From: Xiaoyao Li <xiaoyao.li@intel.com>
To: Xu Yilun <yilun.xu@linux.intel.com>,
x86@kernel.org, kvm@vger.kernel.org, linux-coco@lists.linux.dev,
linux-kernel@vger.kernel.org
Cc: djbw@kernel.org, kas@kernel.org, rick.p.edgecombe@intel.com,
yilun.xu@intel.com, sohil.mehta@intel.com,
adrian.hunter@intel.com, kishen.maloor@intel.com,
tony.lindgren@linux.intel.com, peter.fang@intel.com,
baolu.lu@linux.intel.com, zhenzhong.duan@intel.com,
dave.hansen@intel.com, dave.hansen@linux.intel.com,
seanjc@google.com
Subject: Re: [PATCH v2 02/17] x86/virt/tdx: Configure add-on features on TDX module init and update
Date: Fri, 24 Jul 2026 16:15:21 +0800 [thread overview]
Message-ID: <823bf577-51a1-4a8a-b240-ef4a0d5573be@intel.com> (raw)
In-Reply-To: <20260618081355.3253581-3-yilun.xu@linux.intel.com>
On 6/18/2026 4:13 PM, Xu Yilun wrote:
> In addition to basic TDX functionalities, TDX module provides add-on
> features that can be progressively enabled as the kernel supports them.
"add-on features" looks like a new term introduced by this sereis for
TDX. So what is add-on features? all the features defined in
TDX_FEATURE0/1? Or only the features needs to be explicitly enabled by
R9 and R10 of TDH.SYS.CONFIG? ...
> The kernel should explicitly configure these features at boot or
> post-update initialization time.
... So the answer is the latter. Then why only these bits are add-on
features while the rest in TDX_FEATURES01 are not?
btw, s/should/needs/ is better?
> Configuring an add-on feature, such as
> TDX Quoting, that uses extension SEAMCALLs is the prerequisite for
> initializing TDX module extensions.
Though the statement is right, it leads to the impression that the
reason we are configuring the add-on feature is to initialize the TDX
module extensions.
However, the truth is kenrel wants to enable/use an add-on feature and
the add-on feature requires the functionalities provided by some TDX
module extension. So kernel needs to enable the TDX module extensions.
> TDX Quoting is the target feature to
> enable but defer it for now until full kernel support is in place.
>
> TDX module extends TDH.SYS.CONFIG and TDH.SYS.UPDATE with new bitmap
> input parameters to specify which add-on features to configure. The
> bitmap uses the same definitions as TDX_FEATURES0.
>
> For runtime update, Linux applies a policy that no newer features should
> be added after update to avoid disrupting live TDX operations. To adhere
> to this, TDH.SYS.UPDATE must configure the same features as the
> TDH.SYS.CONFIG. Record the kernel required add-on feature bitmap in a
> global var so that both phases can use it.
>
> TDX module advances the version of TDH.SYS.CONFIG and TDH.SYS.UPDATE for
> the change, so use the latest version (v1) for add-on feature enabling.
> But supporting existing modules which only support v0 is still necessary
> until they are deprecated. In fact, it is unlikely that TDH.SYS.CONFIG
> ever needs to change again and the code would stay in v1. So there is
> little value in worrying about deprecating v0 to save a couple lines of
> code in 5-7 years when these original TDX platforms sunset.
>
> Signed-off-by: Xu Yilun <yilun.xu@linux.intel.com>
> ---
> arch/x86/virt/vmx/tdx/tdx.h | 6 ++++--
> arch/x86/virt/vmx/tdx/tdx.c | 28 ++++++++++++++++++++++++++--
> 2 files changed, 30 insertions(+), 4 deletions(-)
>
> diff --git a/arch/x86/virt/vmx/tdx/tdx.h b/arch/x86/virt/vmx/tdx/tdx.h
> index fbb520704662..a47e872480c7 100644
> --- a/arch/x86/virt/vmx/tdx/tdx.h
> +++ b/arch/x86/virt/vmx/tdx/tdx.h
> @@ -58,9 +58,11 @@
> #define TDH_PHYMEM_CACHE_WB 40
> #define TDH_PHYMEM_PAGE_WBINVD 41
> #define TDH_VP_WR 43
> -#define TDH_SYS_CONFIG 45
> +#define TDH_SYS_CONFIG_V0 45
> +#define TDH_SYS_CONFIG SEAMCALL_LEAF_VER(TDH_SYS_CONFIG_V0, 1)
> #define TDH_SYS_SHUTDOWN 52
> -#define TDH_SYS_UPDATE 53
> +#define TDH_SYS_UPDATE_V0 53
> +#define TDH_SYS_UPDATE SEAMCALL_LEAF_VER(TDH_SYS_UPDATE_V0, 1)
> #define TDH_SYS_DISABLE 69
>
> /* TDX page types */
> diff --git a/arch/x86/virt/vmx/tdx/tdx.c b/arch/x86/virt/vmx/tdx/tdx.c
> index 2a03152796e6..92305b5ea90d 100644
> --- a/arch/x86/virt/vmx/tdx/tdx.c
> +++ b/arch/x86/virt/vmx/tdx/tdx.c
> @@ -57,6 +57,7 @@ static struct tdx_module_state tdx_module_state;
> static u32 tdx_global_keyid __ro_after_init;
> static u32 tdx_guest_keyid_start __ro_after_init;
> static u32 tdx_nr_guest_keyids __ro_after_init;
> +static u64 tdx_addon_feature0 __ro_after_init;
>
> static DEFINE_IDA(tdx_guest_keyid_pool);
>
> @@ -1004,9 +1005,18 @@ static __init int construct_tdmrs(struct list_head *tmb_list,
> return ret;
> }
>
> +static __init void set_tdx_addon_features(void)
> +{
> + /*
> + * To add DICE-based TDX Quoting feature bit in tdx_addon_feature0 when
> + * kernel is ready.
> + */
> +}
> +
> static __init int config_tdx_module(struct tdmr_info_list *tdmr_list,
> u64 global_keyid)
> {
> + u64 seamcall_fn = TDH_SYS_CONFIG_V0;
> struct tdx_module_args args = {};
> u64 *tdmr_pa_array;
> size_t array_sz;
> @@ -1032,7 +1042,15 @@ static __init int config_tdx_module(struct tdmr_info_list *tdmr_list,
> args.rcx = __pa(tdmr_pa_array);
> args.rdx = tdmr_list->nr_consumed_tdmrs;
> args.r8 = global_keyid;
> - ret = seamcall_prerr(TDH_SYS_CONFIG, &args);
> +
> + set_tdx_addon_features();
Maybe move the set_tdx_addon_features() out of config_tdx_module()? how
about putting it after check_features(). config_tdx_module() looks like
just a wrapper to invoke TDH.SYS.CONFIG, while the params of it are
determined outside of it.
Just my feeling.
> +
> + if (tdx_addon_feature0) {
> + args.r9 = tdx_addon_feature0;
> + seamcall_fn = TDH_SYS_CONFIG;
> + }
> +
> + ret = seamcall_prerr(seamcall_fn, &args);
>
> /* Free the array as it is not required anymore. */
> kfree(tdmr_pa_array);
> @@ -1314,10 +1332,16 @@ int tdx_module_shutdown(void)
>
> int tdx_module_run_update(void)
> {
> + u64 seamcall_fn = TDH_SYS_UPDATE_V0;
> struct tdx_module_args args = {};
> int ret;
>
> - ret = seamcall_prerr(TDH_SYS_UPDATE, &args);
> + if (tdx_addon_feature0) {
> + args.r9 = tdx_addon_feature0;
> + seamcall_fn = TDH_SYS_UPDATE;
> + }
> +
> + ret = seamcall_prerr(seamcall_fn, &args);
> if (ret)
> return ret;
>
next prev parent reply other threads:[~2026-07-24 8:15 UTC|newest]
Thread overview: 111+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-18 8:13 [PATCH v2 00/17] Enable DICE-based TDX Quoting Extension Xu Yilun
2026-06-18 8:13 ` [PATCH v2 01/17] x86/virt/tdx: Embed version info in SEAMCALL leaf function definitions Xu Yilun
2026-06-18 14:45 ` Dave Hansen
2026-06-22 12:05 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 02/17] x86/virt/tdx: Configure add-on features on TDX module init and update Xu Yilun
2026-06-18 15:04 ` Dave Hansen
2026-06-22 13:15 ` Xu Yilun
2026-06-24 12:00 ` Xu Yilun
2026-06-24 22:10 ` Peter Fang
2026-06-25 6:33 ` Xu Yilun
2026-06-23 8:43 ` Chao Gao
2026-06-25 10:50 ` Xu Yilun
2026-07-24 8:15 ` Xiaoyao Li [this message]
2026-07-27 10:48 ` Xu Yilun
2026-07-27 17:50 ` Edgecombe, Rick P
2026-07-28 16:29 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 03/17] x86/virt/tdx: Detect if the extensions initialization is required Xu Yilun
2026-06-25 5:19 ` Tony Lindgren
2026-06-25 10:57 ` Xu Yilun
2026-07-27 17:51 ` Edgecombe, Rick P
2026-06-29 6:33 ` Chao Gao
2026-06-30 11:10 ` Xu Yilun
2026-07-24 8:44 ` Xiaoyao Li
2026-07-27 12:43 ` Xu Yilun
2026-07-24 8:42 ` Xiaoyao Li
2026-07-27 12:38 ` Xu Yilun
2026-07-27 17:56 ` Edgecombe, Rick P
2026-07-29 3:50 ` Xu Yilun
2026-07-29 13:48 ` Edgecombe, Rick P
2026-07-29 17:08 ` Xu Yilun
2026-07-29 22:55 ` Edgecombe, Rick P
2026-06-18 8:13 ` [PATCH v2 04/17] x86/virt/tdx: Add extra memory to TDX module for the extensions Xu Yilun
2026-06-18 8:54 ` sashiko-bot
2026-06-24 1:53 ` Xu Yilun
2026-06-29 7:56 ` Chao Gao
2026-06-30 10:27 ` Xu Yilun
2026-07-27 18:16 ` Edgecombe, Rick P
2026-07-29 11:07 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 05/17] x86/virt/tdx: Make TDX module initialize " Xu Yilun
2026-06-18 8:54 ` sashiko-bot
2026-06-23 17:03 ` Xu Yilun
2026-07-27 8:23 ` Xiaoyao Li
2026-07-27 18:30 ` Edgecombe, Rick P
2026-06-18 8:13 ` [PATCH v2 06/17] x86/virt/tdx: Re-initialize the extensions on runtime TDX module update Xu Yilun
2026-06-18 8:58 ` sashiko-bot
2026-06-25 7:01 ` Xu Yilun
2026-06-29 8:12 ` Chao Gao
2026-06-30 11:14 ` Xu Yilun
2026-07-27 18:37 ` Edgecombe, Rick P
2026-07-30 11:10 ` Xu Yilun
2026-07-30 16:01 ` Xu Yilun
2026-07-30 18:41 ` Edgecombe, Rick P
2026-07-31 2:30 ` Xu Yilun
2026-07-27 18:36 ` Edgecombe, Rick P
2026-06-18 8:13 ` [PATCH v2 07/17] x86/virt/tdx: Initialize Quoting extension Xu Yilun
2026-06-18 8:50 ` sashiko-bot
2026-06-25 10:24 ` Peter Fang
2026-06-29 8:33 ` Chao Gao
2026-06-30 5:20 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 08/17] x86/virt/tdx: Prepare Quote buffer during extension bringup Xu Yilun
2026-06-25 6:08 ` Tony Lindgren
2026-06-30 4:12 ` Peter Fang
2026-07-01 19:56 ` Dave Hansen
2026-07-08 9:25 ` Peter Fang
2026-07-08 7:52 ` Nikolay Borisov
2026-07-13 10:19 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 09/17] x86/virt/tdx: Add interface to check Quoting availability Xu Yilun
2026-06-25 6:09 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 10/17] x86/virt/tdx: Move tdx_tdr_pa() up in the file Xu Yilun
2026-06-25 6:10 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 11/17] x86/virt/tdx: Add interface to generate a Quote Xu Yilun
2026-06-18 8:49 ` sashiko-bot
2026-06-30 15:28 ` Peter Fang
2026-06-25 6:05 ` Tony Lindgren
2026-06-30 4:22 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 12/17] x86/virt/tdx: Reinitialize the Quoting extension after TDX module update Xu Yilun
2026-06-25 6:12 ` Tony Lindgren
2026-07-27 18:33 ` Edgecombe, Rick P
2026-08-11 4:29 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 13/17] x86/virt/tdx: Enable Quoting extension Xu Yilun
2026-06-25 6:13 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 14/17] x86/tdx: Move and rename Quote request structure Xu Yilun
2026-06-25 6:15 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 15/17] KVM: TDX: Factor out userspace return path from tdx_get_quote() Xu Yilun
2026-06-25 6:16 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 16/17] KVM: TDX: Add in-kernel Quote generation Xu Yilun
2026-06-18 9:03 ` sashiko-bot
2026-06-30 15:52 ` Peter Fang
2026-06-25 18:01 ` Sean Christopherson
2026-06-29 10:03 ` Peter Fang
2026-06-30 0:42 ` Sean Christopherson
2026-06-30 23:33 ` Edgecombe, Rick P
2026-07-01 0:24 ` Dan Williams (nvidia)
2026-07-01 17:25 ` Sean Christopherson
2026-07-01 18:45 ` Edgecombe, Rick P
2026-07-04 5:43 ` Peter Fang
2026-07-06 17:57 ` Sean Christopherson
2026-07-08 20:47 ` Dave Hansen
2026-07-08 21:16 ` Sean Christopherson
2026-07-08 22:09 ` Peter Fang
2026-07-08 22:28 ` Sean Christopherson
2026-07-08 23:38 ` Edgecombe, Rick P
2026-07-10 9:01 ` Nikolay Borisov
2026-07-10 9:38 ` Peter Fang
2026-07-08 21:37 ` Sean Christopherson
2026-07-10 12:52 ` Peter Fang
2026-07-10 14:48 ` Sean Christopherson
2026-07-10 22:59 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 17/17] KVM: TDX: Support event-notify interrupts only with userspace Quoting Xu Yilun
2026-06-25 6:28 ` Tony Lindgren
2026-06-30 6:36 ` Peter Fang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=823bf577-51a1-4a8a-b240-ef4a0d5573be@intel.com \
--to=xiaoyao.li@intel.com \
--cc=adrian.hunter@intel.com \
--cc=baolu.lu@linux.intel.com \
--cc=dave.hansen@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=djbw@kernel.org \
--cc=kas@kernel.org \
--cc=kishen.maloor@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=peter.fang@intel.com \
--cc=rick.p.edgecombe@intel.com \
--cc=seanjc@google.com \
--cc=sohil.mehta@intel.com \
--cc=tony.lindgren@linux.intel.com \
--cc=x86@kernel.org \
--cc=yilun.xu@intel.com \
--cc=yilun.xu@linux.intel.com \
--cc=zhenzhong.duan@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.