From: Peter Fang <peter.fang@intel.com>
To: <sashiko-reviews@lists.linux.dev>
Cc: Xu Yilun <yilun.xu@linux.intel.com>, <kvm@vger.kernel.org>
Subject: Re: [PATCH v2 11/17] x86/virt/tdx: Add interface to generate a Quote
Date: Tue, 30 Jun 2026 08:28:40 -0700 [thread overview]
Message-ID: <20260630152840.GG1743876@pedri> (raw)
In-Reply-To: <20260618084940.C48821F000E9@smtp.kernel.org>
On Thu, Jun 18, 2026 at 08:49:40AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] tdx_quote_generate() uses an uninterruptible mutex lock for a guest-triggered hardware operation, creating a potential host-level denial of service.
> --
>
> > +void *tdx_quote_generate(struct tdx_td *td, void *in_data, u32 in_data_len,
> > + u32 *quote_len)
> > +{
> > + struct tdx_quote_data *qdata = &tdx_quote;
> > + void *quote_dup = NULL;
> > + u64 r, out_len;
> > +
> > + if (!tdx_quote_enabled())
> > + return NULL;
> > +
> > + mutex_lock(&tdx_quote_lock);
>
> [Severity: High]
> Since this path can be triggered by a guest, could using an uninterruptible
> mutex_lock() here lead to a host-level denial of service?
>
> If a guest rapidly requests quotes from multiple vCPUs, it could monopolize
> the global tdx_quote_lock. Other vCPU threads waiting for the lock would
> block in an uninterruptible sleep (D state). If an administrator attempts
> to kill the waiting VMs, the threads will not respond to fatal signals until
> they acquire the lock.
>
> Would it be safer to use mutex_lock_killable() here to allow fatal signals
> to interrupt the wait and permit VM teardown?
This is a good idea, but I think graceful teardown can be addressed
later.
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20260618081355.3253581-1-yilun.xu@linux.intel.com?part=11
>
next prev parent reply other threads:[~2026-06-30 15:28 UTC|newest]
Thread overview: 64+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-18 8:13 [PATCH v2 00/17] Enable DICE-based TDX Quoting Extension Xu Yilun
2026-06-18 8:13 ` [PATCH v2 01/17] x86/virt/tdx: Embed version info in SEAMCALL leaf function definitions Xu Yilun
2026-06-18 14:45 ` Dave Hansen
2026-06-22 12:05 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 02/17] x86/virt/tdx: Configure add-on features on TDX module init and update Xu Yilun
2026-06-18 15:04 ` Dave Hansen
2026-06-22 13:15 ` Xu Yilun
2026-06-24 12:00 ` Xu Yilun
2026-06-24 22:10 ` Peter Fang
2026-06-25 6:33 ` Xu Yilun
2026-06-23 8:43 ` Chao Gao
2026-06-25 10:50 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 03/17] x86/virt/tdx: Detect if the extensions initialization is required Xu Yilun
2026-06-25 5:19 ` Tony Lindgren
2026-06-25 10:57 ` Xu Yilun
2026-06-29 6:33 ` Chao Gao
2026-06-30 11:10 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 04/17] x86/virt/tdx: Add extra memory to TDX module for the extensions Xu Yilun
2026-06-18 8:54 ` sashiko-bot
2026-06-24 1:53 ` Xu Yilun
2026-06-29 7:56 ` Chao Gao
2026-06-30 10:27 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 05/17] x86/virt/tdx: Make TDX module initialize " Xu Yilun
2026-06-18 8:54 ` sashiko-bot
2026-06-23 17:03 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 06/17] x86/virt/tdx: Re-initialize the extensions on runtime TDX module update Xu Yilun
2026-06-18 8:58 ` sashiko-bot
2026-06-25 7:01 ` Xu Yilun
2026-06-29 8:12 ` Chao Gao
2026-06-30 11:14 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 07/17] x86/virt/tdx: Initialize Quoting extension Xu Yilun
2026-06-18 8:50 ` sashiko-bot
2026-06-25 10:24 ` Peter Fang
2026-06-29 8:33 ` Chao Gao
2026-06-30 5:20 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 08/17] x86/virt/tdx: Prepare Quote buffer during extension bringup Xu Yilun
2026-06-25 6:08 ` Tony Lindgren
2026-06-30 4:12 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 09/17] x86/virt/tdx: Add interface to check Quoting availability Xu Yilun
2026-06-25 6:09 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 10/17] x86/virt/tdx: Move tdx_tdr_pa() up in the file Xu Yilun
2026-06-25 6:10 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 11/17] x86/virt/tdx: Add interface to generate a Quote Xu Yilun
2026-06-18 8:49 ` sashiko-bot
2026-06-30 15:28 ` Peter Fang [this message]
2026-06-25 6:05 ` Tony Lindgren
2026-06-30 4:22 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 12/17] x86/virt/tdx: Reinitialize the Quoting extension after TDX module update Xu Yilun
2026-06-25 6:12 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 13/17] x86/virt/tdx: Enable Quoting extension Xu Yilun
2026-06-25 6:13 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 14/17] x86/tdx: Move and rename Quote request structure Xu Yilun
2026-06-25 6:15 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 15/17] KVM: TDX: Factor out userspace return path from tdx_get_quote() Xu Yilun
2026-06-25 6:16 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 16/17] KVM: TDX: Add in-kernel Quote generation Xu Yilun
2026-06-18 9:03 ` sashiko-bot
2026-06-30 15:52 ` Peter Fang
2026-06-25 18:01 ` Sean Christopherson
2026-06-29 10:03 ` Peter Fang
2026-06-30 0:42 ` Sean Christopherson
2026-06-18 8:13 ` [PATCH v2 17/17] KVM: TDX: Support event-notify interrupts only with userspace Quoting Xu Yilun
2026-06-25 6:28 ` Tony Lindgren
2026-06-30 6:36 ` Peter Fang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260630152840.GG1743876@pedri \
--to=peter.fang@intel.com \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=yilun.xu@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox