[tip: x86/tdx] x86/tdx: Restrict attestation exports to the tdx-guest driver
From: tip-bot2 for Nikolay Borisov
Date: Mon Sep 28 2026 - 11:57:22 EST
The following commit has been merged into the x86/tdx branch of tip:
Commit-ID: a49e2d257594931772ab8f0024708c3076f3aa1d
Gitweb: https://git.kernel.org/tip/a49e2d257594931772ab8f0024708c3076f3aa1d
Author: Nikolay Borisov <nik.borisov@xxxxxxxx>
AuthorDate: Fri, 25 Sep 2026 16:18:08 +03:00
Committer: Dave Hansen <dave.hansen@xxxxxxxxxxxxxxx>
CommitterDate: Mon, 28 Sep 2026 08:51:45 -07:00
x86/tdx: Restrict attestation exports to the tdx-guest driver
There are few remaining attestation related functions which are exported
via EXPORT_SYMBOL_GPL, yet they are solely used by the 'tdx-guest'
driver. Let's just limit their visibility by using the namespaced
EXPORT_SYMBOL_FOR_MODULES.
Suggested-by: Michal Koutný <mkoutny@xxxxxxxx>
Signed-off-by: Nikolay Borisov <nik.borisov@xxxxxxxx>
Signed-off-by: Dave Hansen <dave.hansen@xxxxxxxxxxxxxxx>
Reviewed-by: Kiryl Shutsemau (Meta) <kas@xxxxxxxxxx>
Reviewed-by: Xiaoyao Li <xiaoyao.li@xxxxxxxxx>
Link: https://patch.msgid.link/20260925131808.2415177-1-nik.borisov@xxxxxxxx
---
arch/x86/coco/tdx/tdx.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/arch/x86/coco/tdx/tdx.c b/arch/x86/coco/tdx/tdx.c
index f904a63..a38e444 100644
--- a/arch/x86/coco/tdx/tdx.c
+++ b/arch/x86/coco/tdx/tdx.c
@@ -139,7 +139,7 @@ int tdx_mcall_get_report0(u8 *reportdata, u8 *tdreport)
return 0;
}
-EXPORT_SYMBOL_GPL(tdx_mcall_get_report0);
+EXPORT_SYMBOL_FOR_MODULES(tdx_mcall_get_report0, "tdx-guest");
/**
* tdx_mcall_extend_rtmr() - Wrapper to extend RTMR registers using
@@ -175,7 +175,7 @@ int tdx_mcall_extend_rtmr(u8 index, u8 *data)
return 0;
}
-EXPORT_SYMBOL_GPL(tdx_mcall_extend_rtmr);
+EXPORT_SYMBOL_FOR_MODULES(tdx_mcall_extend_rtmr, "tdx-guest");
/**
* tdx_hcall_get_quote() - Wrapper to request TD Quote using GetQuote
@@ -196,7 +196,7 @@ u64 tdx_hcall_get_quote(u8 *buf, size_t size)
/* Since buf is a shared memory, set the shared (decrypted) bits */
return _tdx_hypercall(TDVMCALL_GET_QUOTE, cc_mkdec(virt_to_phys(buf)), size, 0, 0);
}
-EXPORT_SYMBOL_GPL(tdx_hcall_get_quote);
+EXPORT_SYMBOL_FOR_MODULES(tdx_hcall_get_quote, "tdx-guest");
static void __noreturn tdx_panic(const char *msg)
{