From: Xiaoyao Li <xiaoyao.li@intel.com>
To: Xu Yilun <yilun.xu@linux.intel.com>,
x86@kernel.org, kvm@vger.kernel.org, linux-coco@lists.linux.dev,
linux-kernel@vger.kernel.org
Cc: djbw@kernel.org, kas@kernel.org, rick.p.edgecombe@intel.com,
yilun.xu@intel.com, sohil.mehta@intel.com,
adrian.hunter@intel.com, kishen.maloor@intel.com,
tony.lindgren@linux.intel.com, peter.fang@intel.com,
baolu.lu@linux.intel.com, zhenzhong.duan@intel.com,
dave.hansen@intel.com, dave.hansen@linux.intel.com,
seanjc@google.com
Subject: Re: [PATCH v2 02/17] x86/virt/tdx: Configure add-on features on TDX module init and update
Date: Fri, 24 Jul 2026 16:15:21 +0800 [thread overview]
Message-ID: <823bf577-51a1-4a8a-b240-ef4a0d5573be@intel.com> (raw)
In-Reply-To: <20260618081355.3253581-3-yilun.xu@linux.intel.com>
On 6/18/2026 4:13 PM, Xu Yilun wrote:
> In addition to basic TDX functionalities, TDX module provides add-on
> features that can be progressively enabled as the kernel supports them.
"add-on features" looks like a new term introduced by this sereis for
TDX. So what is add-on features? all the features defined in
TDX_FEATURE0/1? Or only the features needs to be explicitly enabled by
R9 and R10 of TDH.SYS.CONFIG? ...
> The kernel should explicitly configure these features at boot or
> post-update initialization time.
... So the answer is the latter. Then why only these bits are add-on
features while the rest in TDX_FEATURES01 are not?
btw, s/should/needs/ is better?
> Configuring an add-on feature, such as
> TDX Quoting, that uses extension SEAMCALLs is the prerequisite for
> initializing TDX module extensions.
Though the statement is right, it leads to the impression that the
reason we are configuring the add-on feature is to initialize the TDX
module extensions.
However, the truth is kenrel wants to enable/use an add-on feature and
the add-on feature requires the functionalities provided by some TDX
module extension. So kernel needs to enable the TDX module extensions.
> TDX Quoting is the target feature to
> enable but defer it for now until full kernel support is in place.
>
> TDX module extends TDH.SYS.CONFIG and TDH.SYS.UPDATE with new bitmap
> input parameters to specify which add-on features to configure. The
> bitmap uses the same definitions as TDX_FEATURES0.
>
> For runtime update, Linux applies a policy that no newer features should
> be added after update to avoid disrupting live TDX operations. To adhere
> to this, TDH.SYS.UPDATE must configure the same features as the
> TDH.SYS.CONFIG. Record the kernel required add-on feature bitmap in a
> global var so that both phases can use it.
>
> TDX module advances the version of TDH.SYS.CONFIG and TDH.SYS.UPDATE for
> the change, so use the latest version (v1) for add-on feature enabling.
> But supporting existing modules which only support v0 is still necessary
> until they are deprecated. In fact, it is unlikely that TDH.SYS.CONFIG
> ever needs to change again and the code would stay in v1. So there is
> little value in worrying about deprecating v0 to save a couple lines of
> code in 5-7 years when these original TDX platforms sunset.
>
> Signed-off-by: Xu Yilun <yilun.xu@linux.intel.com>
> ---
> arch/x86/virt/vmx/tdx/tdx.h | 6 ++++--
> arch/x86/virt/vmx/tdx/tdx.c | 28 ++++++++++++++++++++++++++--
> 2 files changed, 30 insertions(+), 4 deletions(-)
>
> diff --git a/arch/x86/virt/vmx/tdx/tdx.h b/arch/x86/virt/vmx/tdx/tdx.h
> index fbb520704662..a47e872480c7 100644
> --- a/arch/x86/virt/vmx/tdx/tdx.h
> +++ b/arch/x86/virt/vmx/tdx/tdx.h
> @@ -58,9 +58,11 @@
> #define TDH_PHYMEM_CACHE_WB 40
> #define TDH_PHYMEM_PAGE_WBINVD 41
> #define TDH_VP_WR 43
> -#define TDH_SYS_CONFIG 45
> +#define TDH_SYS_CONFIG_V0 45
> +#define TDH_SYS_CONFIG SEAMCALL_LEAF_VER(TDH_SYS_CONFIG_V0, 1)
> #define TDH_SYS_SHUTDOWN 52
> -#define TDH_SYS_UPDATE 53
> +#define TDH_SYS_UPDATE_V0 53
> +#define TDH_SYS_UPDATE SEAMCALL_LEAF_VER(TDH_SYS_UPDATE_V0, 1)
> #define TDH_SYS_DISABLE 69
>
> /* TDX page types */
> diff --git a/arch/x86/virt/vmx/tdx/tdx.c b/arch/x86/virt/vmx/tdx/tdx.c
> index 2a03152796e6..92305b5ea90d 100644
> --- a/arch/x86/virt/vmx/tdx/tdx.c
> +++ b/arch/x86/virt/vmx/tdx/tdx.c
> @@ -57,6 +57,7 @@ static struct tdx_module_state tdx_module_state;
> static u32 tdx_global_keyid __ro_after_init;
> static u32 tdx_guest_keyid_start __ro_after_init;
> static u32 tdx_nr_guest_keyids __ro_after_init;
> +static u64 tdx_addon_feature0 __ro_after_init;
>
> static DEFINE_IDA(tdx_guest_keyid_pool);
>
> @@ -1004,9 +1005,18 @@ static __init int construct_tdmrs(struct list_head *tmb_list,
> return ret;
> }
>
> +static __init void set_tdx_addon_features(void)
> +{
> + /*
> + * To add DICE-based TDX Quoting feature bit in tdx_addon_feature0 when
> + * kernel is ready.
> + */
> +}
> +
> static __init int config_tdx_module(struct tdmr_info_list *tdmr_list,
> u64 global_keyid)
> {
> + u64 seamcall_fn = TDH_SYS_CONFIG_V0;
> struct tdx_module_args args = {};
> u64 *tdmr_pa_array;
> size_t array_sz;
> @@ -1032,7 +1042,15 @@ static __init int config_tdx_module(struct tdmr_info_list *tdmr_list,
> args.rcx = __pa(tdmr_pa_array);
> args.rdx = tdmr_list->nr_consumed_tdmrs;
> args.r8 = global_keyid;
> - ret = seamcall_prerr(TDH_SYS_CONFIG, &args);
> +
> + set_tdx_addon_features();
Maybe move the set_tdx_addon_features() out of config_tdx_module()? how
about putting it after check_features(). config_tdx_module() looks like
just a wrapper to invoke TDH.SYS.CONFIG, while the params of it are
determined outside of it.
Just my feeling.
> +
> + if (tdx_addon_feature0) {
> + args.r9 = tdx_addon_feature0;
> + seamcall_fn = TDH_SYS_CONFIG;
> + }
> +
> + ret = seamcall_prerr(seamcall_fn, &args);
>
> /* Free the array as it is not required anymore. */
> kfree(tdmr_pa_array);
> @@ -1314,10 +1332,16 @@ int tdx_module_shutdown(void)
>
> int tdx_module_run_update(void)
> {
> + u64 seamcall_fn = TDH_SYS_UPDATE_V0;
> struct tdx_module_args args = {};
> int ret;
>
> - ret = seamcall_prerr(TDH_SYS_UPDATE, &args);
> + if (tdx_addon_feature0) {
> + args.r9 = tdx_addon_feature0;
> + seamcall_fn = TDH_SYS_UPDATE;
> + }
> +
> + ret = seamcall_prerr(seamcall_fn, &args);
> if (ret)
> return ret;
>
next prev parent reply other threads:[~2026-07-24 8:15 UTC|newest]
Thread overview: 76+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-18 8:13 [PATCH v2 00/17] Enable DICE-based TDX Quoting Extension Xu Yilun
2026-06-18 8:13 ` [PATCH v2 01/17] x86/virt/tdx: Embed version info in SEAMCALL leaf function definitions Xu Yilun
2026-06-18 14:45 ` Dave Hansen
2026-06-22 12:05 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 02/17] x86/virt/tdx: Configure add-on features on TDX module init and update Xu Yilun
2026-06-18 15:04 ` Dave Hansen
2026-06-22 13:15 ` Xu Yilun
2026-06-24 12:00 ` Xu Yilun
2026-06-24 22:10 ` Peter Fang
2026-06-25 6:33 ` Xu Yilun
2026-06-23 8:43 ` Chao Gao
2026-06-25 10:50 ` Xu Yilun
2026-07-24 8:15 ` Xiaoyao Li [this message]
2026-06-18 8:13 ` [PATCH v2 03/17] x86/virt/tdx: Detect if the extensions initialization is required Xu Yilun
2026-06-25 5:19 ` Tony Lindgren
2026-06-25 10:57 ` Xu Yilun
2026-06-29 6:33 ` Chao Gao
2026-06-30 11:10 ` Xu Yilun
2026-07-24 8:44 ` Xiaoyao Li
2026-07-24 8:42 ` Xiaoyao Li
2026-06-18 8:13 ` [PATCH v2 04/17] x86/virt/tdx: Add extra memory to TDX module for the extensions Xu Yilun
2026-06-29 7:56 ` Chao Gao
2026-06-30 10:27 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 05/17] x86/virt/tdx: Make TDX module initialize " Xu Yilun
2026-06-18 8:13 ` [PATCH v2 06/17] x86/virt/tdx: Re-initialize the extensions on runtime TDX module update Xu Yilun
2026-06-29 8:12 ` Chao Gao
2026-06-30 11:14 ` Xu Yilun
2026-06-18 8:13 ` [PATCH v2 07/17] x86/virt/tdx: Initialize Quoting extension Xu Yilun
2026-06-29 8:33 ` Chao Gao
2026-06-30 5:20 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 08/17] x86/virt/tdx: Prepare Quote buffer during extension bringup Xu Yilun
2026-06-25 6:08 ` Tony Lindgren
2026-06-30 4:12 ` Peter Fang
2026-07-01 19:56 ` Dave Hansen
2026-07-08 9:25 ` Peter Fang
2026-07-08 7:52 ` Nikolay Borisov
2026-07-13 10:19 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 09/17] x86/virt/tdx: Add interface to check Quoting availability Xu Yilun
2026-06-25 6:09 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 10/17] x86/virt/tdx: Move tdx_tdr_pa() up in the file Xu Yilun
2026-06-25 6:10 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 11/17] x86/virt/tdx: Add interface to generate a Quote Xu Yilun
2026-06-25 6:05 ` Tony Lindgren
2026-06-30 4:22 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 12/17] x86/virt/tdx: Reinitialize the Quoting extension after TDX module update Xu Yilun
2026-06-25 6:12 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 13/17] x86/virt/tdx: Enable Quoting extension Xu Yilun
2026-06-25 6:13 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 14/17] x86/tdx: Move and rename Quote request structure Xu Yilun
2026-06-25 6:15 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 15/17] KVM: TDX: Factor out userspace return path from tdx_get_quote() Xu Yilun
2026-06-25 6:16 ` Tony Lindgren
2026-06-18 8:13 ` [PATCH v2 16/17] KVM: TDX: Add in-kernel Quote generation Xu Yilun
2026-06-25 18:01 ` Sean Christopherson
2026-06-29 10:03 ` Peter Fang
2026-06-30 0:42 ` Sean Christopherson
2026-06-30 23:33 ` Edgecombe, Rick P
2026-07-01 0:24 ` Dan Williams (nvidia)
2026-07-01 17:25 ` Sean Christopherson
2026-07-01 18:45 ` Edgecombe, Rick P
2026-07-04 5:43 ` Peter Fang
2026-07-06 17:57 ` Sean Christopherson
2026-07-08 20:47 ` Dave Hansen
2026-07-08 21:16 ` Sean Christopherson
2026-07-08 22:09 ` Peter Fang
2026-07-08 22:28 ` Sean Christopherson
2026-07-08 23:38 ` Edgecombe, Rick P
2026-07-10 9:01 ` Nikolay Borisov
2026-07-10 9:38 ` Peter Fang
2026-07-08 21:37 ` Sean Christopherson
2026-07-10 12:52 ` Peter Fang
2026-07-10 14:48 ` Sean Christopherson
2026-07-10 22:59 ` Peter Fang
2026-06-18 8:13 ` [PATCH v2 17/17] KVM: TDX: Support event-notify interrupts only with userspace Quoting Xu Yilun
2026-06-25 6:28 ` Tony Lindgren
2026-06-30 6:36 ` Peter Fang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=823bf577-51a1-4a8a-b240-ef4a0d5573be@intel.com \
--to=xiaoyao.li@intel.com \
--cc=adrian.hunter@intel.com \
--cc=baolu.lu@linux.intel.com \
--cc=dave.hansen@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=djbw@kernel.org \
--cc=kas@kernel.org \
--cc=kishen.maloor@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=peter.fang@intel.com \
--cc=rick.p.edgecombe@intel.com \
--cc=seanjc@google.com \
--cc=sohil.mehta@intel.com \
--cc=tony.lindgren@linux.intel.com \
--cc=x86@kernel.org \
--cc=yilun.xu@intel.com \
--cc=yilun.xu@linux.intel.com \
--cc=zhenzhong.duan@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox