Re: [RFC PATCH 01/15] x86/tdx: Export tdg_vm_rd() for tdx-guest module
From: Xu Yilun
Date: Thu Oct 01 2026 - 08:56:37 EST
On Wed, Sep 30, 2026 at 03:13:40PM -0700, Peter Fang wrote:
> On Thu, Sep 24, 2026 at 12:10:18PM +0800, Zhenzhong Duan wrote:
> > Export tdg_vm_rd() to allow the tdx-guest driver module to directly
> > read TD-scoped metadata fields from the Trust Domain Control Structure
> > (TDCS) via TDG.VM.RD TDCALL.
> >
> > Since tdg_vm_rd() is read-only and cannot cause harm, exporting it
> > directly is simpler and more flexible. This allows the tdx-guest driver
> > to read any TDCS field it needs.
> >
> > In a following patch, the tdx-guest driver will use tdg_vm_rd() to read
> > TDCS_CONFIG_FLAGS field directly.
>
> Can this be a separate helper? I'm adding another helper for
> TDCS_QUOTE_MAX_SIZE [1]. I think maybe their patterns should stay consistent.
>
> Yilun, any thoughts on this?
There was a helper in the series before this public RFC, but was then
dropped, something like:
int tdx_get_config_flags(u64 *flags)
{
u64 sret;
sret = tdg_vm_rd(TDCS_CONFIG_FLAGS, flags);
if (sret)
return -EIO;
return 0;
}
EXPORT_SYMBOL_FOR_MODULES(tdx_get_config_flags, "tdx-guest");
The concern is how risky is the tdg_vm_rd() export, and how it impacts
the existing tdg_vm_rd() usage, and the tdh_mng_rd() export which reads
the same data set on host.
My initial concern about the cons of tdg_vm_rd() export are, the
SEAMCALL reads any TDCS fields, some of them are writable by tdg_vm_wr()
and there is no synchronization between them, so seems not a good kAPI.
Reducing the scope to read-only fields (e.g. TDCS_CONFIG_FLAGS) may be a
good start.
Now there are 2 cases in flight: tdx_get_max_quote_size() helper in DICE
and tdg_vm_rd() export here. Maybe we need more cases to see which is
better but anyway I agree we'd better stay consistent now.
>
> Thanks,
> Peter
>
> [1] https://lore.kernel.org/kvm/20260930103739.2851980-6-peter.fang@xxxxxxxxx/
>
> >
> > Signed-off-by: Zhenzhong Duan <zhenzhong.duan@xxxxxxxxx>