Linux Confidential Computing Development
 help / color / mirror / Atom feed
From: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>
To: "seanjc@google.com" <seanjc@google.com>
Cc: "kvm@vger.kernel.org" <kvm@vger.kernel.org>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"dave.hansen@linux.intel.com" <dave.hansen@linux.intel.com>,
	"bp@alien8.de" <bp@alien8.de>, "kas@kernel.org" <kas@kernel.org>,
	"binbin.wu@linux.intel.com" <binbin.wu@linux.intel.com>,
	"Li, Xiaoyao" <xiaoyao.li@intel.com>,
	"sathyanarayanan.kuppuswamy@linux.intel.com"
	<sathyanarayanan.kuppuswamy@linux.intel.com>,
	"mingo@redhat.com" <mingo@redhat.com>,
	"hpa@zytor.com" <hpa@zytor.com>,
	"tglx@kernel.org" <tglx@kernel.org>,
	"Fang, Peter" <peter.fang@intel.com>,
	"linux-coco@lists.linux.dev" <linux-coco@lists.linux.dev>,
	"x86@kernel.org" <x86@kernel.org>,
	"Bityutskiy, Artem" <artem.bityutskiy@intel.com>
Subject: Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
Date: Wed, 12 Aug 2026 23:30:07 +0000	[thread overview]
Message-ID: <c697ff1d97fe62882eaf3bd86a4213bf2e79fc09.camel@intel.com> (raw)
In-Reply-To: <anz9b6CDkhr5D5RG@google.com>

On Wed, 2026-08-12 at 16:10 -0700, Sean Christopherson wrote:
> > Yea that was my suspicion. I'm not sure if separating them was really Sean's
> > understanding or not. 
> 
> LOL, most definitely not.  Though I have a naive question at this point: why
> can't the TDX-Module extract the bits from the report and put them in the
> right places when generating the quote?

It totally can. If we do the platform scoped quote operation option, then we
grow the report to include all the TD details. Then the quote operation would
extract them from the TDX specific report and put them in their DICE quote
location. It doesn't need to have its own access to the TD details. They come in
the report.

This is what drives the fallout of growing the report in that option. And I
guess defining some new report formats to hold the new stuff. But that is TDX's
job to manage.

> 
> > But the other part is that the verifiers and other VMM infrastructures are
> > already expecting this standard format. It would have a lot of downsides.
> > 
> > But the "grow the report" or "grow the report and quote" are still options
> > that leave the quote in the expected DICE format, right? Sean I'll assume
> > you still prefer the "grow both" option for the sake of kicking the quoting
> > responsibilities out of KVM.
> 
> Not necessarily.  If doing the right thing from a "what's intended and sane"
> perspective is to put some quoting responsibilities on KVM, then so be it. 

I think the only pure answer is go back in time and delete the SGX based
attestation. Between the two options here I give "TD scoped quote" the narrow
win. If you add in that we (Intel Linux TDX folks here) don't need to go push
for changes to the module, then it's a clear win. But even without that, still a
narrow win I think.

> But I would like to have a passing understanding of what all is going on, if
> only so that I can justify why the new uAPI is being added when I send Paolo a
> pull request.  I'm pushing back purely because I quite literally don't
> understand why KVM needs to be involved.

Totally makes sense. And I only entertained the wild "split them" idea because I
don't see any harm in enumerating *all* the options. I have faith we will come
to some reasonable decision.

Hmm, let me flag Artem to see if he can add anymore weight one way or the other
from the migration POV.

  reply	other threads:[~2026-08-12 23:30 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-07-29 18:29   ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-07-29 18:47   ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
2026-07-29 21:21 ` [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Edgecombe, Rick P
2026-08-11 22:40   ` Edgecombe, Rick P
2026-08-12 14:08     ` Sean Christopherson
2026-08-12 16:02       ` Edgecombe, Rick P
2026-08-12 16:43         ` Sean Christopherson
2026-08-12 17:22           ` Edgecombe, Rick P
2026-08-12 22:37             ` Peter Fang
2026-08-12 22:47               ` Edgecombe, Rick P
2026-08-12 23:10                 ` Sean Christopherson
2026-08-12 23:30                   ` Edgecombe, Rick P [this message]
2026-08-12 23:27                 ` Peter Fang
2026-08-12 21:02         ` Peter Fang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=c697ff1d97fe62882eaf3bd86a4213bf2e79fc09.camel@intel.com \
    --to=rick.p.edgecombe@intel.com \
    --cc=artem.bityutskiy@intel.com \
    --cc=binbin.wu@linux.intel.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=kas@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=peter.fang@intel.com \
    --cc=sathyanarayanan.kuppuswamy@linux.intel.com \
    --cc=seanjc@google.com \
    --cc=tglx@kernel.org \
    --cc=x86@kernel.org \
    --cc=xiaoyao.li@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox