[PATCH v1 0/8] TDX: Stop auto-generating the global metadata code

Chao Gao <[email protected]>
Newsgroups dev.linux.lists.linux-coco,org.kernel.vger.kvm,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
This is a long-overdue cleanup of the TDX global metadata, based on work
from Dave [1].  Patches 1-6 keep Dave's authorship -- I only reworded the
commit messages and comments, with no significant changes to the code.
Note that they are missing Dave's Signed-off-by.

Changes on top of the original:

  - Rebased onto the latest tip/x86/tdx branch
  - Converted the newly added metadata (tdx module handoff)
  - Fixed up the __init annotations. The version and handoff tables must
    not be __initconst
  - Refined the commit messages and comments: dropped forward references
    to later patches and stopped restating what the code already says.
  - Added two patches: cleaning up error handling in get_tdx_sys_info(),
    and turning the runtime size check into a build-time one.

The series is also available at:
  https://github.com/gaochaointel/linux-dev.git tdx-metadata-v1

---
The TDX module exposes its capabilities and limits through "Global Scope
Metadata" fields, defined in the Intel TDX Module ABI spec.  The kernel
mirrors a small subset of those fields in C structures under struct
tdx_sys_info, populated by reading each field via TDH.SYS.RD.

Both the structures and the code that fills them are nominally generated
by an out-of-tree script from a JSON file describing the module's
metadata.  That made it trivial to add a new field, but everything else
suffered for it:

  - The generated files are edited by hand in practice, for different
    reasons.  The VMXON rework added __init annotations to the readers,
    and the handoff metadata is read at module shutdown into a
    caller-local struct rather than into tdx_sys_info.  In-flight series
    will add more: DPAMT and TDX module extension metadata may only be
    read when the corresponding TDX_FEATURES0 bit is set.  Regenerating
    the files would clobber all of these edits.

  - The generated code is opaque to anyone who doesn't have the script
    and the JSON file handy.  Each field is identified by a bare 64-bit
    hex literal, so verifying any one line means cross-referencing the
    JSON file.

  - The script ships outside the tree, so reproducing changes requires
    fetching it from a mailing list link.

  - The structures are short and stable, so the script's value over
    hand-maintained code is small.

So switch to a hand-maintained implementation.  Name each field ID after
the spec, then describe the field-ID-to-C-member mapping as a table: one
row per field, pairing the named spec field ID with the C member that
holds it.  Reading is then a walk over the table.

[1]: https://git.kernel.org/pub/scm/linux/kernel/git/daveh/devel.git/log/?h=tdxtable

Chao Gao (2):
  x86/virt/tdx: Clean up error handling in get_tdx_sys_info()
  x86/virt/tdx: Verify the C member size against the metadata field ID

Dave Hansen (6):
  x86/virt/tdx: Stop treating tdx_global_metadata.h as auto-generated
  x86/virt/tdx: Name the TDX module global metadata field IDs
  x86/virt/tdx: Add a table-driven TDX global metadata reader
  x86/virt/tdx: Convert version/tdmr/td_ctrl/handoff readers
  x86/virt/tdx: Convert td_conf reader
  x86/virt/tdx: Remove the auto-generated tdx_global_metadata.c

 arch/x86/include/asm/tdx_global_metadata.h  |  13 +-
 arch/x86/virt/vmx/tdx/tdx.c                 | 216 +++++++++++++++++++-
 arch/x86/virt/vmx/tdx/tdx.h                 |  66 ++++++
 arch/x86/virt/vmx/tdx/tdx_global_metadata.c | 133 ------------
 4 files changed, 290 insertions(+), 138 deletions(-)
 delete mode 100644 arch/x86/virt/vmx/tdx/tdx_global_metadata.c

-- 
2.52.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.