Linux Confidential Computing Development
 help / color / mirror / Atom feed
* [PATCH v3] x86/tdx: Restrict attestation exports to the tdx-guest driver
@ 2026-09-25 13:18 Nikolay Borisov
  2026-09-25 13:34 ` Kiryl Shutsemau
  2026-09-28  5:17 ` Xiaoyao Li
  0 siblings, 2 replies; 3+ messages in thread
From: Nikolay Borisov @ 2026-09-25 13:18 UTC (permalink / raw)
  To: kas, rick.p.edgecombe
  Cc: dave.hansen, xiaoyao.li, linux-coco, x86, Nikolay Borisov,
	Michal Koutný

There are few remaining attestation related functions which are exported
via EXPORT_SYMBOL_GPL, yet they are solely used by the 'tdx-guest'
driver. Let's just limit their visibility by using the namespaced
EXPORT_SYMBOL_FOR_MODULES.

Suggested-by: Michal Koutný <mkoutny@suse.com>
Signed-off-by: Nikolay Borisov <nik.borisov@suse.com>
---
 arch/x86/coco/tdx/tdx.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/arch/x86/coco/tdx/tdx.c b/arch/x86/coco/tdx/tdx.c
index f904a636d449..a38e44401840 100644
--- a/arch/x86/coco/tdx/tdx.c
+++ b/arch/x86/coco/tdx/tdx.c
@@ -139,7 +139,7 @@ int tdx_mcall_get_report0(u8 *reportdata, u8 *tdreport)
 
 	return 0;
 }
-EXPORT_SYMBOL_GPL(tdx_mcall_get_report0);
+EXPORT_SYMBOL_FOR_MODULES(tdx_mcall_get_report0, "tdx-guest");
 
 /**
  * tdx_mcall_extend_rtmr() - Wrapper to extend RTMR registers using
@@ -175,7 +175,7 @@ int tdx_mcall_extend_rtmr(u8 index, u8 *data)
 
 	return 0;
 }
-EXPORT_SYMBOL_GPL(tdx_mcall_extend_rtmr);
+EXPORT_SYMBOL_FOR_MODULES(tdx_mcall_extend_rtmr, "tdx-guest");
 
 /**
  * tdx_hcall_get_quote() - Wrapper to request TD Quote using GetQuote
@@ -196,7 +196,7 @@ u64 tdx_hcall_get_quote(u8 *buf, size_t size)
 	/* Since buf is a shared memory, set the shared (decrypted) bits */
 	return _tdx_hypercall(TDVMCALL_GET_QUOTE, cc_mkdec(virt_to_phys(buf)), size, 0, 0);
 }
-EXPORT_SYMBOL_GPL(tdx_hcall_get_quote);
+EXPORT_SYMBOL_FOR_MODULES(tdx_hcall_get_quote, "tdx-guest");
 
 static void __noreturn tdx_panic(const char *msg)
 {
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH v3] x86/tdx: Restrict attestation exports to the tdx-guest driver
  2026-09-25 13:18 [PATCH v3] x86/tdx: Restrict attestation exports to the tdx-guest driver Nikolay Borisov
@ 2026-09-25 13:34 ` Kiryl Shutsemau
  2026-09-28  5:17 ` Xiaoyao Li
  1 sibling, 0 replies; 3+ messages in thread
From: Kiryl Shutsemau @ 2026-09-25 13:34 UTC (permalink / raw)
  To: Nikolay Borisov
  Cc: rick.p.edgecombe, dave.hansen, xiaoyao.li, linux-coco, x86,
	Michal Koutný

On Fri, Sep 25, 2026 at 04:18:08PM +0300, Nikolay Borisov wrote:
> There are few remaining attestation related functions which are exported
> via EXPORT_SYMBOL_GPL, yet they are solely used by the 'tdx-guest'
> driver. Let's just limit their visibility by using the namespaced
> EXPORT_SYMBOL_FOR_MODULES.
> 
> Suggested-by: Michal Koutný <mkoutny@suse.com>
> Signed-off-by: Nikolay Borisov <nik.borisov@suse.com>

Reviewed-by: Kiryl Shutsemau (Meta) <kas@kernel.org>

-- 
  Kiryl Shutsemau / Kirill A. Shutemov

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH v3] x86/tdx: Restrict attestation exports to the tdx-guest driver
  2026-09-25 13:18 [PATCH v3] x86/tdx: Restrict attestation exports to the tdx-guest driver Nikolay Borisov
  2026-09-25 13:34 ` Kiryl Shutsemau
@ 2026-09-28  5:17 ` Xiaoyao Li
  1 sibling, 0 replies; 3+ messages in thread
From: Xiaoyao Li @ 2026-09-28  5:17 UTC (permalink / raw)
  To: Nikolay Borisov, kas, rick.p.edgecombe
  Cc: dave.hansen, linux-coco, x86, Michal Koutný

On 9/25/2026 9:18 PM, Nikolay Borisov wrote:
> There are few remaining attestation related functions which are exported
> via EXPORT_SYMBOL_GPL, yet they are solely used by the 'tdx-guest'
> driver. Let's just limit their visibility by using the namespaced
> EXPORT_SYMBOL_FOR_MODULES.

Nit: Drop "Let's just" for tip maintainers.

> Suggested-by: Michal Koutný <mkoutny@suse.com>
> Signed-off-by: Nikolay Borisov <nik.borisov@suse.com>

Reviewed-by: Xiaoyao Li <xiaoyao.li@intel.com>

> ---
>  arch/x86/coco/tdx/tdx.c | 6 +++---
>  1 file changed, 3 insertions(+), 3 deletions(-)
> 
> diff --git a/arch/x86/coco/tdx/tdx.c b/arch/x86/coco/tdx/tdx.c
> index f904a636d449..a38e44401840 100644
> --- a/arch/x86/coco/tdx/tdx.c
> +++ b/arch/x86/coco/tdx/tdx.c
> @@ -139,7 +139,7 @@ int tdx_mcall_get_report0(u8 *reportdata, u8 *tdreport)
>  
>  	return 0;
>  }
> -EXPORT_SYMBOL_GPL(tdx_mcall_get_report0);
> +EXPORT_SYMBOL_FOR_MODULES(tdx_mcall_get_report0, "tdx-guest");
>  
>  /**
>   * tdx_mcall_extend_rtmr() - Wrapper to extend RTMR registers using
> @@ -175,7 +175,7 @@ int tdx_mcall_extend_rtmr(u8 index, u8 *data)
>  
>  	return 0;
>  }
> -EXPORT_SYMBOL_GPL(tdx_mcall_extend_rtmr);
> +EXPORT_SYMBOL_FOR_MODULES(tdx_mcall_extend_rtmr, "tdx-guest");
>  
>  /**
>   * tdx_hcall_get_quote() - Wrapper to request TD Quote using GetQuote
> @@ -196,7 +196,7 @@ u64 tdx_hcall_get_quote(u8 *buf, size_t size)
>  	/* Since buf is a shared memory, set the shared (decrypted) bits */
>  	return _tdx_hypercall(TDVMCALL_GET_QUOTE, cc_mkdec(virt_to_phys(buf)), size, 0, 0);
>  }
> -EXPORT_SYMBOL_GPL(tdx_hcall_get_quote);
> +EXPORT_SYMBOL_FOR_MODULES(tdx_hcall_get_quote, "tdx-guest");
>  
>  static void __noreturn tdx_panic(const char *msg)
>  {


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-28  5:17 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-25 13:18 [PATCH v3] x86/tdx: Restrict attestation exports to the tdx-guest driver Nikolay Borisov
2026-09-25 13:34 ` Kiryl Shutsemau
2026-09-28  5:17 ` Xiaoyao Li

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox