[PATCH v1 0/8] TDX: Stop auto-generating the global metadata code
Chao Gao <[email protected]> Tue, 4 Aug 2026 04:29:28 -0700
| Newsgroups | org.kernel.vger.kvm,dev.linux.lists.linux-coco,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
This is a long-overdue cleanup of the TDX global metadata, based on work
from Dave [1]. Patches 1-6 keep Dave's authorship -- I only reworded the
commit messages and comments, with no significant changes to the code.
Note that they are missing Dave's Signed-off-by.
Changes on top of the original:
- Rebased onto the latest tip/x86/tdx branch
- Converted the newly added metadata (tdx module handoff)
- Fixed up the __init annotations. The version and handoff tables must
not be __initconst
- Refined the commit messages and comments: dropped forward references
to later patches and stopped restating what the code already says.
- Added two patches: cleaning up error handling in get_tdx_sys_info(),
and turning the runtime size check into a build-time one.
The series is also available at:
https://github.com/gaochaointel/linux-dev.git tdx-metadata-v1
---
The TDX module exposes its capabilities and limits through "Global Scope
Metadata" fields, defined in the Intel TDX Module ABI spec. The kernel
mirrors a small subset of those fields in C structures under struct
tdx_sys_info, populated by reading each field via TDH.SYS.RD.
Both the structures and the code that fills them are nominally generated
by an out-of-tree script from a JSON file describing the module's
metadata. That made it trivial to add a new field, but everything else
suffered for it:
- The generated files are edited by hand in practice, for different
reasons. The VMXON rework added __init annotations to the readers,
and the handoff metadata is read at module shutdown into a
caller-local struct rather than into tdx_sys_info. In-flight series
will add more: DPAMT and TDX module extension metadata may only be
read when the corresponding TDX_FEATURES0 bit is set. Regenerating
the files would clobber all of these edits.
- The generated code is opaque to anyone who doesn't have the script
and the JSON file handy. Each field is identified by a bare 64-bit
hex literal, so verifying any one line means cross-referencing the
JSON file.
- The script ships outside the tree, so reproducing changes requires
fetching it from a mailing list link.
- The structures are short and stable, so the script's value over
hand-maintained code is small.
So switch to a hand-maintained implementation. Name each field ID after
the spec, then describe the field-ID-to-C-member mapping as a table: one
row per field, pairing the named spec field ID with the C member that
holds it. Reading is then a walk over the table.
[1]: https://git.kernel.org/pub/scm/linux/kernel/git/daveh/devel.git/log/?h=tdxtable
Chao Gao (2):
x86/virt/tdx: Clean up error handling in get_tdx_sys_info()
x86/virt/tdx: Verify the C member size against the metadata field ID
Dave Hansen (6):
x86/virt/tdx: Stop treating tdx_global_metadata.h as auto-generated
x86/virt/tdx: Name the TDX module global metadata field IDs
x86/virt/tdx: Add a table-driven TDX global metadata reader
x86/virt/tdx: Convert version/tdmr/td_ctrl/handoff readers
x86/virt/tdx: Convert td_conf reader
x86/virt/tdx: Remove the auto-generated tdx_global_metadata.c
arch/x86/include/asm/tdx_global_metadata.h | 13 +-
arch/x86/virt/vmx/tdx/tdx.c | 216 +++++++++++++++++++-
arch/x86/virt/vmx/tdx/tdx.h | 66 ++++++
arch/x86/virt/vmx/tdx/tdx_global_metadata.c | 133 ------------
4 files changed, 290 insertions(+), 138 deletions(-)
delete mode 100644 arch/x86/virt/vmx/tdx/tdx_global_metadata.c
--
2.52.0