From: Artem Bityutskiy <dedekind1@gmail.com>
To: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>,
"seanjc@google.com" <seanjc@google.com>
Cc: "kvm@vger.kernel.org" <kvm@vger.kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"dave.hansen@linux.intel.com" <dave.hansen@linux.intel.com>,
"bp@alien8.de" <bp@alien8.de>, "kas@kernel.org" <kas@kernel.org>,
"binbin.wu@linux.intel.com" <binbin.wu@linux.intel.com>,
"Li, Xiaoyao" <xiaoyao.li@intel.com>,
"sathyanarayanan.kuppuswamy@linux.intel.com"
<sathyanarayanan.kuppuswamy@linux.intel.com>,
"mingo@redhat.com" <mingo@redhat.com>,
"hpa@zytor.com" <hpa@zytor.com>,
"tglx@kernel.org" <tglx@kernel.org>,
"Fang, Peter" <peter.fang@intel.com>,
"linux-coco@lists.linux.dev" <linux-coco@lists.linux.dev>,
"x86@kernel.org" <x86@kernel.org>
Subject: Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
Date: Thu, 13 Aug 2026 22:32:20 +0300 [thread overview]
Message-ID: <98dcc8a12f117745a1cb9981dc8f0f1548e9c96f.camel@gmail.com> (raw)
In-Reply-To: <c697ff1d97fe62882eaf3bd86a4213bf2e79fc09.camel@intel.com>
On Wed, 2026-08-12 at 23:30 +0000, Edgecombe, Rick P wrote:
> Hmm, let me flag Artem to see if he can add anymore weight one way or the other
> from the migration POV.
Hi,
I will just assume the question is: "Is a TD-scoped quote seamcall
fundamentally wrong or acceptable?"
Short answer: I would say acceptable. I see it as a practical tradeoff.
Let me lay out my mental model, which should explain how I came to this
conclusion.
Mental model
============
1. SGX-based attestation
The original SGX-style flow is two steps:
1. The TD gets TD report.
2. A quoting agent signs that report and produces the quote.
What is quoting agent: a process using a special SGX enclave.
Why 2-step: the key limitation is that the quoting agent cannot fetch
TD evidence such as FW hash or other per-TD data. So the quote is
conceptually:
- TD report body
- signature over the report body
- trust material such as the public attestation key and certificate
chain
2. DICE-based attestation
The DICE-based model keeps the same two-step flow for compatibility,
but the quoting service runs in the TDX module and can read TD
evidence directly. As a result, the quote can include:
- TD report body
- extra per-TD evidence
- signature over the report body and the extra evidence
- trust material
IOW: in the SGX-based design, it is impossible to add TD evidence to
the quote. In the DICE-based design, it is possible.
But the question is - OK, it is possible, but why should it be done?
3. Why freezing TD report size
Linux supports 1024-byte TD reports via the `TDX_CMD_GET_REPORT0`
ioctl. It is already full, no more TD evidence fits, and changing TD
report size would require a new ioctl.
Also, as I understand it, based on TDX feature requests from customers,
there may be a need to increase TD report size more often and more
significantly than one would expect.
Therefore, for DICE-based attestation the TDX module adds new TD
evidence in the quote instead of expanding the TD report.
Is this the cleanest approach? Maybe not. A clear separation of
concern, with TD evidence in the report and the quote only adding
signature and trust material, does feel cleaner.
But on the other hand:
- The quote itself is already a per-TD data structure
- The it is inherently variable size because it contains
cryptographic material and trust data
- A fixed-size TD report means that at least one of them is fixed
size, not both.
4. Migration-specific case
For the normal user attestation path, the TD report is TD-scoped. For
migration, the report is effectively platform-scoped, just because the
migration flow does not need TD-specific evidence.
I would say that clean design is when Linux does not need to know this
and care about this specific case: be able to treat all TD reports as
per-TD.
Thanks,
Artem.
next prev parent reply other threads:[~2026-08-13 19:32 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-07-29 18:29 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-07-29 12:58 ` sashiko-bot
2026-07-29 18:47 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
2026-07-29 12:55 ` sashiko-bot
2026-07-29 21:21 ` [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Edgecombe, Rick P
2026-08-11 22:40 ` Edgecombe, Rick P
2026-08-12 14:08 ` Sean Christopherson
2026-08-12 16:02 ` Edgecombe, Rick P
2026-08-12 16:43 ` Sean Christopherson
2026-08-12 17:22 ` Edgecombe, Rick P
2026-08-12 22:37 ` Peter Fang
2026-08-12 22:47 ` Edgecombe, Rick P
2026-08-12 23:10 ` Sean Christopherson
2026-08-12 23:30 ` Edgecombe, Rick P
2026-08-13 19:32 ` Artem Bityutskiy [this message]
2026-08-13 20:14 ` Edgecombe, Rick P
2026-08-14 5:45 ` Artem Bityutskiy
2026-08-14 7:37 ` Peter Fang
2026-08-14 15:55 ` Edgecombe, Rick P
2026-08-12 23:27 ` Peter Fang
2026-08-12 21:02 ` Peter Fang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=98dcc8a12f117745a1cb9981dc8f0f1548e9c96f.camel@gmail.com \
--to=dedekind1@gmail.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=peter.fang@intel.com \
--cc=rick.p.edgecombe@intel.com \
--cc=sathyanarayanan.kuppuswamy@linux.intel.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.