* [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
@ 2026-07-29 12:29 Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
` (4 more replies)
0 siblings, 5 replies; 13+ messages in thread
From: Peter Fang @ 2026-07-29 12:29 UTC (permalink / raw)
To: Dave Hansen, Kiryl Shutsemau, Rick Edgecombe,
Kuppuswamy Sathyanarayanan
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu, Peter Fang
Hi,
A new TDX module ABI provides the maximum attestation report size. This
series changes the TDX guest driver's report buffer size from a fixed
constant to that queried value. So effectively:
s/FIXED_BUF_SIZE/queried_buf_size/g
...in the TDX guest driver.
Terminology
===========
A "TD Quote" is an attestation structure signed with a platform key. It
contains information about a TDX guest and the platform it's running on.
The "Quote buffer" in the TDX guest driver is a memory buffer shared
between the TDX guest and the host VMM to retrieve TD Quotes. It has a
header defined in the GHCI spec [1].
Device Identifier Composition Engine ("DICE") provides a framework for
layering attestation evidence. This replaces the SGX model of contacting
an Intel server to obtain a certificate.
Problem
=======
The fixed-size Quote buffer approach is not sustainable. As
cryptographic algorithms evolve, TD Quote sizes also grow. A previous
commit [2] increased the guest driver's fixed-size Quote buffer to 128
KB to accommodate DICE Quotes, but it may still be insufficient when
those Quotes use post-quantum cryptography (PQC). PQC certificate chains
are roughly 10x-15x larger than conventional ones, which can increase
Quote sizes significantly.
What's in this series
=====================
To avoid changing the driver whenever the Quote buffer becomes too
small, newer TDX modules report their maximum Quote size via a metadata
field. The guest driver uses this value for its Quote buffer when
available. Older TDX modules continue to use the 128 KB buffer.
Patches 2 and 3 refactor the existing fixed buffer handling. Patch 4
then makes the buffer size dynamic.
The "outblob" file in configfs-tsm no longer has a fixed maximum size.
The limit can now come from this new TDX module ABI.
Patch 1/4: Add a helper to read the QUOTE_MAX_SIZE metadata field.
Patch 2/4: Calculate the Quote buffer size with struct_size_t().
Patch 3/4: Store the Quote buffer size in a variable instead of a
constant.
Patch 4/4: Allocate the Quote buffer using the queried size, when
available.
AI use
======
I used Claude:claude-opus-4-8 to help edit this cover letter and the
changelogs, and to collect the review feedback on lore. The series also
underwent AI code review (Claude:claude-opus-4-7), but its comments were
limited to style suggestions.
v2: https://lore.kernel.org/all/20260717214349.4075994-1-peter.fang@intel.com/
Changes in v3:
- Split the v2 "Allocate Quote buffer dynamically" patch to do the
refactoring first, then make the buffer size dynamic. [Dave]
- Improve patterns for readability. [Dave]
- Drop __GFP_NOWARN so an allocation failure warns. [Dave, Rick, Kiryl]
- Add Binbin's Reviewed-by to patch 1.
- Drop the Reviewed-by tags (Kiryl, Binbin) as the patch was reworked.
v1: https://lore.kernel.org/all/20260612110853.3188196-1-peter.fang@intel.com/
Changes in v2:
- Collect Reviewed-by tags. [Kiryl, Xiaoyao, Binbin, Sathya]
- Keep the explicit (u32) cast in tdx_get_max_quote_size(). [Binbin]
- Calculate the Quote buffer size with struct_size_t(). [Kiryl, Binbin]
- Add __GFP_NOWARN to the allocation since its size comes from the
host. [sashiko]
- Rename quote_data_size to quote_data_len. [Sathya]
- Drop the Assisted-by tags, as AI was not used to write the code.
[1] Guest Hypervisor Communication Interface (GHCI) Specification,
Version 1.5, Section "TDG.VP.VMCALL<GetQuote>"
[2] 43185067c6fd ("configfs-tsm-report: tdx_guest: Increase Quote buffer
size to 128KB")
Kuppuswamy Sathyanarayanan (1):
virt: tdx-guest: Allocate Quote buffer dynamically
Peter Fang (3):
x86/tdx: Add helper to query maximum TD Quote size
virt: tdx-guest: Calculate the Quote buffer size safely
virt: tdx-guest: Use a variable to store the Quote buffer size
arch/x86/coco/tdx/tdx.c | 19 ++++++++++
arch/x86/include/asm/shared/tdx.h | 1 +
arch/x86/include/asm/tdx.h | 2 ++
drivers/virt/coco/tdx-guest/tdx-guest.c | 46 ++++++++++++++++++-------
4 files changed, 55 insertions(+), 13 deletions(-)
base-commit: f5098b6bae761e346ebcd9da7f95622c04733cff
--
2.53.0
^ permalink raw reply [flat|nested] 13+ messages in thread
* [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
@ 2026-07-29 12:29 ` Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
` (3 subsequent siblings)
4 siblings, 0 replies; 13+ messages in thread
From: Peter Fang @ 2026-07-29 12:29 UTC (permalink / raw)
To: Dave Hansen, Kiryl Shutsemau, Rick Edgecombe,
Kuppuswamy Sathyanarayanan
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu, Peter Fang
TDX attestation report ("Quote") sizes can grow with newer cryptographic
schemes, so guests can no longer rely on a fixed-size buffer for the
Quote.
Newer TDX modules report the maximum Quote size via a TD-scope metadata
field. Add a helper to query the size instead of exposing tdg_vm_rd()
directly, as it can read arbitrary metadata fields.
Thanks to Xu Yilun for suggesting this in an off-list discussion.
Reviewed-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
Reviewed-by: Xiaoyao Li <xiaoyao.li@intel.com>
Reviewed-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
Signed-off-by: Peter Fang <peter.fang@intel.com>
---
v3:
- No code changes. Add Binbin's Reviewed-by.
v2:
- Keep the explicit (u32) cast to document the metadata field width.
[Binbin]
- Note that Xu Yilun's suggestion was made in an off-list discussion.
[Sathya]
- Drop the Assisted-by tags, as the code was not written by AI.
---
arch/x86/coco/tdx/tdx.c | 19 +++++++++++++++++++
arch/x86/include/asm/shared/tdx.h | 1 +
arch/x86/include/asm/tdx.h | 2 ++
3 files changed, 22 insertions(+)
diff --git a/arch/x86/coco/tdx/tdx.c b/arch/x86/coco/tdx/tdx.c
index 29b6f1ed59ec..fa2ed012e736 100644
--- a/arch/x86/coco/tdx/tdx.c
+++ b/arch/x86/coco/tdx/tdx.c
@@ -198,6 +198,25 @@ u64 tdx_hcall_get_quote(u8 *buf, size_t size)
}
EXPORT_SYMBOL_GPL(tdx_hcall_get_quote);
+/**
+ * tdx_get_max_quote_size() - Get the maximum TD Quote size
+ *
+ * Read the maximum size of a TD Quote from a 4-byte TD metadata field. The TDX
+ * guest driver uses it to size the buffer for Quote retrieval. Older TDX
+ * modules do not support this field and return an error.
+ *
+ * Return: Maximum Quote size in bytes on success, or 0 on failure.
+ */
+u32 tdx_get_max_quote_size(void)
+{
+ u64 val, ret;
+
+ ret = tdg_vm_rd(TDCS_QUOTE_MAX_SIZE, &val);
+
+ return ret ? 0 : (u32)val;
+}
+EXPORT_SYMBOL_GPL(tdx_get_max_quote_size);
+
static void __noreturn tdx_panic(const char *msg)
{
struct tdx_module_args args = {
diff --git a/arch/x86/include/asm/shared/tdx.h b/arch/x86/include/asm/shared/tdx.h
index f20e91d7ac35..a58751321613 100644
--- a/arch/x86/include/asm/shared/tdx.h
+++ b/arch/x86/include/asm/shared/tdx.h
@@ -50,6 +50,7 @@
/* TDX TD-Scope Metadata. To be used by TDG.VM.WR and TDG.VM.RD */
#define TDCS_CONFIG_FLAGS 0x1110000300000016
#define TDCS_TD_CTLS 0x1110000300000017
+#define TDCS_QUOTE_MAX_SIZE 0x9010000200000008
#define TDCS_NOTIFY_ENABLES 0x9100000000000010
#define TDCS_TOPOLOGY_ENUM_CONFIGURED 0x9100000000000019
diff --git a/arch/x86/include/asm/tdx.h b/arch/x86/include/asm/tdx.h
index 89e97d5761d8..a75dbbe004bd 100644
--- a/arch/x86/include/asm/tdx.h
+++ b/arch/x86/include/asm/tdx.h
@@ -83,6 +83,8 @@ int tdx_mcall_extend_rtmr(u8 index, u8 *data);
u64 tdx_hcall_get_quote(u8 *buf, size_t size);
+u32 tdx_get_max_quote_size(void);
+
void __init tdx_dump_attributes(u64 td_attr);
void __init tdx_dump_td_ctls(u64 td_ctls);
--
2.53.0
^ permalink raw reply related [flat|nested] 13+ messages in thread
* [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
@ 2026-07-29 12:29 ` Peter Fang
2026-07-29 18:29 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
` (2 subsequent siblings)
4 siblings, 1 reply; 13+ messages in thread
From: Peter Fang @ 2026-07-29 12:29 UTC (permalink / raw)
To: Dave Hansen, Kiryl Shutsemau, Rick Edgecombe,
Kuppuswamy Sathyanarayanan
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu, Peter Fang
struct tdx_quote_buf has a trailing flexible array member.
struct_size_t() calculates the size of this kind of struct safely. It
handles overflow, which is an important property since the Quote size
comes from the host.
Use it in place of the fixed length limit.
Signed-off-by: Peter Fang <peter.fang@intel.com>
---
v3:
- Split out the use of struct_size_t() for buffer length from the v2
"Allocate Quote buffer dynamically" patch to refactor first. [Dave]
- Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
reworked.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index d0303e31e816..f47c5429d002 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -170,7 +170,7 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
#define GET_QUOTE_SUCCESS 0
#define GET_QUOTE_IN_FLIGHT 0xffffffffffffffff
-#define TDX_QUOTE_MAX_LEN (GET_QUOTE_BUF_SIZE - sizeof(struct tdx_quote_buf))
+#define TDX_QUOTE_BUF_LEN(n) struct_size_t(struct tdx_quote_buf, data, n)
/* struct tdx_quote_buf: Format of Quote request buffer.
* @version: Quote format version, filled by TD.
@@ -315,7 +315,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
out_len = READ_ONCE(quote_buf->out_len);
- if (out_len > TDX_QUOTE_MAX_LEN)
+ if (TDX_QUOTE_BUF_LEN(out_len) > GET_QUOTE_BUF_SIZE)
return -EFBIG;
buf = kvmemdup(quote_buf->data, out_len, GFP_KERNEL);
--
2.53.0
^ permalink raw reply related [flat|nested] 13+ messages in thread
* [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
@ 2026-07-29 12:29 ` Peter Fang
2026-07-29 18:47 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
2026-07-29 21:21 ` [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Edgecombe, Rick P
4 siblings, 1 reply; 13+ messages in thread
From: Peter Fang @ 2026-07-29 12:29 UTC (permalink / raw)
To: Dave Hansen, Kiryl Shutsemau, Rick Edgecombe,
Kuppuswamy Sathyanarayanan
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu, Peter Fang
In preparation for dynamic Quote buffer sizes, replace the fixed size
constant with a variable.
The size is currently a constant sprinkled across several places. Store
it in a variable and have all the users read it from there.
Signed-off-by: Peter Fang <peter.fang@intel.com>
---
v3:
- Split out using a variable for the buffer size from the v2 "Allocate
Quote buffer dynamically" patch to refactor first. [Dave]
- Pass the buffer size into alloc_quote_buf() by value. [Dave]
- Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
reworked.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 22 +++++++++++-----------
1 file changed, 11 insertions(+), 11 deletions(-)
diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index f47c5429d002..3d3f79ab45af 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -191,8 +191,9 @@ struct tdx_quote_buf {
u8 data[];
};
-/* Quote data buffer */
+/* Quote data buffer and length */
static void *quote_data;
+static size_t quote_data_len;
/* Lock to streamline quote requests */
static DEFINE_MUTEX(quote_lock);
@@ -209,9 +210,8 @@ static long tdx_get_report0(struct tdx_report_req __user *req)
USER_SOCKPTR(req->tdreport));
}
-static void free_quote_buf(void *buf)
+static void free_quote_buf(void *buf, size_t len)
{
- size_t len = PAGE_ALIGN(GET_QUOTE_BUF_SIZE);
unsigned int count = len >> PAGE_SHIFT;
if (set_memory_encrypted((unsigned long)buf, count)) {
@@ -222,9 +222,8 @@ static void free_quote_buf(void *buf)
free_pages_exact(buf, len);
}
-static void *alloc_quote_buf(void)
+static void *alloc_quote_buf(size_t len)
{
- size_t len = PAGE_ALIGN(GET_QUOTE_BUF_SIZE);
unsigned int count = len >> PAGE_SHIFT;
void *addr;
@@ -285,7 +284,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
if (desc->inblob_len != TDX_REPORTDATA_LEN)
return -EINVAL;
- memset(quote_data, 0, GET_QUOTE_BUF_SIZE);
+ memset(quote_data, 0, quote_data_len);
/* Update Quote buffer header */
quote_buf->version = GET_QUOTE_CMD_VER;
@@ -296,7 +295,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
if (ret)
return ret;
- err = tdx_hcall_get_quote(quote_data, GET_QUOTE_BUF_SIZE);
+ err = tdx_hcall_get_quote(quote_data, quote_data_len);
if (err) {
pr_err("GetQuote hypercall failed, status:%llx\n", err);
return -EIO;
@@ -315,7 +314,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
out_len = READ_ONCE(quote_buf->out_len);
- if (TDX_QUOTE_BUF_LEN(out_len) > GET_QUOTE_BUF_SIZE)
+ if (TDX_QUOTE_BUF_LEN(out_len) > quote_data_len)
return -EFBIG;
buf = kvmemdup(quote_buf->data, out_len, GFP_KERNEL);
@@ -417,7 +416,8 @@ static int __init tdx_guest_init(void)
if (ret)
goto deinit_mr;
- quote_data = alloc_quote_buf();
+ quote_data_len = GET_QUOTE_BUF_SIZE;
+ quote_data = alloc_quote_buf(quote_data_len);
if (!quote_data) {
pr_err("Failed to allocate Quote buffer\n");
ret = -ENOMEM;
@@ -431,7 +431,7 @@ static int __init tdx_guest_init(void)
return 0;
free_quote:
- free_quote_buf(quote_data);
+ free_quote_buf(quote_data, quote_data_len);
free_misc:
misc_deregister(&tdx_misc_dev);
deinit_mr:
@@ -444,7 +444,7 @@ module_init(tdx_guest_init);
static void __exit tdx_guest_exit(void)
{
tsm_report_unregister(&tdx_tsm_ops);
- free_quote_buf(quote_data);
+ free_quote_buf(quote_data, quote_data_len);
misc_deregister(&tdx_misc_dev);
tdx_mr_deinit(tdx_attr_groups[0]);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 13+ messages in thread
* [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
` (2 preceding siblings ...)
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
@ 2026-07-29 12:29 ` Peter Fang
2026-07-29 21:21 ` [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Edgecombe, Rick P
4 siblings, 0 replies; 13+ messages in thread
From: Peter Fang @ 2026-07-29 12:29 UTC (permalink / raw)
To: Dave Hansen, Kiryl Shutsemau, Rick Edgecombe,
Kuppuswamy Sathyanarayanan
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu, Peter Fang
From: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
A new TDX module ABI reports the TD Quote size limit in a metadata
field. This size used to be fixed at 128 KB.
The guest driver's Quote buffer is shared with the host VMM. The current
fixed size may be too small for Quotes using schemes such as
post-quantum cryptography (PQC), where larger certificate chains can
increase the Quote size significantly.
Allocate the Quote buffer based on the reported limit. This avoids
wasting memory on platforms that do not require larger Quotes. Older
platforms fall back to the default 128 KB buffer.
As a result, the maximum size of the "outblob" file in configfs-tsm now
depends on the TDX module.
Because the Quote buffer must be physically contiguous, its size is
bound by the buddy allocator's maximum page order (4 MB), which should
be sufficient for current attestation needs.
Signed-off-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
Signed-off-by: Peter Fang <peter.fang@intel.com>
---
v3:
- Split out from the v2 "Allocate Quote buffer dynamically" patch. Add
the dynamic buffer feature on top of the refactoring. [Dave]
- Improve the get_quote_buf_size() pattern for better readability.
[Dave]
- Drop __GFP_NOWARN so an allocation failure warns. [Dave, Rick, Kiryl]
- Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
reworked.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 24 ++++++++++++++++++++++--
1 file changed, 22 insertions(+), 2 deletions(-)
diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index 3d3f79ab45af..8919b1a1154e 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -162,7 +162,7 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
* DICE-based attestation uses layered evidence that requires
* larger Quote size (~100K).
*/
-#define GET_QUOTE_BUF_SIZE SZ_128K
+#define GET_QUOTE_DEFAULT_BUF_SIZE SZ_128K
#define GET_QUOTE_CMD_VER 1
@@ -222,11 +222,31 @@ static void free_quote_buf(void *buf, size_t len)
free_pages_exact(buf, len);
}
+/* Return a buffer size large enough to hold a Quote */
+static size_t get_quote_buf_size(void)
+{
+ u32 quote_size = tdx_get_max_quote_size();
+
+ /*
+ * Older TDX modules do not report a maximum Quote size, so use
+ * the default.
+ */
+ if (!quote_size)
+ return GET_QUOTE_DEFAULT_BUF_SIZE;
+
+ /* The reported size does not include the buffer header */
+ return PAGE_ALIGN(TDX_QUOTE_BUF_LEN(quote_size));
+}
+
static void *alloc_quote_buf(size_t len)
{
unsigned int count = len >> PAGE_SHIFT;
void *addr;
+ /*
+ * This fails if the requested size exceeds the buddy allocator's
+ * maximum order (order-10, 4MB).
+ */
addr = alloc_pages_exact(len, GFP_KERNEL | __GFP_ZERO);
if (!addr)
return NULL;
@@ -416,7 +436,7 @@ static int __init tdx_guest_init(void)
if (ret)
goto deinit_mr;
- quote_data_len = GET_QUOTE_BUF_SIZE;
+ quote_data_len = get_quote_buf_size();
quote_data = alloc_quote_buf(quote_data_len);
if (!quote_data) {
pr_err("Failed to allocate Quote buffer\n");
--
2.53.0
^ permalink raw reply related [flat|nested] 13+ messages in thread
* Re: [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
@ 2026-07-29 18:29 ` Kuppuswamy Sathyanarayanan
0 siblings, 0 replies; 13+ messages in thread
From: Kuppuswamy Sathyanarayanan @ 2026-07-29 18:29 UTC (permalink / raw)
To: Peter Fang, Dave Hansen, Kiryl Shutsemau, Rick Edgecombe
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu
Hi,
On 7/29/2026 5:29 AM, Peter Fang wrote:
> struct tdx_quote_buf has a trailing flexible array member.
> struct_size_t() calculates the size of this kind of struct safely. It
> handles overflow, which is an important property since the Quote size
> comes from the host.
>
> Use it in place of the fixed length limit.
>
> Signed-off-by: Peter Fang <peter.fang@intel.com>
> ---
> v3:
> - Split out the use of struct_size_t() for buffer length from the v2
> "Allocate Quote buffer dynamically" patch to refactor first. [Dave]
> - Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
> reworked.
> ---
Reviewed-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
> drivers/virt/coco/tdx-guest/tdx-guest.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
> index d0303e31e816..f47c5429d002 100644
> --- a/drivers/virt/coco/tdx-guest/tdx-guest.c
> +++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
> @@ -170,7 +170,7 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
> #define GET_QUOTE_SUCCESS 0
> #define GET_QUOTE_IN_FLIGHT 0xffffffffffffffff
>
> -#define TDX_QUOTE_MAX_LEN (GET_QUOTE_BUF_SIZE - sizeof(struct tdx_quote_buf))
> +#define TDX_QUOTE_BUF_LEN(n) struct_size_t(struct tdx_quote_buf, data, n)
>
> /* struct tdx_quote_buf: Format of Quote request buffer.
> * @version: Quote format version, filled by TD.
> @@ -315,7 +315,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
>
> out_len = READ_ONCE(quote_buf->out_len);
>
> - if (out_len > TDX_QUOTE_MAX_LEN)
> + if (TDX_QUOTE_BUF_LEN(out_len) > GET_QUOTE_BUF_SIZE)
> return -EFBIG;
>
> buf = kvmemdup(quote_buf->data, out_len, GFP_KERNEL);
--
Sathyanarayanan Kuppuswamy
Linux Kernel Developer
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
@ 2026-07-29 18:47 ` Kuppuswamy Sathyanarayanan
0 siblings, 0 replies; 13+ messages in thread
From: Kuppuswamy Sathyanarayanan @ 2026-07-29 18:47 UTC (permalink / raw)
To: Peter Fang, Dave Hansen, Kiryl Shutsemau, Rick Edgecombe
Cc: Thomas Gleixner, Ingo Molnar, Borislav Petkov, x86,
H. Peter Anvin, linux-kernel, linux-coco, kvm, Xiaoyao Li,
Binbin Wu
On 7/29/2026 5:29 AM, Peter Fang wrote:
> In preparation for dynamic Quote buffer sizes, replace the fixed size
sizes -> size?
> constant with a variable.
>
> The size is currently a constant sprinkled across several places. Store
> it in a variable and have all the users read it from there.
You are also dropping PAGE_ALIGN() in alloc and free calls. You can
mention it in commit log.
>
> Signed-off-by: Peter Fang <peter.fang@intel.com>
> ---
Reviewed-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
> v3:
> - Split out using a variable for the buffer size from the v2 "Allocate
> Quote buffer dynamically" patch to refactor first. [Dave]
> - Pass the buffer size into alloc_quote_buf() by value. [Dave]
> - Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
> reworked.
> ---
> drivers/virt/coco/tdx-guest/tdx-guest.c | 22 +++++++++++-----------
> 1 file changed, 11 insertions(+), 11 deletions(-)
>
> diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
> index f47c5429d002..3d3f79ab45af 100644
> --- a/drivers/virt/coco/tdx-guest/tdx-guest.c
> +++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
> @@ -191,8 +191,9 @@ struct tdx_quote_buf {
> u8 data[];
> };
>
> -/* Quote data buffer */
> +/* Quote data buffer and length */
> static void *quote_data;
> +static size_t quote_data_len;
>
> /* Lock to streamline quote requests */
> static DEFINE_MUTEX(quote_lock);
> @@ -209,9 +210,8 @@ static long tdx_get_report0(struct tdx_report_req __user *req)
> USER_SOCKPTR(req->tdreport));
> }
>
> -static void free_quote_buf(void *buf)
> +static void free_quote_buf(void *buf, size_t len)
> {
> - size_t len = PAGE_ALIGN(GET_QUOTE_BUF_SIZE);
> unsigned int count = len >> PAGE_SHIFT;
>
> if (set_memory_encrypted((unsigned long)buf, count)) {
> @@ -222,9 +222,8 @@ static void free_quote_buf(void *buf)
> free_pages_exact(buf, len);
> }
>
> -static void *alloc_quote_buf(void)
> +static void *alloc_quote_buf(size_t len)
> {
> - size_t len = PAGE_ALIGN(GET_QUOTE_BUF_SIZE);
> unsigned int count = len >> PAGE_SHIFT;
> void *addr;
>
> @@ -285,7 +284,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
> if (desc->inblob_len != TDX_REPORTDATA_LEN)
> return -EINVAL;
>
> - memset(quote_data, 0, GET_QUOTE_BUF_SIZE);
> + memset(quote_data, 0, quote_data_len);
>
> /* Update Quote buffer header */
> quote_buf->version = GET_QUOTE_CMD_VER;
> @@ -296,7 +295,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
> if (ret)
> return ret;
>
> - err = tdx_hcall_get_quote(quote_data, GET_QUOTE_BUF_SIZE);
> + err = tdx_hcall_get_quote(quote_data, quote_data_len);
> if (err) {
> pr_err("GetQuote hypercall failed, status:%llx\n", err);
> return -EIO;
> @@ -315,7 +314,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
>
> out_len = READ_ONCE(quote_buf->out_len);
>
> - if (TDX_QUOTE_BUF_LEN(out_len) > GET_QUOTE_BUF_SIZE)
> + if (TDX_QUOTE_BUF_LEN(out_len) > quote_data_len)
> return -EFBIG;
>
> buf = kvmemdup(quote_buf->data, out_len, GFP_KERNEL);
> @@ -417,7 +416,8 @@ static int __init tdx_guest_init(void)
> if (ret)
> goto deinit_mr;
>
> - quote_data = alloc_quote_buf();
> + quote_data_len = GET_QUOTE_BUF_SIZE;
> + quote_data = alloc_quote_buf(quote_data_len);
> if (!quote_data) {
> pr_err("Failed to allocate Quote buffer\n");
> ret = -ENOMEM;
> @@ -431,7 +431,7 @@ static int __init tdx_guest_init(void)
> return 0;
>
> free_quote:
> - free_quote_buf(quote_data);
> + free_quote_buf(quote_data, quote_data_len);
> free_misc:
> misc_deregister(&tdx_misc_dev);
> deinit_mr:
> @@ -444,7 +444,7 @@ module_init(tdx_guest_init);
> static void __exit tdx_guest_exit(void)
> {
> tsm_report_unregister(&tdx_tsm_ops);
> - free_quote_buf(quote_data);
> + free_quote_buf(quote_data, quote_data_len);
> misc_deregister(&tdx_misc_dev);
> tdx_mr_deinit(tdx_attr_groups[0]);
> }
--
Sathyanarayanan Kuppuswamy
Linux Kernel Developer
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
` (3 preceding siblings ...)
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
@ 2026-07-29 21:21 ` Edgecombe, Rick P
2026-08-11 22:40 ` Edgecombe, Rick P
4 siblings, 1 reply; 13+ messages in thread
From: Edgecombe, Rick P @ 2026-07-29 21:21 UTC (permalink / raw)
To: sathyanarayanan.kuppuswamy@linux.intel.com, kas@kernel.org,
Fang, Peter, dave.hansen@linux.intel.com
Cc: bp@alien8.de, x86@kernel.org, binbin.wu@linux.intel.com,
hpa@zytor.com, mingo@redhat.com, linux-kernel@vger.kernel.org,
Li, Xiaoyao, tglx@kernel.org, kvm@vger.kernel.org,
linux-coco@lists.linux.dev
On Wed, 2026-07-29 at 05:29 -0700, Peter Fang wrote:
> Problem
> =======
>
> The fixed-size Quote buffer approach is not sustainable. As
> cryptographic algorithms evolve, TD Quote sizes also grow. A previous
> commit [2] increased the guest driver's fixed-size Quote buffer to 128
> KB to accommodate DICE Quotes, but it may still be insufficient when
> those Quotes use post-quantum cryptography (PQC). PQC certificate chains
> are roughly 10x-15x larger than conventional ones, which can increase
> Quote sizes significantly.
For the DICE host changes, the reason given for why the host side quote
operation is TD scoped was to avoid changing the guest by increasing the report
size. But actually, as this coverletter points out, the guest buffer sizes do
get changed. So I think we should pause this series until we sort out the
inconsistencies in the reasoning. Depending, we may want to circle back with KVM
folks on what the options actually are for the DICE quote operation.
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
2026-07-29 21:21 ` [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Edgecombe, Rick P
@ 2026-08-11 22:40 ` Edgecombe, Rick P
2026-08-12 14:08 ` Sean Christopherson
0 siblings, 1 reply; 13+ messages in thread
From: Edgecombe, Rick P @ 2026-08-11 22:40 UTC (permalink / raw)
To: sathyanarayanan.kuppuswamy@linux.intel.com, kas@kernel.org,
seanjc@google.com, Fang, Peter, dave.hansen@linux.intel.com,
Bityutskiy, Artem
Cc: bp@alien8.de, x86@kernel.org, binbin.wu@linux.intel.com,
hpa@zytor.com, mingo@redhat.com, linux-kernel@vger.kernel.org,
Li, Xiaoyao, tglx@kernel.org, kvm@vger.kernel.org,
linux-coco@lists.linux.dev
Sean, Dave, Kiryl,
In PUCK we talked about how the TD scoped quote operation avoids changes
in the guest. But this series is actually changing the guest, so is
somewhat at odds to that assertion. It turns out there are some tradeoffs
here that also connect to TDX migration uAPI. Please see below for an
explanation and recommended course of action.
As a gentle recall helper... The general attestation flow converts a
report to a quote, which then gets checked by a verifier. The report is
like a snapshot of the guest and its environment. The quote is a signed
version of the report plus hardware certs. It's signed with a hardware key
and can use different kinds of crypto.
These pieces are evolving to handle a few problems at once:
- The stuff that needs to be attested is growing. Basically more platform
details and devices are getting added to the blobs.
- The crypto stuff is growing. The post quantum crypto stuff is large,
etc. That stuff lives in the quote.
- Migration wants a quote that is platform specific and not TD specific.
Because the platform details are growing, they need to either go into a
larger report or added later via a TD scoped quote. But the post quantum
crypto stuff is going to bloat the quote either way.
If the report grows to include all the TD specific details, then the QUOTE
seamcall can be platform scoped because all the details that it needs are
passed in as args.
But if it is TD scoped, the report can stay the same size and the extra
details can just be added during the quote operation. For migration, it
only needs a platform scoped quote. If there are extra details about a
specific TD, the migration stuff can be fine to just ignore them. (i.e. it
can get what it needs from TD scoped quotes or platform scoped quotes).
The current QUOTE seamcall supports both: platform scoped and TD scoped
operations. But since we could get by with either only a platform or TD
scoped seamcall for both operations, we could reduce the kernel's uAPIs,
or change the API's location. Per recent discussion, Sean sees TD scoped
APIs living in KVM and platform scoped things living in the host
driver/tip. So all that leaves us with something like this:
|Normal quote |Migration quote |Report size|Quote size|uAPI location |
-|----------------|----------------|-----------|----------|---------------|
1|Platform scoped |Platform scoped |Grows |Grows |TDX host driver|
2|TD scoped |TD scoped |Fixed |Grows |KVM |
3|TD scoped |Platform scoped |Fixed |Grows |Both |
I'm thinking we should proceed with 2 because only the quote size changes.
So less guest changes over time. 3 is not really a disaster either, but we
shouldn't need 2 uABIs. For 1, from early discussion it seems it can be
made to work but sounds like it will require some more extensive changes
to the TDX attestation stuff. So probably needs a bit more investigation
before we can say it won't disturb some other VMM vendor, etc.
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
2026-08-11 22:40 ` Edgecombe, Rick P
@ 2026-08-12 14:08 ` Sean Christopherson
2026-08-12 16:02 ` Edgecombe, Rick P
0 siblings, 1 reply; 13+ messages in thread
From: Sean Christopherson @ 2026-08-12 14:08 UTC (permalink / raw)
To: Rick P Edgecombe
Cc: sathyanarayanan.kuppuswamy@linux.intel.com, kas@kernel.org,
Peter Fang, dave.hansen@linux.intel.com, Artem Bityutskiy,
bp@alien8.de, x86@kernel.org, binbin.wu@linux.intel.com,
hpa@zytor.com, mingo@redhat.com, linux-kernel@vger.kernel.org,
Xiaoyao Li, tglx@kernel.org, kvm@vger.kernel.org,
linux-coco@lists.linux.dev
On Tue, Aug 11, 2026, Rick P Edgecombe wrote:
> Sean, Dave, Kiryl,
>
> In PUCK we talked about how the TD scoped quote operation avoids changes
> in the guest. But this series is actually changing the guest, so is
> somewhat at odds to that assertion. It turns out there are some tradeoffs
> here that also connect to TDX migration uAPI. Please see below for an
> explanation and recommended course of action.
>
> As a gentle recall helper... The general attestation flow converts a
> report to a quote, which then gets checked by a verifier. The report is
> like a snapshot of the guest and its environment. The quote is a signed
> version of the report plus hardware certs. It's signed with a hardware key
> and can use different kinds of crypto.
>
> These pieces are evolving to handle a few problems at once:
> - The stuff that needs to be attested is growing. Basically more platform
> details and devices are getting added to the blobs.
> - The crypto stuff is growing. The post quantum crypto stuff is large,
> etc. That stuff lives in the quote.
> - Migration wants a quote that is platform specific and not TD specific.
>
> Because the platform details are growing, they need to either go into a
> larger report or added later via a TD scoped quote. But the post quantum
> crypto stuff is going to bloat the quote either way.
>
> If the report grows to include all the TD specific details, then the QUOTE
> seamcall can be platform scoped because all the details that it needs are
> passed in as args.
>
> But if it is TD scoped, the report can stay the same size and the extra
> details can just be added during the quote operation. For migration, it
> only needs a platform scoped quote. If there are extra details about a
> specific TD, the migration stuff can be fine to just ignore them. (i.e. it
> can get what it needs from TD scoped quotes or platform scoped quotes).
>
> The current QUOTE seamcall supports both: platform scoped and TD scoped
> operations. But since we could get by with either only a platform or TD
> scoped seamcall for both operations, we could reduce the kernel's uAPIs,
> or change the API's location. Per recent discussion, Sean sees TD scoped
> APIs living in KVM and platform scoped things living in the host
> driver/tip. So all that leaves us with something like this:
>
> |Normal quote |Migration quote |Report size|Quote size|uAPI location |
> -|----------------|----------------|-----------|----------|---------------|
> 1|Platform scoped |Platform scoped |Grows |Grows |TDX host driver|
With my KVM hat on, this option looks very attractive.
And with the caveat that I'm most definitely not an attestation expert, from a
separate of concerns perspective, IMO it seems like the report should contain the
TD-specific information while the quote just wraps that information in platform-
specific goo.
In other words, to me, TD-scoped quotes feel like a hack that was thrown in to
avoid having to modify the guest because y'all didn't plan ahead.
> 2|TD scoped |TD scoped |Fixed |Grows |KVM |
> 3|TD scoped |Platform scoped |Fixed |Grows |Both |
>
>
> I'm thinking we should proceed with 2 because only the quote size changes.
> So less guest changes over time. 3 is not really a disaster either, but we
> shouldn't need 2 uABIs. For 1, from early discussion it seems it can be
> made to work but sounds like it will require some more extensive changes
> to the TDX attestation stuff. So probably needs a bit more investigation
> before we can say it won't disturb some other VMM vendor, etc.
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
2026-08-12 14:08 ` Sean Christopherson
@ 2026-08-12 16:02 ` Edgecombe, Rick P
2026-08-12 16:43 ` Sean Christopherson
0 siblings, 1 reply; 13+ messages in thread
From: Edgecombe, Rick P @ 2026-08-12 16:02 UTC (permalink / raw)
To: seanjc@google.com
Cc: hpa@zytor.com, Li, Xiaoyao, bp@alien8.de, kas@kernel.org,
binbin.wu@linux.intel.com, x86@kernel.org,
sathyanarayanan.kuppuswamy@linux.intel.com, mingo@redhat.com,
dave.hansen@linux.intel.com, linux-kernel@vger.kernel.org,
Bityutskiy, Artem, Fang, Peter, tglx@kernel.org,
linux-coco@lists.linux.dev, kvm@vger.kernel.org
On Wed, 2026-08-12 at 07:08 -0700, Sean Christopherson wrote:
> > |Normal quote |Migration quote |Report size|Quote size|uAPI location |
> > -|----------------|----------------|-----------|----------|---------------|
> > 1|Platform scoped |Platform scoped |Grows |Grows |TDX host driver|
>
> With my KVM hat on, this option looks very attractive.
>
> And with the caveat that I'm most definitely not an attestation expert, from a
> separate of concerns perspective, IMO it seems like the report should contain
> the TD-specific information while the quote just wraps that information in
> platform-specific goo.
>
> In other words, to me, TD-scoped quotes feel like a hack that was thrown in to
> avoid having to modify the guest because y'all didn't plan ahead.
Caveman crypto person here too. It seems scattered and makes me similarly
suspicious about some lack of planning. But I kind of came to a different
conclusion on what went wrong.
It seems to me that from the overall solution level, the report should never
have had the details in it. It should just be some nonce or some type of thing
that can tie the guest request to the quote that it ends up getting
back. Doesn't it seem weird to get a bunch of details from the TDX module, then
pass them from the guest to host KVM to host userspace then back to the TDX
module... which already had all those details?
My understanding was that the original SGX attestation was a complicator of the
design of this stuff. Because I'm not sure that SGX had all those details about
the TD. In fact I can't see how it could have. Is that right Peter? So it needs
them all to be passed in. All the extra validations etc of this shuffling is
TDX's problems to deal with, but for Linux, it would be at least a lot less
confusing if there was not two things that have the TD details in them.
That said, from KVM POV, (1) kicks the attestation out of KVM. I see the
benefit. But a TD quote is a TD scoped operation in concept. To me at least.
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
2026-08-12 16:02 ` Edgecombe, Rick P
@ 2026-08-12 16:43 ` Sean Christopherson
2026-08-12 17:22 ` Edgecombe, Rick P
0 siblings, 1 reply; 13+ messages in thread
From: Sean Christopherson @ 2026-08-12 16:43 UTC (permalink / raw)
To: Rick P Edgecombe
Cc: hpa@zytor.com, Xiaoyao Li, bp@alien8.de, kas@kernel.org,
binbin.wu@linux.intel.com, x86@kernel.org,
sathyanarayanan.kuppuswamy@linux.intel.com, mingo@redhat.com,
dave.hansen@linux.intel.com, linux-kernel@vger.kernel.org,
Artem Bityutskiy, Peter Fang, tglx@kernel.org,
linux-coco@lists.linux.dev, kvm@vger.kernel.org
On Wed, Aug 12, 2026, Rick P Edgecombe wrote:
> On Wed, 2026-08-12 at 07:08 -0700, Sean Christopherson wrote:
> > > |Normal quote |Migration quote |Report size|Quote size|uAPI location |
> > > -|----------------|----------------|-----------|----------|---------------|
> > > 1|Platform scoped |Platform scoped |Grows |Grows |TDX host driver|
> >
> > With my KVM hat on, this option looks very attractive.
> >
> > And with the caveat that I'm most definitely not an attestation expert, from a
> > separate of concerns perspective, IMO it seems like the report should contain
> > the TD-specific information while the quote just wraps that information in
> > platform-specific goo.
> >
> > In other words, to me, TD-scoped quotes feel like a hack that was thrown in to
> > avoid having to modify the guest because y'all didn't plan ahead.
>
> Caveman crypto person here too. It seems scattered and makes me similarly
> suspicious about some lack of planning. But I kind of came to a different
> conclusion on what went wrong.
>
> It seems to me that from the overall solution level, the report should never
> have had the details in it. It should just be some nonce or some type of thing
> that can tie the guest request to the quote that it ends up getting
> back. Doesn't it seem weird to get a bunch of details from the TDX module, then
> pass them from the guest to host KVM to host userspace then back to the TDX
> module... which already had all those details?
Hmm, my mental model of this is that the report contains the "real" payload, i.e.
the metadata describing what is running and whatnot, while the quote effectively
signs the payload to prove the provenance of the report. That's why I view the
report as TD-specific (what's running) and the quote as platform-specific (provides
root of trust).
> My understanding was that the original SGX attestation was a complicator of the
> design of this stuff. Because I'm not sure that SGX had all those details about
> the TD. In fact I can't see how it could have. Is that right Peter? So it needs
> them all to be passed in. All the extra validations etc of this shuffling is
> TDX's problems to deal with, but for Linux, it would be at least a lot less
> confusing if there was not two things that have the TD details in them.
>
> That said, from KVM POV, (1) kicks the attestation out of KVM. I see the
> benefit. But a TD quote is a TD scoped operation in concept. To me at least.
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
2026-08-12 16:43 ` Sean Christopherson
@ 2026-08-12 17:22 ` Edgecombe, Rick P
0 siblings, 0 replies; 13+ messages in thread
From: Edgecombe, Rick P @ 2026-08-12 17:22 UTC (permalink / raw)
To: seanjc@google.com
Cc: tglx@kernel.org, linux-coco@lists.linux.dev, bp@alien8.de,
kas@kernel.org, binbin.wu@linux.intel.com, hpa@zytor.com,
mingo@redhat.com, sathyanarayanan.kuppuswamy@linux.intel.com,
x86@kernel.org, linux-kernel@vger.kernel.org, Bityutskiy, Artem,
Li, Xiaoyao, dave.hansen@linux.intel.com, Fang, Peter,
kvm@vger.kernel.org
On Wed, 2026-08-12 at 09:43 -0700, Sean Christopherson wrote:
> > It seems to me that from the overall solution level, the report should never
> > have had the details in it. It should just be some nonce or some type of
> > thing that can tie the guest request to the quote that it ends up getting
> > back. Doesn't it seem weird to get a bunch of details from the TDX module,
> > then pass them from the guest to host KVM to host userspace then back to the
> > TDX module... which already had all those details?
>
> Hmm, my mental model of this is that the report contains the "real" payload,
> i.e. the metadata describing what is running and whatnot, while the quote
> effectively signs the payload to prove the provenance of the report. That's
> why I view the report as TD-specific (what's running) and the quote as
> platform-specific (provides root of trust).
Argh. So I think I was not clear enough in the description. And hopefully Peter
will appear soon and clarify this is all correct, because I'm relaying what he
explained to me.
We think quote *operation* can be platform specific instead of TD specific if we
want. Meaning the SEAMCALL isn't passed a TDR. But the bits that actually are in
the resulting quote are TD specific. In other words, at least some of the bits
in the report end up in the quote too. Those TD specific bits either come from
the passed in report, or added later during the quote operation based on the TDX
module's TD knowledge. Because of course the attestation needs to know about the
TD details.
Or I guess... if we wanted to hand the report and quote to the verifier as
separate payloads. Then... from my basic crypto understanding, it could work
too. Is that your model? I think it would be a major change at least.
But part of this too, is that "DICE" is an industry standard [0]. Some of the
existing TDX attestation format is TDX specific, and moving to the standard is
expected to make the verifier better. So TDX does not have full flexibility in
choosing which bits go where. There is some. But I'm not sure which.
I think I mentioned this, but what we experienced internally on this feature is
that basic questions like "where should the quote uABI live" quickly spiral into
a lot of TDX arch tradeoffs and legacy complications. I'll take it we should
prove out (1) a bit more to get better clarity on if there are any snags.
[0] https://trustedcomputinggroup.org/resource/dice-attestation-architecture/
^ permalink raw reply [flat|nested] 13+ messages in thread
end of thread, other threads:[~2026-08-12 17:22 UTC | newest]
Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-07-29 18:29 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-07-29 18:47 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
2026-07-29 21:21 ` [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Edgecombe, Rick P
2026-08-11 22:40 ` Edgecombe, Rick P
2026-08-12 14:08 ` Sean Christopherson
2026-08-12 16:02 ` Edgecombe, Rick P
2026-08-12 16:43 ` Sean Christopherson
2026-08-12 17:22 ` Edgecombe, Rick P
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox