Re: [PATCH v2 1/3] x86/tdx: Share tdx_panic() with the EFI stub

From: Kiryl Shutsemau

Date: Fri Sep 25 2026 - 07:45:25 EST


On Fri, Sep 25, 2026 at 09:51:39AM +0200, Ard Biesheuvel wrote:
> Move the implementation of tdx_panic() into the source file that is
> shared with the decompressor and the EFI stub.
>
> Use memcpy() and strnlen() instead of strtomem_pad(), as the latter does
> not exist in the early boot code. Avoid fortify instrumentation in the
> decompressor/EFI stub by #define'ing __NO_FORTIFY before including
> tdx-shared.c
>
> Note that __tdx_hypercall() may call __tdx_hypercall_failed() if the
> hypercall returns with an error (while it should never return to begin
> with). __tdx_hypercall_failed() calls the decompressor's error()
> routine, which prints a message and then loops forever.
>
> When called from the EFI stub, this error() call may attempt to use port
> I/O to the default serial port rather than the TDX hypercalls which the
> decompressor uses normally to print diagnostics to the console, but this
> is fine: given that this situation only occurs after a catastrophic
> error, and a subsequent spurious return from tdx_panic(), whether
> error() uses port I/O or not is rather moot at that point, as long as it
> never returns.
>
> Signed-off-by: Ard Biesheuvel <ardb@xxxxxxxxxx>

Reviewed-by: Kiryl Shutsemau (Meta) <kas@xxxxxxxxxx>

--
Kiryl Shutsemau / Kirill A. Shutemov