[PATCH v3 4/4] virt: tdx-guest: Allocate Quote buffer dynamically
From: Peter Fang
Date: Wed Jul 29 2026 - 08:48:32 EST
From: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@xxxxxxxxxxxxxxx>
A new TDX module ABI reports the TD Quote size limit in a metadata
field. This size used to be fixed at 128 KB.
The guest driver's Quote buffer is shared with the host VMM. The current
fixed size may be too small for Quotes using schemes such as
post-quantum cryptography (PQC), where larger certificate chains can
increase the Quote size significantly.
Allocate the Quote buffer based on the reported limit. This avoids
wasting memory on platforms that do not require larger Quotes. Older
platforms fall back to the default 128 KB buffer.
As a result, the maximum size of the "outblob" file in configfs-tsm now
depends on the TDX module.
Because the Quote buffer must be physically contiguous, its size is
bound by the buddy allocator's maximum page order (4 MB), which should
be sufficient for current attestation needs.
Signed-off-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@xxxxxxxxxxxxxxx>
Signed-off-by: Peter Fang <peter.fang@xxxxxxxxx>
---
v3:
- Split out from the v2 "Allocate Quote buffer dynamically" patch. Add
the dynamic buffer feature on top of the refactoring. [Dave]
- Improve the get_quote_buf_size() pattern for better readability.
[Dave]
- Drop __GFP_NOWARN so an allocation failure warns. [Dave, Rick, Kiryl]
- Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
reworked.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 24 ++++++++++++++++++++++--
1 file changed, 22 insertions(+), 2 deletions(-)
diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index 3d3f79ab45af..8919b1a1154e 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -162,7 +162,7 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
* DICE-based attestation uses layered evidence that requires
* larger Quote size (~100K).
*/
-#define GET_QUOTE_BUF_SIZE SZ_128K
+#define GET_QUOTE_DEFAULT_BUF_SIZE SZ_128K
#define GET_QUOTE_CMD_VER 1
@@ -222,11 +222,31 @@ static void free_quote_buf(void *buf, size_t len)
free_pages_exact(buf, len);
}
+/* Return a buffer size large enough to hold a Quote */
+static size_t get_quote_buf_size(void)
+{
+ u32 quote_size = tdx_get_max_quote_size();
+
+ /*
+ * Older TDX modules do not report a maximum Quote size, so use
+ * the default.
+ */
+ if (!quote_size)
+ return GET_QUOTE_DEFAULT_BUF_SIZE;
+
+ /* The reported size does not include the buffer header */
+ return PAGE_ALIGN(TDX_QUOTE_BUF_LEN(quote_size));
+}
+
static void *alloc_quote_buf(size_t len)
{
unsigned int count = len >> PAGE_SHIFT;
void *addr;
+ /*
+ * This fails if the requested size exceeds the buddy allocator's
+ * maximum order (order-10, 4MB).
+ */
addr = alloc_pages_exact(len, GFP_KERNEL | __GFP_ZERO);
if (!addr)
return NULL;
@@ -416,7 +436,7 @@ static int __init tdx_guest_init(void)
if (ret)
goto deinit_mr;
- quote_data_len = GET_QUOTE_BUF_SIZE;
+ quote_data_len = get_quote_buf_size();
quote_data = alloc_quote_buf(quote_data_len);
if (!quote_data) {
pr_err("Failed to allocate Quote buffer\n");
--
2.53.0