[PATCH v2 2/6] percpu: Bound decrypted storage for all x86 encrypted guests

From: Zack Rusin

Date: Tue Sep 29 2026 - 00:04:58 EST


TDX also needs shared per-CPU buffers. Use X86_MEM_ENCRYPT for their
definition and placement, and provide page-aligned boundaries so the
architecture can convert each CPU's whole section before registration.

Define the boundaries in the SMP template or UP data as appropriate.
Drop the unused DECLARE_PER_CPU_DECRYPTED() macro.

Suggested-by: Kiryl Shutsemau <kas@xxxxxxxxxx>
Link: https://lore.kernel.org/r/aqqGUAX65s4LdJkr@thinkstation
Signed-off-by: Zack Rusin <zack.rusin@xxxxxxxxxxxx>
---
include/asm-generic/vmlinux.lds.h | 12 ++++++++----
include/linux/percpu-defs.h | 7 ++-----
2 files changed, 10 insertions(+), 9 deletions(-)

diff --git a/include/asm-generic/vmlinux.lds.h b/include/asm-generic/vmlinux.lds.h
index 64bc2bfdd2ec..145fcdbbe9db 100644
--- a/include/asm-generic/vmlinux.lds.h
+++ b/include/asm-generic/vmlinux.lds.h
@@ -368,11 +368,13 @@
/*
* .data section
*/
-#if defined(CONFIG_AMD_MEM_ENCRYPT) && !defined(CONFIG_SMP)
+#if defined(CONFIG_X86_MEM_ENCRYPT) && !defined(CONFIG_SMP)
#define DATA_DECRYPTED \
. = ALIGN(PAGE_SIZE); \
+ __start_percpu_decrypted = .; \
*(.data..decrypted) \
- . = ALIGN(PAGE_SIZE);
+ . = ALIGN(PAGE_SIZE); \
+ __end_percpu_decrypted = .;
#else
#define DATA_DECRYPTED *(.data..decrypted)
#endif
@@ -1022,11 +1024,13 @@
* Note: We use a separate section so that only this section gets
* decrypted to avoid exposing more than we wish.
*/
-#ifdef CONFIG_AMD_MEM_ENCRYPT
+#if defined(CONFIG_X86_MEM_ENCRYPT) && defined(CONFIG_SMP)
#define PERCPU_DECRYPTED_SECTION \
. = ALIGN(PAGE_SIZE); \
+ __start_percpu_decrypted = .; \
*(.data..percpu..decrypted) \
- . = ALIGN(PAGE_SIZE);
+ . = ALIGN(PAGE_SIZE); \
+ __end_percpu_decrypted = .;
#else
#define PERCPU_DECRYPTED_SECTION
#endif
diff --git a/include/linux/percpu-defs.h b/include/linux/percpu-defs.h
index dbe3267a0a13..fdb666a1b4de 100644
--- a/include/linux/percpu-defs.h
+++ b/include/linux/percpu-defs.h
@@ -169,13 +169,10 @@
DEFINE_PER_CPU_SECTION(type, name, "..read_mostly")

/*
- * Declaration/definition used for per-CPU variables that should be accessed
+ * Definition used for built-in per-CPU variables that should be accessed
* as decrypted when memory encryption is enabled in the guest.
*/
-#ifdef CONFIG_AMD_MEM_ENCRYPT
-#define DECLARE_PER_CPU_DECRYPTED(type, name) \
- DECLARE_PER_CPU_SECTION(type, name, "..decrypted")
-
+#ifdef CONFIG_X86_MEM_ENCRYPT
#define DEFINE_PER_CPU_DECRYPTED(type, name) \
DEFINE_PER_CPU_SECTION(type, name, "..decrypted")
#else
--
2.53.0