lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:   Tue, 5 Oct 2021 07:43:02 -0700
From:   "Kuppuswamy, Sathyanarayanan" 
To:     Dave Hansen <>,
        Sathyanarayanan Kuppuswamy Natarajan 
        Randy Dunlap <>
Cc:     Thomas Gleixner <>,
        Ingo Molnar <>, Borislav Petkov <>,, Paolo Bonzini <>,
        David Hildenbrand <>,
        Andrea Arcangeli <>,
        Josh Poimboeuf <>,
        Juergen Gross <>, Deep Shah <>,
        VMware Inc <>,
        Vitaly Kuznetsov <>,
        Wanpeng Li <>,
        Jim Mattson <>,
        Joerg Roedel <>, Peter H Anvin <>,
        Tony Luck <>,
        Dan Williams <>,
        Andi Kleen <>,
        Kirill Shutemov <>,
        Sean Christopherson <>,
        Linux Kernel Mailing List <>
Subject: Re: [PATCH v8 02/11] x86/tdx: Introduce INTEL_TDX_GUEST config option

On 10/5/21 7:09 AM, Dave Hansen wrote:
>> For the TDX guest, x2apic will be emulated. So it will exist in our
>> case. Even if x2apic or TDX guest is not supported by CPU, it will
>> boot just fine.
> This doesn't really explain the "select X86_X2APIC", though.
> You just said that TDX doesn't*require*  X2APIC.  So, why is it being

I meant for a valid TD guest, x2APIC will *always* be emulated. It is
also specified in the spec.

Please check sec "TD Hardware" in Intel TDX Virtual Firmware Design Guide
or "Interrupt Handling and APIC Virtualization" section in Intel Trust
Domain Extensions Module specification.

For the case without x2APIC, TDX initialization should fail (hence TDX)
will not be enabled). So in non-TDX mode, kernel will boot fine. But
in TDX mode, current behavior should be "kernel hang"

> selected?  What is the specific connection between TDX and X2APIC?

X2APIC is used manage interrupts in virtualized environment (like TDX
guest). So it is required for interrupt management.

Sathyanarayanan Kuppuswamy
Linux Kernel Developer

Powered by blists - more mailing lists