From: Tony Lindgren <tony.lindgren@linux.intel.com>
To: Binbin Wu <binbin.wu@linux.intel.com>
Cc: linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
seanjc@google.com, pbonzini@redhat.com,
dave.hansen@linux.intel.com, andrew.cooper3@citrix.com,
nik.borisov@suse.com, kas@kernel.org, rick.p.edgecombe@intel.com,
xiaoyao.li@intel.com, chao.gao@intel.com
Subject: Re: [PATCH v3 4/4] KVM: TDX: Validate userspace CPUID input for KVM_TDX_INIT_VM
Date: Tue, 1 Sep 2026 09:47:34 +0300 [thread overview]
Message-ID: <apZ1BoWQxT8dDGMu@tlindgre-MOBL1> (raw)
In-Reply-To: <20260827031837.2863609-5-binbin.wu@linux.intel.com>
On Thu, Aug 27, 2026 at 11:18:37AM +0800, Binbin Wu wrote:
> Validate the CPUID configuration provided by userspace through
> KVM_TDX_INIT_VM against KVM's TDX allowlist, and drop the hardcoded
> denylist based check.
>
> The TDX module lets the VMM configure certain CPUID features for a TD at
> initialization time, but KVM must strictly govern which of them userspace
> can actually enable, otherwise a host state clobbering feature could be
> enabled behind KVM's back. The existing check only rejects TSX and
> WAITPKG, i.e. it is not fail-safe, as any bit that a future TDX module
> makes configurable would be accepted even if KVM has no idea about the
> feature.
>
> Add tdx_has_unsupported_cfg_cpuid_bit() and reject KVM_TDX_INIT_VM if
> userspace sets any bit outside the mask returned by
> tdx_get_allowed_cfg_cpuid_mask(). There is no need to first mask the
> userspace input with the bits the TDX module reports as directly
> configurable, as anything outside that set is rejected by the TDX module
> itself.
>
> Also reject CPUID entries whose index differs from the value expected by
> the TDX module, as kvm_find_cpuid_entry2() ignores the index when
> KVM_CPUID_FLAG_SIGNIFCANT_INDEX is cleared, and so a mismatching entry
> could otherwise be applied to the wrong subleaf.
This nicely cleans up the earlier handling:
Reviewed-by: Tony Lindgren <tony.lindgren@linux.intel.com>
next prev parent reply other threads:[~2026-09-01 6:47 UTC|newest]
Thread overview: 63+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 3:18 [PATCH v3 0/4] KVM: TDX: Validate directly configurable CPUID bits Binbin Wu
2026-08-27 3:18 ` [PATCH v3 1/4] KVM: TDX: Track configurable CPUID bits allowed by KVM Binbin Wu
2026-09-01 6:29 ` Tony Lindgren
2026-09-01 8:23 ` Binbin Wu
2026-09-01 8:27 ` Tony Lindgren
2026-09-01 14:35 ` Xiaoyao Li
2026-09-02 0:33 ` Binbin Wu
2026-09-02 15:09 ` Xiaoyao Li
2026-09-02 16:19 ` Binbin Wu
2026-09-02 16:22 ` Edgecombe, Rick P
2026-09-02 16:25 ` Binbin Wu
2026-09-03 7:28 ` Xiaoyao Li
2026-09-03 8:57 ` Binbin Wu
2026-09-08 21:13 ` Edgecombe, Rick P
2026-09-09 16:39 ` Xiaoyao Li
2026-09-09 22:29 ` Sean Christopherson
2026-09-09 23:18 ` Edgecombe, Rick P
2026-09-10 2:39 ` Binbin Wu
2026-09-10 2:53 ` Xiaoyao Li
2026-09-08 21:15 ` Edgecombe, Rick P
2026-08-27 3:18 ` [PATCH v3 2/4] KVM: TDX: Report CORE_CAPABILITIES as configurable Binbin Wu
2026-09-01 6:45 ` Tony Lindgren
2026-09-02 17:43 ` Kishen Maloor
2026-09-03 2:22 ` Binbin Wu
2026-09-03 6:10 ` Kishen Maloor
2026-09-03 8:12 ` Binbin Wu
2026-08-27 3:18 ` [PATCH v3 3/4] KVM: TDX: Filter configurable CPUID bits Binbin Wu
2026-09-01 6:44 ` Tony Lindgren
2026-09-01 8:42 ` Binbin Wu
2026-09-01 9:09 ` Tony Lindgren
2026-09-03 8:04 ` Xiaoyao Li
2026-09-03 8:23 ` Binbin Wu
2026-08-27 3:18 ` [PATCH v3 4/4] KVM: TDX: Validate userspace CPUID input for KVM_TDX_INIT_VM Binbin Wu
2026-08-27 3:24 ` sashiko-bot
2026-08-27 7:25 ` Binbin Wu
2026-09-01 6:47 ` Tony Lindgren [this message]
2026-08-27 19:33 ` [PATCH v3 0/4] KVM: TDX: Validate directly configurable CPUID bits Edgecombe, Rick P
2026-08-28 3:19 ` Binbin Wu
2026-08-28 16:58 ` Edgecombe, Rick P
2026-08-31 5:01 ` Binbin Wu
2026-09-01 9:42 ` Xiaoyao Li
2026-09-01 10:21 ` Xiaoyao Li
2026-09-02 16:09 ` Edgecombe, Rick P
2026-09-02 16:21 ` Binbin Wu
2026-09-09 1:46 ` Binbin Wu
2026-09-01 9:38 ` Xiaoyao Li
2026-09-01 17:41 ` Edgecombe, Rick P
2026-09-02 10:29 ` Xiaoyao Li
2026-09-02 13:13 ` Edgecombe, Rick P
2026-09-02 13:39 ` Xiaoyao Li
2026-09-02 13:53 ` Edgecombe, Rick P
2026-09-02 14:21 ` Xiaoyao Li
2026-09-02 16:26 ` Binbin Wu
2026-09-08 9:42 ` Artem Bityutskiy
2026-09-09 0:04 ` Binbin Wu
2026-09-08 20:30 ` Artem Bityutskiy
2026-09-08 22:31 ` Edgecombe, Rick P
2026-09-09 6:52 ` Artem Bityutskiy
2026-09-09 8:48 ` Binbin Wu
2026-09-09 11:20 ` Artem Bityutskiy
2026-09-10 2:54 ` Binbin Wu
2026-09-08 23:54 ` Binbin Wu
2026-09-09 5:37 ` Binbin Wu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apZ1BoWQxT8dDGMu@tlindgre-MOBL1 \
--to=tony.lindgren@linux.intel.com \
--cc=andrew.cooper3@citrix.com \
--cc=binbin.wu@linux.intel.com \
--cc=chao.gao@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nik.borisov@suse.com \
--cc=pbonzini@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=seanjc@google.com \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.