Re: [RFC PATCH 01/15] x86/tdx: Export tdg_vm_rd() for tdx-guest module

From: Edgecombe, Rick P

Date: Thu Oct 08 2026 - 12:30:49 EST


On Thu, 2026-10-08 at 06:45 +0000, Duan, Zhenzhong wrote:
> > The concern is how risky is the tdg_vm_rd() export, and how it impacts
> > the existing tdg_vm_rd() usage, and the tdh_mng_rd() export which reads
> > the same data set on host.
> >
> > My initial concern about the cons of tdg_vm_rd() export are, the
> > SEAMCALL reads any TDCS fields, some of them are writable by tdg_vm_wr()
> > and there is no synchronization between them, so seems not a good kAPI.
> > Reducing the scope to read-only fields (e.g. TDCS_CONFIG_FLAGS) may be a
> > good start.
> >
> > Now there are 2 cases in flight: tdx_get_max_quote_size() helper in DICE
> > and tdg_vm_rd() export here. Maybe we need more cases to see which is
> > better but anyway I agree we'd better stay consistent now.
>
> We have below existing use cases which are open-coded.
> Maybe need to stay consistent to them?
>
>              tdg_vm_rd(TDCS_TD_CTLS, &controls);
>              tdg_vm_rd(TDCS_TOPOLOGY_ENUM_CONFIGURED, &configured);

Yea I agree it doesn't seem too risky. Regarding synchronization. It is a
monolithic kernel. We don't need/want to have excessive defensive code. We can
keep an eye on it.

For the quote size stuff, with only one user, there is little reason to export
the generic helper. But going forward, yea, makes sense to export to me. Let's
save some patches.

It would be good to hear Kiryl's opinion on it though.