)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"eedd204522582c2fabd0dd881ac35b378b75b61f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"eaee1f17_ab32419c","updated":"2026-08-13 13:07:33.000000000","message":"OK the new stateless requirement are noted","commit_id":"b050013ded02e626067b438221c19c78cc95a85a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"f6b7811ef97b5953d27c6a652243033c71d0f9cf","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"918316f8_b90546f8","updated":"2026-08-18 22:48:59.000000000","message":"honestly tdx supprot in qemu and libvirt feels premature to be integrating in nova with all the hacks and limations this requries.\n\nim not goign to block on this but we have called features experimental for less\nso i storgnly feel we should position this as experimental as well in our documeation and release notes.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"cc24e7c9_549dd624","updated":"2026-08-21 03:19:18.000000000","message":"nice document, though a few comments and suggestions","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"63bbeed50e4883be06c8c2ac8dc08ef5b432009f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"ffe4d505_4f637c21","updated":"2026-08-14 08:34:23.000000000","message":"thanks","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"d54df6a3512fd497c1d14ed6f62d37091eca5d9f","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"125c1eb4_5a4b340a","in_reply_to":"8e769701_ccb3fd64","updated":"2026-08-21 13:00:51.000000000","message":"well its got a lot of limiation and its not tested in ci\n\nthe only time we allow a new featur to be added that does not supprot live migraiton is if it phsicyly cant becuase of a hardware limiation or if our depeices like qemu have not implemented it yet.\n\nits true that many of these limaitoan are specif to TDX regarless fo the palthform\nbut the requirement for Host-passhtough is not somethign we have ever depended on and i think that really does make this more of an expermintal feature then a production ready one.\n\nim with droping the term but i dont hink the functioanlity in qemu and libvirt really is ready for production use yet.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"8e769701_ccb3fd64","in_reply_to":"918316f8_b90546f8","updated":"2026-08-21 03:19:18.000000000","message":"I am not sure if calling it \u0027experimental\u0027 provides any clearity here. As long as we are documenting the limitation and user able to create TDX VM (even with some limitation), it is still supported for me.\n\nI might be ok to call it experimental if we know that those limitation are going to be fixed soon or in Nova scope. Anyone wanted TDX VM knows about those limitation and other non-openstack cloud might have the same set of limitation.\n\nAs those limitation are out of nova scope, I will say we should call it \"supported with existing/general TDX limitations\"","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"74281d2039eacf479450e7393ed77aeaa9818525","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"82220b76_66b023a8","updated":"2026-08-26 13:40:14.000000000","message":"recheck requeue","commit_id":"51928db00915238e60df98b2cb0eb4c296a6f273"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"d9618f0d7116ec31daa1a31ab5118d5d3fb4e4ad","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"f80726fc_64afa210","updated":"2026-08-22 03:03:03.000000000","message":"this lgtm. calling it experimental or not, i will leave the call to you all.","commit_id":"51928db00915238e60df98b2cb0eb4c296a6f273"}],"doc/source/admin/tdx.rst":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"6f5932f01b52e17c1d02423c70ac744139631a34","unresolved":true,"context_lines":[{"line_number":87,"context_line":"     provides ``ovmf-inteltdx``)."},{"line_number":88,"context_line":""},{"line_number":89,"context_line":"     Nova uses QEMU\u0027s firmware auto-selection, which is based on firmware"},{"line_number":90,"context_line":"     descriptors, to select the matching firmware for TDs.More details on"},{"line_number":91,"context_line":"     these firmware descriptors can be found in the `QEMU firmware descriptor"},{"line_number":92,"context_line":"     documentation`_."},{"line_number":93,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"8b6b22ac_50dcd479","line":90,"range":{"start_line":90,"start_character":56,"end_line":90,"end_character":59},"updated":"2026-08-07 13:22:31.000000000","message":"nit: missing space","commit_id":"f7b9ec3119015d6b1dea8ac1ebb3c61435a62d08"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"5634fc620c4f6da2e05d57bb3d1db67b2caa97ad","unresolved":false,"context_lines":[{"line_number":87,"context_line":"     provides ``ovmf-inteltdx``)."},{"line_number":88,"context_line":""},{"line_number":89,"context_line":"     Nova uses QEMU\u0027s firmware auto-selection, which is based on firmware"},{"line_number":90,"context_line":"     descriptors, to select the matching firmware for TDs.More details on"},{"line_number":91,"context_line":"     these firmware descriptors can be found in the `QEMU firmware descriptor"},{"line_number":92,"context_line":"     documentation`_."},{"line_number":93,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"57813809_60f0ef4b","line":90,"range":{"start_line":90,"start_character":56,"end_line":90,"end_character":59},"in_reply_to":"8b6b22ac_50dcd479","updated":"2026-08-11 14:23:12.000000000","message":"Done","commit_id":"f7b9ec3119015d6b1dea8ac1ebb3c61435a62d08"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"6f5932f01b52e17c1d02423c70ac744139631a34","unresolved":false,"context_lines":[{"line_number":178,"context_line":"    affect the confidentiality or integrity provided by Intel TDX. A"},{"line_number":179,"context_line":"    host with a missing or broken QGS will still successfully boot TDs."},{"line_number":180,"context_line":"    Conversely, successfully launching a TD does not guarantee that attestation"},{"line_number":181,"context_line":"    is functioning correctly."},{"line_number":182,"context_line":""},{"line_number":183,"context_line":".. note::"},{"line_number":184,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"5972666f_e6258c42","line":181,"updated":"2026-08-07 13:22:31.000000000","message":"yeah. Also qemu does not kill the VM if attestation fails, e.g. due to a not accessible qgsd socket, it just logs an error to the domain logs.","commit_id":"f7b9ec3119015d6b1dea8ac1ebb3c61435a62d08"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"6f5932f01b52e17c1d02423c70ac744139631a34","unresolved":false,"context_lines":[{"line_number":200,"context_line":"- Because of missing support in the Linux kernel, TDs cannot yet be"},{"line_number":201,"context_line":"  live-migrated or suspended. At the moment, TDs need to be fully shut down"},{"line_number":202,"context_line":"  before migrating off a Intel TDX host, e.g. if maintenance is required on the"},{"line_number":203,"context_line":"  host."},{"line_number":204,"context_line":""},{"line_number":205,"context_line":"- For security hardening purposes, TDVF limits the supported features"},{"line_number":206,"context_line":"  of the virtualized platform. As a result, some features that are normally"}],"source_content_type":"text/x-rst","patch_set":1,"id":"2064da21_adaccbf2","line":203,"updated":"2026-08-07 13:22:31.000000000","message":"yepp. I tested, resize works","commit_id":"f7b9ec3119015d6b1dea8ac1ebb3c61435a62d08"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"7147d0b6958b30c2c186498edcb7c2518600881d","unresolved":true,"context_lines":[{"line_number":137,"context_line":"to ``none`` to not attach a video device. Intel TDX also requires stateless"},{"line_number":138,"context_line":"firmware, which is enabled by the ``hw_firmware_stateless`` property set to"},{"line_number":139,"context_line":"``true``."},{"line_number":140,"context_line":""},{"line_number":141,"context_line":"Attestation"},{"line_number":142,"context_line":"-----------"},{"line_number":143,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"885573f7_02f2c174","line":140,"updated":"2026-08-13 13:50:03.000000000","message":"lets mention setting os_secure_boot\u003doptional in case the host OS does not provide descriptors of firmwares for non secure boot by default (as is the case in centos 10 stream today)","commit_id":"b050013ded02e626067b438221c19c78cc95a85a"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"63bbeed50e4883be06c8c2ac8dc08ef5b432009f","unresolved":false,"context_lines":[{"line_number":137,"context_line":"to ``none`` to not attach a video device. Intel TDX also requires stateless"},{"line_number":138,"context_line":"firmware, which is enabled by the ``hw_firmware_stateless`` property set to"},{"line_number":139,"context_line":"``true``."},{"line_number":140,"context_line":""},{"line_number":141,"context_line":"Attestation"},{"line_number":142,"context_line":"-----------"},{"line_number":143,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"4d05fe79_3bce887b","line":140,"in_reply_to":"885573f7_02f2c174","updated":"2026-08-14 08:34:23.000000000","message":"Done","commit_id":"b050013ded02e626067b438221c19c78cc95a85a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":true,"context_lines":[{"line_number":3,"context_line":"Intel TDX (Intel Trust Domain Extensions)"},{"line_number":4,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":5,"context_line":""},{"line_number":6,"context_line":".. versionadded:: 33.0.0 (Hibiscus)"},{"line_number":7,"context_line":""},{"line_number":8,"context_line":"`Intel Trust Domain Extensions (Intel TDX)`__ is a Confidential Computing"},{"line_number":9,"context_line":"technology from Intel, which provides a hardware-based Trusted Execution"}],"source_content_type":"text/x-rst","patch_set":4,"id":"214e00b8_ffb504d3","line":6,"range":{"start_line":6,"start_character":18,"end_line":6,"end_character":24},"updated":"2026-08-21 03:19:18.000000000","message":"\u002734.0.0\u0027 as \u002733.0.0\u0027 is gazpacho","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"884edaffa550c6f534a41839ec3c344cddd5dab7","unresolved":false,"context_lines":[{"line_number":3,"context_line":"Intel TDX (Intel Trust Domain Extensions)"},{"line_number":4,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":5,"context_line":""},{"line_number":6,"context_line":".. versionadded:: 33.0.0 (Hibiscus)"},{"line_number":7,"context_line":""},{"line_number":8,"context_line":"`Intel Trust Domain Extensions (Intel TDX)`__ is a Confidential Computing"},{"line_number":9,"context_line":"technology from Intel, which provides a hardware-based Trusted Execution"}],"source_content_type":"text/x-rst","patch_set":4,"id":"2ab97b1b_daa57e67","line":6,"range":{"start_line":6,"start_character":18,"end_line":6,"end_character":24},"in_reply_to":"214e00b8_ffb504d3","updated":"2026-08-21 13:44:46.000000000","message":"Acknowledged","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"f6b7811ef97b5953d27c6a652243033c71d0f9cf","unresolved":true,"context_lines":[{"line_number":48,"context_line":"- A cloud administrator will need to define one or more Intel TDX-enabled"},{"line_number":49,"context_line":"  flavors :ref:`as described below \u003cextra-specs-memory-encryption-tdx\u003e`."},{"line_number":50,"context_line":""},{"line_number":51,"context_line":"- Configure :oslo.config:option:`libvirt.cpu_mode` to ``host-passthrough``."},{"line_number":52,"context_line":"  Intel TDX requires the guest to see the full, unmodified feature set of the"},{"line_number":53,"context_line":"  host CPU, so unlike some other hardware-feature-gated functionality, a"},{"line_number":54,"context_line":"  curated ``custom`` CPU model via :oslo.config:option:`libvirt.cpu_models`"},{"line_number":55,"context_line":"  is not sufficient here."},{"line_number":56,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"90e05028_c80cd378","line":53,"range":{"start_line":51,"start_character":1,"end_line":53,"end_character":11},"updated":"2026-08-18 22:48:59.000000000","message":"That is technially not what ``host-passthrough`` does.\n\n`host-passthrough` effectivly set -cpu host on the qemu commadn line\n\nthat prestna all the host vituralisable cpu flags to the guest but that is not the same thing as an `unmodified feature set of the host CPU`\n\nthere are som ecpu flags that will not be expsoed when using host-passthough\n\nlibvirt descibes it as follows but that stirctly speaking not entirly corect either\n\n```\nhost-passthrough\n\n    With this mode, the CPU visible to the guest should be exactly the same as the host CPU even in the aspects that libvirt does not understand. Though the downside of this mode is that the guest environment cannot be reproduced on different hardware. Thus, if you hit any bugs, you are on your own. Further details of that CPU can be changed using feature elements. Migration of a guest using host-passthrough is dangerous if the source and destination hosts are not identical in both hardware, QEMU version, microcode version and configuration. If such a migration is attempted then the guest may hang or crash upon resuming execution on the destination host. Depending on hypervisor version the virtual CPU may or may not contain features which may block migration even to an identical host. Since 6.5.0 optional migratable attribute may be used to explicitly request such features to be removed from (on) or kept in (off) the virtual CPU. This attribute does not make migration to another host safer: even with migratable\u003d\u0027on\u0027 migration will be dangerous unless both hosts are identical as described above.\n```\n\nhttps://libvirt.org/formatdomain.html#:~:text\u003dhost%2Dpassthrough,-With\n\nqemu is more exact\n\nhttps://www.qemu.org/docs/master/system/qemu-cpu-models.html?utm_source\u003dchatgpt.com#two-ways-to-configure-cpu-models-with-qemu-kvm\n\n```\nHost passthrough\n\nThis passes the host CPU model features, model, stepping, exactly to the guest. Note that KVM may filter out some host CPU model features if they cannot be supported with virtualization. Live migration is unsafe when this mode is used as libvirt / QEMU cannot guarantee a stable CPU is exposed to the guest across hosts. This is the recommended CPU to use, provided live migration is not required.\n```\n\ndo we know if migratable\u003d\u0027on\u0027 work with tdx? \n\nwe dont currently set that but if tdx means you cannot live migrate that a very sever limitation that shoudl eb called out promently at the top of the doc.\n\nmigratable\u003d\u0027on\u0027 does not mean live migration will work with `host-passthrough` but its somethign we shoudl look into going forward","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"d36e20b925972d3079a59c7cd9d310c254d6b09b","unresolved":true,"context_lines":[{"line_number":48,"context_line":"- A cloud administrator will need to define one or more Intel TDX-enabled"},{"line_number":49,"context_line":"  flavors :ref:`as described below \u003cextra-specs-memory-encryption-tdx\u003e`."},{"line_number":50,"context_line":""},{"line_number":51,"context_line":"- Configure :oslo.config:option:`libvirt.cpu_mode` to ``host-passthrough``."},{"line_number":52,"context_line":"  Intel TDX requires the guest to see the full, unmodified feature set of the"},{"line_number":53,"context_line":"  host CPU, so unlike some other hardware-feature-gated functionality, a"},{"line_number":54,"context_line":"  curated ``custom`` CPU model via :oslo.config:option:`libvirt.cpu_models`"},{"line_number":55,"context_line":"  is not sufficient here."},{"line_number":56,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"eb33b69e_02fefa04","line":53,"range":{"start_line":51,"start_character":1,"end_line":53,"end_character":11},"in_reply_to":"90e05028_c80cd378","updated":"2026-08-19 08:27:16.000000000","message":"\u003e That is technially not what host-passthrough does.\n\nI can update it to be more technically correct\n\n\u003e do we know if migratable\u003d\u0027on\u0027 work with tdx?\n\nLive migration is not currently supported by the kernel for TDX, as noted under limitations below. This note is similar to that in the AMD SEV documentation. Live migration limitation is widely considered consistent with confidential computing and the overall technology.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"f6b7811ef97b5953d27c6a652243033c71d0f9cf","unresolved":true,"context_lines":[{"line_number":62,"context_line":"  x86_64 images use the ``q35`` machine type by default, avoiding the"},{"line_number":63,"context_line":"  need to set the ``hw_machine_type`` property on every Intel TDX-bootable"},{"line_number":64,"context_line":"  image."},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"  .. caution::"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"     Consider carefully whether to set this option. It is particularly"},{"line_number":69,"context_line":"     important since a limitation of the implementation prevents the"},{"line_number":70,"context_line":"     user from receiving an error message with a helpful explanation"},{"line_number":71,"context_line":"     if they try to boot an Intel TDX instance when neither this"},{"line_number":72,"context_line":"     configuration option nor the image property are set to select"},{"line_number":73,"context_line":"     a ``q35`` machine type."},{"line_number":74,"context_line":""},{"line_number":75,"context_line":"     On the other hand, setting it to ``q35`` may have other"},{"line_number":76,"context_line":"     undesirable side-effects on other images which were expecting to"},{"line_number":77,"context_line":"     be booted with ``pc``, so it is suggested to set it on a single"},{"line_number":78,"context_line":"     compute node or aggregate, and perform careful testing of typical"},{"line_number":79,"context_line":"     images before rolling out the setting to all Intel TDX-capable compute"},{"line_number":80,"context_line":"     hosts."},{"line_number":81,"context_line":""},{"line_number":82,"context_line":".. note::"},{"line_number":83,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"140b35ff_45685f0a","line":80,"range":{"start_line":65,"start_character":1,"end_line":80,"end_character":11},"updated":"2026-08-18 22:48:59.000000000","message":"this caution is very hard to follow\n\nfirst i think caustion is not correct to use hter \n\nnote or impartant but not cations setting hw_machine_type is not dangourse whihc cation impleis\n\n```suggestion\n\n  .. important::\n\n     The libvirt hw_machine_type config option provides a per host overried\n     for the drivers default machine type, this will be used for any instance\n     that does not request a machine type via the slected glance image.\n     \n     Any image that depend on a specific machine type should alwasy define\n     hw_machine_type in its image properteis, intel TDX required the Q35\n     machine type to function and this can be defiend via the image or the\n     libvirt hw_machine_type config option. As the livbirt config option applies\n     to all vms schduled to a host hwne not set in the image it is recommened\n     to set the machine type request in the image when using TDX to avoid\n     impacting other workloads.\n     \n     Nova will recored the machine type used to first create a vm durign intial\n     boot and htere is no way to modify that as a normal user without a rebuild.\n     admin can force a machine type change using nova-manage but htis may break\n     the guest VM and shoudl be avoided.\n```\n\nmaybe somting like that is better\n\nwe shoudl not recommend usign the host level cofnig option as the primary way to confiure tdx \n\nideally you either sat that confg option the same on all hosts or you do not set it\nat all\n\none of the pirmary reasons for having triats for TDX is so that the administroatr does nto need to create host aggates to group the TDX capable host. that happesn automaticly vai traits.\n\n\nwe simialrly do not recomemnt crating host aggreats for SEV. you can but you shoudl never need too for thing to work correctly.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"d36e20b925972d3079a59c7cd9d310c254d6b09b","unresolved":true,"context_lines":[{"line_number":62,"context_line":"  x86_64 images use the ``q35`` machine type by default, avoiding the"},{"line_number":63,"context_line":"  need to set the ``hw_machine_type`` property on every Intel TDX-bootable"},{"line_number":64,"context_line":"  image."},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"  .. caution::"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"     Consider carefully whether to set this option. It is particularly"},{"line_number":69,"context_line":"     important since a limitation of the implementation prevents the"},{"line_number":70,"context_line":"     user from receiving an error message with a helpful explanation"},{"line_number":71,"context_line":"     if they try to boot an Intel TDX instance when neither this"},{"line_number":72,"context_line":"     configuration option nor the image property are set to select"},{"line_number":73,"context_line":"     a ``q35`` machine type."},{"line_number":74,"context_line":""},{"line_number":75,"context_line":"     On the other hand, setting it to ``q35`` may have other"},{"line_number":76,"context_line":"     undesirable side-effects on other images which were expecting to"},{"line_number":77,"context_line":"     be booted with ``pc``, so it is suggested to set it on a single"},{"line_number":78,"context_line":"     compute node or aggregate, and perform careful testing of typical"},{"line_number":79,"context_line":"     images before rolling out the setting to all Intel TDX-capable compute"},{"line_number":80,"context_line":"     hosts."},{"line_number":81,"context_line":""},{"line_number":82,"context_line":".. note::"},{"line_number":83,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"b2978e97_1e489450","line":80,"range":{"start_line":65,"start_character":1,"end_line":80,"end_character":11},"in_reply_to":"140b35ff_45685f0a","updated":"2026-08-19 08:27:16.000000000","message":"This caution was taken almost in full from the SEV documentation:\nhttps://docs.openstack.org/nova/latest/admin/sev.html\n\nI only adapted it to TDX.\n\nI can update it with your suggestions.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"f6b7811ef97b5953d27c6a652243033c71d0f9cf","unresolved":true,"context_lines":[{"line_number":120,"context_line":""},{"line_number":121,"context_line":"  .. code-block:: console"},{"line_number":122,"context_line":""},{"line_number":123,"context_line":"    $ openstack image set IMAGE-NAME \\"},{"line_number":124,"context_line":"        --property hw:mem_encryption\u003dtrue \\"},{"line_number":125,"context_line":"        --property hw:mem_encryption_model\u003dintel-tdx"},{"line_number":126,"context_line":""},{"line_number":127,"context_line":"If a guest specifically needs to be scheduled to Intel TDX-capable hardware,"},{"line_number":128,"context_line":"independent of ``hw:mem_encryption_model``, this can also be ensured"}],"source_content_type":"text/x-rst","patch_set":4,"id":"3e923772_fb14ed0f","line":125,"range":{"start_line":123,"start_character":2,"end_line":125,"end_character":52},"updated":"2026-08-18 22:48:59.000000000","message":"in the image we use _ not : \n\n\n\n```suggestion\n    $ openstack image set IMAGE-NAME \\\n        --property hw_mem_encryption\u003dtrue \\\n        --property hw_mem_encryption_model\u003dintel-tdx\n```\n\nnova has the concpet of extra spec namespaces sperated form the extra spec key or name by a `:` in glance that is not a thing in the api so we map our namesapce seperator to _ to alignt to the glance nameing scheme\n\nthat why the flavor has `hw:` and the image has `hw_`","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"d36e20b925972d3079a59c7cd9d310c254d6b09b","unresolved":true,"context_lines":[{"line_number":120,"context_line":""},{"line_number":121,"context_line":"  .. code-block:: console"},{"line_number":122,"context_line":""},{"line_number":123,"context_line":"    $ openstack image set IMAGE-NAME \\"},{"line_number":124,"context_line":"        --property hw:mem_encryption\u003dtrue \\"},{"line_number":125,"context_line":"        --property hw:mem_encryption_model\u003dintel-tdx"},{"line_number":126,"context_line":""},{"line_number":127,"context_line":"If a guest specifically needs to be scheduled to Intel TDX-capable hardware,"},{"line_number":128,"context_line":"independent of ``hw:mem_encryption_model``, this can also be ensured"}],"source_content_type":"text/x-rst","patch_set":4,"id":"dbf1f421_bceb9ae0","line":125,"range":{"start_line":123,"start_character":2,"end_line":125,"end_character":52},"in_reply_to":"3e923772_fb14ed0f","updated":"2026-08-19 08:27:16.000000000","message":"Good catch, I mixed them up. I will update","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"884edaffa550c6f534a41839ec3c344cddd5dab7","unresolved":true,"context_lines":[{"line_number":120,"context_line":""},{"line_number":121,"context_line":"  .. code-block:: console"},{"line_number":122,"context_line":""},{"line_number":123,"context_line":"    $ openstack image set IMAGE-NAME \\"},{"line_number":124,"context_line":"        --property hw:mem_encryption\u003dtrue \\"},{"line_number":125,"context_line":"        --property hw:mem_encryption_model\u003dintel-tdx"},{"line_number":126,"context_line":""},{"line_number":127,"context_line":"If a guest specifically needs to be scheduled to Intel TDX-capable hardware,"},{"line_number":128,"context_line":"independent of ``hw:mem_encryption_model``, this can also be ensured"}],"source_content_type":"text/x-rst","patch_set":4,"id":"86685ab3_ae3e2317","line":125,"range":{"start_line":123,"start_character":2,"end_line":125,"end_character":52},"in_reply_to":"dbf1f421_bceb9ae0","updated":"2026-08-21 13:44:46.000000000","message":"fixed","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"f6b7811ef97b5953d27c6a652243033c71d0f9cf","unresolved":true,"context_lines":[{"line_number":124,"context_line":"        --property hw:mem_encryption\u003dtrue \\"},{"line_number":125,"context_line":"        --property hw:mem_encryption_model\u003dintel-tdx"},{"line_number":126,"context_line":""},{"line_number":127,"context_line":"If a guest specifically needs to be scheduled to Intel TDX-capable hardware,"},{"line_number":128,"context_line":"independent of ``hw:mem_encryption_model``, this can also be ensured"},{"line_number":129,"context_line":"with the placement trait :nova:extra-spec:`trait{group}:HW_CPU_X86_INTEL_TDX`"},{"line_number":130,"context_line":"set to ``required``."},{"line_number":131,"context_line":""},{"line_number":132,"context_line":"Intel TDX instances can only be booted from images which have the"},{"line_number":133,"context_line":"``hw_firmware_type`` property set to ``uefi``, and only when the"},{"line_number":134,"context_line":"machine type is set to ``q35``."}],"source_content_type":"text/x-rst","patch_set":4,"id":"0a4644f9_9f4d7bf2","line":131,"range":{"start_line":127,"start_character":0,"end_line":131,"end_character":1},"updated":"2026-08-18 22:48:59.000000000","message":"so why are we docuejmtning this\n\nrequesting `trait:HW_CPU_X86_INTEL_TDX\u003drequired`\n\nwill schdule to a host htat has TDX capablilty but will nto enabel TDX supprot for that vm  unless you also set  `hw:mem_encryption\u003dtrue` \n\nand even then we do not want to encurage that usage.\n\n`hw:mem_encryption_model` should be the primary way in docuemation we request a spcicyig tyep of memory encyptions.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"d36e20b925972d3079a59c7cd9d310c254d6b09b","unresolved":true,"context_lines":[{"line_number":124,"context_line":"        --property hw:mem_encryption\u003dtrue \\"},{"line_number":125,"context_line":"        --property hw:mem_encryption_model\u003dintel-tdx"},{"line_number":126,"context_line":""},{"line_number":127,"context_line":"If a guest specifically needs to be scheduled to Intel TDX-capable hardware,"},{"line_number":128,"context_line":"independent of ``hw:mem_encryption_model``, this can also be ensured"},{"line_number":129,"context_line":"with the placement trait :nova:extra-spec:`trait{group}:HW_CPU_X86_INTEL_TDX`"},{"line_number":130,"context_line":"set to ``required``."},{"line_number":131,"context_line":""},{"line_number":132,"context_line":"Intel TDX instances can only be booted from images which have the"},{"line_number":133,"context_line":"``hw_firmware_type`` property set to ``uefi``, and only when the"},{"line_number":134,"context_line":"machine type is set to ``q35``."}],"source_content_type":"text/x-rst","patch_set":4,"id":"8f04893c_a43487bf","line":131,"range":{"start_line":127,"start_character":0,"end_line":131,"end_character":1},"in_reply_to":"0a4644f9_9f4d7bf2","updated":"2026-08-19 08:27:16.000000000","message":"I agree, I will drop this","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"884edaffa550c6f534a41839ec3c344cddd5dab7","unresolved":true,"context_lines":[{"line_number":124,"context_line":"        --property hw:mem_encryption\u003dtrue \\"},{"line_number":125,"context_line":"        --property hw:mem_encryption_model\u003dintel-tdx"},{"line_number":126,"context_line":""},{"line_number":127,"context_line":"If a guest specifically needs to be scheduled to Intel TDX-capable hardware,"},{"line_number":128,"context_line":"independent of ``hw:mem_encryption_model``, this can also be ensured"},{"line_number":129,"context_line":"with the placement trait :nova:extra-spec:`trait{group}:HW_CPU_X86_INTEL_TDX`"},{"line_number":130,"context_line":"set to ``required``."},{"line_number":131,"context_line":""},{"line_number":132,"context_line":"Intel TDX instances can only be booted from images which have the"},{"line_number":133,"context_line":"``hw_firmware_type`` property set to ``uefi``, and only when the"},{"line_number":134,"context_line":"machine type is set to ``q35``."}],"source_content_type":"text/x-rst","patch_set":4,"id":"3d0503c9_94544e1e","line":131,"range":{"start_line":127,"start_character":0,"end_line":131,"end_character":1},"in_reply_to":"8f04893c_a43487bf","updated":"2026-08-21 13:44:46.000000000","message":"This is now removed","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":true,"context_lines":[{"line_number":124,"context_line":"        --property hw:mem_encryption\u003dtrue \\"},{"line_number":125,"context_line":"        --property hw:mem_encryption_model\u003dintel-tdx"},{"line_number":126,"context_line":""},{"line_number":127,"context_line":"If a guest specifically needs to be scheduled to Intel TDX-capable hardware,"},{"line_number":128,"context_line":"independent of ``hw:mem_encryption_model``, this can also be ensured"},{"line_number":129,"context_line":"with the placement trait :nova:extra-spec:`trait{group}:HW_CPU_X86_INTEL_TDX`"},{"line_number":130,"context_line":"set to ``required``."},{"line_number":131,"context_line":""},{"line_number":132,"context_line":"Intel TDX instances can only be booted from images which have the"},{"line_number":133,"context_line":"``hw_firmware_type`` property set to ``uefi``, and only when the"},{"line_number":134,"context_line":"machine type is set to ``q35``."},{"line_number":135,"context_line":""},{"line_number":136,"context_line":"Additionally the guest video device model (``hw_video_model``) needs to be set"},{"line_number":137,"context_line":"to ``none`` to not attach a video device. Intel TDX also requires stateless"},{"line_number":138,"context_line":"firmware, which is enabled by the ``hw_firmware_stateless`` property set to"},{"line_number":139,"context_line":"``true``."},{"line_number":140,"context_line":""},{"line_number":141,"context_line":".. note::"},{"line_number":142,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"f3f20460_9d5f2176","line":139,"range":{"start_line":127,"start_character":0,"end_line":139,"end_character":9},"updated":"2026-08-21 03:19:18.000000000","message":"I will amke these also #3 and #4","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"f6b7811ef97b5953d27c6a652243033c71d0f9cf","unresolved":true,"context_lines":[{"line_number":136,"context_line":"Additionally the guest video device model (``hw_video_model``) needs to be set"},{"line_number":137,"context_line":"to ``none`` to not attach a video device. Intel TDX also requires stateless"},{"line_number":138,"context_line":"firmware, which is enabled by the ``hw_firmware_stateless`` property set to"},{"line_number":139,"context_line":"``true``."},{"line_number":140,"context_line":""},{"line_number":141,"context_line":".. note::"},{"line_number":142,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"ded76ae5_5af61aeb","line":139,"updated":"2026-08-18 22:48:59.000000000","message":"i asked this else where but by setting `hw_video_model\u003d\"none\"` in the image it means that the spice and vnc consoles wont work\nhave we tested the serial console or the concole log functionatliy?","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"d36e20b925972d3079a59c7cd9d310c254d6b09b","unresolved":true,"context_lines":[{"line_number":136,"context_line":"Additionally the guest video device model (``hw_video_model``) needs to be set"},{"line_number":137,"context_line":"to ``none`` to not attach a video device. Intel TDX also requires stateless"},{"line_number":138,"context_line":"firmware, which is enabled by the ``hw_firmware_stateless`` property set to"},{"line_number":139,"context_line":"``true``."},{"line_number":140,"context_line":""},{"line_number":141,"context_line":".. note::"},{"line_number":142,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"4fa86a05_10e54d36","line":139,"in_reply_to":"ded76ae5_5af61aeb","updated":"2026-08-19 08:27:16.000000000","message":"I will try to use the serial console and console log to see how it interacts","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"884edaffa550c6f534a41839ec3c344cddd5dab7","unresolved":false,"context_lines":[{"line_number":124,"context_line":"        --property hw:mem_encryption\u003dtrue \\"},{"line_number":125,"context_line":"        --property hw:mem_encryption_model\u003dintel-tdx"},{"line_number":126,"context_line":""},{"line_number":127,"context_line":"If a guest specifically needs to be scheduled to Intel TDX-capable hardware,"},{"line_number":128,"context_line":"independent of ``hw:mem_encryption_model``, this can also be ensured"},{"line_number":129,"context_line":"with the placement trait :nova:extra-spec:`trait{group}:HW_CPU_X86_INTEL_TDX`"},{"line_number":130,"context_line":"set to ``required``."},{"line_number":131,"context_line":""},{"line_number":132,"context_line":"Intel TDX instances can only be booted from images which have the"},{"line_number":133,"context_line":"``hw_firmware_type`` property set to ``uefi``, and only when the"},{"line_number":134,"context_line":"machine type is set to ``q35``."},{"line_number":135,"context_line":""},{"line_number":136,"context_line":"Additionally the guest video device model (``hw_video_model``) needs to be set"},{"line_number":137,"context_line":"to ``none`` to not attach a video device. Intel TDX also requires stateless"},{"line_number":138,"context_line":"firmware, which is enabled by the ``hw_firmware_stateless`` property set to"},{"line_number":139,"context_line":"``true``."},{"line_number":140,"context_line":""},{"line_number":141,"context_line":".. note::"},{"line_number":142,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"ea791d5c_d44c44bc","line":139,"range":{"start_line":127,"start_character":0,"end_line":139,"end_character":9},"in_reply_to":"f3f20460_9d5f2176","updated":"2026-08-21 13:44:46.000000000","message":"Done","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":true,"context_lines":[{"line_number":142,"context_line":""},{"line_number":143,"context_line":"  Some distributions ship only a secure boot version of the firmware. In that"},{"line_number":144,"context_line":"  case, the ``os_secure_boot`` property must be set to either ``optional`` or"},{"line_number":145,"context_line":"  ``required`` to select the secure boot version."},{"line_number":146,"context_line":""},{"line_number":147,"context_line":"Attestation"},{"line_number":148,"context_line":"-----------"}],"source_content_type":"text/x-rst","patch_set":4,"id":"ee25ef6d_83bce779","line":145,"range":{"start_line":145,"start_character":4,"end_line":145,"end_character":12},"updated":"2026-08-21 03:19:18.000000000","message":"\u0027requried\u0027 but TDX cannot support/enable it right? I commented in the below change that let\u0027s fail if secure boot is reqeusted.\n\nI will add it as #5 item and saying that ``os_secure_boot`` is not supported in TDX so you need to explicitly set it to DISABLED","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"d9618f0d7116ec31daa1a31ab5118d5d3fb4e4ad","unresolved":false,"context_lines":[{"line_number":142,"context_line":""},{"line_number":143,"context_line":"  Some distributions ship only a secure boot version of the firmware. In that"},{"line_number":144,"context_line":"  case, the ``os_secure_boot`` property must be set to either ``optional`` or"},{"line_number":145,"context_line":"  ``required`` to select the secure boot version."},{"line_number":146,"context_line":""},{"line_number":147,"context_line":"Attestation"},{"line_number":148,"context_line":"-----------"}],"source_content_type":"text/x-rst","patch_set":4,"id":"dad2fa70_988e9356","line":145,"range":{"start_line":145,"start_character":4,"end_line":145,"end_character":12},"in_reply_to":"9bf5e0db_485287c0","updated":"2026-08-22 03:03:03.000000000","message":"Done","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"542046038da9f50bab69dc4ca6e07dd9c0a017de","unresolved":true,"context_lines":[{"line_number":142,"context_line":""},{"line_number":143,"context_line":"  Some distributions ship only a secure boot version of the firmware. In that"},{"line_number":144,"context_line":"  case, the ``os_secure_boot`` property must be set to either ``optional`` or"},{"line_number":145,"context_line":"  ``required`` to select the secure boot version."},{"line_number":146,"context_line":""},{"line_number":147,"context_line":"Attestation"},{"line_number":148,"context_line":"-----------"}],"source_content_type":"text/x-rst","patch_set":4,"id":"9bf5e0db_485287c0","line":145,"range":{"start_line":145,"start_character":4,"end_line":145,"end_character":12},"in_reply_to":"ee25ef6d_83bce779","updated":"2026-08-21 14:59:49.000000000","message":"This is no longer necessary since https://review.opendev.org/c/openstack/nova/+/1000472 now comes before this, and it resolves the issue with secure boot.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"f6b7811ef97b5953d27c6a652243033c71d0f9cf","unresolved":true,"context_lines":[{"line_number":144,"context_line":"  case, the ``os_secure_boot`` property must be set to either ``optional`` or"},{"line_number":145,"context_line":"  ``required`` to select the secure boot version."},{"line_number":146,"context_line":""},{"line_number":147,"context_line":"Attestation"},{"line_number":148,"context_line":"-----------"},{"line_number":149,"context_line":""},{"line_number":150,"context_line":"Intel TDX provides a mechanism to remotely verify the integrity of a TD called"},{"line_number":151,"context_line":"*remote attestation*. This process always has two parts: evidence generation and"},{"line_number":152,"context_line":"evidence verification. The first part is always performed by the Intel"},{"line_number":153,"context_line":"TDX-capable host, while the second part is performed by a relying party, which"},{"line_number":154,"context_line":"can be any entity that wants to verify the integrity of a TD, such as a cloud"},{"line_number":155,"context_line":"operator or a customer of a cloud operator."},{"line_number":156,"context_line":""},{"line_number":157,"context_line":"In the case of Intel TDX, the evidence is called a *TD Quote*, which is"},{"line_number":158,"context_line":"cryptographically protected and contains security-critical information about the"},{"line_number":159,"context_line":"TD and the underlying hardware, e.g., the TD\u0027s initial configuration, the"},{"line_number":160,"context_line":"virtual firmware, the CPU state."},{"line_number":161,"context_line":""},{"line_number":162,"context_line":"TD Quote generation always starts from within the TD, which requests a TD Report"},{"line_number":163,"context_line":"from the CPU. The TD Report is then sent to QEMU, which forwards it to a **Quote"},{"line_number":164,"context_line":"Generation Service (QGS)**. The QGS does certain verifications and generates a"},{"line_number":165,"context_line":"TD Quote from the TD Report. The TD Quote is then sent back to the TD, which can"},{"line_number":166,"context_line":"forward it to a relying party for verification."},{"line_number":167,"context_line":""},{"line_number":168,"context_line":"Communication between QEMU and the QGS is possible over VSocks and Unix sockets."},{"line_number":169,"context_line":"As upstream libvirt only supports communication over Unix socket, this is also"},{"line_number":170,"context_line":"the default communication method used by Nova. The current Nova implementation"},{"line_number":171,"context_line":"does not configure the QGS location itself, nor does it currently expose any"},{"line_number":172,"context_line":"option to point at a non-default one. Instead, it exposes the default Unix"},{"line_number":173,"context_line":"socket path used by Intel\u0027s tooling."},{"line_number":174,"context_line":""},{"line_number":175,"context_line":" .. note::"},{"line_number":176,"context_line":""},{"line_number":177,"context_line":"    At the time of writing, the default Unix socket path is:"},{"line_number":178,"context_line":"    ``/var/run/tdx-qgs/qgs.socket``"},{"line_number":179,"context_line":""},{"line_number":180,"context_line":"Operators must install and enable QGS on every Intel TDX-capable"},{"line_number":181,"context_line":"compute host as part of host setup, before it is added to the compute"},{"line_number":182,"context_line":"plane. This is a manual, host-level step. Nova does not deploy,"},{"line_number":183,"context_line":"manage the lifecycle of, or health-check the QGS on the operator\u0027s"},{"line_number":184,"context_line":"behalf."},{"line_number":185,"context_line":""},{"line_number":186,"context_line":".. note::"},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"    The QGS only affects whether a TD Quote can be generated. It has no"},{"line_number":189,"context_line":"    bearing on whether a TD starts or continues running, nor does it"},{"line_number":190,"context_line":"    affect the confidentiality or integrity provided by Intel TDX. A"},{"line_number":191,"context_line":"    host with a missing or broken QGS will still successfully boot TDs."},{"line_number":192,"context_line":"    Conversely, successfully launching a TD does not guarantee that attestation"},{"line_number":193,"context_line":"    is functioning correctly."},{"line_number":194,"context_line":""},{"line_number":195,"context_line":".. note::"},{"line_number":196,"context_line":""},{"line_number":197,"context_line":"    Nova does not perform any attestations by itself, it only makes it possible."},{"line_number":198,"context_line":"    Performing an attestation and verifying the TD Quote is the responsibility"},{"line_number":199,"context_line":"    of the end user. Nova does not provide such means or gate anything on"},{"line_number":200,"context_line":"    whether an attestation attempt succeeds or fails."},{"line_number":201,"context_line":""},{"line_number":202,"context_line":"Limitations"},{"line_number":203,"context_line":"-----------"},{"line_number":204,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"c40331ae_7890fee2","line":201,"range":{"start_line":147,"start_character":0,"end_line":201,"end_character":1},"updated":"2026-08-18 22:48:59.000000000","message":"we are not supproting this in nova correct?\n\ni dont think we shoudl supprot this tyep fo attestation by defualt \nthis shoudl have its own extra spec imo and be off by defualt.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"884edaffa550c6f534a41839ec3c344cddd5dab7","unresolved":true,"context_lines":[{"line_number":144,"context_line":"  case, the ``os_secure_boot`` property must be set to either ``optional`` or"},{"line_number":145,"context_line":"  ``required`` to select the secure boot version."},{"line_number":146,"context_line":""},{"line_number":147,"context_line":"Attestation"},{"line_number":148,"context_line":"-----------"},{"line_number":149,"context_line":""},{"line_number":150,"context_line":"Intel TDX provides a mechanism to remotely verify the integrity of a TD called"},{"line_number":151,"context_line":"*remote attestation*. This process always has two parts: evidence generation and"},{"line_number":152,"context_line":"evidence verification. The first part is always performed by the Intel"},{"line_number":153,"context_line":"TDX-capable host, while the second part is performed by a relying party, which"},{"line_number":154,"context_line":"can be any entity that wants to verify the integrity of a TD, such as a cloud"},{"line_number":155,"context_line":"operator or a customer of a cloud operator."},{"line_number":156,"context_line":""},{"line_number":157,"context_line":"In the case of Intel TDX, the evidence is called a *TD Quote*, which is"},{"line_number":158,"context_line":"cryptographically protected and contains security-critical information about the"},{"line_number":159,"context_line":"TD and the underlying hardware, e.g., the TD\u0027s initial configuration, the"},{"line_number":160,"context_line":"virtual firmware, the CPU state."},{"line_number":161,"context_line":""},{"line_number":162,"context_line":"TD Quote generation always starts from within the TD, which requests a TD Report"},{"line_number":163,"context_line":"from the CPU. The TD Report is then sent to QEMU, which forwards it to a **Quote"},{"line_number":164,"context_line":"Generation Service (QGS)**. The QGS does certain verifications and generates a"},{"line_number":165,"context_line":"TD Quote from the TD Report. The TD Quote is then sent back to the TD, which can"},{"line_number":166,"context_line":"forward it to a relying party for verification."},{"line_number":167,"context_line":""},{"line_number":168,"context_line":"Communication between QEMU and the QGS is possible over VSocks and Unix sockets."},{"line_number":169,"context_line":"As upstream libvirt only supports communication over Unix socket, this is also"},{"line_number":170,"context_line":"the default communication method used by Nova. The current Nova implementation"},{"line_number":171,"context_line":"does not configure the QGS location itself, nor does it currently expose any"},{"line_number":172,"context_line":"option to point at a non-default one. Instead, it exposes the default Unix"},{"line_number":173,"context_line":"socket path used by Intel\u0027s tooling."},{"line_number":174,"context_line":""},{"line_number":175,"context_line":" .. note::"},{"line_number":176,"context_line":""},{"line_number":177,"context_line":"    At the time of writing, the default Unix socket path is:"},{"line_number":178,"context_line":"    ``/var/run/tdx-qgs/qgs.socket``"},{"line_number":179,"context_line":""},{"line_number":180,"context_line":"Operators must install and enable QGS on every Intel TDX-capable"},{"line_number":181,"context_line":"compute host as part of host setup, before it is added to the compute"},{"line_number":182,"context_line":"plane. This is a manual, host-level step. Nova does not deploy,"},{"line_number":183,"context_line":"manage the lifecycle of, or health-check the QGS on the operator\u0027s"},{"line_number":184,"context_line":"behalf."},{"line_number":185,"context_line":""},{"line_number":186,"context_line":".. note::"},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"    The QGS only affects whether a TD Quote can be generated. It has no"},{"line_number":189,"context_line":"    bearing on whether a TD starts or continues running, nor does it"},{"line_number":190,"context_line":"    affect the confidentiality or integrity provided by Intel TDX. A"},{"line_number":191,"context_line":"    host with a missing or broken QGS will still successfully boot TDs."},{"line_number":192,"context_line":"    Conversely, successfully launching a TD does not guarantee that attestation"},{"line_number":193,"context_line":"    is functioning correctly."},{"line_number":194,"context_line":""},{"line_number":195,"context_line":".. note::"},{"line_number":196,"context_line":""},{"line_number":197,"context_line":"    Nova does not perform any attestations by itself, it only makes it possible."},{"line_number":198,"context_line":"    Performing an attestation and verifying the TD Quote is the responsibility"},{"line_number":199,"context_line":"    of the end user. Nova does not provide such means or gate anything on"},{"line_number":200,"context_line":"    whether an attestation attempt succeeds or fails."},{"line_number":201,"context_line":""},{"line_number":202,"context_line":"Limitations"},{"line_number":203,"context_line":"-----------"},{"line_number":204,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"5b4c71be_a9e19c8f","line":201,"range":{"start_line":147,"start_character":0,"end_line":201,"end_character":1},"in_reply_to":"20bd9394_49915012","updated":"2026-08-21 13:44:46.000000000","message":"Agreed to clarify that Nova doesn\u0027t actively support attestation. This has been added as a warning.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"d36e20b925972d3079a59c7cd9d310c254d6b09b","unresolved":true,"context_lines":[{"line_number":144,"context_line":"  case, the ``os_secure_boot`` property must be set to either ``optional`` or"},{"line_number":145,"context_line":"  ``required`` to select the secure boot version."},{"line_number":146,"context_line":""},{"line_number":147,"context_line":"Attestation"},{"line_number":148,"context_line":"-----------"},{"line_number":149,"context_line":""},{"line_number":150,"context_line":"Intel TDX provides a mechanism to remotely verify the integrity of a TD called"},{"line_number":151,"context_line":"*remote attestation*. This process always has two parts: evidence generation and"},{"line_number":152,"context_line":"evidence verification. The first part is always performed by the Intel"},{"line_number":153,"context_line":"TDX-capable host, while the second part is performed by a relying party, which"},{"line_number":154,"context_line":"can be any entity that wants to verify the integrity of a TD, such as a cloud"},{"line_number":155,"context_line":"operator or a customer of a cloud operator."