Re: [PATCH v3 0/4] tdx-guest: Make Quote buffer size dynamic

Peter Fang <[email protected]>
Newsgroups dev.linux.lists.linux-coco,org.kernel.vger.kvm,org.kernel.vger.linux-kernel
Message-ID <20260812210243.GC1013044@pedri>
On Wed, Aug 12, 2026 at 09:02:21AM -0700, Edgecombe, Rick P wrote:
> On Wed, 2026-08-12 at 07:08 -0700, Sean Christopherson wrote:
> > >   |Normal quote    |Migration quote |Report size|Quote size|uAPI location  |
> > > -|----------------|----------------|-----------|----------|---------------|
> > > 1|Platform scoped |Platform scoped |Grows      |Grows     |TDX host driver|
> > 
> > With my KVM hat on, this option looks very attractive.
> > 
> > And with the caveat that I'm most definitely not an attestation expert, from a
> > separate of concerns perspective, IMO it seems like the report should contain
> > the TD-specific information while the quote just wraps that information in
> > platform-specific goo.
> > 
> > In other words, to me, TD-scoped quotes feel like a hack that was thrown in to
> > avoid having to modify the guest because y'all didn't plan ahead.
> 
> Caveman crypto person here too. It seems scattered and makes me similarly
> suspicious about some lack of planning. But I kind of came to a different
> conclusion on what went wrong.
> 
> It seems to me that from the overall solution level, the report should never
> have had the details in it. It should just be some nonce or some type of thing
> that can tie the guest request to the quote that it ends up getting
> back. Doesn't it seem weird to get a bunch of details from the TDX module, then
> pass them from the guest to host KVM to host userspace then back to the TDX
> module... which already had all those details?

Yeah this has been a source of much debate internally. I feel that the
directions boil down to: is now a good opportunity to design something
that's more future looking (like can scale better wrt future attestation
needs) or is it better to keep the old SGX design a little longer...

> 
> My understanding was that the original SGX attestation was a complicator of the
> design of this stuff. Because I'm not sure that SGX had all those details about
> the TD. In fact I can't see how it could have. Is that right Peter? So it needs
> them all to be passed in. All the extra validations etc of this shuffling is
> TDX's problems to deal with, but for Linux, it would be at least a lot less
> confusing if there was not two things that have the TD details in them.

Yep this is correct IMO. Basically the report has lots of old SGX
baggage.

> 
> That said, from KVM POV, (1) kicks the attestation out of KVM. I see the
> benefit. But a TD quote is a TD scoped operation in concept. To me at least.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.