[tip: x86/tdx] virt: tdx-guest: Calculate the Quote buffer size safely

From: tip-bot2 for Peter Fang

Date: Fri Oct 02 2026 - 07:55:27 EST


The following commit has been merged into the x86/tdx branch of tip:

Commit-ID: b37769d84f321cbb524acc23d0f5bbda4ea1f574
Gitweb: https://git.kernel.org/tip/b37769d84f321cbb524acc23d0f5bbda4ea1f574
Author: Peter Fang <peter.fang@xxxxxxxxx>
AuthorDate: Wed, 30 Sep 2026 03:30:52 -07:00
Committer: Dave Hansen <dave.hansen@xxxxxxxxxxxxxxx>
CommitterDate: Fri, 02 Oct 2026 04:38:52 -07:00

virt: tdx-guest: Calculate the Quote buffer size safely

struct tdx_quote_buf has a trailing flexible array member.
struct_size() calculates the size of this kind of struct safely. It
handles overflow, which helps since the Quote size comes from the host.

Use it to rewrite the bounds check logic, since

"header_size + data_size > buf_size"

... is more readable than "data_size > buf_size - header_size".

This also prepares for a later change that needs the same
"header_size + data_size" calculation for the Quote buffer size.

AI was used under supervision to collect/apply feedback, review code and
workshop logs.

Signed-off-by: Peter Fang <peter.fang@xxxxxxxxx>
Signed-off-by: Dave Hansen <dave.hansen@xxxxxxxxxxxxxxx>
Reviewed-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@xxxxxxxxxxxxxxx>
Reviewed-by: Tony Lindgren <tony.lindgren@xxxxxxxxxxxxxxx>
Reviewed-by: Xiaoyao Li <xiaoyao.li@xxxxxxxxx>
Reviewed-by: Binbin Wu <binbin.wu@xxxxxxxxxxxxxxx>
Reviewed-by: Kiryl Shutsemau (Meta) <kas@xxxxxxxxxx>
Reviewed-by:
Link: https://patch.msgid.link/20260930103739.2851980-4-peter.fang@xxxxxxxxx
---
drivers/virt/coco/tdx-guest/tdx-guest.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index 83322cd..77c63c3 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -170,8 +170,6 @@ static void tdx_mr_deinit(const struct attribute_group *mr_grp)
#define GET_QUOTE_SUCCESS 0
#define GET_QUOTE_IN_FLIGHT 0xffffffffffffffff

-#define TDX_QUOTE_MAX_LEN (GET_QUOTE_BUF_SIZE - sizeof(struct tdx_quote_buf))
-
/* struct tdx_quote_buf: Format of Quote request buffer.
* @version: Quote format version, filled by TD.
* @status: Status code of Quote request, filled by VMM.
@@ -313,7 +311,7 @@ static int tdx_report_new_locked(struct tsm_report *report)

out_len = READ_ONCE(quote_buf->out_len);

- if (out_len > TDX_QUOTE_MAX_LEN)
+ if (struct_size(quote_buf, data, out_len) > GET_QUOTE_BUF_SIZE)
return -EFBIG;

buf = kvmemdup(quote_buf->data, out_len, GFP_KERNEL);