From: Sean Christopherson <seanjc@google.com>
To: Rick P Edgecombe <rick.p.edgecombe@intel.com>
Cc: Vishal Annapurve <vannapurve@google.com>,
Yilun Xu <yilun.xu@intel.com>,
Elena Reshetova <elena.reshetova@intel.com>,
Binbin Wu <binbin.wu@intel.com>,
Dave Hansen <dave.hansen@intel.com>,
"kas@kernel.org" <kas@kernel.org>,
"pbonzini@redhat.com" <pbonzini@redhat.com>,
Peter Fang <peter.fang@intel.com>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>
Subject: Re: TDG quote analysis
Date: Thu, 24 Sep 2026 09:28:15 -0700 [thread overview]
Message-ID: <arVPn7HcMLd7VgTZ@google.com> (raw)
In-Reply-To: <3ae12b120c7aa2ca56e46bb9a5b2a7b7fc501131.camel@intel.com>
On Thu, Sep 24, 2026, Rick P Edgecombe wrote:
> On Wed, 2026-09-23 at 17:18 -0700, Sean Christopherson wrote:
> > From an upstream perspective, I think we don't care? Or rather, we *shouldn't*
> > have to care beyond letting the admin flip a TDX Module switch. I'm a-ok letting
> > end users opt-in to ultra-paranoid mode, with a pile of disclaimers around the
> > shortcomings and tradeoffs involved. I.e. I don't really care how the quote is
> > generated, I just don't want to carry any kernel/KVM code to make it less painful
> > (and it should absolutely be opt-in).
>
> I think the direction is to basically punt on Linux S3M design for the initial
> upstream implementation. But based on today, I think we would have several
> options. This is good thing to do for now I think, because the TDX arch side of
> S3M based attestation is still fuzzy.
Ya, and what I'm saying is that one of the goals of the TDX Module should be to
provide a common interface for signing quotes, regardless of what is doing the
actual signing. I.e. beyond flipping a switch at boot time, we shouldn't need
to modify the host or guest kernels. Host userspace and maybe guest userspace
will need to be aware of which signing implementation is being used, because it
will significantly impact VM scheduling and behavior, but the kernel really
shouldn't have to care.
next prev parent reply other threads:[~2026-09-24 16:28 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 0:48 TDG quote analysis Edgecombe, Rick P
2026-09-16 18:00 ` Sean Christopherson
2026-09-16 18:49 ` Edgecombe, Rick P
2026-09-16 19:27 ` Sean Christopherson
2026-09-16 22:31 ` Edgecombe, Rick P
2026-09-16 23:00 ` Peter Fang
2026-09-16 23:57 ` Sean Christopherson
2026-09-17 0:56 ` Edgecombe, Rick P
2026-09-17 13:37 ` Sean Christopherson
2026-09-17 18:12 ` Edgecombe, Rick P
2026-09-17 19:57 ` Sean Christopherson
2026-09-17 21:32 ` Edgecombe, Rick P
2026-09-18 0:04 ` Sean Christopherson
2026-09-18 2:39 ` Edgecombe, Rick P
2026-09-18 13:13 ` Sean Christopherson
2026-09-18 18:12 ` Edgecombe, Rick P
2026-09-18 21:32 ` Sean Christopherson
2026-09-21 23:00 ` Peter Fang
2026-09-21 23:06 ` Dave Hansen
2026-09-23 4:09 ` Vishal Annapurve
2026-09-24 0:03 ` Vishal Annapurve
2026-09-24 0:18 ` Sean Christopherson
2026-09-24 0:44 ` Edgecombe, Rick P
2026-09-24 16:28 ` Sean Christopherson [this message]
2026-09-21 23:04 ` Dave Hansen
2026-09-21 23:19 ` Sean Christopherson
2026-09-21 23:36 ` Dave Hansen
2026-09-21 23:46 ` Sean Christopherson
2026-09-22 0:03 ` Dave Hansen
2026-09-22 6:48 ` Reshetova, Elena
2026-09-22 17:07 ` Edgecombe, Rick P
2026-09-23 8:50 ` Reshetova, Elena
2026-09-23 22:50 ` Peter Fang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arVPn7HcMLd7VgTZ@google.com \
--to=seanjc@google.com \
--cc=binbin.wu@intel.com \
--cc=dave.hansen@intel.com \
--cc=elena.reshetova@intel.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=peter.fang@intel.com \
--cc=rick.p.edgecombe@intel.com \
--cc=vannapurve@google.com \
--cc=yilun.xu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox