Re: [PATCH v5 3/6] virt: tdx-guest: Calculate the Quote buffer size safely
From: Peter Fang
Date: Mon Sep 28 2026 - 16:54:04 EST
On Mon, Sep 28, 2026 at 08:50:10AM -0700, Dave Hansen wrote:
> On 9/28/26 03:08, Peter Fang wrote:
> > -#define TDX_QUOTE_MAX_LEN (GET_QUOTE_BUF_SIZE - sizeof(struct tdx_quote_buf))
> > +#define TDX_QUOTE_TOTAL_SIZE(n) struct_size_t(struct tdx_quote_buf, data, n)
> >
> > /* struct tdx_quote_buf: Format of Quote request buffer.
> > * @version: Quote format version, filled by TD.
> > @@ -314,7 +314,7 @@ static int tdx_report_new_locked(struct tsm_report *report, void *data)
> >
> > out_len = READ_ONCE(quote_buf->out_len);
> >
> > - if (out_len > TDX_QUOTE_MAX_LEN)
> > + if (TDX_QUOTE_TOTAL_SIZE(out_len) > GET_QUOTE_BUF_SIZE)
> > return -EFBIG;
>
> Gah, this is awful. There are two different literal "data" things:
>
> 1. The function argument: void *data
> 2. The flexible array member: tdx_quote_buf->data[]
>
> Worse, I think the function argument isn't even used, despite being
> passed through at least one level of static, file-local TDX calls.
>
> It becomes a *total* liability since there are so many "data" names
> being tossed around.
>
> I just committed this:
>
> > https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?h=x86/tdx&id=d48b2d347105436365280a3697a265aa4d37e96c
>
> Any reason not to keep it?
Thanks Dave! Your change makes perfect sense to me. I totally agree.
There are so many uses of "data" in this driver.
Dave actually suggested offline removing TDX_QUOTE_TOTAL_SIZE()
altogether because it really doesn't add much value, forces the reader
to look for the macro def, and doesn't even reduce LOC. So the next
version won't have this macro anymore. That also reduces one line of
code which is a small win.