Re: [PATCH v2 16/17] KVM: TDX: Add in-kernel Quote generation
From: Peter Fang
Date: Fri Jul 10 2026 - 05:40:01 EST
On Fri, Jul 10, 2026 at 12:01:41PM +0300, Nikolay Borisov wrote:
>
>
> On 7/4/26 08:43, Peter Fang wrote:
> > On Wed, Jul 01, 2026 at 11:45:53AM -0700, Edgecombe, Rick P wrote:
> > > On Wed, 2026-07-01 at 10:25 -0700, Sean Christopherson wrote:
> > > > > > That is a good question. The answer is partly historical reasons, but I
> > > > > > think the pros/cons don’t really move the needle too much.
> > > > > >
> > > > > > The main benefit of doing it with the host in the loop is that the guest
> > > > > > side TDVMCALL quoting interface can stay the same. There is also a wrinkle
> > > > > > in that there is a limited HW resource involved in the quoting,
> > > >
> > > > What is this magical resource?
> > >
> > > It's a HW crypto thing. I'll let Peter explain more.
> >
> > It's called S3M (Secured Startup Services). There was once a public
> > document about it, but it was removed for some reason. It basically
>
> Are you referring to this:
> https://www.scribd.com/document/970439243/S3M-Intel-White-Paper ?
Yep. The internet never forgets :)
>
> <snip>