hypervisor: Allow configuring TDX measurement registers - #28
Merged
Merged
Conversation
There was a problem hiding this comment.
🟢 Approval recommended
No unresolved review issues were identified.
Pull request overview
Adds configurable TDX measurement registers, validating and forwarding SHA384 digests to KVM during VM initialization.
Changes:
- Adds three optional
--platformdigest options. - Extends TDX initialization and KVM ABI handling.
- Documents configuration and adds parser tests.
File summaries
| File | Description |
|---|---|
vmm/src/vm.rs |
Supplies configured measurements during TDX initialization |
vmm/src/vm_config.rs |
Adds measurement configuration fields |
vmm/src/config.rs |
Parses, validates, decodes, and tests digests |
vmm/Cargo.toml |
Enables the hexadecimal decoder |
hypervisor/src/vm.rs |
Extends the TDX initialization interface |
hypervisor/src/kvm/tdx.rs |
Represents measurement registers in the KVM ABI |
hypervisor/src/kvm/mod.rs |
Forwards measurements to KVM |
docs/intel_tdx.md |
Documents configuration and defaults |
Review details
- Files reviewed: 8/8 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
liangzhou121
force-pushed
the
zhoul1/dev/measurement
branch
from
September 21, 2026 01:22
a9a1cba to
a2773b5
Compare
KVM_TDX_INIT_VM carries three tenant/owner measurement-configuration digests -- MRCONFIGID, MROWNER and MROWNERCONFIG -- that are baked into the TD's attestation report. Cloud Hypervisor previously hardcoded all three to zero, so a tenant could not bind non-owner configuration or owner identity into the measurement, unlike QEMU which exposes them. Add three optional `--platform` options (mrconfigid, mrowner, mrownerconfig) accepting 96-character hex SHA384 digests. Signed-off-by: Fan Du <fan.du@intel.com> Signed-off-by: Liang, Zhou <liang1.zhou@intel.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
KVM_TDX_INIT_VM carries three tenant/owner measurement-configuration digests -- MRCONFIGID, MROWNER and MROWNERCONFIG -- that are baked into the TD's attestation report. Cloud Hypervisor previously hardcoded all three to zero, so a tenant could not bind non-owner configuration or owner identity into the measurement, unlike QEMU which exposes them.
Add three optional
--platformoptions (mrconfigid, mrowner, mrownerconfig) accepting 96-character hex SHA384 digests.