From: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>
To: "kvm@vger.kernel.org" <kvm@vger.kernel.org>,
"linux-coco@lists.linux.dev" <linux-coco@lists.linux.dev>,
"Huang, Kai" <kai.huang@intel.com>,
"Hansen, Dave" <dave.hansen@intel.com>,
"Zhao, Yan Y" <yan.y.zhao@intel.com>,
"tony.lindgren@linux.intel.com" <tony.lindgren@linux.intel.com>,
"Wu, Binbin" <binbin.wu@intel.com>,
"kas@kernel.org" <kas@kernel.org>,
"seanjc@google.com" <seanjc@google.com>,
"mingo@redhat.com" <mingo@redhat.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"pbonzini@redhat.com" <pbonzini@redhat.com>,
"nik.borisov@suse.com" <nik.borisov@suse.com>,
"linux-doc@vger.kernel.org" <linux-doc@vger.kernel.org>,
"hpa@zytor.com" <hpa@zytor.com>,
"tglx@kernel.org" <tglx@kernel.org>,
"Annapurve, Vishal" <vannapurve@google.com>,
"Mehta, Sohil" <sohil.mehta@intel.com>,
"bp@alien8.de" <bp@alien8.de>, "Gao, Chao" <chao.gao@intel.com>,
"x86@kernel.org" <x86@kernel.org>
Cc: "binbin.wu@linux.intel.com" <binbin.wu@linux.intel.com>,
"hongyu.ning@linux.intel.com" <hongyu.ning@linux.intel.com>
Subject: Re: [PATCH v10 10/11] Documentation/x86: Add documentation for TDX's Dynamic PAMT
Date: Thu, 3 Sep 2026 19:31:29 +0000 [thread overview]
Message-ID: <7cd4a38ed0ab1618a90e1afc8d56b450d57a9374.camel@intel.com> (raw)
In-Reply-To: <225572f8-5636-41fd-9315-ef5efb78f0a5@intel.com>
On Thu, 2026-09-03 at 08:47 -0700, Dave Hansen wrote:
> On 9/2/26 18:51, Rick Edgecombe wrote:
> > +Dynamic PAMT is only enabled when supported and the ``tdx_dpamt=`` kernel
> > +parameter is set to "on". The feature is off by default because TDX module
> > +internal details prevent Dynamic PAMT from working on all keyid partitioning
> > +configurations. When the TDX module is fixed to include these constraints in
> > +its enumeration of Dynamic PAMT support, kernel support can be changed to
> > +default on. For more information, consult the Intel TDX documentation about
> > +Dynamic PAMT.
>
> What's the end user visible effect of hitting one of these troublesome
> "keyid partitioning configurations"?
DPAMT gets turned on via the TDH_SYS_CONFIG SEAMCALL in config_tdx_module().
Inside the TDX module, this SEAMCALL does some checks about the number of
configured keyids, and will fail the call if it doesn't like the configured
keyids. For a server with 52 bit physical address width, it should require at
least 16 hkids (4 bits). If a lower number of bits is set, TDH_SYS_CONFIG will
fail and it will cascade into a TDX init failure.
The TDX module exposes if DPAMT is supported via a features0 bit. If DPAMT is
not supported due to the hkids limits, the module still reports it as supported.
The module folks agreed to change the behavior of this bit to say if DPAMT is
actually supported (i.e. do the keyid bit checks itself).
So we have:
1. If you are inclined to think support bits should actually report whether
something is supported, then this kinda is a TDX module bug that we are working
around by making DPAMT an opt-in.
2. The bug will only be hit if anyone has configured a low number of hkids.
We could optimistically think the TDX module with the fix will be distributed
before anyone with this configuration hits it? And if that is wrong, add the
keyid checking or opt-in as a fix. Then maybe we save some code long term.
next prev parent reply other threads:[~2026-09-03 19:31 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 1:51 [PATCH v10 00/11] Dynamic PAMT Rick Edgecombe
2026-09-03 1:51 ` [PATCH v10 01/11] x86/virt/tdx: Simplify PAMT layout calculation Rick Edgecombe
2026-09-03 1:51 ` [PATCH v10 02/11] x86/virt/tdx: Allocate page bitmap for Dynamic PAMT Rick Edgecombe
2026-09-03 1:51 ` [PATCH v10 03/11] x86/virt/tdx: Add __tdx_pamt_get/put() helpers Rick Edgecombe
2026-09-03 15:28 ` Dave Hansen
2026-09-03 1:51 ` [PATCH v10 04/11] x86/virt/tdx: Allocate refcounts for Dynamic PAMT memory Rick Edgecombe
2026-09-03 15:30 ` Dave Hansen
2026-09-03 18:33 ` Edgecombe, Rick P
2026-09-03 1:51 ` [PATCH v10 05/11] x86/virt/tdx: Handle multiple callers in tdx_pamt_get/put() Rick Edgecombe
[not found] ` <20260903020303.349961F000E9@smtp.kernel.org>
2026-09-03 23:16 ` Edgecombe, Rick P
2026-09-03 1:51 ` [PATCH v10 06/11] KVM: TDX: Allocate PAMT memory for TD and vCPU control structures Rick Edgecombe
2026-09-03 1:51 ` [PATCH v10 07/11] x86/virt/tdx: Add APIs to support Dynamic PAMT ops from KVM's fault path Rick Edgecombe
2026-09-03 1:51 ` [PATCH v10 08/11] KVM: TDX: Get/put PAMT pages when (un)mapping private memory Rick Edgecombe
2026-09-03 1:51 ` [PATCH v10 09/11] x86/virt/tdx: Enable Dynamic PAMT Rick Edgecombe
2026-09-03 15:38 ` Dave Hansen
2026-09-03 1:51 ` [PATCH v10 10/11] Documentation/x86: Add documentation for TDX's " Rick Edgecombe
2026-09-03 15:47 ` Dave Hansen
2026-09-03 19:31 ` Edgecombe, Rick P [this message]
2026-09-03 19:36 ` Dave Hansen
2026-09-03 20:39 ` Edgecombe, Rick P
2026-09-03 20:45 ` Dave Hansen
2026-09-03 1:51 ` [PATCH v10 11/11] x86/virt/tdx: Optimize tdx_pamt_get/put() Rick Edgecombe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=7cd4a38ed0ab1618a90e1afc8d56b450d57a9374.camel@intel.com \
--to=rick.p.edgecombe@intel.com \
--cc=binbin.wu@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=chao.gao@intel.com \
--cc=dave.hansen@intel.com \
--cc=hongyu.ning@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kai.huang@intel.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=nik.borisov@suse.com \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=sohil.mehta@intel.com \
--cc=tglx@kernel.org \
--cc=tony.lindgren@linux.intel.com \
--cc=vannapurve@google.com \
--cc=x86@kernel.org \
--cc=yan.y.zhao@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox