From: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>
To: "seanjc@google.com" <seanjc@google.com>
Cc: "dave.hansen@linux.intel.com" <dave.hansen@linux.intel.com>,
"kas@kernel.org" <kas@kernel.org>,
"binbin.wu@linux.intel.com" <binbin.wu@linux.intel.com>,
"Li, Xiaoyao" <xiaoyao.li@intel.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"Zhao, Yan Y" <yan.y.zhao@intel.com>,
"Huang, Kai" <kai.huang@intel.com>,
"pbonzini@redhat.com" <pbonzini@redhat.com>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
"linux-coco@lists.linux.dev" <linux-coco@lists.linux.dev>,
"x86@kernel.org" <x86@kernel.org>
Subject: Re: [PATCH] KVM: VMX: Explicitly track TDX VMs' root level instead of guessing it from CPUID
Date: Wed, 19 Aug 2026 18:56:39 +0000 [thread overview]
Message-ID: <e5979a0a4d7c24d88f57981aba0fda6d8a5e2f29.camel@intel.com> (raw)
In-Reply-To: <aoX5sbITQYeB7USY@google.com>
On Wed, 2026-08-19 at 11:45 -0700, Sean Christopherson wrote:
> > Elsewhere we use kvm_has_mirrored_tdp(vcpu->kvm) for these kind of checks.
> > Would
> > be nice to be consistent and not add any uncertainty of whether
> > mirror_root_level can be set without kvm_has_mirrored_tdp() being true.
>
> Hmm, for defense in depth, I want to explicitly check mirror_root_level,
> because returning '0' would likely have dire consequences. How about this?
:) Sure.
Yan and I were discussing what might be a new level of defense on MMU checking.
We were basically trying to work out your thinking on some of the defensive
patches lately. It seems there has also been a new level of activity on the bugs
front so we want to adapt to any learnings you had. I actually planned to bring
it up in PUCK, but...
Can you share any thoughts? Should we be more paranoid in general, or same as
always? Or more specifically paranoid where issues hit?
>
> if (kvm_has_mirrored_tdp(vcpu->kvm) &&
> !WARN_ON_ONCE(!vcpu->kvm->arch.mirror_root_level))
> return vcpu->kvm->arch.mirror_root_level;
>
> > > @@ -2760,6 +2754,14 @@ DEFINE_CLASS(tdx_vm_state_guard,
> > > tdx_vm_state_guard_t,
> > > if (!IS_ERR(_T)) tdx_release_vm_state_locks(_T),
> > > tdx_acquire_vm_state_locks(kvm), struct kvm *kvm);
> > >
> > > +static __always_inline void tdx_set_mirror_root_level(struct kvm *kvm,
> > > int
> > > level)
> > > +{
> > > + BUILD_BUG_ON(level != 4 && level != 5);
> > > +
> > > + kvm->arch.mirror_root_level = level;
> > > + kvm->arch.gfn_direct_bits = gpa_to_gfn(BIT_ULL(level == 4 ? 47 :
> > > 51));
> >
> > No need to remove TDX_SHARED_BIT_PWL_4/5 in this patch either anymore. Since
> > this lives in TDX code.
>
> Killing them off dedups the code, and more importantly makes it all but
> impossible for mirror_root_level and the mirror root level to get out of sync.
Eh, I can see it. I weigh it against "magic numbers" though.
next prev parent reply other threads:[~2026-08-19 18:56 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-14 22:45 [PATCH] KVM: VMX: Explicitly track TDX VMs' root level instead of guessing it from CPUID Sean Christopherson
2026-08-19 0:53 ` Edgecombe, Rick P
2026-08-19 0:59 ` Sean Christopherson
2026-08-19 14:35 ` Edgecombe, Rick P
2026-08-19 15:56 ` Sean Christopherson
2026-08-19 17:35 ` Edgecombe, Rick P
2026-08-19 18:45 ` Sean Christopherson
2026-08-19 18:56 ` Edgecombe, Rick P [this message]
2026-08-19 19:41 ` Sean Christopherson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e5979a0a4d7c24d88f57981aba0fda6d8a5e2f29.camel@intel.com \
--to=rick.p.edgecombe@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=kai.huang@intel.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
--cc=yan.y.zhao@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox