RE: [RFC PATCH 08/15] x86/tdx: Add TDG.MMIO.ACCEPT module call wrapper for TDX Connect

From: Duan, Zhenzhong

Date: Thu Oct 08 2026 - 01:50:09 EST




>-----Original Message-----
>From: Edgecombe, Rick P <rick.p.edgecombe@xxxxxxxxx>
>Subject: Re: [RFC PATCH 08/15] x86/tdx: Add TDG.MMIO.ACCEPT module call
>wrapper for TDX Connect
>
>On Thu, 2026-09-24 at 12:10 +0800, Zhenzhong Duan wrote:
>> TDG.MMIO.ACCEPT verifies and accepts a pending private MMIO range for
>> a trusted device.
>>
>> The MMIO range to be accepted can be a sub-range of the MMIO ranges
>> originally defined in the Device Interface Report. Because the TDX
>> module caches these ranges from the Device Interface Report, the guest
>> does not need to pass the explicit physical start and end addresses of
>> the MMIO range. Instead, it only needs to provide the target MMIO
>> range index, the offset within that range, and the size to be accepted.
>>
>> Translate TDX module return codes into Linux errno values.
>>
>> Signed-off-by: Zhenzhong Duan <zhenzhong.duan@xxxxxxxxx>
>
>We are going to need a lot more info about what this TDG call is doing. Look at
>the host side seamcall wrapper commits for examples.

OK, will do.

>
>> ---
>> arch/x86/coco/tdx/tdx_connect.c | 38 +++++++++++++++++++++++++++++++
>> arch/x86/include/asm/shared/tdx.h | 1 +
>> arch/x86/include/asm/tdx.h | 1 +
>> 3 files changed, 40 insertions(+)
>>
>> diff --git a/arch/x86/coco/tdx/tdx_connect.c
>b/arch/x86/coco/tdx/tdx_connect.c
>> index 1409b1a30cc6..09a92fe23357 100644
>> --- a/arch/x86/coco/tdx/tdx_connect.c
>> +++ b/arch/x86/coco/tdx/tdx_connect.c
>> @@ -71,3 +71,41 @@ int tdx_mcall_tdi_read(u64 func_id, u64 field, u64 *value)
>> return tdx_mcall_tdi_to_errno(ret);
>> }
>> EXPORT_SYMBOL_FOR_MODULES(tdx_mcall_tdi_read, "tdx-guest");
>> +
>> +/**
>> + * tdx_mcall_mmio_accept() - Accept a pending private MMIO mapping of a
>> + * Trust Device Interface (TDI) instance
>> + * @func_id: Function identifier specifying the TDI instance
>> + * @index: MMIO range index from the Device Interface Report
>> + * @pg_offset: Range offset to start accepting the subrange from, in pages
>> + * @page_cnt: Count of pages to accept
>> + * @gpa: GPA base address the subrange mapped to
>> + *
>> + * Verify and accept a pending private MMIO mapping. Upon success, the
>MMIO
>> + * pages are set as mapped in the TDX module.
>> + *
>> + * Return 0 on success, -EINVAL for unaligned GPA, -ENXIO for invalid operands,
>> + * -EBUSY for busy operation, -ENODEV for TDI not present or invalid metadata,
>> + * or -EIO on other TDCALL failures.
>> + *
>> + */
>> +int tdx_mcall_mmio_accept(u64 func_id, u64 index, u32 pg_offset, u32
>page_cnt, phys_addr_t gpa)
>> +{
>
>offset is 0 for all callers in this series. So I'd think to drop it unless there
>is some other code coming very very soon.

Will do.

>
>Can we turn some of these others into proper types? Why not pass struct
>pci_tsm_mmio_entry or struct pci_dev pointers instead of raw unsigned ints?
>
>Actually, the only caller just accepts the whole pci_tsm_mmio_entry, so you just
>need:
>
>int tdx_mcall_mmio_accept(struct pci_dev *dev, struct pci_tsm_mmio_entry
>*entry)
>
>What do you think?

Yes, it's cleaner. But how about below to use func_id as first parameter to align with other TDI specific mcalls.

int tdx_mcall_mmio_accept(u64 func_id, struct pci_tsm_mmio_entry *entry)

Or maybe passing "struct pci_dev *dev" for all TDI specific mcalls?

>
>> + struct tdx_module_args args = {
>> + .rcx = gpa | TDX_PS_4K,
>
>Always 4KB?

Spec says:

"RCX GPA_BASE_AND_LVL: GPA Base address. MMIOMT_L0 level (4KB pages) is supported"

> Needs an explanation in the log at least.

Sure, will do.

Thanks
Zhenzhong