All of lore.kernel.org
 help / color / mirror / Atom feed
From: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
To: Peter Fang <peter.fang@intel.com>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	Kiryl Shutsemau <kas@kernel.org>,
	Rick Edgecombe <rick.p.edgecombe@intel.com>
Cc: Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
	Borislav Petkov <bp@alien8.de>,
	x86@kernel.org, "H. Peter Anvin" <hpa@zytor.com>,
	linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev,
	kvm@vger.kernel.org, Xiaoyao Li <xiaoyao.li@intel.com>,
	Binbin Wu <binbin.wu@linux.intel.com>,
	Tony Lindgren <tony.lindgren@linux.intel.com>,
	Sean Christopherson <seanjc@google.com>,
	Artem Bityutskiy <artem.bityutskiy@intel.com>
Subject: Re: [PATCH v5 6/6] virt: tdx-guest: Make the Quote buffer size dynamic
Date: Mon, 28 Sep 2026 13:37:11 -0700	[thread overview]
Message-ID: <224672fa-8e29-4b0a-b472-6721e057b8a3@linux.intel.com> (raw)
In-Reply-To: <20260928100913.2265687-7-peter.fang@intel.com>

Hi,

On 9/28/2026 3:08 AM, Peter Fang wrote:
> Support a new TDX module ABI that reports the Quote size limit in a
> metadata field. The fixed 128KB buffer in the driver may be too small
> for Quotes that use new algorithms like post-quantum cryptography (PQC),
> which can produce much larger certificates. With this ABI, the guest
> sizes the buffer to the platform's needs and no longer has to rely on
> some empirical number.
> 
> The shared buffer comes from the buddy allocator, as the host expects it
> to be physically contiguous. The allocator's page order limit should be
> sufficient for current attestation needs. Platforms that don't report
> the limit fall back to the default 128KB buffer.
> 
> AI was used under supervision to collect/apply feedback, review code and
> workshop logs.
> 
> Based on a patch originally by Kuppuswamy Sathyanarayanan.
> 
> Signed-off-by: Peter Fang <peter.fang@intel.com>
> ---
> v5:
>  - Do the export here, and use EXPORT_SYMBOL_FOR_MODULES() instead.
>    [Xiaoyao, Dave]
>  - Drop the comment about the buddy allocator. [Dave]
>  - Drop the RB tags, as the code changed substantially.
> v4:
>  - Move the PAGE_ALIGN() out of get_quote_buf_size(). [Xiaoyao]
>  - Improve the get_quote_buf_size() pattern again.
>  - Document that the reported size covers every Quote type. [Xiaoyao]
>  - Document that a module update does not change the reported size.
>    [Tony]
>  - Add Tony's Reviewed-by.
> v3:
>  - Split out from the v2 "Allocate Quote buffer dynamically" patch. Add
>    the dynamic buffer feature on top of the refactoring. [Dave]
>  - Improve the get_quote_buf_size() pattern for better readability.
>    [Dave]
>  - Drop __GFP_NOWARN so an allocation failure warns. [Dave, Rick, Kiryl]
>  - Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
>    reworked.
> ---
>  arch/x86/coco/tdx/tdx.c                 |  1 +
>  drivers/virt/coco/tdx-guest/tdx-guest.c | 13 ++++++++++++-
>  2 files changed, 13 insertions(+), 1 deletion(-)
> 
> diff --git a/arch/x86/coco/tdx/tdx.c b/arch/x86/coco/tdx/tdx.c
> index 323e1efc78ea..847430fc639f 100644
> --- a/arch/x86/coco/tdx/tdx.c
> +++ b/arch/x86/coco/tdx/tdx.c
> @@ -213,6 +213,7 @@ int tdx_get_max_quote_size(u64 *max_quote_size)
>  
>  	return 0;
>  }
> +EXPORT_SYMBOL_FOR_MODULES(tdx_get_max_quote_size, "tdx-guest");

I think you can cleanup other exports consumed by tdx-guest driver
to use the same format (in a prep patch).

tdx_hcall_get_quote(), tdx_mcall_get_report0() and tdx_mcall_extend_rtmr(0.

>  
>  static void __noreturn tdx_panic(const char *msg)
>  {
> diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
> index b79b4325da3a..ad2cb4740898 100644
> --- a/drivers/virt/coco/tdx-guest/tdx-guest.c
> +++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
> @@ -212,11 +212,22 @@ static long tdx_get_report0(struct tdx_report_req __user *req)
>  static size_t get_quote_buf_size(void)
>  {
>  	static size_t quote_buf_size;
> +	u64 max_quote_size;
>  
>  	if (quote_buf_size)
>  		return quote_buf_size;
>  
> -	quote_buf_size = PAGE_ALIGN(TDX_DEFAULT_QUOTE_SIZE);
> +	/* Start with the default buffer size */
> +	quote_buf_size = TDX_DEFAULT_QUOTE_SIZE;
> +
> +	/*
> +	 * Override the default when the TDX module reports a size. Add room
> +	 * for the header metadata.
> +	 */
> +	if (!tdx_get_max_quote_size(&max_quote_size))
> +		quote_buf_size = TDX_QUOTE_TOTAL_SIZE(max_quote_size);
> +
> +	quote_buf_size = PAGE_ALIGN(quote_buf_size);
>  
>  	return quote_buf_size;
>  }

-- 
Sathyanarayanan Kuppuswamy
Linux Kernel Developer


  reply	other threads:[~2026-09-28 20:37 UTC|newest]

Thread overview: 40+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 10:08 [PATCH v5 0/6] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-09-28 10:08 ` [PATCH v5 1/6] x86/tdx: Take the Quote buffer as a generic pointer Peter Fang
2026-09-28 19:04   ` Edgecombe, Rick P
2026-09-28 20:37     ` Peter Fang
2026-09-28 20:10   ` Kuppuswamy Sathyanarayanan
2026-09-28 10:08 ` [PATCH v5 2/6] virt: tdx-guest: Give the Quote buffer an explicit type Peter Fang
2026-09-28 19:14   ` Edgecombe, Rick P
2026-09-28 20:16   ` Kuppuswamy Sathyanarayanan
2026-09-29  2:13   ` Binbin Wu
2026-09-29  7:41     ` Peter Fang
2026-09-29  7:43       ` Binbin Wu
2026-09-28 10:08 ` [PATCH v5 3/6] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-09-28 15:50   ` Dave Hansen
2026-09-28 20:53     ` Peter Fang
2026-09-28 10:08 ` [PATCH v5 4/6] virt: tdx-guest: Add a helper for the Quote buffer size Peter Fang
2026-09-28 16:13   ` Dave Hansen
2026-09-28 19:13     ` Edgecombe, Rick P
2026-09-29 10:32       ` Peter Fang
2026-09-29 15:45         ` Edgecombe, Rick P
2026-09-29 16:03           ` Peter Fang
2026-09-29 10:08     ` Peter Fang
2026-09-28 18:23   ` Edgecombe, Rick P
2026-09-29 16:38     ` Peter Fang
2026-09-28 10:08 ` [PATCH v5 5/6] x86/tdx: Add a helper to query maximum Quote size Peter Fang
2026-09-28 18:35   ` Edgecombe, Rick P
2026-09-28 21:00     ` Peter Fang
2026-09-28 18:50   ` Edgecombe, Rick P
2026-09-28 21:13     ` Peter Fang
2026-09-28 21:25       ` Edgecombe, Rick P
2026-09-28 21:25         ` Edgecombe, Rick P
2026-09-28 22:47           ` Peter Fang
2026-09-28 23:01         ` Peter Fang
2026-09-29 10:40       ` Peter Fang
2026-09-28 20:32   ` Kuppuswamy Sathyanarayanan
2026-09-29  9:18     ` Peter Fang
2026-09-29 14:18       ` Dave Hansen
2026-09-29 15:38         ` Peter Fang
2026-09-28 10:08 ` [PATCH v5 6/6] virt: tdx-guest: Make the Quote buffer size dynamic Peter Fang
2026-09-28 20:37   ` Kuppuswamy Sathyanarayanan [this message]
2026-09-29  7:23     ` Peter Fang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=224672fa-8e29-4b0a-b472-6721e057b8a3@linux.intel.com \
    --to=sathyanarayanan.kuppuswamy@linux.intel.com \
    --cc=artem.bityutskiy@intel.com \
    --cc=binbin.wu@linux.intel.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=kas@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=peter.fang@intel.com \
    --cc=rick.p.edgecombe@intel.com \
    --cc=seanjc@google.com \
    --cc=tglx@kernel.org \
    --cc=tony.lindgren@linux.intel.com \
    --cc=x86@kernel.org \
    --cc=xiaoyao.li@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.