Re: [PATCH v4 1/4] KVM: TDX: Track configurable CPUID bits allowed by KVM
From: Binbin Wu
Date: Mon Sep 28 2026 - 20:20:04 EST
On 9/29/2026 7:58 AM, Edgecombe, Rick P wrote:
>
>>
>> My consideration was maybe some userspace could set this bit.
>>
>> But userspace is expected to consult KVM_TDX_CAPABILITIES for the configurable
>> bits before invoking KVM_TDX_INIT_VM
>
> If a guest is already using it, then even if the bit disappears from
> KVM_TDX_CAPABILITIES it could cause a regression when it doesn't get configured
> in the guest.
The precondition is these excluded features bits are not in kvm_cpu_caps[], i.e.
these features are
- Obsolete or
- Not supported by KVM, there would have been issues if a guest is
using them.
I will add the precondition when describe it in the change log.
>
>> , regardless of this patch series, there is no risk to break userspace, except
>> for CORE_CAPABILITIES, which is the only
>> special case as it was defined as fixed-1.
>>
>> I think there is no need to add XTPR to the allow list either.
>