Re: [PATCH v5 5/6] x86/tdx: Add a helper to query maximum Quote size

From: Edgecombe, Rick P

Date: Mon Sep 28 2026 - 14:45:03 EST


On Mon, 2026-09-28 at 03:08 -0700, Peter Fang wrote:
> TDX attestation report ("Quote") sizes can grow with newer crypto
> algorithms, so guests can no longer rely on a fixed-size buffer for the
> Quote.
>
> The TDX module added a new ABI that reports the largest possible Quote
> size via a metadata field [1]. Add a helper to query the size instead of
> exposing tdg_vm_rd() directly, as it can read arbitrary metadata fields.
>
> The reported size covers every Quote type the platform can produce,
> including SGX-based Quotes.
>
> Thanks to Xu Yilun for suggesting this in an off-list discussion.

Suggesting what?

>
> AI was used under supervision to collect/apply feedback, review code and
> workshop logs.
>
> [1] Intel TDX Module ABI Definitions, August 2026, TD-scope metadata
> field "TD_QUOTE_MAX_SIZE"
>
> Signed-off-by: Peter Fang <peter.fang@xxxxxxxxx>
> ---
> v5:
> - Drop unused EXPORT_SYMBOL_GPL(). [Dave]
> - Use an error code to report failure. [Dave]
> - Drop the u32 cast. [Dave]
> - Replace the kernel-doc comment with a one-liner. [Dave]
> - Drop the RB tags, as the code changed substantially.
> v4:
> - Update the TDCS_QUOTE_MAX_SIZE encoding to 0x9010000200000007. [1]
> - Provide documentation for the metadata field. [Rick, Kiryl]
> - Document that the reported size covers every Quote type. [Xiaoyao]
> - Document that a module update does not change the reported size.
> [Tony]
> - Add Tony's Reviewed-by.
> v3:
> - No code changes. Add Binbin's Reviewed-by.
> v2:
> - Keep the explicit (u32) cast to document the metadata field width.
> [Binbin]
> - Note that Xu Yilun's suggestion was made in an off-list discussion.
> [Sathya]
> - Drop the Assisted-by tags, as the code was not written by AI.
> ---
> arch/x86/coco/tdx/tdx.c | 16 ++++++++++++++++
> arch/x86/include/asm/shared/tdx.h | 1 +
> arch/x86/include/asm/tdx.h | 2 ++
> 3 files changed, 19 insertions(+)
>
> diff --git a/arch/x86/coco/tdx/tdx.c b/arch/x86/coco/tdx/tdx.c
> index bcaf4180a8db..323e1efc78ea 100644
> --- a/arch/x86/coco/tdx/tdx.c
> +++ b/arch/x86/coco/tdx/tdx.c
> @@ -198,6 +198,22 @@ u64 tdx_hcall_get_quote(void *buf, size_t size)
> }
> EXPORT_SYMBOL_GPL(tdx_hcall_get_quote);
>
> +/*
> + * Ask the TDX module what the largest possible Quote might be.

How about adding the "largest on the host platform" detail to this comment.

> + */
> +int tdx_get_max_quote_size(u64 *max_quote_size)
> +{
> + u64 err;
> +
> + err = tdg_vm_rd(TDCS_QUOTE_MAX_SIZE, max_quote_size);
> +
> + /* Old modules do not support this. Tell the caller. */
> + if (err)
> + return -EINVAL;
> +
> + return 0;
> +}
> +
> static void __noreturn tdx_panic(const char *msg)
> {
> struct tdx_module_args args = {
> diff --git a/arch/x86/include/asm/shared/tdx.h b/arch/x86/include/asm/shared/tdx.h
> index f20e91d7ac35..6f106d4b1a58 100644
> --- a/arch/x86/include/asm/shared/tdx.h
> +++ b/arch/x86/include/asm/shared/tdx.h
> @@ -50,6 +50,7 @@
> /* TDX TD-Scope Metadata. To be used by TDG.VM.WR and TDG.VM.RD */
> #define TDCS_CONFIG_FLAGS 0x1110000300000016
> #define TDCS_TD_CTLS 0x1110000300000017
> +#define TDCS_QUOTE_MAX_SIZE 0x9010000200000007
> #define TDCS_NOTIFY_ENABLES 0x9100000000000010
> #define TDCS_TOPOLOGY_ENUM_CONFIGURED 0x9100000000000019
>
> diff --git a/arch/x86/include/asm/tdx.h b/arch/x86/include/asm/tdx.h
> index a3c37d61e676..6a465827d8f9 100644
> --- a/arch/x86/include/asm/tdx.h
> +++ b/arch/x86/include/asm/tdx.h
> @@ -83,6 +83,8 @@ int tdx_mcall_extend_rtmr(u8 index, u8 *data);
>
> u64 tdx_hcall_get_quote(void *buf, size_t size);
>
> +int tdx_get_max_quote_size(u64 *max_quote_size);
> +
> void __init tdx_dump_attributes(u64 td_attr);
> void __init tdx_dump_td_ctls(u64 td_ctls);
>