Re: [PATCH v4 1/4] KVM: TDX: Track configurable CPUID bits allowed by KVM

From: Xiaoyao Li

Date: Wed Sep 23 2026 - 22:07:57 EST


On 9/23/2026 10:25 PM, Edgecombe, Rick P wrote:
>> But for TDX,
>> there is not interface to report KVM's support capabilities. After this
>> series, KVM_TDX_CAPABILITIES can serve as the interface. So it looks like a
>> bug fix to me.
> KVM needs to support all the bits that are 1 in the TD. Either directly
> configurable or fixed-1 or whatever. Userspace doesn't find out which bits these
> are until it does the KVM_TDX_GET_CPUID, at which point it finds out the
> "support" in a heavy handed way. So I think userspace does learn everything it
> needs already. And as long we don't have new fixed-1 bits, we will avoid KVM
> being forced to support things too early.

Do you mean after this series of before this series?

Before this series, i.e. with current KVM, KVM_TDX_GET_CPUID can tell userspace
the "support" bit for a given TD, but some of the "support" bits might not be
supported by KVM. For example, current userspace can set RDT_A and RDT_M, and
they will be reported as 1 on KVM_TDX_GET_CPUID. However, KVM doesn't support them.

After this series, KVM will not report such bits like RDT_A and RDT_M any more,
and userspace will no longer be able to set them for a TD neither.