From: Zhenzhong Duan <zhenzhong.duan@intel.com>
To: x86@kernel.org, linux-coco@lists.linux.dev, linux-kernel@vger.kernel.org
Cc: dave.hansen@linux.intel.com, tglx@kernel.org, mingo@redhat.com,
bp@alien8.de, hpa@zytor.com, dave.hansen@intel.com,
kas@kernel.org, rick.p.edgecombe@intel.com, jgg@nvidia.com,
nicolinc@nvidia.com, aik@amd.com, aneesh.kumar@kernel.org,
seanjc@google.com, pbonzini@redhat.com, yilun.xu@linux.intel.com,
chao.gao@intel.com, vishal.l.verma@intel.com,
xiaoyao.li@intel.com, kevin.tian@intel.com,
chao.p.peng@intel.com
Subject: [RFC PATCH 02/15] x86/tdx: Add TDCM hypercall wrapper for TDX Connect
Date: Thu, 24 Sep 2026 12:10:19 +0800 [thread overview]
Message-ID: <20260924041032.1096569-3-zhenzhong.duan@intel.com> (raw)
In-Reply-To: <20260924041032.1096569-1-zhenzhong.duan@intel.com>
TDX Connect is a TDX feature that enables secure device assignment,
allowing a TDX guest to directly interact with TEE-IO capable devices.
The TEE-IO Device Control and Management (TDCM) hypercall
(TDG.VP.VMCALL<TDCM>, defined in TDX GHCI v2.0 specification) is the
primary interface through which a TDX guest issues device management
commands to the host. The host processes these commands and returns
responses via a shared memory buffer.
Abstract the underlying leaf call and pass the shared buffer physical
address as a decrypted mapping. Add a runtime page alignment check
for the buffer to enforce correct usage.
Place the implementation in a separate tdx_connect.c file to keep TDX
Connect specific code isolated from core tdx.c.
CONFIG_TDX_CONNECT_GUEST referenced in the header guard will be
introduced in a later patch in this series.
Signed-off-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
---
arch/x86/coco/tdx/Makefile | 2 ++
arch/x86/coco/tdx/tdx_connect.c | 32 +++++++++++++++++++++++++++++++
arch/x86/include/asm/shared/tdx.h | 1 +
arch/x86/include/asm/tdx.h | 4 ++++
4 files changed, 39 insertions(+)
create mode 100644 arch/x86/coco/tdx/tdx_connect.c
diff --git a/arch/x86/coco/tdx/Makefile b/arch/x86/coco/tdx/Makefile
index b3c47d3700e2..2ab2dbbdd3d2 100644
--- a/arch/x86/coco/tdx/Makefile
+++ b/arch/x86/coco/tdx/Makefile
@@ -1,3 +1,5 @@
# SPDX-License-Identifier: GPL-2.0
obj-y += debug.o tdcall.o tdx.o tdx-shared.o
+
+obj-$(CONFIG_TDX_CONNECT_GUEST) += tdx_connect.o
diff --git a/arch/x86/coco/tdx/tdx_connect.c b/arch/x86/coco/tdx/tdx_connect.c
new file mode 100644
index 000000000000..0c6ca650771a
--- /dev/null
+++ b/arch/x86/coco/tdx/tdx_connect.c
@@ -0,0 +1,32 @@
+// SPDX-License-Identifier: GPL-2.0
+/* Copyright (C) 2026 Intel Corporation */
+
+#undef pr_fmt
+#define pr_fmt(fmt) "tdx_connect: " fmt
+
+#include <linux/io.h>
+#include <asm/tdx.h>
+#include <linux/mm.h>
+
+/*
+ * tdx_hcall_tdcm - Send a TDCM command to the host via TDG.VP.VMCALL<TDCM>.
+ *
+ * @devid: Device identifier of the target TEE-IO device.
+ * @buf: Shared, directly mapped buffer containing the TDCM command on
+ * input and the host response on output.
+ * @size: Size of @buf in bytes.
+ * @vector: Event notification interrupt vector, or 0 for synchronous operation.
+ *
+ * The buffer physical address is passed to the host with decrypted/shared
+ * mark.
+ *
+ * Returns 0 on success or a TDX VMCALL status code on failure. See
+ * TDG.VP.VMCALL<TDCM> in the TDX GHCI v2.0 specification for status codes.
