[PATCH v1 8/8] x86/virt/tdx: Verify the C member size against the metadata field ID
Chao Gao <[email protected]> Tue, 4 Aug 2026 04:29:36 -0700
| Newsgroups | org.kernel.vger.kvm,dev.linux.lists.linux-coco,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
Each TDX global metadata field ID encodes the size of that field. read_sys_metadata_table() stores each value at the width recorded in the table, which TD_SYSINFO_MAP() derives from the destination C member. Nothing checks that the two agree. A table entry naming the wrong field ID, or a struct member declared at the wrong width, would silently truncate the value read from the TDX module. That is a kernel-side bug rather than a TDX module problem. Add macros to extract the encoded size from a field ID, and use them in TD_SYSINFO_MAP() to assert that it matches the member size. Both are compile-time constants, so the check costs nothing at runtime. Note that BUILD_BUG_ON() cannot be used in a structure initializer; use BUILD_BUG_ON_ZERO() instead, which yields 0 and so can be folded into the .size initializer without changing its value. No functional change intended. Assisted-by: Claude:claude-opus-5 Signed-off-by: Chao Gao <[email protected]> --- arch/x86/virt/vmx/tdx/tdx.c | 9 ++++++++- arch/x86/virt/vmx/tdx/tdx.h | 15 +++++++++++++++ 2 files changed, 23 insertions(+), 1 deletion(-) diff --git a/arch/x86/virt/vmx/tdx/tdx.c b/arch/x86/virt/vmx/tdx/tdx.c index 4bf21848df62..59099cc15f7a 100644 --- a/arch/x86/virt/vmx/tdx/tdx.c +++ b/arch/x86/virt/vmx/tdx/tdx.c @@ -357,11 +357,18 @@ struct tdx_sys_field { u8 size; }; +/* + * The size encoded in the field ID and the size of the destination C + * member must agree; BUILD_BUG_ON_ZERO() enforces this at compile time. + */ #define TD_SYSINFO_MAP(_field_id, _struct, _member) \ { \ .field_id = MD_FIELD_ID_##_field_id, \ .offset = offsetof(struct _struct, _member), \ - .size = sizeof_field(struct _struct, _member), \ + .size = sizeof_field(struct _struct, _member) + \ + BUILD_BUG_ON_ZERO( \ + sizeof_field(struct _struct, _member) != \ + MD_FIELD_ID_ELE_SIZE(MD_FIELD_ID_##_field_id)), \ } /* diff --git a/arch/x86/virt/vmx/tdx/tdx.h b/arch/x86/virt/vmx/tdx/tdx.h index 5f567cb6c07a..c612b1cf7c14 100644 --- a/arch/x86/virt/vmx/tdx/tdx.h +++ b/arch/x86/virt/vmx/tdx/tdx.h @@ -109,6 +109,21 @@ #define MD_FIELD_ID_CPUID_CONFIG_LEAVES 0x9900000300000400ULL #define MD_FIELD_ID_CPUID_CONFIG_VALUES 0x9900000300000500ULL +/* + * Sub-field definitions of MD_FIELD_ID. + * + * See "MD_FIELD_ID (Metadata Field Identifier / Sequence Header) + * Definition" in the Intel TDX Module ABI spec. + * + * - Bit 33:32: ELEMENT_SIZE_CODE -- log2 of a single metadata + * element's size in bytes + */ +#define MD_FIELD_ID_ELE_SIZE_CODE(field_id) \ + (((field_id) & GENMASK_ULL(33, 32)) >> 32) + +#define MD_FIELD_ID_ELE_SIZE(field_id) \ + (1 << MD_FIELD_ID_ELE_SIZE_CODE(field_id)) + /* TDX page types */ #define PT_NDA 0x0 #define PT_RSVD 0x1 -- 2.52.0