[PATCH v5 3/6] virt: tdx-guest: Calculate the Quote buffer size safely

From: Peter Fang

Date: Mon Sep 28 2026 - 06:16:44 EST


struct tdx_quote_buf has a trailing flexible array member.
struct_size_t() calculates the size of this kind of struct safely. It
handles overflow, which helps since the Quote size comes from the host.

Use it to rewrite the bounds check logic, since

"header_size + data_size > buf_size"

... is more readable than "data_size > buf_size - header_size".

This also prepares for a later change that needs the same
"header_size + data_size" calculation for the Quote buffer size.

AI was used to review code.

Signed-off-by: Peter Fang <peter.fang@xxxxxxxxx>
Reviewed-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@xxxxxxxxxxxxxxx>
Reviewed-by: Tony Lindgren <tony.lindgren@xxxxxxxxxxxxxxx>
Reviewed-by: Xiaoyao Li <xiaoyao.li@xxxxxxxxx>
Reviewed-by: Binbin Wu <binbin.wu@xxxxxxxxxxxxxxx>
Reviewed-by: Kiryl Shutsemau (Meta) <kas@xxxxxxxxxx>
---
v5:
- Rename TDX_QUOTE_BUF_LEN() to TDX_QUOTE_TOTAL_SIZE(). [Dave]
- Add Kiryl's Reviewed-by.
v4:
- No code changes.
- Add Reviewed-by tags. [Sathya, Tony, Xiaoyao, Binbin]
v3:
- Split out the use of struct_size_t() for buffer length from the v2
"Allocate Quote buffer dynamically" patch to refactor first. [Dave]
- Drop the Reviewed-by tags from v2 (Kiryl, Binbin) as the patch was
reworked.
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index 896eb0a09c4a..b30439584886 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -170,7 +170,7 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
#define GET_QUOTE_SUCCESS 0
#define GET_QUOTE_IN_FLIGHT 0xffffffffffffffff

-#define TDX_QUOTE_MAX_LEN (GET_QUOTE_BUF_SIZE - sizeof(struct tdx_quote_buf))
+#define TDX_QUOTE_TOTAL_SIZE(n) struct_size_t(struct tdx_quote_buf, data, n)

/* struct tdx_quote_buf: Format of Quote request buffer.
* @version: Quote format version, filled by TD.
@@ -314,7 +314,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)

out_len = READ_ONCE(quote_buf->out_len);

- if (out_len > TDX_QUOTE_MAX_LEN)
+ if (TDX_QUOTE_TOTAL_SIZE(out_len) > GET_QUOTE_BUF_SIZE)
return -EFBIG;

buf = kvmemdup(quote_buf->data, out_len, GFP_KERNEL);
--
2.53.0