[RFC PATCH 02/15] x86/tdx: Add TDCM hypercall wrapper for TDX Connect
From: Zhenzhong Duan
Date: Thu Sep 24 2026 - 00:11:16 EST
TDX Connect is a TDX feature that enables secure device assignment,
allowing a TDX guest to directly interact with TEE-IO capable devices.
The TEE-IO Device Control and Management (TDCM) hypercall
(TDG.VP.VMCALL<TDCM>, defined in TDX GHCI v2.0 specification) is the
primary interface through which a TDX guest issues device management
commands to the host. The host processes these commands and returns
responses via a shared memory buffer.
Abstract the underlying leaf call and pass the shared buffer physical
address as a decrypted mapping. Add a runtime page alignment check
for the buffer to enforce correct usage.
Place the implementation in a separate tdx_connect.c file to keep TDX
Connect specific code isolated from core tdx.c.
CONFIG_TDX_CONNECT_GUEST referenced in the header guard will be
introduced in a later patch in this series.
Signed-off-by: Zhenzhong Duan <zhenzhong.duan@xxxxxxxxx>
---
arch/x86/coco/tdx/Makefile | 2 ++
arch/x86/coco/tdx/tdx_connect.c | 32 +++++++++++++++++++++++++++++++
arch/x86/include/asm/shared/tdx.h | 1 +
arch/x86/include/asm/tdx.h | 4 ++++
4 files changed, 39 insertions(+)
create mode 100644 arch/x86/coco/tdx/tdx_connect.c
diff --git a/arch/x86/coco/tdx/Makefile b/arch/x86/coco/tdx/Makefile
index b3c47d3700e2..2ab2dbbdd3d2 100644
--- a/arch/x86/coco/tdx/Makefile
+++ b/arch/x86/coco/tdx/Makefile
@@ -1,3 +1,5 @@
# SPDX-License-Identifier: GPL-2.0
obj-y += debug.o tdcall.o tdx.o tdx-shared.o
+
+obj-$(CONFIG_TDX_CONNECT_GUEST) += tdx_connect.o
diff --git a/arch/x86/coco/tdx/tdx_connect.c b/arch/x86/coco/tdx/tdx_connect.c
new file mode 100644
index 000000000000..0c6ca650771a
--- /dev/null
+++ b/arch/x86/coco/tdx/tdx_connect.c
@@ -0,0 +1,32 @@
+// SPDX-License-Identifier: GPL-2.0
+/* Copyright (C) 2026 Intel Corporation */
+
+#undef pr_fmt
+#define pr_fmt(fmt) "tdx_connect: " fmt
+
+#include <linux/io.h>
+#include <asm/tdx.h>
+#include <linux/mm.h>
+
+/*
+ * tdx_hcall_tdcm - Send a TDCM command to the host via TDG.VP.VMCALL<TDCM>.
+ *
+ * @devid: Device identifier of the target TEE-IO device.
+ * @buf: Shared, directly mapped buffer containing the TDCM command on
+ * input and the host response on output.
+ * @size: Size of @buf in bytes.
+ * @vector: Event notification interrupt vector, or 0 for synchronous operation.
+ *
+ * The buffer physical address is passed to the host with decrypted/shared
+ * mark.
+ *
+ * Returns 0 on success or a TDX VMCALL status code on failure. See
+ * TDG.VP.VMCALL<TDCM> in the TDX GHCI v2.0 specification for status codes.
+ */
+u64 tdx_hcall_tdcm(u16 devid, void *buf, size_t size, u8 vector)
+{
+ WARN_ON_ONCE(!PAGE_ALIGNED(buf) || !PAGE_ALIGNED(size));
+
+ return _tdx_hypercall(TDVMCALL_TDCM, devid, cc_mkdec(virt_to_phys(buf)), size, vector);
+}
+EXPORT_SYMBOL_FOR_MODULES(tdx_hcall_tdcm, "tdx-guest");
diff --git a/arch/x86/include/asm/shared/tdx.h b/arch/x86/include/asm/shared/tdx.h
index f20e91d7ac35..f46a3171a512 100644
--- a/arch/x86/include/asm/shared/tdx.h
+++ b/arch/x86/include/asm/shared/tdx.h
@@ -74,6 +74,7 @@
#define TDVMCALL_GET_QUOTE 0x10002
#define TDVMCALL_REPORT_FATAL_ERROR 0x10003
#define TDVMCALL_SETUP_EVENT_NOTIFY_INTERRUPT 0x10004ULL
+#define TDVMCALL_TDCM 0x10007
/*
* TDG.VP.VMCALL Status Codes (returned in R10)
diff --git a/arch/x86/include/asm/tdx.h b/arch/x86/include/asm/tdx.h
index 884bb8067521..df4496ef8a6a 100644
--- a/arch/x86/include/asm/tdx.h
+++ b/arch/x86/include/asm/tdx.h
@@ -85,6 +85,10 @@ int tdx_mcall_extend_rtmr(u8 index, u8 *data);
u64 tdx_hcall_get_quote(u8 *buf, size_t size);
+#ifdef CONFIG_TDX_CONNECT_GUEST
+u64 tdx_hcall_tdcm(u16 devid, void *buf, size_t size, u8 vector);
+#endif
+
void __init tdx_dump_attributes(u64 td_attr);
void __init tdx_dump_td_ctls(u64 td_ctls);
--
2.52.0