Re: [PATCH v3 10/10] x86/virt/tdx: Verify structure member sizes against metadata field IDs

From: Chao Gao

Date: Thu Oct 01 2026 - 09:28:34 EST


On Thu, Oct 01, 2026 at 08:29:53AM +0800, Edgecombe, Rick P wrote:
>On Tue, 2026-09-29 at 22:38 -0700, Chao Gao wrote:
>> +/*
>> + * Bits 33:32 of a field ID hold the log2 of the metadata field size in
>> + * bytes. See "Metadata Field Identifier" in the Intel TDX Module ABI
>> + * Specification.
>> + */
>> +#define TDX_FIELD_SIZE(field_id) (1 << (((field_id) >> 32) & 0x3))
>> +
>
>Would it maybe be clearer to just encode the 4 possible cases? I prompted an AI
>with "...maybe the 4 cases could just be encoded instead of the masking and bit
>shifting" and a bit of followup, and it generated:
>
>#define TDX_FIELD_SIZE_MASK GENMASK_ULL(33, 32)
>
>#define TDX_FIELD_SIZE_CODE(_size) \
> ((_size) == 1 ? 0 : \
> (_size) == 2 ? BIT_ULL(32) : \
> (_size) == 4 ? BIT_ULL(33) : \
> (_size) == 8 ? TDX_FIELD_SIZE_MASK : \
> ~0ULL)
>
>#define TDX_FIELD_SIZE_CHECK(_field, _type, _member) \
> BUILD_BUG_ON_ZERO(((u64)(_field) & TDX_FIELD_SIZE_MASK) != \
> TDX_FIELD_SIZE_CODE(sizeof_field(_type, _member)))
>
>Reverses the format being checked. Looks a bit simpler to me.

The above drops the bit shifts and the 0x3 masking from my one-liner. So, yes,
it is easier to follow. I will switch to this approach unless someone objects.