From: Sean Christopherson <seanjc@google.com>
To: David Woodhouse <dwmw2@infradead.org>
Cc: kas@kernel.org, rick.p.edgecombe@intel.com, pbonzini@redhat.com,
kys@microsoft.com, haiyangz@microsoft.com, wei.liu@kernel.org,
decui@microsoft.com, longli@microsoft.com,
ajay.kaher@broadcom.com, alexey.makhalov@broadcom.com,
jan.kiszka@siemens.com, dave.hansen@linux.intel.com,
luto@kernel.org, peterz@infradead.org, jgross@suse.com,
daniel.lezcano@kernel.org, tglx@kernel.org, jstultz@google.com,
x86@kernel.org, linux-coco@lists.linux.dev, kvm@vger.kernel.org,
linux-hyperv@vger.kernel.org, virtualization@lists.linux.dev,
linux-kernel@vger.kernel.org, xen-devel@lists.xenproject.org
Subject: Re: [PATCH v6 10/51] x86/tdx: Force TSC frequency with CPUID-based info provided by the TDX-Module
Date: Mon, 10 Aug 2026 07:30:04 -0700 [thread overview]
Message-ID: <anngbOavdPam2kKy@google.com> (raw)
In-Reply-To: <b8c0e3537904e29f233cbb03f4d3ddb5247e2af7.camel@infradead.org>
On Sat, Aug 08, 2026, David Woodhouse wrote:
> On Thu, 2026-08-06 at 16:35 -0700, Sean Christopherson wrote:
> > When running as a TDX guest, explicitly set the TSC frequency to a known
> > value, using CPUID-based information, instead of potentially relying on a
> > hypervisor-controlled PV routine. For TDX guests, CPUID.0x15 is always
> > emulated by the TDX-Module, i.e. the information from CPUID is more
> > trustworthy than the information provided by the hypervisor.
> >
> > To maintain backwards compatibility with TDX guest kernels that use native
> > calibration, and because it's the least awful option, retain
> > native_calibrate_tsc()'s stuffing of the local APIC bus period using the
> > core crystal frequency. While it's entirely possible for the hypervisor
> > to emulate the APIC timer at a different frequency than the core crystal
> > frequency, the commonly accepted interpretation of Intel's SDM is that APIC
> > timer runs at the core crystal frequency when that latter is enumerated via
> > CPUID:
> >
> > The APIC timer frequency will be the processor's bus clock or core
> > crystal clock frequency (when TSC/core crystal clock ratio is enumerated
> > in CPUID leaf 0x15).
> >
> > If the hypervisor is malicious and deliberately runs the APIC timer at the
> > wrong frequency, nothing would stop the hypervisor from modifying the
> > frequency at any time, i.e. attempting to manually calibrate the frequency
> > out of paranoia would be futile.
> >
> > Deliberately leave CPU frequency calibration as is, since the TDX-Module
> > doesn't provide any guarantees with respect to CPUID.0x16.
> >
> > Expose and use cpuid_get_tsc_info() instead of providing a wrapper to
> > get the TSC and core crystal frequency, as TDX is the only anticipated
> > user outside of the TSC code, i.e. adding a helper to dedup the math won't
> > actually dedup anything. Having TDX use "struct cpuid_tsc_info" also
> > avoids the temptation of declaring a local "tsc_khz" variable and thus
> > unintentionally creating a shadow of the global "tsc_khz".
> >
> > Cc: Kiryl Shutsemau (Meta) <kas@kernel.org>
> > Signed-off-by: Sean Christopherson <seanjc@google.com>
>
> I don't know if we should set X86_FEATURE_TSC_RELIABLE before bailing
> out in the case where cpuid_get_tsc_info() fails, or just not care
> about that because it Can Never Happen™? Previously it was set
> unconditionally from tdx_early_init().
>
> Whatever...
Heh, yeah, "whatever" is about my thought exactly. I could go either way. I
would buy an argument that the TSC itself is still reliable even if the frequency
isn't known. On the other hand, the frequency could be computed via calibration,
at which point the frequency is no longer reliable and arguably should be sanity
checked.
next prev parent reply other threads:[~2026-08-10 14:30 UTC|newest]
Thread overview: 68+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-06 23:35 [PATCH v6 00/51] x86: Try to wrangle PV clocks vs. TSC Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 01/51] x86/apic: Provide helpers to set local APIC timer frequency in hz and khz Sean Christopherson
2026-08-08 10:36 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 02/51] x86/apic: Add CONFIG_X86_LOCAL_APIC=n stubs for APIC timer frequency APIs Sean Christopherson
2026-08-08 10:37 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 03/51] x86/tsc: Ensure that TSC recalibration doesn't run if TSC frequency is known Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 04/51] x86/tsc: Restrict recalibrate_cpu_khz() export to p4-clockmod and powernow-k7 Sean Christopherson
2026-08-08 14:39 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 05/51] x86/sev: Mark TSC as reliable when configuring Secure TSC Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 06/51] x86/sev: Don't override CPU frequency calibration for SNP's " Sean Christopherson
2026-08-08 14:48 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 07/51] x86/sev: Move check for SNP Secure TSC support to tsc_early_init() Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 08/51] x86/sev: Shove SNP's secure/trusted TSC frequency directly into "calibration" Sean Christopherson
2026-08-08 14:50 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 09/51] x86/tsc: Add a standalone helper for getting TSC info from CPUID.0x15 Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 10/51] x86/tdx: Force TSC frequency with CPUID-based info provided by the TDX-Module Sean Christopherson
2026-08-08 14:53 ` David Woodhouse
2026-08-10 14:30 ` Sean Christopherson [this message]
2026-08-06 23:35 ` [PATCH v6 11/51] x86/tsc: Add dedicated hypervisor hooks for getting known TSC/CPU frequencies Sean Christopherson
2026-08-08 14:55 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 12/51] x86/acrn: Register TSC/CPU frequency callbacks iff frequency is actually in CPUID Sean Christopherson
2026-08-08 14:57 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 13/51] x86/acrn: Mark TSC frequency as known when using ACRN for calibration Sean Christopherson
2026-08-08 14:59 ` David Woodhouse
2026-08-10 13:56 ` Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 14/51] x86/tsc: Consolidate forcing of X86_FEATURE_TSC_KNOWN_FREQ for PV code Sean Christopherson
2026-08-08 15:00 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 15/51] x86/tsc: Kill off x86_platform_ops.calibrate_{cpu,tsc}() hooks Sean Christopherson
2026-08-08 15:01 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 16/51] x86/tsc: Rename pit_hpet_ptimer_calibrate_cpu() => native_calibrate_cpu_late() Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 17/51] x86/tsc: Fold native_calibrate_cpu() into recalibrate_cpu_khz() Sean Christopherson
2026-08-08 15:03 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 18/51] x86/kvmclock: Rename kvm_get_tsc_khz() to kvmclock_get_tsc_khz() Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 19/51] x86/kvmclock: Drop dead check on TSC being unstable during kvmclock_init() Sean Christopherson
2026-08-08 15:05 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 20/51] KVM: x86: Officially define CPUID 0x40000010 as PV Timing Info (TSC and Bus) Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 21/51] x86/kvm: Obtain TSC frequency from PV CPUID if present Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 22/51] x86/kvm: Mark TSC as reliable when it's constant and nonstop Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 23/51] x86/tsc: Add standalone helper for getting CPU frequency from CPUID Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 24/51] x86/kvm: Get CPU base frequency from CPUID when it's available Sean Christopherson
2026-08-08 15:06 ` David Woodhouse
2026-08-06 23:35 ` [PATCH v6 25/51] clocksource: hyper-v: Register sched_clock save/restore iff it's necessary Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 26/51] clocksource: hyper-v: Drop wrappers to sched_clock save/restore helpers Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 27/51] clocksource: hyper-v: Don't save/restore TSC offset when using HV sched_clock Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 28/51] x86/kvmclock: Setup kvmclock for secondary CPUs iff CONFIG_SMP=y Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 29/51] x86/kvm: Don't disable kvmclock on BSP in syscore_suspend() Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 30/51] x86/paravirt: Remove unnecessary PARAVIRT=n stub for paravirt_set_sched_clock() Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 31/51] x86/paravirt: Move handling of unstable PV clocks into paravirt_set_sched_clock() Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 32/51] x86/kvmclock: Move sched_clock save/restore helpers up in kvmclock.c Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 33/51] x86/xen/time: NOP-ify x86_platform's sched_clock save/restore hooks Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 34/51] x86/vmware: NOP-ify save/restore hooks when using VMware's sched_clock Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 35/51] x86/tsc: WARN if TSC sched_clock save/restore used with PV sched_clock Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 36/51] x86/paravirt: Pass sched_clock save/restore helpers during registration Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 37/51] x86/kvmclock: Move kvm_sched_clock_init() down in kvmclock.c Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 38/51] x86/xen/time: Mark xen_setup_vsyscall_time_info() as __init Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 39/51] x86/pvclock: Mark setup helpers and related various as __init/__ro_after_init Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 40/51] x86/pvclock: WARN if pvclock's valid_flags are overwritten Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 41/51] x86/kvmclock: Refactor handling of PVCLOCK_TSC_STABLE_BIT during kvmclock_init() Sean Christopherson
2026-08-06 23:35 ` [PATCH v6 42/51] timekeeping: Resume clocksources before reading persistent clock Sean Christopherson
2026-08-06 23:36 ` [PATCH v6 43/51] x86/kvmclock: Hook clocksource.suspend/resume when kvmclock isn't sched_clock Sean Christopherson
2026-08-06 23:36 ` [PATCH v6 44/51] x86/kvmclock: WARN if wall clock is read while kvmclock is suspended Sean Christopherson
2026-08-06 23:36 ` [PATCH v6 45/51] x86/paravirt: Mark __paravirt_set_sched_clock() as __init Sean Christopherson
2026-08-06 23:36 ` [PATCH v6 46/51] x86/paravirt: Plumb a return code into __paravirt_set_sched_clock() Sean Christopherson
2026-08-06 23:36 ` [PATCH v6 47/51] x86/paravirt: Don't use a PV sched_clock in CoCo guests with trusted TSC Sean Christopherson
2026-08-06 23:36 ` [PATCH v6 48/51] x86/kvmclock: Use TSC for sched_clock if it's constant and non-stop Sean Christopherson
2026-08-06 23:36 ` [PATCH v6 49/51] x86/kvmclock: Plumb in AP-online and BSP-resume to kvmlock, for documentation Sean Christopherson
2026-08-06 23:36 ` [PATCH v6 50/51] x86/paravirt: Move using_native_sched_clock() stub into timer.h Sean Christopherson
2026-08-06 23:36 ` [PATCH v6 51/51] x86/kvm: Get local APIC bus frequency from PV CPUID Timing Info Sean Christopherson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=anngbOavdPam2kKy@google.com \
--to=seanjc@google.com \
--cc=ajay.kaher@broadcom.com \
--cc=alexey.makhalov@broadcom.com \
--cc=daniel.lezcano@kernel.org \
--cc=dave.hansen@linux.intel.com \
--cc=decui@microsoft.com \
--cc=dwmw2@infradead.org \
--cc=haiyangz@microsoft.com \
--cc=jan.kiszka@siemens.com \
--cc=jgross@suse.com \
--cc=jstultz@google.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=kys@microsoft.com \
--cc=linux-coco@lists.linux.dev \
--cc=linux-hyperv@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=longli@microsoft.com \
--cc=luto@kernel.org \
--cc=pbonzini@redhat.com \
--cc=peterz@infradead.org \
--cc=rick.p.edgecombe@intel.com \
--cc=tglx@kernel.org \
--cc=virtualization@lists.linux.dev \
--cc=wei.liu@kernel.org \
--cc=x86@kernel.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox