Re: [PATCH v3 5/6] x86/virt/tdx: Re-initialize the extensions on runtime TDX module update

From: Edgecombe, Rick P

Date: Fri Oct 09 2026 - 15:26:52 EST


On Tue, 2026-10-06 at 01:41 +0800, Xu Yilun wrote:
> Runtime TDX module update introduces a mechanism to update the module
> firmware while preserving and restoring TDX operations. The extensions
> functionalities should also be re-initialized as part of the restoration
> process.
>
> The TDX architecture supports an update flow which allows updated
> extensions to consume more memory than their original boot-time
> requirement. So the arch defines the extensions re-initialization flow
> the same as boot-up initialization: the host queries TDX module how much
> additional memory needed, allocates it, adds it to the module via
> TDH.EXT.MEM.ADD, then re-initializes the extensions via TDH.EXT.INIT.
>
> Linux runs the updates in stop_machine() context, which prevents memory
> allocation. So for Linux, a compatible update must not install updated
> extensions that require additional memory.
>
> Given that the memory for the extensions must not increase, the
> re-initialization skips the memory adding steps. It is simplified as:
>
>   - Check if the extensions are supported via TDX_FEATURES0_EXT. If not,
>     skip the extensions re-initialization.
>
>   - Re-initialize the extensions via TDH.EXT.INIT. The SEAMCALL leaf
>     will fail if the updated extensions require more memory, which
>     indicates the update image is not compatible.
>
> Signed-off-by: Xu Yilun <yilun.xu@xxxxxxxxxxxxxxx>

Reviewed-by: Rick Edgecombe <rick.p.edgecome@xxxxxxxxx>