Re: [PATCH v4 1/4] KVM: TDX: Track configurable CPUID bits allowed by KVM

From: Edgecombe, Rick P

Date: Mon Sep 28 2026 - 19:59:06 EST


On Mon, 2026-09-28 at 16:08 +0800, Binbin Wu wrote:
> > > I don't know why the CPUID is disconnected with the MSR.
> > > But this bit is present on the host, I think we can add it to the
> > > allowlist.
> >
> > I have opposite opinion. Since 1) this feature is related to hardware
> > processor PIN, 2) KVM never advertise it to normal VMs, and 3) no usage in
> > kernel for this feature. I think no TD relies on it and don't allow it
> > should be OK.

Yea, I lean towards educated guesses that userspace/guests are not relying on
these kind of features. If we guess wrong, we can revert the change. If we allow
it for years, then we have another line in the allow list forever that maybe
nobody is using.

>
> My consideration was maybe some userspace could set this bit.
>
> But userspace is expected to consult KVM_TDX_CAPABILITIES for the configurable
> bits before invoking KVM_TDX_INIT_VM

If a guest is already using it, then even if the bit disappears from
KVM_TDX_CAPABILITIES it could cause a regression when it doesn't get configured
in the guest.

> , regardless of this patch series, there is no risk to break userspace, except
> for CORE_CAPABILITIES, which is the only
> special case as it was defined as fixed-1.
>
> I think there is no need to add XTPR to the allow list either.