From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f70.google.com (mail-pj1-f70.google.com [209.85.216.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9C7194C10CB for ; Thu, 1 Oct 2026 19:38:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.70 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790883529; cv=none; b=CZPyLRYLWvPImUYu8qmDePT9/xqHgfzVr/AB1RxAC9HPEZotYjWksfCxWexhsL7oHRMUKy7y+WTTiiuLdgl9P8Q/7Z42AwKEhCRBgEmAF6UmUiN6xL/An8tWYrxXOVVPyR4S0G7wZN5VvXgoseUGDtBhJ+FEu7OG/vuBwEKQe0E= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790883529; c=relaxed/simple; bh=Croj8xCN+pglFgr13Z/ncTi9hY9hJgJfecTI+QWCphE=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=G5Ju9coYe6CBITjg1+fPxQ1SFTC/u5HIlXkwxz8HuKZq8/SHuL4vQpP5Pq9LgiFGP0SqNOTOIMzzMm4ra+r3hhiw17PyRg3zxPerDqyK5wFB4wGUdQ5ktMM3/uItwG/yO5Jfaywl4lDx6qv24yQm4wON8NU0HuuItG0xI2Zs0mE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--wyihan.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=CQOr+sOH; arc=none smtp.client-ip=209.85.216.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--wyihan.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="CQOr+sOH" Received: by mail-pj1-f70.google.com with SMTP id 98e67ed59e1d1-3a4f7eb79f2so1233707a91.1 for ; Thu, 01 Oct 2026 12:38:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1790883525; x=1791488325; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=IPPhENoMkklpvlYM7ybijAawXTvy2rZPZ0/TBrLhj98=; b=CQOr+sOHQjbDbLX6950rVnHLdbzFtxLcYbLODwltCh/CsdA+NLuI9G3gytIuTH7S9l tSGrv7W40vLsOvyuLC9vC8jLCBvYhMf5UQ+Kv9XXZEOMHpjitOCBppMYw+NLu1MFEC1+ moYzfRoDHcRShdme8M5E8SAGI6CZZ513E7acbcGuXfru2nMkPFwOEdPV7v0ui2yLrcwF 76H681YWLYEvYmAc8Z1qYsZbAbI53r2zjDJ3Mr/a4KYnvLxfIB4hm4BsT+JyklDT7lRX ZioY3LFlbVIIBl0RouXWNA0pnXzEb8ofxbU3SiTRFld86aGoGA7qZxEXk2NDJJ5s+UGT vhfA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790883525; x=1791488325; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=IPPhENoMkklpvlYM7ybijAawXTvy2rZPZ0/TBrLhj98=; b=jI4tvtHO1O6wOTx3JFkj1yqoH7BvqZVulHqsZigUDuOqkgsONZdY8nzFvqqCfQSPiP 2g79OVSAUOGQ8iRRLY9kjQl722BqO6NkH/bsSMJoQkXnljU5EGerNvQ7JRtImCxwYjo8 mBBRupnI9sQdiARuC9iIKa8EsUSTIV9hyWVdaxu2z7gEOiWNnNXSFT4b2KnNxhdQEUNB 3gxWW15MMfK2+IwpjzFlHp357h6HNhbFrIwXzSFr9zyC7n6EKkPPVy4M95s8Rjy7gcZ7 zJnXeA5gu0Z8X/4f+picytMm/rOU5B/ReLqTSWuEJ112b7jrYsSpNs1VQ3xbibvJqHjC vCVg== X-Forwarded-Encrypted: i=1; AKwUvByvvzg2GjCKXSZAbkaYns3tj4WpkJwk4jk0flySH71x+7ErcG55MnoBmBaYfI3oWfEpCMo=@vger.kernel.org X-Gm-Message-State: AFq9FYIDZNTM6ykZPzZqPDTnRVby6I2S5OCTWSKOlyF5ulo412ErQLIq XWLPXnGYQjQ7PlxUOlbr99wHByGv1sq9ASR+x7b4He5j3aRaT38nicngiZXPR/NL8xTdmE9zJrQ VxQubvA== X-Received: from pjue13.prod.google.com ([2002:a17:90a:e4cd:b0:3a5:d81:11dc]) (user=wyihan job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:3846:b0:3a0:c276:1ec2 with SMTP id 98e67ed59e1d1-3a6ce6af085mr258389a91.19.1790883524669; Thu, 01 Oct 2026 12:38:44 -0700 (PDT) Date: Thu, 01 Oct 2026 19:37:30 +0000 In-Reply-To: <20261001-tdx-selftests-v15-0-7c62a5d8a992@google.com> Precedence: bulk X-Mailing-List: kvm@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20261001-tdx-selftests-v15-0-7c62a5d8a992@google.com> X-Developer-Key: i=wyihan@google.com; a=ed25519; pk=cRi0fKzS5BMxlHyHY2pJv3w/1zcgfYKr6EYGYppdMYc= X-Developer-Signature: v=1; a=ed25519-sha256; t=1790883521; l=9163; i=wyihan@google.com; s=20260319; h=from:subject:message-id; bh=HYFzwki4JJczVxoJZ/+f8OrG8mhCNA9OKpNv1dBVhZs=; b=5o2eUXvczOY249QmvfUwdJKWv/c+NCF9p8EItbAOnB3LayqZSHWb1dRXhFPsm+PVLRAAWdYy2 8bwNWkM6rcFAqhPW7+YJhP2RziCvac5Dh9TsJkKRSYJ4jWpUD3PSLYd X-Mailer: b4 0.14.3 Message-ID: <20261001-tdx-selftests-v15-3-7c62a5d8a992@google.com> Subject: [PATCH v15 03/23] KVM: selftests: Initialize the TDX VM From: Lisa Wang To: Andrew Jones , Ackerley Tng , Binbin Wu , Chao Gao , Chenyi Qiang , Dave Hansen , Erdem Aktas , Ira Weiny , Isaku Yamahata , Kiryl Shutsemau , linux-kselftest@vger.kernel.org, Paolo Bonzini , "Pratik R. Sampat" , Reinette Chatre , Rick Edgecombe , Roger Wang , Ryan Afranji , Sagi Shahar , Sean Christopherson , Shuah Khan , Xiaoyao Li , Oliver Upton Cc: Jeremiah McReynolds , kvm@vger.kernel.org, linux-coco@lists.linux.dev, linux-kernel@vger.kernel.org, x86@kernel.org, Lisa Wang , Ira Weiny Content-Type: text/plain; charset="utf-8" From: Sagi Shahar Add tdx_init_vm() to handle the mandatory VM-level initialization sequence required for Intel TDX. For TDX, the VM's CPUID configuration must be "sealed" during KVM_TDX_INIT_VM before any vCPUs are created. This is necessary because the TDX module does not allow the host to create and initialize any vCPUs before the VM's CPUID configuration is accepted and sealed into the TDCS. Additionally, to satisfy the strict requirements of the TDH.MNG.INIT SEAMCALL, the helper masks the host-supported CPUID (kvm_get_supported_cpuid()) against the "directly configurable" bits reported by KVM_TDX_CAPABILITIES. Co-developed-by: Isaku Yamahata Signed-off-by: Isaku Yamahata Co-developed-by: Rick Edgecombe Signed-off-by: Rick Edgecombe Signed-off-by: Sagi Shahar Signed-off-by: Lisa Wang Reviewed-by: Ira Weiny --- tools/testing/selftests/kvm/Makefile.kvm | 1 + .../testing/selftests/kvm/include/x86/processor.h | 2 + .../selftests/kvm/include/x86/tdx/tdx_util.h | 37 +++++++ tools/testing/selftests/kvm/lib/x86/processor.c | 21 +++- tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c | 121 +++++++++++++++++++++ 5 files changed, 178 insertions(+), 4 deletions(-) diff --git a/tools/testing/selftests/kvm/Makefile.kvm b/tools/testing/selftests/kvm/Makefile.kvm index 239bc61ea384..8f514008daa2 100644 --- a/tools/testing/selftests/kvm/Makefile.kvm +++ b/tools/testing/selftests/kvm/Makefile.kvm @@ -28,6 +28,7 @@ LIBKVM_x86 += lib/x86/pmu.c LIBKVM_x86 += lib/x86/processor.c LIBKVM_x86 += lib/x86/sev.c LIBKVM_x86 += lib/x86/svm.c +LIBKVM_x86 += lib/x86/tdx/tdx_util.c LIBKVM_x86 += lib/x86/ucall.c LIBKVM_x86 += lib/x86/vmx.c diff --git a/tools/testing/selftests/kvm/include/x86/processor.h b/tools/testing/selftests/kvm/include/x86/processor.h index ed50007e3504..08b7b194f213 100644 --- a/tools/testing/selftests/kvm/include/x86/processor.h +++ b/tools/testing/selftests/kvm/include/x86/processor.h @@ -1024,6 +1024,8 @@ static inline void vcpu_xcrs_set(struct kvm_vcpu *vcpu, struct kvm_xcrs *xcrs) vcpu_ioctl(vcpu, KVM_SET_XCRS, xcrs); } +const struct kvm_cpuid_entry2 *__get_cpuid_entry(const struct kvm_cpuid2 *cpuid, + u32 function, u32 index); const struct kvm_cpuid_entry2 *get_cpuid_entry(const struct kvm_cpuid2 *cpuid, u32 function, u32 index); const struct kvm_cpuid2 *kvm_get_supported_cpuid(void); diff --git a/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h b/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h index f647e6ca6b34..571f7ce4b8fe 100644 --- a/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h +++ b/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h @@ -11,4 +11,41 @@ static inline bool is_tdx_vm(struct kvm_vm *vm) return vm->type == KVM_X86_TDX_VM; } +/* + * TDX ioctls + * Use underscores to avoid collisions with struct member names. + */ +#define __tdx_vm_ioctl(vm, cmd, _flags, arg, hw_err) \ +({ \ + u64 *__hw_err = (hw_err); \ + int r; \ + \ + union { \ + struct kvm_tdx_cmd c; \ + unsigned long raw; \ + } tdx_cmd = { .c = { \ + .id = (cmd), \ + .flags = (u32)(_flags), \ + .data = (u64)(arg), \ + } }; \ + \ + r = __vm_ioctl(vm, KVM_MEMORY_ENCRYPT_OP, &tdx_cmd.raw); \ + if (__hw_err) \ + *__hw_err = tdx_cmd.c.hw_error; \ + r; \ +}) + +#define tdx_vm_ioctl(vm, cmd, flags, arg) \ +({ \ + u64 hw_error; \ + int ret = __tdx_vm_ioctl(vm, cmd, flags, arg, &hw_error); \ + \ + TEST_ASSERT(!ret, \ + "%s failed, rc: %d errno: %i (%s) hw_error: 0x%llx",\ + #cmd, ret, errno, strerror(errno), \ + (unsigned long long)hw_error); \ +}) + +void tdx_init_vm(struct kvm_vm *vm); + #endif /* SELFTESTS_TDX_TDX_UTIL_H */ diff --git a/tools/testing/selftests/kvm/lib/x86/processor.c b/tools/testing/selftests/kvm/lib/x86/processor.c index 24395a8e654a..b87ba7d8538b 100644 --- a/tools/testing/selftests/kvm/lib/x86/processor.c +++ b/tools/testing/selftests/kvm/lib/x86/processor.c @@ -829,6 +829,9 @@ void kvm_arch_vm_post_create(struct kvm_vm *vm, unsigned int nr_vcpus) vm_sev_ioctl(vm, KVM_SEV_INIT2, &init); } + if (is_tdx_vm(vm)) + tdx_init_vm(vm); + r = __vm_ioctl(vm, KVM_GET_TSC_KHZ, NULL); TEST_ASSERT(r > 0, "KVM_GET_TSC_KHZ did not provide a valid TSC frequency."); guest_tsc_khz = r; @@ -1347,8 +1350,8 @@ void kvm_init_vm_address_properties(struct kvm_vm *vm) } } -const struct kvm_cpuid_entry2 *get_cpuid_entry(const struct kvm_cpuid2 *cpuid, - u32 function, u32 index) +const struct kvm_cpuid_entry2 *__get_cpuid_entry(const struct kvm_cpuid2 *cpuid, + u32 function, u32 index) { int i; @@ -1358,11 +1361,21 @@ const struct kvm_cpuid_entry2 *get_cpuid_entry(const struct kvm_cpuid2 *cpuid, return &cpuid->entries[i]; } - TEST_FAIL("CPUID function 0x%x index 0x%x not found ", function, index); - return NULL; } +const struct kvm_cpuid_entry2 *get_cpuid_entry(const struct kvm_cpuid2 *cpuid, + u32 function, u32 index) +{ + const struct kvm_cpuid_entry2 *entry; + + entry = __get_cpuid_entry(cpuid, function, index); + if (!entry) + TEST_FAIL("CPUID function 0x%x index 0x%x not found ", function, index); + + return entry; +} + #define X86_HYPERCALL(inputs...) \ ({ \ u64 r; \ diff --git a/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c b/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c new file mode 100644 index 000000000000..3a8900ff2540 --- /dev/null +++ b/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c @@ -0,0 +1,121 @@ +// SPDX-License-Identifier: GPL-2.0-only + +#include "processor.h" +#include "tdx/tdx_util.h" + +static const struct kvm_tdx_capabilities *tdx_read_capabilities(struct kvm_vm *vm) +{ + static struct kvm_tdx_capabilities *tdx_cap; + int nr_cpuid_configs = 4; + int rc = -1; + int i; + + if (tdx_cap) + return tdx_cap; + + do { + nr_cpuid_configs *= 2; + + tdx_cap = realloc(tdx_cap, sizeof(*tdx_cap) + + (sizeof(struct kvm_cpuid_entry2) * nr_cpuid_configs)); + TEST_ASSERT(tdx_cap, + "Could not allocate memory for tdx capability nr_cpuid_configs %d\n", + nr_cpuid_configs); + + tdx_cap->cpuid.nent = nr_cpuid_configs; + rc = __tdx_vm_ioctl(vm, KVM_TDX_CAPABILITIES, 0, tdx_cap, NULL); + } while (rc < 0 && errno == E2BIG); + + TEST_ASSERT(rc == 0, "KVM_TDX_CAPABILITIES failed: %d %d", + rc, errno); + + pr_debug("tdx_cap: supported_attrs: 0x%016llx\n" + "tdx_cap: supported_xfam 0x%016llx\n", + tdx_cap->supported_attrs, tdx_cap->supported_xfam); + + for (i = 0; i < tdx_cap->cpuid.nent; i++) { + const struct kvm_cpuid_entry2 *config = &tdx_cap->cpuid.entries[i]; + + pr_debug("cpuid config[%d]: leaf 0x%x sub_leaf 0x%x eax 0x%08x ebx 0x%08x ecx 0x%08x edx 0x%08x\n", + i, config->function, config->index, + config->eax, config->ebx, config->ecx, config->edx); + } + + return tdx_cap; +} + +/* + * Filter CPUID based on TDX supported capabilities + * + * Input Args: + * vm - Virtual Machine + * cpuid_data - CPUID fields to filter + * + * Output Args: None + * + * Return: None + * + * For each CPUID leaf, filter out unsupported bits based on the capabilities + * reported by the TDX module + */ +static void tdx_filter_cpuid(struct kvm_vm *vm, + struct kvm_cpuid2 *cpuid_data) +{ + const struct kvm_tdx_capabilities *tdx_cap; + const struct kvm_cpuid_entry2 *config; + struct kvm_cpuid_entry2 *e; + int i; + + tdx_cap = tdx_read_capabilities(vm); + + i = 0; + while (i < cpuid_data->nent) { + e = cpuid_data->entries + i; + config = __get_cpuid_entry(&tdx_cap->cpuid, e->function, e->index); + + if (!config) { + int left = cpuid_data->nent - i - 1; + + if (left > 0) + memmove(cpuid_data->entries + i, + cpuid_data->entries + i + 1, + sizeof(*cpuid_data->entries) * left); + cpuid_data->nent--; + continue; + } + + e->eax &= config->eax; + e->ebx &= config->ebx; + e->ecx &= config->ecx; + e->edx &= config->edx; + + i++; + } +} + +void tdx_init_vm(struct kvm_vm *vm) +{ + struct kvm_tdx_init_vm *init_vm; + const struct kvm_cpuid2 *tmp; + struct kvm_cpuid2 *cpuid; + + tmp = kvm_get_supported_cpuid(); + + cpuid = allocate_kvm_cpuid2(tmp->nent); + memcpy(cpuid, tmp, kvm_cpuid2_size(tmp->nent)); + tdx_filter_cpuid(vm, cpuid); + + init_vm = calloc(1, sizeof(*init_vm) + + sizeof(init_vm->cpuid.entries[0]) * cpuid->nent); + TEST_ASSERT(init_vm, "init_vm allocation failed"); + + memcpy(&init_vm->cpuid, cpuid, kvm_cpuid2_size(cpuid->nent)); + free(cpuid); + + init_vm->attributes = 0; + init_vm->xfam = 0; + + tdx_vm_ioctl(vm, KVM_TDX_INIT_VM, 0, init_vm); + + free(init_vm); +} -- 2.56.0.rc1.315.gc6ed9934b7-goog