All of lore.kernel.org
 help / color / mirror / Atom feed
From: Peter Fang <peter.fang@intel.com>
To: Lisa Wang <wyihan@google.com>
Cc: Andrew Jones <ajones@ventanamicro.com>,
	Ackerley Tng <ackerleytng@google.com>,
	Binbin Wu <binbin.wu@linux.intel.com>,
	Chao Gao <chao.gao@intel.com>,
	Chenyi Qiang <chenyi.qiang@intel.com>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	Erdem Aktas <erdemaktas@google.com>,
	Ira Weiny <ira.weiny@intel.com>,
	Isaku Yamahata <isaku.yamahata@intel.com>,
	"Kiryl Shutsemau" <kas@kernel.org>,
	<linux-kselftest@vger.kernel.org>,
	Paolo Bonzini <pbonzini@redhat.com>,
	"Pratik R. Sampat" <pratikrajesh.sampat@amd.com>,
	Reinette Chatre <reinette.chatre@intel.com>,
	Rick Edgecombe <rick.p.edgecombe@intel.com>,
	Roger Wang <runanwang@google.com>,
	Ryan Afranji <afranji@google.com>, Sagi Shahar <sagis@google.com>,
	Sean Christopherson <seanjc@google.com>,
	Shuah Khan <shuah@kernel.org>, Xiaoyao Li <xiaoyao.li@intel.com>,
	Oliver Upton <oupton@kernel.org>,
	Jeremiah McReynolds <jmcrey@google.com>, <kvm@vger.kernel.org>,
	<linux-coco@lists.linux.dev>, <linux-kernel@vger.kernel.org>,
	<x86@kernel.org>
Subject: Re: [PATCH v14 10/22] KVM: selftests: Set up TDX boot code region
Date: Mon, 24 Aug 2026 12:27:02 -0700	[thread overview]
Message-ID: <20260824192702.GA3694338@pedri> (raw)
In-Reply-To: <20260722-tdx-selftests-v14-10-15ad654a50db@google.com>

On Wed, Jul 22, 2026 at 11:13:15PM +0000, Lisa Wang wrote:
> From: Sagi Shahar <sagis@google.com>
> 
> Add memory for TDX boot code in a separate memslot.
> 
> Use virt_map() to get identity map in this memory region to allow for
> seamless transition from paging disabled to paging enabled code.
> 
> Copy the boot code into the memory region and set up the reset vector
> at this point. While it's possible to separate the memory allocation and
> boot code initialization into separate functions, having all the
> calculations for memory size and offsets in one place simplifies the
> code and avoids duplications.
> 
> Handcode the reset vector as suggested by Sean Christopherson.
> 
> Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
> Suggested-by: Sean Christopherson <seanjc@google.com>
> Co-developed-by: Erdem Aktas <erdemaktas@google.com>
> Signed-off-by: Erdem Aktas <erdemaktas@google.com>
> Signed-off-by: Sagi Shahar <sagis@google.com>
> Signed-off-by: Lisa Wang <wyihan@google.com>
> ---
>  .../selftests/kvm/include/x86/tdx/tdx_util.h       |  1 +
>  tools/testing/selftests/kvm/lib/x86/processor.c    |  4 +-
>  tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c | 46 ++++++++++++++++++++++
>  3 files changed, 50 insertions(+), 1 deletion(-)
> 

[ ... ]

> +
> +void tdx_vm_setup_boot_code_region(struct kvm_vm *vm)
> +{
> +	size_t total_code_size = TD_BOOT_CODE_SIZE + X86_RESET_VECTOR_SIZE;
> +	gpa_t boot_code_gpa = X86_RESET_VECTOR - TD_BOOT_CODE_SIZE;
> +	gpa_t alloc_gpa = round_down(boot_code_gpa, PAGE_SIZE);
> +	size_t nr_pages = DIV_ROUND_UP(total_code_size, PAGE_SIZE);
> +	const u64 gmem_flags = 0;
> +	gpa_t gpa;
> +	u8 *hva;
> +
> +	vm_mem_add(vm, VM_MEM_SRC_SHMEM, alloc_gpa, TD_BOOT_CODE_SLOT,
> +		   nr_pages, KVM_MEM_GUEST_MEMFD, -1, 0, gmem_flags);
> +
> +	gpa = vm_phy_pages_alloc(vm, nr_pages, alloc_gpa, TD_BOOT_CODE_SLOT);
> +	TEST_ASSERT(gpa == alloc_gpa, "Failed vm_phy_pages_alloc\n");
> +
> +	virt_map(vm, alloc_gpa, alloc_gpa, nr_pages);
> +	hva = addr_gpa2hva(vm, boot_code_gpa);
> +	memcpy(hva, td_boot, TD_BOOT_CODE_SIZE);
> +
> +	hva += TD_BOOT_CODE_SIZE;
> +	TEST_ASSERT(hva == addr_gpa2hva(vm, X86_RESET_VECTOR),
> +		    "Expected RESET vector at hva 0x%lx, got %lx",
> +		    (unsigned long)addr_gpa2hva(vm, X86_RESET_VECTOR), (unsigned long)hva);
> +
> +	/*
> +	 * Handcode "JMP rel8" at the RESET vector to jump back to the TD boot
> +	 * code, as there are only 16 bytes at the RESET vector before RIP will
> +	 * wrap back to zero. Insert a trailing int3 so that the vCPU crashes in
> +	 * case the JMP somehow falls through. Note! The target address is
> +	 * relative to the end of the instruction!
> +	 */
> +	TEST_ASSERT(TD_BOOT_CODE_SIZE + 2 <= 128,
> +		    "TD boot code not addressable by 'JMP rel8'");
> +	hva[0] = 0xeb;
> +	hva[1] = 256 - 2 - TD_BOOT_CODE_SIZE;
> +	hva[2] = 0xcc;

This handcoding has persisted for several versions (since v9) so I only
want to comment gently... The current code looks correct but I think
this could be simpler. But feel free to keep the current implementation.

I can see handcoding "JMP rel8" generates a jump instruction
predictably. But having to calculate and sanity check the boot code
offset by hand seems quite painful. And the math is quite tricky. I was
thinking the assembler could do a lot more heavy lifting here.

A nice property of this boot code is the fact that it's executed in
32-bit mode from the get go. So there's no need for 16-bit programming
and "JMP rel32" is readily available. I.e. a "jmp td_boot" in td_boot.S
should suffice and the assembler screams if td_boot isn't reachable. And
the int3's after the jump can probably go away as well since the jump is
now very, very likely to succeed.

There shouldn't be a need to "pad reset_vector to its full size of 16
bytes" as stated in v8 [1]. The exported "reset_vector" symbol in v8,
plus the boot code start & end markers, should be enough to help
tdx_vm_setup_boot_code_region() put this boot blob in the right place.


[1] https://lore.kernel.org/all/aJpO_zN3buvaQoAW@google.com/


> +}
> +
>  static struct kvm_tdx_capabilities *tdx_read_capabilities(struct kvm_vm *vm)
>  {
>  	static struct kvm_tdx_capabilities *tdx_cap;
> 
> -- 
> 2.55.0.229.g6434b31f56-goog
> 
> 

  parent reply	other threads:[~2026-08-24 19:27 UTC|newest]

Thread overview: 66+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22 23:13 [PATCH v14 00/22] TDX KVM selftests Lisa Wang
2026-07-22 23:13 ` [PATCH v14 01/22] KVM: selftests: Add macros to simplify creating VM shapes for non-default types Lisa Wang
2026-08-19  7:44   ` Peter Fang
2026-07-22 23:13 ` [PATCH v14 02/22] KVM: selftests: Update kvm_init_vm_address_properties() for TDX Lisa Wang
2026-08-13 23:17   ` Edgecombe, Rick P
2026-07-22 23:13 ` [PATCH v14 03/22] KVM: selftests: Initialize the TDX VM Lisa Wang
2026-07-23  8:44   ` Xiaoyao Li
2026-08-13 23:41     ` Edgecombe, Rick P
2026-08-15  9:17       ` Xiaoyao Li
2026-08-13 23:41   ` Edgecombe, Rick P
2026-08-14 21:18     ` Peter Fang
2026-08-20  8:46   ` Peter Fang
2026-07-22 23:13 ` [PATCH v14 04/22] KVM: selftests: TDX: Use KVM_TDX_CAPABILITIES to validate TDs' attribute configuration Lisa Wang
2026-08-13 23:45   ` Edgecombe, Rick P
2026-07-22 23:13 ` [PATCH v14 05/22] KVM: selftests: Expose segment definitions to assembly files Lisa Wang
2026-08-13 23:50   ` Edgecombe, Rick P
2026-07-22 23:13 ` [PATCH v14 06/22] tools: include: Add kbuild.h for assembly structure offsets Lisa Wang
2026-07-22 23:13 ` [PATCH v14 07/22] KVM: selftests: Introduce structures for TDX guest boot parameters Lisa Wang
2026-07-22 23:13 ` [PATCH v14 08/22] KVM: selftests: Add TDX boot code Lisa Wang
2026-07-23 11:17   ` Xiaoyao Li
2026-08-21  5:16   ` Peter Fang
2026-07-22 23:13 ` [PATCH v14 09/22] KVM: selftests: Expose functions to get default sregs values Lisa Wang
2026-07-23 10:19   ` Xiaoyao Li
2026-08-14  0:44   ` Edgecombe, Rick P
2026-08-14  2:36     ` Xiaoyao Li
2026-08-14 15:14       ` Edgecombe, Rick P
2026-07-22 23:13 ` [PATCH v14 10/22] KVM: selftests: Set up TDX boot code region Lisa Wang
2026-07-23 10:24   ` Xiaoyao Li
2026-08-24 19:27   ` Peter Fang [this message]
2026-08-24 20:00     ` Sean Christopherson
2026-07-22 23:13 ` [PATCH v14 11/22] KVM: selftests: Set up TDX boot parameters region Lisa Wang
2026-07-23 10:34   ` Xiaoyao Li
2026-08-11  6:32   ` Binbin Wu
2026-08-25  8:14   ` Peter Fang
2026-07-22 23:13 ` [PATCH v14 12/22] KVM: selftests: Require guest_memfd for TDX VMs Lisa Wang
2026-08-11  7:43   ` Binbin Wu
2026-08-14  7:42   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 13/22] KVM: selftests: Support guest_memfd in-place conversion Lisa Wang
2026-08-18  8:17   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 14/22] KVM: selftests: Expose function to allocate vCPU stack Lisa Wang
2026-08-14  8:10   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 15/22] KVM: selftests: Call KVM_TDX_INIT_VCPU when creating a new TDX vcpu Lisa Wang
2026-08-14  8:32   ` Xiaoyao Li
2026-08-18  8:58     ` Binbin Wu
2026-07-22 23:13 ` [PATCH v14 16/22] KVM: selftests: Load per-vCPU guest stack in TDX boot parameters Lisa Wang
2026-08-14  8:39   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 17/22] KVM: selftests: Set entry point for TDX guest code Lisa Wang
2026-08-14  8:43   ` Xiaoyao Li
2026-08-18  9:04   ` Binbin Wu
2026-07-22 23:13 ` [PATCH v14 18/22] KVM: selftests: Add helpers to init TDX memory and finalize VM Lisa Wang
2026-08-17  6:47   ` Xiaoyao Li
2026-08-17 13:52     ` Ackerley Tng
2026-08-18  7:33       ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 19/22] KVM: selftests: Finalize TD memory as part of kvm_arch_vm_finalize_vcpus Lisa Wang
2026-08-17  7:04   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 20/22] KVM: selftests: Implement MMIO WRITE for the TDX VM Lisa Wang
2026-07-28 22:56   ` Ackerley Tng
2026-08-17  8:56   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 21/22] KVM: selftests: Add ucall support for TDX Lisa Wang
2026-08-17  8:38   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 22/22] KVM: selftests: Add TDX lifecycle test Lisa Wang
2026-08-17  9:04   ` Xiaoyao Li
2026-08-13 22:47 ` [PATCH v14 00/22] TDX KVM selftests Edgecombe, Rick P
2026-08-13 23:05   ` Edgecombe, Rick P
2026-08-17  4:19     ` Ackerley Tng
2026-08-17 17:54       ` Edgecombe, Rick P

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260824192702.GA3694338@pedri \
    --to=peter.fang@intel.com \
    --cc=ackerleytng@google.com \
    --cc=afranji@google.com \
    --cc=ajones@ventanamicro.com \
    --cc=binbin.wu@linux.intel.com \
    --cc=chao.gao@intel.com \
    --cc=chenyi.qiang@intel.com \
    --cc=dave.hansen@linux.intel.com \
    --cc=erdemaktas@google.com \
    --cc=ira.weiny@intel.com \
    --cc=isaku.yamahata@intel.com \
    --cc=jmcrey@google.com \
    --cc=kas@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=oupton@kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=pratikrajesh.sampat@amd.com \
    --cc=reinette.chatre@intel.com \
    --cc=rick.p.edgecombe@intel.com \
    --cc=runanwang@google.com \
    --cc=sagis@google.com \
    --cc=seanjc@google.com \
    --cc=shuah@kernel.org \
    --cc=wyihan@google.com \
    --cc=x86@kernel.org \
    --cc=xiaoyao.li@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.