificate chains can
increase the Quote size significantly.
Allocate the Quote buffer based on the reported limit. This avoids
wasting memory on platforms that do not require larger Quotes. Older
platforms fall back to the default 128 KB buffer.
As a result, the maximum size of the "outblob" file in configfs-tsm now
depends on the TDX module.
Because the Quote buffer must be physically contiguous, its size is
bound by the buddy allocator's maximum page order (4 MB), which should
be sufficient for current attestation needs.
Signed-off-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
Signed-off-by: Peter Fang <peter.fang@intel.com>
---
v3:
- Split out from the v2 "Allocate Quote buffer dynamically" patch. Add
the dynamic buffer feature on top of the refactoring. [Dave]
- Improve the get_quote_buf_size() pattern for better readability.
[Dave]
- Drop __GFP_NOWARN so an allocation failure warns. [Dave, Rick, Kiryl]
- Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
reworked.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 24 ++++++++++++++++++++++--
1 file changed, 22 insertions(+), 2 deletions(-)
diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index 3d3f79ab45af..8919b1a1154e 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -162,7 +162,7 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
* DICE-based attestation uses layered evidence that requires
* larger Quote size (~100K).
*/
-#define GET_QUOTE_BUF_SIZE SZ_128K
+#define GET_QUOTE_DEFAULT_BUF_SIZE SZ_128K
#define GET_QUOTE_CMD_VER 1
@@ -222,11 +222,31 @@ static void free_quote_buf(void *buf, size_t len)
free_pages_exact(buf, len);
}
+/* Return a buffer size large enough to hold a Quote */
+static size_t get_quote_buf_size(void)
+{
+ u32 quote_size = tdx_get_max_quote_size();
+
+ /*
+ * Older TDX modules do not report a maximum Quote size, so use
+ * the default.
+ */
+ if (!quote_size)
+ return GET_QUOTE_DEFAULT_BUF_SIZE;
+
+ /* The reported size does not include the buffer header */
+ return PAGE_ALIGN(TDX_QUOTE_BUF_LEN(quote_size));
+}
+
static void *alloc_quote_buf(size_t len)
{
unsigned int count = len >> PAGE_SHIFT;
void *addr;
+ /*
+ * This fails if the requested size exceeds the buddy allocator's
+ * maximum order (order-10, 4MB).
+ */
addr = alloc_pages_exact(len, GFP_KERNEL | __GFP_ZERO);
if (!addr)
return NULL;
@@ -416,7 +436,7 @@ static int __init tdx_guest_init(void)
if (ret)
goto deinit_mr;
- quote_data_len = GET_QUOTE_BUF_SIZE;
+ quote_data_len = get_quote_buf_size();
quote_data = alloc_quote_buf(quote_data_len);
if (!quote_data) {
pr_err("Failed to allocate Quote buffer\n");
--
2.53.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
@ 2026-07-29 12:55 ` sashiko-bot
0 siblings, 0 replies; 7+ messages in thread
From: sashiko-bot @ 2026-07-29 12:55 UTC (permalink / raw)
To: Peter Fang; +Cc: kvm
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [High] Untrusted VMM input `TDCS_QUOTE_MAX_SIZE` is passed directly to the page allocator without bounding and without `__GFP_NOWARN`, which can trigger a kernel warning (`WARN_ON_ONCE`) and panic the guest if `panic_on_warn` is set.
Pre-existing issues:
- [High] Pre-existing UAF/Use-After-Unload race condition if module initialization fails after registering the misc device.
--
--- Patch [4]: [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically ---
commit 25802a377289c67ad6c07c5b41f81b3b9c799fbe
Author: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
virt: tdx-guest: Allocate Quote buffer dynamically
This commit modifies the TDX guest driver to dynamically allocate the Quote
buffer based on a size reported by the TDX module, replacing a fixed 128KB
allocation. It removes the __GFP_NOWARN flag to ensure allocation failures
produce a warning.
> diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
> index 3d3f79ab45af0..8919b1a1154e7 100644
> --- a/drivers/virt/coco/tdx-guest/tdx-guest.c
> +++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
[ ... ]
> @@ -222,11 +222,31 @@ static void free_quote_buf(void *buf, size_t len)
> free_pages_exact(buf, len);
> }
>
> +/* Return a buffer size large enough to hold a Quote */
> +static size_t get_quote_buf_size(void)
> +{
> + u32 quote_size = tdx_get_max_quote_size();
> +
> + /*
> + * Older TDX modules do not report a maximum Quote size, so use
> + * the default.
> + */
> + if (!quote_size)
> + return GET_QUOTE_DEFAULT_BUF_SIZE;
> +
> + /* The reported size does not include the buffer header */
> + return PAGE_ALIGN(TDX_QUOTE_BUF_LEN(quote_size));
> +}
> +
> static void *alloc_quote_buf(size_t len)
> {
> unsigned int count = len >> PAGE_SHIFT;
> void *addr;
>
> + /*
> + * This fails if the requested size exceeds the buddy allocator's
> + * maximum order (order-10, 4MB).
> + */
> addr = alloc_pages_exact(len, GFP_KERNEL | __GFP_ZERO);
[Severity: High]
Does this allow an untrusted VMM to trigger a guest panic?
Since tdx_get_max_quote_size() reads the TDCS_QUOTE_MAX_SIZE metadata field,
an untrusted host could supply a value that causes get_quote_buf_size() to
return a length where get_order(size) > MAX_PAGE_ORDER.
Because the __GFP_NOWARN flag was removed, passing this unvalidated size to
alloc_pages_exact() will trigger a WARN_ON_ONCE inside the page allocator.
If the guest boots with panic_on_warn=1, this gives the VMM a trivial denial
of service.
Should the calculated size be clamped to a safe maximum before calling
alloc_pages_exact(), or should the __GFP_NOWARN flag be retained?
> if (!addr)
> return NULL;
[ ... ]
> @@ -416,7 +436,7 @@ static int __init tdx_guest_init(void)
> if (ret)
> goto deinit_mr;
>
> - quote_data_len = GET_QUOTE_BUF_SIZE;
> + quote_data_len = get_quote_buf_size();
> quote_data = alloc_quote_buf(quote_data_len);
> if (!quote_data) {
> pr_err("Failed to allocate Quote buffer\n");
[Severity: High]
This is a pre-existing issue, but does this allocation failure path leave a
window for a use-after-free or use-after-unload race?
The tdx_guest_init() function calls misc_register() just before attempting to
allocate the quote buffer.
If alloc_quote_buf() fails, it will jump to the error path and call
misc_deregister().
However, misc_deregister() does not revoke active open file descriptors.
If a concurrent userspace process opens the misc device between registration
and the allocation failure, it can execute ioctls after the module
initialization fails.
This can result in accessing freed memory or executing unloaded code.
Since alloc_quote_buf() can now attempt larger allocations up to 4MB, it
seems much more likely to fail.
Should misc_register() be moved to the end of the initialization sequence to
prevent userspace from accessing a partially initialized device?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260729122939.1340412-1-peter.fang@intel.com?part=4
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
@ 2026-07-29 12:58 ` sashiko-bot
0 siblings, 0 replies; 7+ messages in thread
From: sashiko-bot @ 2026-07-29 12:58 UTC (permalink / raw)
To: Peter Fang; +Cc: kvm
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] `wait_for_quote_completion` timeout logic is inverted due to an off-by-one error in the loop condition.
--
--- Patch [3]: [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size ---
commit 0a36558aa4f35238ff748cfc6efbe53e1e0e02ea
Author: Peter Fang <peter.fang@intel.com>
virt: tdx-guest: Use a variable to store the Quote buffer size
This commit replaces the fixed GET_QUOTE_BUF_SIZE constant with a dynamic
variable to prepare for future dynamic Quote buffer sizes. All users of
the buffer size have been updated to read from this new variable.
> diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
> index f47c5429d002e..3d3f79ab45af0 100644
> --- a/drivers/virt/coco/tdx-guest/tdx-guest.c
> +++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
[ ... ]
> @@ -285,7 +284,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
> if (desc->inblob_len != TDX_REPORTDATA_LEN)
> return -EINVAL;
>
> - memset(quote_data, 0, GET_QUOTE_BUF_SIZE);
> + memset(quote_data, 0, quote_data_len);
>
> /* Update Quote buffer header */
> quote_buf->version = GET_QUOTE_CMD_VER;
> @@ -296,7 +295,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
> if (ret)
> return ret;
>
> - err = tdx_hcall_get_quote(quote_data, GET_QUOTE_BUF_SIZE);
> + err = tdx_hcall_get_quote(quote_data, quote_data_len);
> if (err) {
> pr_err("GetQuote hypercall failed, status:%llx\n", err);
> return -EIO;
> }
[Severity: High]
This is a pre-existing issue, but while reviewing this code I noticed a
logic flaw in wait_for_quote_completion() which is called immediately after
this hypercall.
drivers/virt/coco/tdx-guest/tdx-guest.c:wait_for_quote_completion() {
...
while (quote_buf->status == GET_QUOTE_IN_FLIGHT && i++ < timeout) {
if (msleep_interruptible(MSEC_PER_SEC))
return -EINTR;
}
return (i == timeout) ? -ETIMEDOUT : 0;
}
Does this timeout condition return the correct value?
Due to the post-increment in i++ < timeout, if the loop actually times out,
i becomes timeout + 1. This causes i == timeout to evaluate to false and
incorrectly return 0 (success).
Conversely, if the quote succeeds exactly on the last iteration,
short-circuiting leaves i == timeout true, which would incorrectly return
-ETIMEDOUT and cause a valid quote to be rejected.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260729122939.1340412-1-peter.fang@intel.com?part=3
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-07-29 12:58 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-07-29 12:58 ` sashiko-bot
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
2026-07-29 12:55 ` sashiko-bot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.