From: Zhenzhong Duan <zhenzhong.duan@intel.com>
To: x86@kernel.org, linux-coco@lists.linux.dev, linux-kernel@vger.kernel.org
Cc: dave.hansen@linux.intel.com, tglx@kernel.org, mingo@redhat.com,
bp@alien8.de, hpa@zytor.com, dave.hansen@intel.com,
kas@kernel.org, rick.p.edgecombe@intel.com, jgg@nvidia.com,
nicolinc@nvidia.com, aik@amd.com, aneesh.kumar@kernel.org,
seanjc@google.com, pbonzini@redhat.com, yilun.xu@linux.intel.com,
chao.gao@intel.com, vishal.l.verma@intel.com,
xiaoyao.li@intel.com, kevin.tian@intel.com,
chao.p.peng@intel.com
Subject: [RFC PATCH 12/15] virt: tdx-guest: Support Trust Device Interface (TDI) activation
Date: Thu, 24 Sep 2026 12:10:29 +0800 [thread overview]
Message-ID: <20260924041032.1096569-13-zhenzhong.duan@intel.com> (raw)
In-Reply-To: <20260924041032.1096569-1-zhenzhong.duan@intel.com>
Store the bind session ID obtained after binding the TDI which is used
by TDG.TDI.START to verify same bind session established by host before
activation.
Add tdx_tdi_start_dev() to signal guest readiness to the TDX module and
issue the TDCM_OP_START_TDI hypercall for the host to complete activation.
The run callback accepts private MMIO ranges, starts the TDI, and verifies
that it reaches TDI_STATE_RUN, finally notifies DMA sub-system device's
ready to DMA to private memory. Note that private DMA is enabled separately
during driver attach by accepting the default DMAR entry.
Signed-off-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
---
drivers/virt/coco/tdx-guest/connect.c | 45 ++++++++++++++++++++++++++-
1 file changed, 44 insertions(+), 1 deletion(-)
diff --git a/drivers/virt/coco/tdx-guest/connect.c b/drivers/virt/coco/tdx-guest/connect.c
index fe8d76ba6f81..a9d41fd38b64 100644
--- a/drivers/virt/coco/tdx-guest/connect.c
+++ b/drivers/virt/coco/tdx-guest/connect.c
@@ -130,6 +130,8 @@ DEFINE_FREE(tdx_tdcm_free, struct tdcm_ctx *,
struct tdx_devsec {
struct pci_tsm_devsec pci;
+
+ u64 bind_session_id;
};
static struct tdx_devsec *to_tdx_devsec(struct pci_tsm *tsm)
@@ -202,6 +204,7 @@ enum tdi_state {
enum tdi_field_code {
TDI_GET_TDISP_STATE = 2,
+ TDI_GET_BIND_SESSION_ID = 5,
};
static int tdx_tdi_read_state(struct tdx_devsec *tdevsec, u8 *state)
@@ -302,10 +305,27 @@ static int tdx_tdi_mmio_accept(struct tdx_devsec *tdevsec)
return 0;
}
+static int tdx_tdi_start_dev(struct tdx_devsec *tdevsec)
+{
+ struct pci_dev *pdev = tdevsec->pci.base_tsm.pdev;
+ int ret;
+
+ ret = tdx_mcall_tdi_start(pci_dev_id(pdev), tdevsec->bind_session_id);
+ if (ret)
+ return ret;
+
+ struct tdcm_ctx *tdcm __free(tdx_tdcm_free) = tdx_tdcm_alloc(pdev, TDCM_OP_START_TDI, 0, 0);
+ if (IS_ERR(tdcm))
+ return PTR_ERR(tdcm);
+
+ return tdx_tdcm_run(tdcm);
+}
+
static struct pci_tsm *tdx_devsec_lock(struct tsm_dev *tsm_dev, struct pci_dev *pdev)
{
struct device_evidence_object *tsm_report;
struct device_evidence *evidence;
+ u64 session_id;
u32 report_sz;
u8 state;
int ret;
@@ -325,6 +345,12 @@ static struct pci_tsm *tdx_devsec_lock(struct tsm_dev *tsm_dev, struct pci_dev *
if (IS_ERR(tdevsec_bind))
return ERR_CAST(tdevsec_bind);
+ ret = tdx_mcall_tdi_read(pci_dev_id(pdev), TDI_GET_BIND_SESSION_ID, &session_id);
+ if (ret)
+ return ERR_PTR(ret);
+
+ tdevsec->bind_session_id = session_id;
+
u8 *report __free(kfree) = tdx_tdi_get_report(tdevsec, &report_sz);
if (IS_ERR(report))
return ERR_CAST(report);
@@ -362,6 +388,7 @@ static void tdx_devsec_unlock(struct pci_tsm *tsm)
tdx_tdi_mmio_teardown(tdevsec);
+ dma_set_cc_private(&tsm->pdev->dev, false);
kfree(evidence->obj[DEVICE_EVIDENCE_TYPE_REPORT].data);
kfree(evidence);
kfree(tdevsec);
@@ -370,6 +397,7 @@ static void tdx_devsec_unlock(struct pci_tsm *tsm)
static int tdx_devsec_run(struct pci_dev *pdev)
{
struct tdx_devsec *tdevsec = to_tdx_devsec(pdev->tsm);
+ u8 state;
int ret;
struct tdx_devsec *tdevsec_mmio __free(tdx_tdi_mmio_teardown) =
@@ -381,7 +409,22 @@ static int tdx_devsec_run(struct pci_dev *pdev)
if (ret)
return ret;
- return -EOPNOTSUPP;
+ ret = tdx_tdi_start_dev(tdevsec);
+ if (ret)
+ return ret;
+
+ ret = tdx_tdi_read_state(tdevsec, &state);
+ if (ret)
+ return ret;
+
+ if (state != TDI_STATE_RUN) {
+ pci_err(pdev, "TDI failed to reach RUN state, current state: 0x%x\n", state);
+ return -EIO;
+ }
+
+ dma_set_cc_private(&pdev->dev, true);
+ retain_and_null_ptr(tdevsec_mmio);
+ return 0;
}
static struct pci_tsm_ops tdx_devsec_ops = {
--
2.52.0
next prev parent reply other threads:[~2026-09-24 4:11 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 4:10 [RFC PATCH 00/15] PCI/TSM: coco/tdx-guest: Implement TDX-Connect PCIe TDISP (phase2) Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 01/15] x86/tdx: Export tdg_vm_rd() for tdx-guest module Zhenzhong Duan
2026-09-30 22:13 ` Peter Fang
2026-10-01 12:38 ` Xu Yilun
2026-10-08 6:45 ` Duan, Zhenzhong
2026-10-08 16:30 ` Edgecombe, Rick P
2026-09-24 4:10 ` [RFC PATCH 02/15] x86/tdx: Add TDCM hypercall wrapper for TDX Connect Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 03/15] x86/tdx: Add TDG.TDI.RD module call " Zhenzhong Duan
2026-09-25 0:06 ` Edgecombe, Rick P
2026-10-08 6:27 ` Duan, Zhenzhong
2026-10-08 16:42 ` Edgecombe, Rick P
2026-09-24 4:10 ` [RFC PATCH 04/15] virt: tdx-guest: Support devsec TSM for secure devices Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 05/15] virt: tdx-guest: Add TDCM helpers and TEE-IO support check Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 06/15] virt: tdx-guest: Support TDI bind and unbind operations Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 07/15] PCI/TSM: Track Device Interface Report MMIO range index Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 08/15] x86/tdx: Add TDG.MMIO.ACCEPT module call wrapper for TDX Connect Zhenzhong Duan
2026-09-24 23:41 ` Edgecombe, Rick P
2026-09-25 0:02 ` Edgecombe, Rick P
2026-10-08 6:01 ` Duan, Zhenzhong
2026-10-08 16:47 ` Edgecombe, Rick P
2026-10-08 5:49 ` Duan, Zhenzhong
2026-10-08 16:44 ` Edgecombe, Rick P
2026-09-24 4:10 ` [RFC PATCH 09/15] virt: tdx-guest: Capture the TDI report during device lock Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 10/15] virt: tdx-guest: Set up and accept private MMIO ranges Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 11/15] x86/tdx: Add TDG.TDI.START module call wrapper for TDX Connect Zhenzhong Duan
2026-09-24 4:10 ` Zhenzhong Duan [this message]
2026-09-24 4:10 ` [RFC PATCH 13/15] x86/tdx: Add __tdcall_saved() helper Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 14/15] x86/tdx: Add TDG.DMAR.ACCEPT module call wrapper for TDX Connect Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 15/15] virt: tdx-guest: Accept default DMAR entry during PCI driver attach Zhenzhong Duan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924041032.1096569-13-zhenzhong.duan@intel.com \
--to=zhenzhong.duan@intel.com \
--cc=aik@amd.com \
--cc=aneesh.kumar@kernel.org \
--cc=bp@alien8.de \
--cc=chao.gao@intel.com \
--cc=chao.p.peng@intel.com \
--cc=dave.hansen@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=jgg@nvidia.com \
--cc=kas@kernel.org \
--cc=kevin.tian@intel.com \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=nicolinc@nvidia.com \
--cc=pbonzini@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=vishal.l.verma@intel.com \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
--cc=yilun.xu@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox