Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Peter Fang <peter.fang@intel.com>
To: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>
Cc: "sathyanarayanan.kuppuswamy@linux.intel.com"
	<sathyanarayanan.kuppuswamy@linux.intel.com>,
	"kas@kernel.org" <kas@kernel.org>,
	"dave.hansen@linux.intel.com" <dave.hansen@linux.intel.com>,
	"bp@alien8.de" <bp@alien8.de>, "x86@kernel.org" <x86@kernel.org>,
	"binbin.wu@linux.intel.com" <binbin.wu@linux.intel.com>,
	"hpa@zytor.com" <hpa@zytor.com>,
	"mingo@redhat.com" <mingo@redhat.com>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"Li, Xiaoyao" <xiaoyao.li@intel.com>,
	"tglx@kernel.org" <tglx@kernel.org>,
	"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
	"linux-coco@lists.linux.dev" <linux-coco@lists.linux.dev>
Subject: Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
Date: Thu, 27 Aug 2026 15:22:46 -0700	[thread overview]
Message-ID: <20260827222246.GE33657@pedri> (raw)
In-Reply-To: <e0a90fba3f8424412387aa08f1fdc708abeedc73.camel@intel.com>

On Wed, Jul 29, 2026 at 02:21:12PM -0700, Edgecombe, Rick P wrote:
> On Wed, 2026-07-29 at 05:29 -0700, Peter Fang wrote:
> > Problem
> > =======
> > 
> > The fixed-size Quote buffer approach is not sustainable. As
> > cryptographic algorithms evolve, TD Quote sizes also grow. A previous
> > commit [2] increased the guest driver's fixed-size Quote buffer to 128
> > KB to accommodate DICE Quotes, but it may still be insufficient when
> > those Quotes use post-quantum cryptography (PQC). PQC certificate chains
> > are roughly 10x-15x larger than conventional ones, which can increase
> > Quote sizes significantly.
> 
> For the DICE host changes, the reason given for why the host side quote
> operation is TD scoped was to avoid changing the guest by increasing the report
> size. But actually, as this coverletter points out, the guest buffer sizes do
> get changed. So I think we should pause this series until we sort out the

This thread has led to a lot of great discussion, and I think perhaps we
can resume reviewing this series? The main open topics now seem to be
the guest report and potential alternatives to GetQuote, but none of
them change the fact that the quote size is growing as crypto stuff
evolves... So this series applies to all the options on the table right
now.

> inconsistencies in the reasoning. Depending, we may want to circle back with KVM
> folks on what the options actually are for the DICE quote operation.

  parent reply	other threads:[~2026-08-27 22:22 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-07-29 18:29   ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-07-29 12:58   ` sashiko-bot
2026-07-29 18:47   ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
2026-07-29 12:55   ` sashiko-bot
2026-07-29 21:21 ` [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Edgecombe, Rick P
2026-08-11 22:40   ` Edgecombe, Rick P
2026-08-12 14:08     ` Sean Christopherson
2026-08-12 16:02       ` Edgecombe, Rick P
2026-08-12 16:43         ` Sean Christopherson
2026-08-12 17:22           ` Edgecombe, Rick P
2026-08-12 22:37             ` Peter Fang
2026-08-12 22:47               ` Edgecombe, Rick P
2026-08-12 23:10                 ` Sean Christopherson
2026-08-12 23:30                   ` Edgecombe, Rick P
2026-08-13 19:32                     ` Artem Bityutskiy
2026-08-13 20:14                       ` Edgecombe, Rick P
2026-08-14  5:45                         ` Artem Bityutskiy
2026-08-14  7:37                           ` Peter Fang
2026-08-14 15:55                           ` Edgecombe, Rick P
2026-08-15 11:39                             ` Artem Bityutskiy
2026-08-17 17:26                               ` Edgecombe, Rick P
2026-08-18 11:09                                 ` Artem Bityutskiy
2026-08-18 20:37                       ` Sean Christopherson
2026-08-18 23:46                         ` Edgecombe, Rick P
2026-08-19 14:57                         ` Artem Bityutskiy
2026-08-12 23:27                 ` Peter Fang
2026-08-12 21:02         ` Peter Fang
2026-08-27 22:22   ` Peter Fang [this message]
2026-08-27 22:41     ` Edgecombe, Rick P

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260827222246.GE33657@pedri \
    --to=peter.fang@intel.com \
    --cc=binbin.wu@linux.intel.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=kas@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=rick.p.edgecombe@intel.com \
    --cc=sathyanarayanan.kuppuswamy@linux.intel.com \
    --cc=tglx@kernel.org \
    --cc=x86@kernel.org \
    --cc=xiaoyao.li@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox