Re: [PATCH v14 10/22] KVM: selftests: Set up TDX boot code region
Sean Christopherson <[email protected]>
| Newsgroups | org.kernel.vger.kvm,dev.linux.lists.linux-coco,org.kernel.vger.linux-kernel,org.kernel.vger.linux-kselftest |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Aug 24, 2026, Peter Fang wrote:
> On Wed, Jul 22, 2026 at 11:13:15PM +0000, Lisa Wang wrote:
> > +void tdx_vm_setup_boot_code_region(struct kvm_vm *vm)
> > +{
> > + size_t total_code_size = TD_BOOT_CODE_SIZE + X86_RESET_VECTOR_SIZE;
> > + gpa_t boot_code_gpa = X86_RESET_VECTOR - TD_BOOT_CODE_SIZE;
> > + gpa_t alloc_gpa = round_down(boot_code_gpa, PAGE_SIZE);
> > + size_t nr_pages = DIV_ROUND_UP(total_code_size, PAGE_SIZE);
> > + const u64 gmem_flags = 0;
> > + gpa_t gpa;
> > + u8 *hva;
> > +
> > + vm_mem_add(vm, VM_MEM_SRC_SHMEM, alloc_gpa, TD_BOOT_CODE_SLOT,
> > + nr_pages, KVM_MEM_GUEST_MEMFD, -1, 0, gmem_flags);
> > +
> > + gpa = vm_phy_pages_alloc(vm, nr_pages, alloc_gpa, TD_BOOT_CODE_SLOT);
> > + TEST_ASSERT(gpa == alloc_gpa, "Failed vm_phy_pages_alloc\n");
> > +
> > + virt_map(vm, alloc_gpa, alloc_gpa, nr_pages);
> > + hva = addr_gpa2hva(vm, boot_code_gpa);
> > + memcpy(hva, td_boot, TD_BOOT_CODE_SIZE);
> > +
> > + hva += TD_BOOT_CODE_SIZE;
> > + TEST_ASSERT(hva == addr_gpa2hva(vm, X86_RESET_VECTOR),
> > + "Expected RESET vector at hva 0x%lx, got %lx",
> > + (unsigned long)addr_gpa2hva(vm, X86_RESET_VECTOR), (unsigned long)hva);
> > +
> > + /*
> > + * Handcode "JMP rel8" at the RESET vector to jump back to the TD boot
> > + * code, as there are only 16 bytes at the RESET vector before RIP will
> > + * wrap back to zero. Insert a trailing int3 so that the vCPU crashes in
> > + * case the JMP somehow falls through. Note! The target address is
> > + * relative to the end of the instruction!
> > + */
> > + TEST_ASSERT(TD_BOOT_CODE_SIZE + 2 <= 128,
> > + "TD boot code not addressable by 'JMP rel8'");
> > + hva[0] = 0xeb;
> > + hva[1] = 256 - 2 - TD_BOOT_CODE_SIZE;
> > + hva[2] = 0xcc;
>
> This handcoding has persisted for several versions (since v9) so I only
> want to comment gently... The current code looks correct but I think
> this could be simpler. But feel free to keep the current implementation.
>
> I can see handcoding "JMP rel8" generates a jump instruction
> predictably. But having to calculate and sanity check the boot code
> offset by hand seems quite painful. And the math is quite tricky. I was
> thinking the assembler could do a lot more heavy lifting here.
>
> A nice property of this boot code is the fact that it's executed in
> 32-bit mode from the get go. So there's no need for 16-bit programming
> and "JMP rel32" is readily available. I.e. a "jmp td_boot" in td_boot.S
> should suffice and the assembler screams if td_boot isn't reachable. And
> the int3's after the jump can probably go away as well since the jump is
> now very, very likely to succeed.
>
> There shouldn't be a need to "pad reset_vector to its full size of 16
> bytes" as stated in v8 [1]. The exported "reset_vector" symbol in v8,
> plus the boot code start & end markers, should be enough to help
> tdx_vm_setup_boot_code_region() put this boot blob in the right place.
Ya, looking at this with fresh eyes, AFAICT there's no reason to handcode anything,
it's just basic arithmetic.
Side topic, this series doesn't compile for me, so the below isn't even properly
compile-tested (I hacked in arbitrary literals to get past the undefined references).
/usr/bin/x86_64-linux-gnu-ld.bfd: tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S:26:(.text+0xf): undefined reference to `TD_BOOT_PARAMETERS_PER_VCPU'
/usr/bin/x86_64-linux-gnu-ld.bfd: tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S:30:(.text+0x17): undefined reference to `TD_PER_VCPU_PARAMETERS_ESP_GVA'
/usr/bin/x86_64-linux-gnu-ld.bfd: tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S:33:(.text+0x1d): undefined reference to `TD_BOOT_PARAMETERS_GDT'
/usr/bin/x86_64-linux-gnu-ld.bfd: tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S:37:(.text+0x26): undefined reference to `TD_BOOT_PARAMETERS_IDT'
/usr/bin/x86_64-linux-gnu-ld.bfd: tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S:44:(.text+0x2f): undefined reference to `TD_BOOT_PARAMETERS_CR4'
/usr/bin/x86_64-linux-gnu-ld.bfd: tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S:46:(.text+0x38): undefined reference to `TD_BOOT_PARAMETERS_CR3'
/usr/bin/x86_64-linux-gnu-ld.bfd: tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S:48:(.text+0x41): undefined reference to `TD_BOOT_PARAMETERS_CR0'
/usr/bin/x86_64-linux-gnu-ld.bfd: tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S:54:(.text+0x51): undefined reference to `TD_PER_VCPU_PARAMETERS_GUEST_CODE'
diff --git a/tools/testing/selftests/kvm/include/x86/tdx/td_boot.h b/tools/testing/selftests/kvm/include/x86/tdx/td_boot.h
index 89cf6c3485be..439d6f10489e 100644
--- a/tools/testing/selftests/kvm/include/x86/tdx/td_boot.h
+++ b/tools/testing/selftests/kvm/include/x86/tdx/td_boot.h
@@ -73,10 +73,9 @@ struct td_boot_parameters {
};
void td_boot(void);
+void td_boot_reset_vector_trampoline(void);
void td_boot_code_end(void);
-#define TD_BOOT_CODE_SIZE (td_boot_code_end - td_boot)
-
#endif /* !defined(__ASSEMBLY__) && !defined(__ASSEMBLER__) */
#endif /* SELFTEST_TDX_TD_BOOT_H */
diff --git a/tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S b/tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S
index bca9a4c3d8f8..2882fb2ea43e 100644
--- a/tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S
+++ b/tools/testing/selftests/kvm/lib/x86/tdx/td_boot.S
@@ -52,6 +52,12 @@ td_boot:
ljmp $(KERNEL_CS),$1f
1:
jmp *TD_PER_VCPU_PARAMETERS_GUEST_CODE(%eax)
+ int3
+
+.globl td_boot_reset_vector_trampoline
+td_boot_reset_vector_trampoline:
+ jmp td_boot
+ int3
/* Leave marker so size of td_boot code can be computed. */
.globl td_boot_code_end
diff --git a/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c b/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c
index 831b0e5160df..170354dcdb66 100644
--- a/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c
+++ b/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c
@@ -15,10 +15,11 @@
void tdx_vm_setup_boot_code_region(struct kvm_vm *vm)
{
- size_t total_code_size = TD_BOOT_CODE_SIZE + X86_RESET_VECTOR_SIZE;
- gpa_t boot_code_gpa = X86_RESET_VECTOR - TD_BOOT_CODE_SIZE;
+ const size_t total_size = td_boot_code_end - td_boot;
+ const size_t boot_code_size = td_boot_reset_vector_trampoline - td_boot;
+ const gpa_t boot_code_gpa = X86_RESET_VECTOR - boot_code_size;
gpa_t alloc_gpa = round_down(boot_code_gpa, PAGE_SIZE);
- size_t nr_pages = DIV_ROUND_UP(total_code_size, PAGE_SIZE);
+ size_t nr_pages = DIV_ROUND_UP(total_size, PAGE_SIZE);
u64 gmem_flags = 0;
gpa_t gpa;
u8 *hva;
@@ -33,25 +34,12 @@ void tdx_vm_setup_boot_code_region(struct kvm_vm *vm)
virt_map(vm, alloc_gpa, alloc_gpa, nr_pages);
hva = addr_gpa2hva(vm, boot_code_gpa);
- memcpy(hva, td_boot, TD_BOOT_CODE_SIZE);
+ memcpy(hva, td_boot, total_size);
- hva += TD_BOOT_CODE_SIZE;
+ hva += boot_code_size;
TEST_ASSERT(hva == addr_gpa2hva(vm, X86_RESET_VECTOR),
"Expected RESET vector at hva 0x%lx, got %lx",
(unsigned long)addr_gpa2hva(vm, X86_RESET_VECTOR), (unsigned long)hva);
-
- /*
- * Handcode "JMP rel8" at the RESET vector to jump back to the TD boot
- * code, as there are only 16 bytes at the RESET vector before RIP will
- * wrap back to zero. Insert a trailing int3 so that the vCPU crashes in
- * case the JMP somehow falls through. Note! The target address is
- * relative to the end of the instruction!
- */
- TEST_ASSERT(TD_BOOT_CODE_SIZE + 2 <= 128,
- "TD boot code not addressable by 'JMP rel8'");
- hva[0] = 0xeb;
- hva[1] = 256 - 2 - TD_BOOT_CODE_SIZE;
- hva[2] = 0xcc;
}
void tdx_vm_setup_boot_parameters_region(struct kvm_vm *vm, u32 nr_runnable_vcpus)