Re: [PATCH v4 2/4] KVM: TDX: Report CORE_CAPABILITIES as configurable

From: Binbin Wu

Date: Tue Sep 22 2026 - 20:04:19 EST


On 9/23/2026 5:11 AM, Edgecombe, Rick P wrote:
> On Thu, 2026-09-17 at 15:25 +0800, Binbin Wu wrote:
>> Add CORE_CAPABILITIES (CPUID.0x7.0.EDX[30]) to KVM's allowlist of TDX
>> directly configurable CPUID feature bits, even though KVM doesn't support
>> MSR_IA32_CORE_CAPS for TDX guests, to accommodate the legacy TDX module
>> definition and userspace's stale knowledge of it.
>>
>> Older TDX specifications define the CORE_CAPABILITIES CPUID bit as
>> fixed-1, so userspace may expect the bit to be enabled for TDs.  #VE
>> reduction turns it into a directly configurable bit, so leaving it out of
>> the allowlist would make the bit impossible to enable once KVM starts
>> validating userspace's CPUID input, i.e. would be a surprising behavior
>> change for such userspace.
>
> Since #VE reduction is controlled from the guest side, this is a bit confusing.
> Turning on #VE reduction can't change CORE_CAPABILITIES configurability status
> because it's too late. You mean that this was changed from fixed-1 to
> configurable to support #VE reduction arch? (I'm not sure why though).

Yes, a fixed-1 bit was changed to directly configurable bit if it is a
#VE reduction bit, regardless the guest enables #VE reduction or not.

I.e. CORE_CAPABILITIES was fixed-1 bit, but now it's directly configurable
by the definition of the specs.