Skip to content

hypervisor: Allow configuring TDX measurement registers - #28

Merged
guzongmin merged 1 commit into
mainfrom
zhoul1/dev/measurement
Sep 21, 2026
Merged

guzongmin merged 1 commit into
mainfrom
zhoul1/dev/measurement

Conversation

@liangzhou121

Copy link
Copy Markdown
Contributor

KVM_TDX_INIT_VM carries three tenant/owner measurement-configuration digests -- MRCONFIGID, MROWNER and MROWNERCONFIG -- that are baked into the TD's attestation report. Cloud Hypervisor previously hardcoded all three to zero, so a tenant could not bind non-owner configuration or owner identity into the measurement, unlike QEMU which exposes them.

Add three optional --platform options (mrconfigid, mrowner, mrownerconfig) accepting 96-character hex SHA384 digests.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved review issues were identified.

Pull request overview

Adds configurable TDX measurement registers, validating and forwarding SHA384 digests to KVM during VM initialization.

Changes:

  • Adds three optional --platform digest options.
  • Extends TDX initialization and KVM ABI handling.
  • Documents configuration and adds parser tests.
File summaries
File Description
vmm/src/vm.rs Supplies configured measurements during TDX initialization
vmm/src/vm_config.rs Adds measurement configuration fields
vmm/src/config.rs Parses, validates, decodes, and tests digests
vmm/Cargo.toml Enables the hexadecimal decoder
hypervisor/src/vm.rs Extends the TDX initialization interface
hypervisor/src/kvm/tdx.rs Represents measurement registers in the KVM ABI
hypervisor/src/kvm/mod.rs Forwards measurements to KVM
docs/intel_tdx.md Documents configuration and defaults
Review details
  • Files reviewed: 8/8 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@guzongmin guzongmin left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@guzongmin
guzongmin merged commit 84a3ab5 into main Sep 21, 2026
17 of 43 checks passed
KVM_TDX_INIT_VM carries three tenant/owner measurement-configuration
digests -- MRCONFIGID, MROWNER and MROWNERCONFIG -- that are baked into
the TD's attestation report. Cloud Hypervisor previously hardcoded all
three to zero, so a tenant could not bind non-owner configuration or
owner identity into the measurement, unlike QEMU which exposes them.

Add three optional `--platform` options (mrconfigid, mrowner,
mrownerconfig) accepting 96-character hex SHA384 digests.

Signed-off-by: Fan Du <fan.du@intel.com>
Signed-off-by: Liang, Zhou <liang1.zhou@intel.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants