From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E23A046A617 for ; Wed, 22 Jul 2026 23:14:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.197 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784762069; cv=none; b=p80WebTfzmfSCLMDWyIO7dBiRJO8l1qt/1+nyOGlEFl3NCFPxO5+R4rcOzDpxn+UTcuiIeXWjlsosw5c+wybqK4TycM4aPRYm9EyncxnwMROtvmZKoDBrO2cAXcvZIfXlQnh41/1OInWDDhELrDCkmvn/WO+3Tne5/zO9zLBLtk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784762069; c=relaxed/simple; bh=uMJpVpNeOdwMaxoQvFL9M1BthKdmt9TO/QVPx01YhrU=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=mEMEozg6tyHOmnEvcUPapDjaZkegRvOpOvG+fM1/OfueHgBe9NnMTxFwPBToyFvXGQo+8xw6MseMYgx3QLvsWiOmQvZ/kqCOvsjqpxGVId+a79WgVDKnF0pZVRfSxfVKzhVP/UNIerpRd+HJJBXg5aiWKI3+41QygZgoBYdulSg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--wyihan.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=tMk0Bx6b; arc=none smtp.client-ip=209.85.214.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--wyihan.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="tMk0Bx6b" Received: by mail-pl1-f197.google.com with SMTP id d9443c01a7336-2cf7dd9fd91so409935ad.1 for ; Wed, 22 Jul 2026 16:14:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784762066; x=1785366866; darn=lists.linux.dev; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=OZfCfgCc362FDxQaAsRRtIxEbjY1lDj4dpO1uwBrjGg=; b=tMk0Bx6bSd9l2pa4Wwp06cINOW28fRAHT4nYkYzdD6L2wJEO2eobXFfc/HhTQLz2WQ WGF7Qk3IlJGzTGVrL/e2y6CaAMI8KRvb9AmAKNhETs9xwKTPHO2dbFRQyJFzK4k3MmTx XZF7tUn/XNv9b5qfvo/11mPLfteujov3D1DLQdRXjk/kR+aolZ82CsW1OjRMhKB8BtA/ 2UDDFJhK/MVeNuOQdwOoEb5uqqC6cOsDCz4tVXGAIEFxMte3FGVpou1l1cmd3WqmYjMd BEp7b4E0VHaRIgMc9USOvpAm9QzT3zTj9ZZJ+6Es9+TWQ663/bLg1to/T7brL+Y8F0+x 3orw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784762066; x=1785366866; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=OZfCfgCc362FDxQaAsRRtIxEbjY1lDj4dpO1uwBrjGg=; b=Gj5303R5U4vLnjA1x0uaDcAqNP/M/ePFOgUwNfM7ZrM5V/pg/njHIuWCgfH5IORO8d nJYLE1a63TsdZqdXdSgvSJzv15+HP6IT+W0MfwmX6618TkwxnEu1E2Q9QrSIMkWNRnAO 47f5W4tOHzUcyVi9Y+t2bpzIkvcF9GX4e07TYksAAkprgFVEIh6F5fc34nBy7W3qYhvV eF0ZCGG2fh7plmgTNXv0F6e/9jyJwMMjDOPajmVcD7ycztCMyiETgsHmvinweEVPromA 1lx1NE9RStKPTpMnEatzh+cApkRRYUa1uZXAfLP2J/j7PNOSnoBEoU+ChWi9AdOC1S6l ekAQ== X-Forwarded-Encrypted: i=1; AHgh+Rrb5rNs7PXA6u4PhyCOC+FK/m2/lqDj5LpgU0JmZMb3Lj41R0sHIAl5wJq7Se+O6xpp3GZoi5EWXoFe@lists.linux.dev X-Gm-Message-State: AOJu0YxPQ14/Uc5d9jgZZhnl4DRT8RCWldRy+MBksLzhr3hTH7kxvBit 46Qsj6+6Lb89uug1L8jy+xPXgAlXr7Rg/qzoZ3PS8/747XwZPxmLhfLRUBQLOnRZ0e0FCT6qpIC BBki7rw== X-Received: from plcm9.prod.google.com ([2002:a17:902:f209:b0:2cf:7342:ecfb]) (user=wyihan job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:ea05:b0:2c9:e9c7:2b59 with SMTP id d9443c01a7336-2cfa6c7569cmr9933285ad.35.1784762065950; Wed, 22 Jul 2026 16:14:25 -0700 (PDT) Date: Wed, 22 Jul 2026 23:13:15 +0000 In-Reply-To: <20260722-tdx-selftests-v14-0-15ad654a50db@google.com> Precedence: bulk X-Mailing-List: linux-coco@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260722-tdx-selftests-v14-0-15ad654a50db@google.com> X-Developer-Key: i=wyihan@google.com; a=ed25519; pk=cRi0fKzS5BMxlHyHY2pJv3w/1zcgfYKr6EYGYppdMYc= X-Developer-Signature: v=1; a=ed25519-sha256; t=1784762054; l=4623; i=wyihan@google.com; s=20260319; h=from:subject:message-id; bh=a5KKFZL0jXGvpSn59PVTTvyWAfVdsMJYuj2P3eOP+Iw=; b=VdXm08FD+Hm10IK7Q5OZXwNMUpOOjkshSUyqDMR+d/KSpGqd1+jni0/d7dOk78ipzaMlLxJiw 0I1AF/Dt+V/Dg0QnyN/jHpUlnCREVUpaq6w4xZAzE19Ka/Ixq8U1Fo+ X-Mailer: b4 0.14.3 Message-ID: <20260722-tdx-selftests-v14-10-15ad654a50db@google.com> Subject: [PATCH v14 10/22] KVM: selftests: Set up TDX boot code region From: Lisa Wang To: Andrew Jones , Ackerley Tng , Binbin Wu , Chao Gao , Chenyi Qiang , Dave Hansen , Erdem Aktas , Ira Weiny , Isaku Yamahata , Kiryl Shutsemau , linux-kselftest@vger.kernel.org, Paolo Bonzini , "Pratik R. Sampat" , Reinette Chatre , Rick Edgecombe , Roger Wang , Ryan Afranji , Sagi Shahar , Sean Christopherson , Shuah Khan , Xiaoyao Li , Oliver Upton Cc: Jeremiah McReynolds , kvm@vger.kernel.org, linux-coco@lists.linux.dev, linux-kernel@vger.kernel.org, x86@kernel.org, Lisa Wang Content-Type: text/plain; charset="utf-8" From: Sagi Shahar Add memory for TDX boot code in a separate memslot. Use virt_map() to get identity map in this memory region to allow for seamless transition from paging disabled to paging enabled code. Copy the boot code into the memory region and set up the reset vector at this point. While it's possible to separate the memory allocation and boot code initialization into separate functions, having all the calculations for memory size and offsets in one place simplifies the code and avoids duplications. Handcode the reset vector as suggested by Sean Christopherson. Reviewed-by: Binbin Wu Suggested-by: Sean Christopherson Co-developed-by: Erdem Aktas Signed-off-by: Erdem Aktas Signed-off-by: Sagi Shahar Signed-off-by: Lisa Wang --- .../selftests/kvm/include/x86/tdx/tdx_util.h | 1 + tools/testing/selftests/kvm/lib/x86/processor.c | 4 +- tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c | 46 ++++++++++++++++++++++ 3 files changed, 50 insertions(+), 1 deletion(-) diff --git a/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h b/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h index eb8602dce0bc..642ffa010da3 100644 --- a/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h +++ b/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h @@ -45,5 +45,6 @@ static inline bool is_tdx_vm(struct kvm_vm *vm) }) void tdx_init_vm(struct kvm_vm *vm, u64 attributes); +void tdx_vm_setup_boot_code_region(struct kvm_vm *vm); #endif /* SELFTESTS_TDX_TDX_UTIL_H */ diff --git a/tools/testing/selftests/kvm/lib/x86/processor.c b/tools/testing/selftests/kvm/lib/x86/processor.c index ad75e19bb3a2..f93953777ca1 100644 --- a/tools/testing/selftests/kvm/lib/x86/processor.c +++ b/tools/testing/selftests/kvm/lib/x86/processor.c @@ -791,8 +791,10 @@ void kvm_arch_vm_post_create(struct kvm_vm *vm, unsigned int nr_vcpus) vm_sev_ioctl(vm, KVM_SEV_INIT2, &init); } - if (is_tdx_vm(vm)) + if (is_tdx_vm(vm)) { tdx_init_vm(vm, 0); + tdx_vm_setup_boot_code_region(vm); + } r = __vm_ioctl(vm, KVM_GET_TSC_KHZ, NULL); TEST_ASSERT(r > 0, "KVM_GET_TSC_KHZ did not provide a valid TSC frequency."); diff --git a/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c b/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c index c01a26567b73..d64d153d19e2 100644 --- a/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c +++ b/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c @@ -1,8 +1,54 @@ // SPDX-License-Identifier: GPL-2.0-only #include "processor.h" +#include "tdx/td_boot.h" #include "tdx/tdx_util.h" +/* Arbitrarily selected to avoid overlaps with anything else */ +#define TD_BOOT_CODE_SLOT 20 + +#define X86_RESET_VECTOR 0xfffffff0ul +#define X86_RESET_VECTOR_SIZE 16 + +void tdx_vm_setup_boot_code_region(struct kvm_vm *vm) +{ + size_t total_code_size = TD_BOOT_CODE_SIZE + X86_RESET_VECTOR_SIZE; + gpa_t boot_code_gpa = X86_RESET_VECTOR - TD_BOOT_CODE_SIZE; + gpa_t alloc_gpa = round_down(boot_code_gpa, PAGE_SIZE); + size_t nr_pages = DIV_ROUND_UP(total_code_size, PAGE_SIZE); + const u64 gmem_flags = 0; + gpa_t gpa; + u8 *hva; + + vm_mem_add(vm, VM_MEM_SRC_SHMEM, alloc_gpa, TD_BOOT_CODE_SLOT, + nr_pages, KVM_MEM_GUEST_MEMFD, -1, 0, gmem_flags); + + gpa = vm_phy_pages_alloc(vm, nr_pages, alloc_gpa, TD_BOOT_CODE_SLOT); + TEST_ASSERT(gpa == alloc_gpa, "Failed vm_phy_pages_alloc\n"); + + virt_map(vm, alloc_gpa, alloc_gpa, nr_pages); + hva = addr_gpa2hva(vm, boot_code_gpa); + memcpy(hva, td_boot, TD_BOOT_CODE_SIZE); + + hva += TD_BOOT_CODE_SIZE; + TEST_ASSERT(hva == addr_gpa2hva(vm, X86_RESET_VECTOR), + "Expected RESET vector at hva 0x%lx, got %lx", + (unsigned long)addr_gpa2hva(vm, X86_RESET_VECTOR), (unsigned long)hva); + + /* + * Handcode "JMP rel8" at the RESET vector to jump back to the TD boot + * code, as there are only 16 bytes at the RESET vector before RIP will + * wrap back to zero. Insert a trailing int3 so that the vCPU crashes in + * case the JMP somehow falls through. Note! The target address is + * relative to the end of the instruction! + */ + TEST_ASSERT(TD_BOOT_CODE_SIZE + 2 <= 128, + "TD boot code not addressable by 'JMP rel8'"); + hva[0] = 0xeb; + hva[1] = 256 - 2 - TD_BOOT_CODE_SIZE; + hva[2] = 0xcc; +} + static struct kvm_tdx_capabilities *tdx_read_capabilities(struct kvm_vm *vm) { static struct kvm_tdx_capabilities *tdx_cap; -- 2.55.0.229.g6434b31f56-goog