From: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>
To: "seanjc@google.com" <seanjc@google.com>
Cc: "hpa@zytor.com" <hpa@zytor.com>,
"Li, Xiaoyao" <xiaoyao.li@intel.com>,
"bp@alien8.de" <bp@alien8.de>, "kas@kernel.org" <kas@kernel.org>,
"binbin.wu@linux.intel.com" <binbin.wu@linux.intel.com>,
"x86@kernel.org" <x86@kernel.org>,
"sathyanarayanan.kuppuswamy@linux.intel.com"
<sathyanarayanan.kuppuswamy@linux.intel.com>,
"mingo@redhat.com" <mingo@redhat.com>,
"dave.hansen@linux.intel.com" <dave.hansen@linux.intel.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"Bityutskiy, Artem" <artem.bityutskiy@intel.com>,
"Fang, Peter" <peter.fang@intel.com>,
"tglx@kernel.org" <tglx@kernel.org>,
"linux-coco@lists.linux.dev" <linux-coco@lists.linux.dev>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>
Subject: Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
Date: Wed, 12 Aug 2026 16:02:21 +0000 [thread overview]
Message-ID: <86d532f33816cd4fa3e29c40079a6003abf89324.camel@intel.com> (raw)
In-Reply-To: <anxvwV_Pz4UYaxxt@google.com>
On Wed, 2026-08-12 at 07:08 -0700, Sean Christopherson wrote:
> > |Normal quote |Migration quote |Report size|Quote size|uAPI location |
> > -|----------------|----------------|-----------|----------|---------------|
> > 1|Platform scoped |Platform scoped |Grows |Grows |TDX host driver|
>
> With my KVM hat on, this option looks very attractive.
>
> And with the caveat that I'm most definitely not an attestation expert, from a
> separate of concerns perspective, IMO it seems like the report should contain
> the TD-specific information while the quote just wraps that information in
> platform-specific goo.
>
> In other words, to me, TD-scoped quotes feel like a hack that was thrown in to
> avoid having to modify the guest because y'all didn't plan ahead.
Caveman crypto person here too. It seems scattered and makes me similarly
suspicious about some lack of planning. But I kind of came to a different
conclusion on what went wrong.
It seems to me that from the overall solution level, the report should never
have had the details in it. It should just be some nonce or some type of thing
that can tie the guest request to the quote that it ends up getting
back. Doesn't it seem weird to get a bunch of details from the TDX module, then
pass them from the guest to host KVM to host userspace then back to the TDX
module... which already had all those details?
My understanding was that the original SGX attestation was a complicator of the
design of this stuff. Because I'm not sure that SGX had all those details about
the TD. In fact I can't see how it could have. Is that right Peter? So it needs
them all to be passed in. All the extra validations etc of this shuffling is
TDX's problems to deal with, but for Linux, it would be at least a lot less
confusing if there was not two things that have the TD details in them.
That said, from KVM POV, (1) kicks the attestation out of KVM. I see the
benefit. But a TD quote is a TD scoped operation in concept. To me at least.
next prev parent reply other threads:[~2026-08-12 16:02 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-07-29 18:29 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-07-29 12:58 ` sashiko-bot
2026-07-29 18:47 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
2026-07-29 12:55 ` sashiko-bot
2026-07-29 21:21 ` [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Edgecombe, Rick P
2026-08-11 22:40 ` Edgecombe, Rick P
2026-08-12 14:08 ` Sean Christopherson
2026-08-12 16:02 ` Edgecombe, Rick P [this message]
2026-08-12 16:43 ` Sean Christopherson
2026-08-12 17:22 ` Edgecombe, Rick P
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=86d532f33816cd4fa3e29c40079a6003abf89324.camel@intel.com \
--to=rick.p.edgecombe@intel.com \
--cc=artem.bityutskiy@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=peter.fang@intel.com \
--cc=sathyanarayanan.kuppuswamy@linux.intel.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.