Subject: [PATCH v3] virt: tdx-guest: Handle GetQuote request error code

The tdx-guest driver marshals quote requests via hypercall to have a
quoting enclave sign attestation evidence about the current state of
the TD. There are 2 possible failures, a transport failure (failure
to communicate with the quoting agent) and payload failure (a failed
quote). The driver only checks the former, update it to consider the
latter payload errors as well.

Fixes: f4738f56d1dc ("virt: tdx-guest: Add Quote generation support using TSM_REPORTS")
Reported-by: Xiaoyao Li <[email protected]>
Closes: https://lore.kernel.org/linux-coco/[email protected]/T/#u
Signed-off-by: Kuppuswamy Sathyanarayanan <[email protected]>
Reviewed-by: Kirill A. Shutemov <[email protected]>
Reviewed-by: Xiaoyao Li <[email protected]>
Acked-by: Kai Huang <[email protected]>
---

Changes since v2:
* Updated the commit log (Dan)
* Removed pr_err message.

Changes since v1:
* Updated the commit log (Kirill)

drivers/virt/coco/tdx-guest/tdx-guest.c | 5 +++++
1 file changed, 5 insertions(+)

diff --git a/drivers/virt/coco/tdx-guest/tdx-guest.c b/drivers/virt/coco/tdx-guest/tdx-guest.c
index 1253bf76b570..c39f0007958d 100644
--- a/drivers/virt/coco/tdx-guest/tdx-guest.c
+++ b/drivers/virt/coco/tdx-guest/tdx-guest.c
@@ -228,6 +228,11 @@ static int tdx_report_new(struct tsm_report *report, void *data)
goto done;
}

+ if (quote_buf->status != GET_QUOTE_SUCCESS) {
+ ret = -EIO;
+ goto done;
+ }
+
buf = kvmemdup(quote_buf->data, quote_buf->out_len, GFP_KERNEL);
if (!buf) {
ret = -ENOMEM;
--
2.25.1



2024-02-27 01:36:40

by Dan Williams

[permalink] [raw]
Subject: RE: [PATCH v3] virt: tdx-guest: Handle GetQuote request error code

Kuppuswamy Sathyanarayanan wrote:
> The tdx-guest driver marshals quote requests via hypercall to have a
> quoting enclave sign attestation evidence about the current state of
> the TD. There are 2 possible failures, a transport failure (failure
> to communicate with the quoting agent) and payload failure (a failed
> quote). The driver only checks the former, update it to consider the
> latter payload errors as well.
>
> Fixes: f4738f56d1dc ("virt: tdx-guest: Add Quote generation support using TSM_REPORTS")
> Reported-by: Xiaoyao Li <[email protected]>
> Closes: https://lore.kernel.org/linux-coco/[email protected]/T/#u
> Signed-off-by: Kuppuswamy Sathyanarayanan <[email protected]>
> Reviewed-by: Kirill A. Shutemov <[email protected]>
> Reviewed-by: Xiaoyao Li <[email protected]>
> Acked-by: Kai Huang <[email protected]>

Looks good to me:

Reviewed-by: Dan Williams <[email protected]>

..if you decide you need a debug print here, or to differentiate the
error codes based on transport vs payload error that can be a follow-on
change.

Subject: Re: [PATCH v3] virt: tdx-guest: Handle GetQuote request error code


On 2/26/24 5:36 PM, Dan Williams wrote:
> Kuppuswamy Sathyanarayanan wrote:
>> The tdx-guest driver marshals quote requests via hypercall to have a
>> quoting enclave sign attestation evidence about the current state of
>> the TD. There are 2 possible failures, a transport failure (failure
>> to communicate with the quoting agent) and payload failure (a failed
>> quote). The driver only checks the former, update it to consider the
>> latter payload errors as well.
>>
>> Fixes: f4738f56d1dc ("virt: tdx-guest: Add Quote generation support using TSM_REPORTS")
>> Reported-by: Xiaoyao Li <[email protected]>
>> Closes: https://lore.kernel.org/linux-coco/[email protected]/T/#u
>> Signed-off-by: Kuppuswamy Sathyanarayanan <[email protected]>
>> Reviewed-by: Kirill A. Shutemov <[email protected]>
>> Reviewed-by: Xiaoyao Li <[email protected]>
>> Acked-by: Kai Huang <[email protected]>
> Looks good to me:
>
> Reviewed-by: Dan Williams <[email protected]>
>
> ...if you decide you need a debug print here, or to differentiate the
> error codes based on transport vs payload error that can be a follow-on
> change.
Yes, will do. I will submit a pr_err() cleanup patch soon.

--
Sathyanarayanan Kuppuswamy
Linux Kernel Developer