Re: [PATCH v2 2/6] percpu: Bound decrypted storage for all x86 encrypted guests

From: Peter Zijlstra

Date: Tue Sep 29 2026 - 03:55:10 EST


On Tue, Sep 29, 2026 at 12:02:51AM -0400, Zack Rusin wrote:
> TDX also needs shared per-CPU buffers. Use X86_MEM_ENCRYPT for their
> definition and placement, and provide page-aligned boundaries so the
> architecture can convert each CPU's whole section before registration.
>
> Define the boundaries in the SMP template or UP data as appropriate.
> Drop the unused DECLARE_PER_CPU_DECRYPTED() macro.
>
> Suggested-by: Kiryl Shutsemau <kas@xxxxxxxxxx>
> Link: https://lore.kernel.org/r/aqqGUAX65s4LdJkr@thinkstation
> Signed-off-by: Zack Rusin <zack.rusin@xxxxxxxxxxxx>
> ---
> include/asm-generic/vmlinux.lds.h | 12 ++++++++----
> include/linux/percpu-defs.h | 7 ++-----
> 2 files changed, 10 insertions(+), 9 deletions(-)
>
> diff --git a/include/asm-generic/vmlinux.lds.h b/include/asm-generic/vmlinux.lds.h
> index 64bc2bfdd2ec..145fcdbbe9db 100644
> --- a/include/asm-generic/vmlinux.lds.h
> +++ b/include/asm-generic/vmlinux.lds.h

> @@ -1022,11 +1024,13 @@
> * Note: We use a separate section so that only this section gets
> * decrypted to avoid exposing more than we wish.
> */
> -#ifdef CONFIG_AMD_MEM_ENCRYPT
> +#if defined(CONFIG_X86_MEM_ENCRYPT) && defined(CONFIG_SMP)
> #define PERCPU_DECRYPTED_SECTION \
> . = ALIGN(PAGE_SIZE); \
> + __start_percpu_decrypted = .; \
> *(.data..percpu..decrypted) \
> - . = ALIGN(PAGE_SIZE);
> + . = ALIGN(PAGE_SIZE); \
> + __end_percpu_decrypted = .;
> #else
> #define PERCPU_DECRYPTED_SECTION
> #endif

So you're page aligning something that will get different protection and
will thus shatter large pages?

That is somewhat uncool. We like large pages, large pages are good.