From: Dave Hansen <dave.hansen@intel.com>
To: Kiryl Shutsemau <kas@kernel.org>, Chao Gao <chao.gao@intel.com>
Cc: kvm@vger.kernel.org, linux-coco@lists.linux.dev,
linux-kernel@vger.kernel.org, x86@kernel.org,
vishal.l.verma@intel.com, kai.huang@intel.com,
dan.j.williams@intel.com, yilun.xu@linux.intel.com,
vannapurve@google.com, Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
"H. Peter Anvin" <hpa@zytor.com>, Ingo Molnar <mingo@redhat.com>,
Rick Edgecombe <rick.p.edgecombe@intel.com>,
Thomas Gleixner <tglx@linutronix.de>
Subject: Re: [PATCH v2 0/3] Expose TDX Module version
Date: Mon, 5 Jan 2026 08:04:21 -0800 [thread overview]
Message-ID: <d45cc504-509c-48a7-88e2-374e00068e79@intel.com> (raw)
In-Reply-To: <dfb66mcbxqw2a6qjyg74jqp7aucmnkztl224rj3u6znrcr7ukw@yy65kqagdsoh>
On 1/5/26 02:38, Kiryl Shutsemau wrote:
>> To address this issue, this series exposes the TDX Module version as
>> sysfs attributes of the tdx_host device [*] and also prints it in dmesg
>> to keep a record.
> The version information is also useful for the guest. Maybe we should
> provide consistent interface for both sides?
Could you elaborate a bit on what constitutes consistency here?
Do you mean simply ensuring that the TDX module version _is_ exposed on
both hosts and guests, like in:
/sys/devices/faux/tdx_host/version
and (making this one up):
/sys/devices/faux/tdx_guest/version
Note the "host" vs. "guest" ^^^^^
Or, that the TDX module version be exposed in the *same* ABI in both
host and guest, like:
/sys/devices/faux/tdx/version
Generally, I find myself really wanting to know how this fits into the
larger picture. Using this "faux" device really seems novel and
TDX-specific. Should it be?
What are other CPU vendors doing for this? SEV? CCA? S390? How are their
firmware versions exposed? What about other things in the Intel world
like CPU microcode or the billion other chunks of firmware? How about
hypervisors? Do they expose their versions to guests with an explicit
ABI? Are those exposed to userspace?
For instance, I hear a lot of talk about updating the TDX module. But is
this interface consistent with doing updates? Long term, I was hoping
that TDX firmware could get treated like any other blob of modern
firmware and have fwupd manage it, so I asked:
https://chatgpt.com/share/695be06c-3d40-8012-97c9-2089fc33cbb3
My read on your approach here is that our new LLM overlords might
consider it the "last resort".
next prev parent reply other threads:[~2026-01-05 16:04 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-01-05 7:43 [PATCH v2 0/3] Expose TDX Module version Chao Gao
2026-01-05 7:43 ` [PATCH v2 1/3] x86/virt/tdx: Retrieve " Chao Gao
2026-01-05 7:43 ` [PATCH v2 2/3] coco/tdx-host: Expose " Chao Gao
2026-01-05 7:43 ` [PATCH v2 3/3] x86/virt/tdx: Print TDX Module version during init Chao Gao
2026-01-05 10:38 ` [PATCH v2 0/3] Expose TDX Module version Kiryl Shutsemau
2026-01-05 16:04 ` Dave Hansen [this message]
2026-01-05 17:04 ` Kiryl Shutsemau
2026-01-05 17:19 ` Dave Hansen
2026-01-05 18:03 ` Kiryl Shutsemau
2026-01-07 21:34 ` dan.j.williams
2026-01-07 22:26 ` Dave Hansen
2026-01-06 10:23 ` Chao Gao
2026-01-06 16:37 ` Dave Hansen
2026-01-06 6:47 ` Chao Gao
2026-01-06 9:17 ` Nikolay Borisov
2026-01-06 11:19 ` Kiryl Shutsemau
2026-01-06 13:31 ` Chao Gao
2026-01-07 0:36 ` dan.j.williams
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=d45cc504-509c-48a7-88e2-374e00068e79@intel.com \
--to=dave.hansen@intel.com \
--cc=bp@alien8.de \
--cc=chao.gao@intel.com \
--cc=dan.j.williams@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kai.huang@intel.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=tglx@linutronix.de \
--cc=vannapurve@google.com \
--cc=vishal.l.verma@intel.com \
--cc=x86@kernel.org \
--cc=yilun.xu@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox