From: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>
To: "sathyanarayanan.kuppuswamy@linux.intel.com"
<sathyanarayanan.kuppuswamy@linux.intel.com>,
"kas@kernel.org" <kas@kernel.org>,
"Fang, Peter" <peter.fang@intel.com>,
"dave.hansen@linux.intel.com" <dave.hansen@linux.intel.com>
Cc: "bp@alien8.de" <bp@alien8.de>, "x86@kernel.org" <x86@kernel.org>,
"binbin.wu@linux.intel.com" <binbin.wu@linux.intel.com>,
"hpa@zytor.com" <hpa@zytor.com>,
"mingo@redhat.com" <mingo@redhat.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"Li, Xiaoyao" <xiaoyao.li@intel.com>,
"tglx@kernel.org" <tglx@kernel.org>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
"linux-coco@lists.linux.dev" <linux-coco@lists.linux.dev>
Subject: Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
Date: Wed, 29 Jul 2026 21:21:12 +0000 [thread overview]
Message-ID: <e0a90fba3f8424412387aa08f1fdc708abeedc73.camel@intel.com> (raw)
In-Reply-To: <20260729122939.1340412-1-peter.fang@intel.com>
On Wed, 2026-07-29 at 05:29 -0700, Peter Fang wrote:
> Problem
> =======
>
> The fixed-size Quote buffer approach is not sustainable. As
> cryptographic algorithms evolve, TD Quote sizes also grow. A previous
> commit [2] increased the guest driver's fixed-size Quote buffer to 128
> KB to accommodate DICE Quotes, but it may still be insufficient when
> those Quotes use post-quantum cryptography (PQC). PQC certificate chains
> are roughly 10x-15x larger than conventional ones, which can increase
> Quote sizes significantly.
For the DICE host changes, the reason given for why the host side quote
operation is TD scoped was to avoid changing the guest by increasing the report
size. But actually, as this coverletter points out, the guest buffer sizes do
get changed. So I think we should pause this series until we sort out the
inconsistencies in the reasoning. Depending, we may want to circle back with KVM
folks on what the options actually are for the DICE quote operation.
prev parent reply other threads:[~2026-07-29 21:21 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-07-29 18:29 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-07-29 12:58 ` sashiko-bot
2026-07-29 18:47 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
2026-07-29 12:55 ` sashiko-bot
2026-07-29 21:21 ` Edgecombe, Rick P [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e0a90fba3f8424412387aa08f1fdc708abeedc73.camel@intel.com \
--to=rick.p.edgecombe@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=peter.fang@intel.com \
--cc=sathyanarayanan.kuppuswamy@linux.intel.com \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.