From: Peter Fang <peter.fang@intel.com>
To: Dave Hansen <dave.hansen@linux.intel.com>,
Kiryl Shutsemau <kas@kernel.org>,
Rick Edgecombe <rick.p.edgecombe@intel.com>,
"Kuppuswamy Sathyanarayanan"
<sathyanarayanan.kuppuswamy@linux.intel.com>
Cc: Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>, <x86@kernel.org>,
"H. Peter Anvin" <hpa@zytor.com>, <linux-kernel@vger.kernel.org>,
<linux-coco@lists.linux.dev>, <kvm@vger.kernel.org>,
Xiaoyao Li <xiaoyao.li@intel.com>,
Binbin Wu <binbin.wu@linux.intel.com>,
Peter Fang <peter.fang@intel.com>
Subject: [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically
Date: Wed, 29 Jul 2026 05:29:34 -0700 [thread overview]
Message-ID: <20260729122939.1340412-5-peter.fang@intel.com> (raw)
In-Reply-To: <20260729122939.1340412-1-peter.fang@intel.com>
From: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
A new TDX module ABI reports the TD Quote size limit in a metadata
field. This size used to be fixed at 128 KB.
The guest driver's Quote buffer is shared with the host VMM. The current
fixed size may be too small for Quotes using schemes such as
post-quantum cryptography (PQC), where larger certificate chains can
increase the Quote size significantly.
Allocate the Quote buffer based on the reported limit. This avoids
wasting memory on platforms that do not require larger Quotes. Older
platforms fall back to the default 128 KB buffer.
As a result, the maximum size of the "outblob" file in configfs-tsm now
depends on the TDX module.
Because the Quote buffer must be physically contiguous, its size is
bound by the buddy allocator's maximum page order (4 MB), which should
be sufficient for current attestation needs.
Signed-off-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
Signed-off-by: Peter Fang <peter.fang@intel.com>
---
v3:
- Split out from the v2 "Allocate Quote buffer dynamically" patch. Add
the dynamic buffer feature on top of the refactoring. [Dave]
- Improve the get_quote_buf_size() pattern for better readability.
[Dave]
- Drop __GFP_NOWARN so an allocation failure warns. [Dave, Rick, Kiryl]
- Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
reworked.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 24 ++++++++++++++++++++++--
1 file changed, 22 insertions(+), 2 deletions(-)
diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index 3d3f79ab45af..8919b1a1154e 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -162,7 +162,7 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
* DICE-based attestation uses layered evidence that requires
* larger Quote size (~100K).
*/
-#define GET_QUOTE_BUF_SIZE SZ_128K
+#define GET_QUOTE_DEFAULT_BUF_SIZE SZ_128K
#define GET_QUOTE_CMD_VER 1
@@ -222,11 +222,31 @@ static void free_quote_buf(void *buf, size_t len)
free_pages_exact(buf, len);
}
+/* Return a buffer size large enough to hold a Quote */
+static size_t get_quote_buf_size(void)
+{
+ u32 quote_size = tdx_get_max_quote_size();
+
+ /*
+ * Older TDX modules do not report a maximum Quote size, so use
+ * the default.
+ */
+ if (!quote_size)
+ return GET_QUOTE_DEFAULT_BUF_SIZE;
+
+ /* The reported size does not include the buffer header */
+ return PAGE_ALIGN(TDX_QUOTE_BUF_LEN(quote_size));
+}
+
static void *alloc_quote_buf(size_t len)
{
unsigned int count = len >> PAGE_SHIFT;
void *addr;
+ /*
+ * This fails if the requested size exceeds the buddy allocator's
+ * maximum order (order-10, 4MB).
+ */
addr = alloc_pages_exact(len, GFP_KERNEL | __GFP_ZERO);
if (!addr)
return NULL;
@@ -416,7 +436,7 @@ static int __init tdx_guest_init(void)
if (ret)
goto deinit_mr;
- quote_data_len = GET_QUOTE_BUF_SIZE;
+ quote_data_len = get_quote_buf_size();
quote_data = alloc_quote_buf(quote_data_len);
if (!quote_data) {
pr_err("Failed to allocate Quote buffer\n");
--
2.53.0
next prev parent reply other threads:[~2026-07-29 12:30 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-07-29 18:29 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-07-29 12:58 ` sashiko-bot
2026-07-29 18:47 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` Peter Fang [this message]
2026-07-29 12:55 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260729122939.1340412-5-peter.fang@intel.com \
--to=peter.fang@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=sathyanarayanan.kuppuswamy@linux.intel.com \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox