From: Peter Fang <peter.fang@intel.com>
To: <sashiko-reviews@lists.linux.dev>
Cc: <kvm@vger.kernel.org>
Subject: Re: [PATCH v6 6/6] virt: tdx-guest: Make the Quote buffer size dynamic
Date: Wed, 30 Sep 2026 06:40:39 -0700 [thread overview]
Message-ID: <ar0RVyfvEGykm0_u@intel.com> (raw)
In-Reply-To: <20260930104949.8677A1F00893@smtp.kernel.org>
On Wed, Sep 30, 2026 at 10:49:49AM +0000, sashiko-bot@kernel.org wrote:
>
> [Severity: High]
> Can this dynamic evaluation cause an out-of-bounds write or buddy allocator
> corruption?
>
> If tdx_get_max_quote_size() fails transiently during initialization when
> alloc_quote_buf() is called, get_quote_buf_size() will return the default
> size, and alloc_pages_exact() will allocate a buffer of that size.
Hmm, I don't think TDX code usually handles "fails transiently" on
SEAMCALLs/TDCALLs. Like mentioned in [1], if attestation fails the TD is
functionally dead.
[1] https://lore.kernel.org/all/amCv00f5Q6QlztyY@thinkstation/
>
> If a subsequent userspace request triggers tdx_report_new_locked(), and the
> size query succeeds this time returning a larger size, could the driver write
> past the end of the allocation?
>
next prev parent reply other threads:[~2026-09-30 13:41 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 10:30 [PATCH v6 0/6] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-09-30 10:30 ` [PATCH v6 1/6] x86/tdx: Take the Quote buffer as a generic pointer Peter Fang
2026-09-30 10:30 ` [PATCH v6 2/6] virt: tdx-guest: Give the Quote buffer an explicit type Peter Fang
2026-09-30 10:30 ` [PATCH v6 3/6] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-09-30 10:30 ` [PATCH v6 4/6] virt: tdx-guest: Add a helper for the Quote buffer size Peter Fang
2026-09-30 22:14 ` Edgecombe, Rick P
2026-09-30 22:52 ` Peter Fang
2026-09-30 22:58 ` Edgecombe, Rick P
2026-09-30 10:30 ` [PATCH v6 5/6] x86/tdx: Add a helper to query maximum Quote size Peter Fang
2026-09-30 10:30 ` [PATCH v6 6/6] virt: tdx-guest: Make the Quote buffer size dynamic Peter Fang
2026-09-30 10:49 ` sashiko-bot
2026-09-30 13:40 ` Peter Fang [this message]
2026-09-30 22:17 ` [PATCH v6 0/6] tdx-guest: Make " Edgecombe, Rick P
2026-09-30 22:54 ` Peter Fang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ar0RVyfvEGykm0_u@intel.com \
--to=peter.fang@intel.com \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.