[PATCH v3 10/10] x86/virt/tdx: Verify structure member sizes against metadata field IDs
From: Chao Gao
Date: Wed Sep 30 2026 - 01:41:48 EST
The TDX module reports its capabilities and limits as a set of metadata
fields, each identified by a field ID, and TDH.SYS.RD reads one field by
its ID. TDH.SYS.RD returns the value as a u64, but metadata fields are not
all 64 bits wide. A field ID therefore encodes the field's size into
bits 33:32.
The kernel mirrors these fields in C structures, and each member's size
must match the size encoded in the field ID. TDX_SYSINFO_MAP() stores the
member size and uses it to decide how many bytes to copy from the value
returned by TDH.SYS.RD. The size in the field ID is never consulted, so any
mismatch goes unnoticed. Declaring a u32 member for a 64-bit field, for
example, would silently store only its low 4 bytes.
Add macros to extract the size encoded in a field ID and check it against
the member size. The check happens at build time, so it catches a wrongly
typed member with no runtime cost.
BUILD_BUG_ON() cannot be used in a structure initializer, so use
BUILD_BUG_ON_ZERO() and add its zero result to the .size initializer. This
performs the build-time check without changing the stored size.
An alternative would be to leave the size bits out of the field ID
definitions and construct the IDs from the member sizes, which makes a
mismatch impossible. But the TDX module ABI definitions list the full field
IDs, and definitions with the size bits stripped would match nothing in the
docs, making them harder to verify. Keep the IDs exactly as documented and
check the size they encode against the C type instead.
AI was used under supervision to review code and workshop logs. It
suggested extracting TDX_FIELD_SIZE_CHECK() instead of open coding the
check in TDX_SYSINFO_MAP(), to keep the .size line from being too long.
Signed-off-by: Chao Gao <chao.gao@xxxxxxxxx>
---
v3:
- Add background on the size bits encoded in a field ID. [Rick]
- Add rationale for checking the size in the field ID instead of
building the ID from the member size. [Rick]
- Squash TDX_MD_FIELD_ELE_SIZE_CODE() and TDX_MD_FIELD_ELE_SIZE() into a
single TDX_FIELD_SIZE(). [Rick]
---
arch/x86/virt/vmx/tdx/tdx.c | 12 +++++++++++-
arch/x86/virt/vmx/tdx/tdx.h | 7 +++++++
2 files changed, 18 insertions(+), 1 deletion(-)
diff --git a/arch/x86/virt/vmx/tdx/tdx.c b/arch/x86/virt/vmx/tdx/tdx.c
index e7d4fc3f350f..360875efb263 100644
--- a/arch/x86/virt/vmx/tdx/tdx.c
+++ b/arch/x86/virt/vmx/tdx/tdx.c
@@ -427,11 +427,21 @@ static int __read_sys_metadata_table(const struct field_mapping *mappings,
#define read_sys_metadata_table(_mappings, _data) \
__read_sys_metadata_table(_mappings, ARRAY_SIZE(_mappings), _data)
+/*
+ * The size encoded in the field ID and the size of the destination C
+ * member must agree.
+ */
+#define TDX_FIELD_SIZE_CHECK(_field, _type, _member) \
+ BUILD_BUG_ON_ZERO(sizeof_field(_type, _member) != \
+ TDX_FIELD_SIZE(_field))
+
#define TDX_SYSINFO_MAP(_field, _type, _member) \
{ \
.field_id = _field, \
.offset = offsetof(_type, _member), \
- .size = sizeof_field(_type, _member), \
+ .size = sizeof_field(_type, _member) + \
+ TDX_FIELD_SIZE_CHECK( \
+ _field, _type, _member), \
}
#define TDX_SYSINFO_MAP_VERSION(_field_id, _member) \
diff --git a/arch/x86/virt/vmx/tdx/tdx.h b/arch/x86/virt/vmx/tdx/tdx.h
index e41fc5e4925e..b3694a80a0c8 100644
--- a/arch/x86/virt/vmx/tdx/tdx.h
+++ b/arch/x86/virt/vmx/tdx/tdx.h
@@ -91,6 +91,13 @@
/* Class "TDX Module Handoff" */
#define TDX_FIELD_MODULE_HV 0x8900000100000000ULL
+/*
+ * Bits 33:32 of a field ID hold the log2 of the metadata field size in
+ * bytes. See "Metadata Field Identifier" in the Intel TDX Module ABI
+ * Specification.
+ */
+#define TDX_FIELD_SIZE(field_id) (1 << (((field_id) >> 32) & 0x3))
+
/* TDX page types */
#define PT_NDA 0x0
#define PT_RSVD 0x1
--
2.52.0