+ */
+u64 tdx_hcall_tdcm(u16 devid, void *buf, size_t size, u8 vector)
+{
+ WARN_ON_ONCE(!PAGE_ALIGNED(buf) || !PAGE_ALIGNED(size));
+
+ return _tdx_hypercall(TDVMCALL_TDCM, devid, cc_mkdec(virt_to_phys(buf)), size, vector);
+}
+EXPORT_SYMBOL_FOR_MODULES(tdx_hcall_tdcm, "tdx-guest");
diff --git a/arch/x86/include/asm/shared/tdx.h b/arch/x86/include/asm/shared/tdx.h
index f20e91d7ac35..f46a3171a512 100644
--- a/arch/x86/include/asm/shared/tdx.h
+++ b/arch/x86/include/asm/shared/tdx.h
@@ -74,6 +74,7 @@
#define TDVMCALL_GET_QUOTE 0x10002
#define TDVMCALL_REPORT_FATAL_ERROR 0x10003
#define TDVMCALL_SETUP_EVENT_NOTIFY_INTERRUPT 0x10004ULL
+#define TDVMCALL_TDCM 0x10007
/*
* TDG.VP.VMCALL Status Codes (returned in R10)
diff --git a/arch/x86/include/asm/tdx.h b/arch/x86/include/asm/tdx.h
index 884bb8067521..df4496ef8a6a 100644
--- a/arch/x86/include/asm/tdx.h
+++ b/arch/x86/include/asm/tdx.h
@@ -85,6 +85,10 @@ int tdx_mcall_extend_rtmr(u8 index, u8 *data);
u64 tdx_hcall_get_quote(u8 *buf, size_t size);
+#ifdef CONFIG_TDX_CONNECT_GUEST
+u64 tdx_hcall_tdcm(u16 devid, void *buf, size_t size, u8 vector);
+#endif
+
void __init tdx_dump_attributes(u64 td_attr);
void __init tdx_dump_td_ctls(u64 td_ctls);
--
2.52.0
next prev parent reply other threads:[~2026-09-24 4:10 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 4:10 [RFC PATCH 00/15] PCI/TSM: coco/tdx-guest: Implement TDX-Connect PCIe TDISP (phase2) Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 01/15] x86/tdx: Export tdg_vm_rd() for tdx-guest module Zhenzhong Duan
2026-09-30 22:13 ` Peter Fang
2026-10-01 12:38 ` Xu Yilun
2026-10-08 6:45 ` Duan, Zhenzhong
2026-10-08 16:30 ` Edgecombe, Rick P
2026-09-24 4:10 ` Zhenzhong Duan [this message]
2026-09-24 4:10 ` [RFC PATCH 03/15] x86/tdx: Add TDG.TDI.RD module call wrapper for TDX Connect Zhenzhong Duan
2026-09-25 0:06 ` Edgecombe, Rick P
2026-10-08 6:27 ` Duan, Zhenzhong
2026-10-08 16:42 ` Edgecombe, Rick P
2026-10-09 2:28 ` Duan, Zhenzhong
2026-09-24 4:10 ` [RFC PATCH 04/15] virt: tdx-guest: Support devsec TSM for secure devices Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 05/15] virt: tdx-guest: Add TDCM helpers and TEE-IO support check Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 06/15] virt: tdx-guest: Support TDI bind and unbind operations Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 07/15] PCI/TSM: Track Device Interface Report MMIO range index Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 08/15] x86/tdx: Add TDG.MMIO.ACCEPT module call wrapper for TDX Connect Zhenzhong Duan
2026-09-24 23:41 ` Edgecombe, Rick P
2026-09-25 0:02 ` Edgecombe, Rick P
2026-10-08 6:01 ` Duan, Zhenzhong
2026-10-08 16:47 ` Edgecombe, Rick P
2026-10-08 5:49 ` Duan, Zhenzhong
2026-10-08 16:44 ` Edgecombe, Rick P
2026-10-09 2:16 ` Duan, Zhenzhong
2026-09-24 4:10 ` [RFC PATCH 09/15] virt: tdx-guest: Capture the TDI report during device lock Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 10/15] virt: tdx-guest: Set up and accept private MMIO ranges Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 11/15] x86/tdx: Add TDG.TDI.START module call wrapper for TDX Connect Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 12/15] virt: tdx-guest: Support Trust Device Interface (TDI) activation Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 13/15] x86/tdx: Add __tdcall_saved() helper Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 14/15] x86/tdx: Add TDG.DMAR.ACCEPT module call wrapper for TDX Connect Zhenzhong Duan
2026-09-24 4:10 ` [RFC PATCH 15/15] virt: tdx-guest: Accept default DMAR entry during PCI driver attach Zhenzhong Duan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924041032.1096569-3-zhenzhong.duan@intel.com \
--to=zhenzhong.duan@intel.com \
--cc=aik@amd.com \
--cc=aneesh.kumar@kernel.org \
--cc=bp@alien8.de \
--cc=chao.gao@intel.com \
--cc=chao.p.peng@intel.com \
--cc=dave.hansen@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=jgg@nvidia.com \
--cc=kas@kernel.org \
--cc=kevin.tian@intel.com \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=nicolinc@nvidia.com \
--cc=pbonzini@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=vishal.l.verma@intel.com \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
--cc=yilun.xu@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox