From: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>
To: "seanjc@google.com" <seanjc@google.com>
Cc: "tglx@kernel.org" <tglx@kernel.org>,
"linux-coco@lists.linux.dev" <linux-coco@lists.linux.dev>,
"bp@alien8.de" <bp@alien8.de>, "kas@kernel.org" <kas@kernel.org>,
"binbin.wu@linux.intel.com" <binbin.wu@linux.intel.com>,
"hpa@zytor.com" <hpa@zytor.com>,
"mingo@redhat.com" <mingo@redhat.com>,
"sathyanarayanan.kuppuswamy@linux.intel.com"
<sathyanarayanan.kuppuswamy@linux.intel.com>,
"x86@kernel.org" <x86@kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"Bityutskiy, Artem" <artem.bityutskiy@intel.com>,
"Li, Xiaoyao" <xiaoyao.li@intel.com>,
"dave.hansen@linux.intel.com" <dave.hansen@linux.intel.com>,
"Fang, Peter" <peter.fang@intel.com>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>
Subject: Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic
Date: Wed, 12 Aug 2026 17:22:11 +0000 [thread overview]
Message-ID: <ed4891a59096c59e43a893910c9f17d0ff6086b8.camel@intel.com> (raw)
In-Reply-To: <anyiwqi9i0NSv0QW@google.com>
On Wed, 2026-08-12 at 09:43 -0700, Sean Christopherson wrote:
> > It seems to me that from the overall solution level, the report should never
> > have had the details in it. It should just be some nonce or some type of
> > thing that can tie the guest request to the quote that it ends up getting
> > back. Doesn't it seem weird to get a bunch of details from the TDX module,
> > then pass them from the guest to host KVM to host userspace then back to the
> > TDX module... which already had all those details?
>
> Hmm, my mental model of this is that the report contains the "real" payload,
> i.e. the metadata describing what is running and whatnot, while the quote
> effectively signs the payload to prove the provenance of the report. That's
> why I view the report as TD-specific (what's running) and the quote as
> platform-specific (provides root of trust).
Argh. So I think I was not clear enough in the description. And hopefully Peter
will appear soon and clarify this is all correct, because I'm relaying what he
explained to me.
We think quote *operation* can be platform specific instead of TD specific if we
want. Meaning the SEAMCALL isn't passed a TDR. But the bits that actually are in
the resulting quote are TD specific. In other words, at least some of the bits
in the report end up in the quote too. Those TD specific bits either come from
the passed in report, or added later during the quote operation based on the TDX
module's TD knowledge. Because of course the attestation needs to know about the
TD details.
Or I guess... if we wanted to hand the report and quote to the verifier as
separate payloads. Then... from my basic crypto understanding, it could work
too. Is that your model? I think it would be a major change at least.
But part of this too, is that "DICE" is an industry standard [0]. Some of the
existing TDX attestation format is TDX specific, and moving to the standard is
expected to make the verifier better. So TDX does not have full flexibility in
choosing which bits go where. There is some. But I'm not sure which.
I think I mentioned this, but what we experienced internally on this feature is
that basic questions like "where should the quote uABI live" quickly spiral into
a lot of TDX arch tradeoffs and legacy complications. I'll take it we should
prove out (1) a bit more to get better clarity on if there are any snags.
[0] https://trustedcomputinggroup.org/resource/dice-attestation-architecture/
next prev parent reply other threads:[~2026-08-12 17:22 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 12:29 [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Peter Fang
2026-07-29 12:29 ` [PATCH v3 1/4] x86/tdx: Add helper to query maximum TD Quote size Peter Fang
2026-07-29 12:29 ` [PATCH v3 2/4] virt: tdx-guest: Calculate the Quote buffer size safely Peter Fang
2026-07-29 18:29 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 3/4] virt: tdx-guest: Use a variable to store the Quote buffer size Peter Fang
2026-07-29 18:47 ` Kuppuswamy Sathyanarayanan
2026-07-29 12:29 ` [PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically Peter Fang
2026-07-29 21:21 ` [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic Edgecombe, Rick P
2026-08-11 22:40 ` Edgecombe, Rick P
2026-08-12 14:08 ` Sean Christopherson
2026-08-12 16:02 ` Edgecombe, Rick P
2026-08-12 16:43 ` Sean Christopherson
2026-08-12 17:22 ` Edgecombe, Rick P [this message]
2026-08-12 22:37 ` Peter Fang
2026-08-12 22:47 ` Edgecombe, Rick P
2026-08-12 23:10 ` Sean Christopherson
2026-08-12 23:30 ` Edgecombe, Rick P
2026-08-12 23:27 ` Peter Fang
2026-08-12 21:02 ` Peter Fang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ed4891a59096c59e43a893910c9f17d0ff6086b8.camel@intel.com \
--to=rick.p.edgecombe@intel.com \
--cc=artem.bityutskiy@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=peter.fang@intel.com \
--cc=sathyanarayanan.kuppuswamy@linux.intel.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox