[PATCH v1 0/8] TDX: Stop auto-generating the global metadata code

Chao Gao posted 8 patches 1 month, 4 weeks ago
There is a newer version of this series
arch/x86/include/asm/tdx_global_metadata.h  |  13 +-
arch/x86/virt/vmx/tdx/tdx.c                 | 216 +++++++++++++++++++-
arch/x86/virt/vmx/tdx/tdx.h                 |  66 ++++++
arch/x86/virt/vmx/tdx/tdx_global_metadata.c | 133 ------------
4 files changed, 290 insertions(+), 138 deletions(-)
delete mode 100644 arch/x86/virt/vmx/tdx/tdx_global_metadata.c
[PATCH v1 0/8] TDX: Stop auto-generating the global metadata code
Posted by Chao Gao 1 month, 4 weeks ago
This is a long-overdue cleanup of the TDX global metadata, based on work
from Dave [1].  Patches 1-6 keep Dave's authorship -- I only reworded the
commit messages and comments, with no significant changes to the code.
Note that they are missing Dave's Signed-off-by.

Changes on top of the original:

  - Rebased onto the latest tip/x86/tdx branch
  - Converted the newly added metadata (tdx module handoff)
  - Fixed up the __init annotations. The version and handoff tables must
    not be __initconst
  - Refined the commit messages and comments: dropped forward references
    to later patches and stopped restating what the code already says.
  - Added two patches: cleaning up error handling in get_tdx_sys_info(),
    and turning the runtime size check into a build-time one.

The series is also available at:
  https://github.com/gaochaointel/linux-dev.git tdx-metadata-v1

---
The TDX module exposes its capabilities and limits through "Global Scope
Metadata" fields, defined in the Intel TDX Module ABI spec.  The kernel
mirrors a small subset of those fields in C structures under struct
tdx_sys_info, populated by reading each field via TDH.SYS.RD.

Both the structures and the code that fills them are nominally generated
by an out-of-tree script from a JSON file describing the module's
metadata.  That made it trivial to add a new field, but everything else
suffered for it:

  - The generated files are edited by hand in practice, for different
    reasons.  The VMXON rework added __init annotations to the readers,
    and the handoff metadata is read at module shutdown into a
    caller-local struct rather than into tdx_sys_info.  In-flight series
    will add more: DPAMT and TDX module extension metadata may only be
    read when the corresponding TDX_FEATURES0 bit is set.  Regenerating
    the files would clobber all of these edits.

  - The generated code is opaque to anyone who doesn't have the script
    and the JSON file handy.  Each field is identified by a bare 64-bit
    hex literal, so verifying any one line means cross-referencing the
    JSON file.

  - The script ships outside the tree, so reproducing changes requires
    fetching it from a mailing list link.

  - The structures are short and stable, so the script's value over
    hand-maintained code is small.

So switch to a hand-maintained implementation.  Name each field ID after
the spec, then describe the field-ID-to-C-member mapping as a table: one
row per field, pairing the named spec field ID with the C member that
holds it.  Reading is then a walk over the table.

[1]: https://git.kernel.org/pub/scm/linux/kernel/git/daveh/devel.git/log/?h=tdxtable

Chao Gao (2):
  x86/virt/tdx: Clean up error handling in get_tdx_sys_info()
  x86/virt/tdx: Verify the C member size against the metadata field ID

Dave Hansen (6):
  x86/virt/tdx: Stop treating tdx_global_metadata.h as auto-generated
  x86/virt/tdx: Name the TDX module global metadata field IDs
  x86/virt/tdx: Add a table-driven TDX global metadata reader
  x86/virt/tdx: Convert version/tdmr/td_ctrl/handoff readers
  x86/virt/tdx: Convert td_conf reader
  x86/virt/tdx: Remove the auto-generated tdx_global_metadata.c

 arch/x86/include/asm/tdx_global_metadata.h  |  13 +-
 arch/x86/virt/vmx/tdx/tdx.c                 | 216 +++++++++++++++++++-
 arch/x86/virt/vmx/tdx/tdx.h                 |  66 ++++++
 arch/x86/virt/vmx/tdx/tdx_global_metadata.c | 133 ------------
 4 files changed, 290 insertions(+), 138 deletions(-)
 delete mode 100644 arch/x86/virt/vmx/tdx/tdx_global_metadata.c

-- 
2.52.0
Re: [PATCH v1 0/8] TDX: Stop auto-generating the global metadata code
Posted by Edgecombe, Rick P 1 month, 3 weeks ago
On Tue, 2026-08-04 at 04:29 -0700, Chao Gao wrote:
> The TDX module exposes its capabilities and limits through "Global Scope
> Metadata" fields, defined in the Intel TDX Module ABI spec.  The kernel
> mirrors a small subset of those fields in C structures under struct
> tdx_sys_info, populated by reading each field via TDH.SYS.RD.
> 
> Both the structures and the code that fills them are nominally generated
> by an out-of-tree script from a JSON file describing the module's
> metadata.  That made it trivial to add a new field, but everything else
> suffered for it:
> 
>   - The generated files are edited by hand in practice, for different
>     reasons.  The VMXON rework added __init annotations to the readers,
>     and the handoff metadata is read at module shutdown into a
>     caller-local struct rather than into tdx_sys_info.  In-flight series
>     will add more: DPAMT and TDX module extension metadata may only be
>     read when the corresponding TDX_FEATURES0 bit is set.  Regenerating
>     the files would clobber all of these edits.
> 
>   - The generated code is opaque to anyone who doesn't have the script
>     and the JSON file handy.  Each field is identified by a bare 64-bit
>     hex literal, so verifying any one line means cross-referencing the
>     JSON file.
> 
>   - The script ships outside the tree, so reproducing changes requires
>     fetching it from a mailing list link.
> 
>   - The structures are short and stable, so the script's value over
>     hand-maintained code is small.
> 
> So switch to a hand-maintained implementation.  Name each field ID after
> the spec, then describe the field-ID-to-C-member mapping as a table: one
> row per field, pairing the named spec field ID with the C member that
> holds it.  Reading is then a walk over the table.

It might help to fill out this problem statement a bit more. The script is
already dead because of problems. But it came about due to other problems. And
we still have problems without the script.

Also, there were previous attempts at a macro based solution that failed to make
it upstream. It would be good to highlight how it avoids those problems.


Re: [PATCH v1 0/8] TDX: Stop auto-generating the global metadata code
Posted by Chao Gao 1 month, 3 weeks ago
>It might help to fill out this problem statement a bit more. The script is
>already dead because of problems. But it came about due to other problems. And
>we still have problems without the script.
>
>Also, there were previous attempts at a macro based solution that failed to make
>it upstream. It would be good to highlight how it avoids those problems.

Sure.  Will improve the problem statement here.

I completely forgot the earlier macro attempts Kai made.  I've now read
those threads and will highlight how this addresses those problems.
Re: [PATCH v1 0/8] TDX: Stop auto-generating the global metadata code
Posted by Dave Hansen 1 month, 4 weeks ago
On 8/4/26 04:29, Chao Gao wrote:
> This is a long-overdue cleanup of the TDX global metadata, based on work
> from Dave [1].

I wouldn't say "from Dave". At best, I'd say "AI slop in response to
Dave's prompt" or "work vibe coded by Dave".

But seriously, all I wanted to do was show my fellow humans that it
wasn't an insurmountable task.

> Patches 1-6 keep Dave's authorship -- I only reworded the
> commit messages and comments, with no significant changes to the code.
> Note that they are missing Dave's Signed-off-by.

Yes, and that was intentional.
Re: [PATCH v1 0/8] TDX: Stop auto-generating the global metadata code
Posted by Chao Gao 1 month, 3 weeks ago
On Tue, Aug 04, 2026 at 04:38:44PM -0700, Dave Hansen wrote:
>On 8/4/26 04:29, Chao Gao wrote:
>> This is a long-overdue cleanup of the TDX global metadata, based on work
>> from Dave [1].
>
>I wouldn't say "from Dave". At best, I'd say "AI slop in response to
>Dave's prompt" or "work vibe coded by Dave".
>
>But seriously, all I wanted to do was show my fellow humans that it
>wasn't an insurmountable task.

Ok. Given this, I'll take authorship of the whole series and credit you in
the cover letter, rather than keeping you as the author on patches 1-6. Let
me know if this doesn't work.

>
>> Patches 1-6 keep Dave's authorship -- I only reworded the
>> commit messages and comments, with no significant changes to the code.
>> Note that they are missing Dave's Signed-off-by.
>
>Yes, and that was intentional.