},{"line_number":156,"context_line":""},{"line_number":157,"context_line":"In the case of Intel TDX, the evidence is called a *TD Quote*, which is"},{"line_number":158,"context_line":"cryptographically protected and contains security-critical information about the"},{"line_number":159,"context_line":"TD and the underlying hardware, e.g., the TD\u0027s initial configuration, the"},{"line_number":160,"context_line":"virtual firmware, the CPU state."},{"line_number":161,"context_line":""},{"line_number":162,"context_line":"TD Quote generation always starts from within the TD, which requests a TD Report"},{"line_number":163,"context_line":"from the CPU. The TD Report is then sent to QEMU, which forwards it to a **Quote"},{"line_number":164,"context_line":"Generation Service (QGS)**. The QGS does certain verifications and generates a"},{"line_number":165,"context_line":"TD Quote from the TD Report. The TD Quote is then sent back to the TD, which can"},{"line_number":166,"context_line":"forward it to a relying party for verification."},{"line_number":167,"context_line":""},{"line_number":168,"context_line":"Communication between QEMU and the QGS is possible over VSocks and Unix sockets."},{"line_number":169,"context_line":"As upstream libvirt only supports communication over Unix socket, this is also"},{"line_number":170,"context_line":"the default communication method used by Nova. The current Nova implementation"},{"line_number":171,"context_line":"does not configure the QGS location itself, nor does it currently expose any"},{"line_number":172,"context_line":"option to point at a non-default one. Instead, it exposes the default Unix"},{"line_number":173,"context_line":"socket path used by Intel\u0027s tooling."},{"line_number":174,"context_line":""},{"line_number":175,"context_line":" .. note::"},{"line_number":176,"context_line":""},{"line_number":177,"context_line":"    At the time of writing, the default Unix socket path is:"},{"line_number":178,"context_line":"    ``/var/run/tdx-qgs/qgs.socket``"},{"line_number":179,"context_line":""},{"line_number":180,"context_line":"Operators must install and enable QGS on every Intel TDX-capable"},{"line_number":181,"context_line":"compute host as part of host setup, before it is added to the compute"},{"line_number":182,"context_line":"plane. This is a manual, host-level step. Nova does not deploy,"},{"line_number":183,"context_line":"manage the lifecycle of, or health-check the QGS on the operator\u0027s"},{"line_number":184,"context_line":"behalf."},{"line_number":185,"context_line":""},{"line_number":186,"context_line":".. note::"},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"    The QGS only affects whether a TD Quote can be generated. It has no"},{"line_number":189,"context_line":"    bearing on whether a TD starts or continues running, nor does it"},{"line_number":190,"context_line":"    affect the confidentiality or integrity provided by Intel TDX. A"},{"line_number":191,"context_line":"    host with a missing or broken QGS will still successfully boot TDs."},{"line_number":192,"context_line":"    Conversely, successfully launching a TD does not guarantee that attestation"},{"line_number":193,"context_line":"    is functioning correctly."},{"line_number":194,"context_line":""},{"line_number":195,"context_line":".. note::"},{"line_number":196,"context_line":""},{"line_number":197,"context_line":"    Nova does not perform any attestations by itself, it only makes it possible."},{"line_number":198,"context_line":"    Performing an attestation and verifying the TD Quote is the responsibility"},{"line_number":199,"context_line":"    of the end user. Nova does not provide such means or gate anything on"},{"line_number":200,"context_line":"    whether an attestation attempt succeeds or fails."},{"line_number":201,"context_line":""},{"line_number":202,"context_line":"Limitations"},{"line_number":203,"context_line":"-----------"},{"line_number":204,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"20bd9394_49915012","line":201,"range":{"start_line":147,"start_character":0,"end_line":201,"end_character":1},"in_reply_to":"c40331ae_7890fee2","updated":"2026-08-19 08:27:16.000000000","message":"\u003e we are not supproting this in nova correct?\n\nJust to be clear Nova is not performing any guest attestations. Nova ensures that the TDX-enabled virtual machine is capable of communicating with the necessary resources for attestation. It is then up to the operator to deploy these resources so that end users can perform attestation from within the guest. Nova does not perform any attestations, it only sets up the necessary parts in Libvirt/QEMU to let the instance communicate correctly with the quote generation service.\n\nThe reason why I included a section on this in the documentation is just to clarify what is required for an operator, and what Nova doesn\u0027t do.\n\n\u003e i dont think we shoudl supprot this tyep fo attestation by defualt\nthis shoudl have its own extra spec imo and be off by defualt.\n\nHow come? This type of attestation is a core component of confidential computing. The only difference would be whether the QuoteGenerationSocket is attached to QEMU.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":true,"context_lines":[{"line_number":202,"context_line":"Limitations"},{"line_number":203,"context_line":"-----------"},{"line_number":204,"context_line":""},{"line_number":205,"context_line":"Impermanent limitations"},{"line_number":206,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":207,"context_line":""},{"line_number":208,"context_line":"The following limitations may be removed in the future as the"}],"source_content_type":"text/x-rst","patch_set":4,"id":"8cee5ad8_2d537e4b","line":205,"range":{"start_line":205,"start_character":0,"end_line":205,"end_character":23},"updated":"2026-08-21 03:19:18.000000000","message":"I will move the \u0027Permanent limitations\u0027 first and then Impermanent","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"884edaffa550c6f534a41839ec3c344cddd5dab7","unresolved":false,"context_lines":[{"line_number":202,"context_line":"Limitations"},{"line_number":203,"context_line":"-----------"},{"line_number":204,"context_line":""},{"line_number":205,"context_line":"Impermanent limitations"},{"line_number":206,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":207,"context_line":""},{"line_number":208,"context_line":"The following limitations may be removed in the future as the"}],"source_content_type":"text/x-rst","patch_set":4,"id":"857d51ac_da4e5972","line":205,"range":{"start_line":205,"start_character":0,"end_line":205,"end_character":23},"in_reply_to":"8cee5ad8_2d537e4b","updated":"2026-08-21 13:44:46.000000000","message":"Done","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":true,"context_lines":[{"line_number":219,"context_line":"  available to non-Intel TDX guests may not be available to TDs. For example,"},{"line_number":220,"context_line":"  TDs cannot use the scsi driver."},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"- Use of spice / VNC / serial / RDP consoles is not reliable with"},{"line_number":223,"context_line":"  Intel TDX guests in practice, even where the underlying feature"},{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."}],"source_content_type":"text/x-rst","patch_set":4,"id":"6c92ac8b_cdcc5e00","line":222,"range":{"start_line":222,"start_character":32,"end_line":222,"end_character":35},"updated":"2026-08-21 03:19:18.000000000","message":"RDP console are gone with hyperV driver so we can remove it from this doc too.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":true,"context_lines":[{"line_number":219,"context_line":"  available to non-Intel TDX guests may not be available to TDs. For example,"},{"line_number":220,"context_line":"  TDs cannot use the scsi driver."},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"- Use of spice / VNC / serial / RDP consoles is not reliable with"},{"line_number":223,"context_line":"  Intel TDX guests in practice, even where the underlying feature"},{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."}],"source_content_type":"text/x-rst","patch_set":4,"id":"58ad8fc7_56521de4","line":222,"range":{"start_line":222,"start_character":23,"end_line":222,"end_character":29},"updated":"2026-08-21 03:19:18.000000000","message":"serial is supported right? \n\nand VNC/Spice console are definitely will not work so let\u0027s explicitly call them out here instead of saying \"not reliable\".","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"884edaffa550c6f534a41839ec3c344cddd5dab7","unresolved":true,"context_lines":[{"line_number":219,"context_line":"  available to non-Intel TDX guests may not be available to TDs. For example,"},{"line_number":220,"context_line":"  TDs cannot use the scsi driver."},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"- Use of spice / VNC / serial / RDP consoles is not reliable with"},{"line_number":223,"context_line":"  Intel TDX guests in practice, even where the underlying feature"},{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."}],"source_content_type":"text/x-rst","patch_set":4,"id":"c815d22e_50960d14","line":222,"range":{"start_line":222,"start_character":23,"end_line":222,"end_character":29},"in_reply_to":"58ad8fc7_56521de4","updated":"2026-08-21 13:44:46.000000000","message":"Yes that makes sense!","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"884edaffa550c6f534a41839ec3c344cddd5dab7","unresolved":false,"context_lines":[{"line_number":219,"context_line":"  available to non-Intel TDX guests may not be available to TDs. For example,"},{"line_number":220,"context_line":"  TDs cannot use the scsi driver."},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"- Use of spice / VNC / serial / RDP consoles is not reliable with"},{"line_number":223,"context_line":"  Intel TDX guests in practice, even where the underlying feature"},{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."}],"source_content_type":"text/x-rst","patch_set":4,"id":"2a1dfd8d_e6e353fa","line":222,"range":{"start_line":222,"start_character":32,"end_line":222,"end_character":35},"in_reply_to":"6c92ac8b_cdcc5e00","updated":"2026-08-21 13:44:46.000000000","message":"Done","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"f6b7811ef97b5953d27c6a652243033c71d0f9cf","unresolved":true,"context_lines":[{"line_number":201,"context_line":""},{"line_number":202,"context_line":"Limitations"},{"line_number":203,"context_line":"-----------"},{"line_number":204,"context_line":""},{"line_number":205,"context_line":"Impermanent limitations"},{"line_number":206,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":207,"context_line":""},{"line_number":208,"context_line":"The following limitations may be removed in the future as the"},{"line_number":209,"context_line":"hardware, firmware, and various layers of software receive new"},{"line_number":210,"context_line":"features:"},{"line_number":211,"context_line":""},{"line_number":212,"context_line":"- Because of missing support in the Linux kernel, TDs cannot yet be"},{"line_number":213,"context_line":"  live-migrated or suspended. At the moment, TDs need to be fully shut down"},{"line_number":214,"context_line":"  before migrating off a Intel TDX host, e.g. if maintenance is required on the"},{"line_number":215,"context_line":"  host."},{"line_number":216,"context_line":""},{"line_number":217,"context_line":"- For security hardening purposes, TDVF limits the supported features"},{"line_number":218,"context_line":"  of the virtualized platform. As a result, some features that are normally"},{"line_number":219,"context_line":"  available to non-Intel TDX guests may not be available to TDs. For example,"},{"line_number":220,"context_line":"  TDs cannot use the scsi driver."},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"- Use of spice / VNC / serial / RDP consoles is not reliable with"},{"line_number":223,"context_line":"  Intel TDX guests in practice, even where the underlying feature"},{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."},{"line_number":226,"context_line":""},{"line_number":227,"context_line":"Permanent limitations"},{"line_number":228,"context_line":"~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":4,"id":"c1de9478_5f134918","line":225,"range":{"start_line":204,"start_character":1,"end_line":225,"end_character":36},"updated":"2026-08-18 22:48:59.000000000","message":"honestly i was not involved in teh spec review of thie propsoal but i woudl have conidre  the fact aht live mgiratoin and teh sercie cosnoel as well as virtio-scis ectra do not work and the ohter limitaiton to mean we woudl not accpet this feature at this tiem\n\ni dont think we shoudl storngly condier marking this feature as expermitanal in the same way we condire qemu emulation fo a differnt cpu archisture to be experimetnal in nova.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"d54df6a3512fd497c1d14ed6f62d37091eca5d9f","unresolved":true,"context_lines":[{"line_number":201,"context_line":""},{"line_number":202,"context_line":"Limitations"},{"line_number":203,"context_line":"-----------"},{"line_number":204,"context_line":""},{"line_number":205,"context_line":"Impermanent limitations"},{"line_number":206,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":207,"context_line":""},{"line_number":208,"context_line":"The following limitations may be removed in the future as the"},{"line_number":209,"context_line":"hardware, firmware, and various layers of software receive new"},{"line_number":210,"context_line":"features:"},{"line_number":211,"context_line":""},{"line_number":212,"context_line":"- Because of missing support in the Linux kernel, TDs cannot yet be"},{"line_number":213,"context_line":"  live-migrated or suspended. At the moment, TDs need to be fully shut down"},{"line_number":214,"context_line":"  before migrating off a Intel TDX host, e.g. if maintenance is required on the"},{"line_number":215,"context_line":"  host."},{"line_number":216,"context_line":""},{"line_number":217,"context_line":"- For security hardening purposes, TDVF limits the supported features"},{"line_number":218,"context_line":"  of the virtualized platform. As a result, some features that are normally"},{"line_number":219,"context_line":"  available to non-Intel TDX guests may not be available to TDs. For example,"},{"line_number":220,"context_line":"  TDs cannot use the scsi driver."},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"- Use of spice / VNC / serial / RDP consoles is not reliable with"},{"line_number":223,"context_line":"  Intel TDX guests in practice, even where the underlying feature"},{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."},{"line_number":226,"context_line":""},{"line_number":227,"context_line":"Permanent limitations"},{"line_number":228,"context_line":"~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":4,"id":"639bd723_0454cd43","line":225,"range":{"start_line":204,"start_character":1,"end_line":225,"end_character":36},"in_reply_to":"433ad3c3_78dc803b","updated":"2026-08-21 13:00:51.000000000","message":"right but we have dicssed changing that several time in the past.\nand making live migration requried for all new feature going forward was one of the propsoals with the only expction being hardware/software limitation that prevent it.\n\nmigration is not the primary concer here for me it really the requirement for host passthough as we do not schduler on that today\n\nso without gating on cpu_mode\n\nhttps://review.opendev.org/c/openstack/nova/+/994421/5/nova/virt/libvirt/host.py#2187\n\nwe woudl not eb abel to properly schdule vms at all but \n\ntaht to me is sort of unprecended in nova\n\nit will work but its not a pater i think we should continue in the future.\n\ni am strongly hoping this limitation goes away with the intoduciton of new cpu models in the future when TDX is more mature\n\nwe can impvoe some of the ux in followups as well\n\ni.e. if hw_video_model is unset and TDX is requested we can default it to NONE so that operatos do not have to set that, and if qemu gains the ablity to supprot virtio-gpu or similr in a new release we can restore the logic to using virtio-gpu by defautl and supprot vnc ectra.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":true,"context_lines":[{"line_number":201,"context_line":""},{"line_number":202,"context_line":"Limitations"},{"line_number":203,"context_line":"-----------"},{"line_number":204,"context_line":""},{"line_number":205,"context_line":"Impermanent limitations"},{"line_number":206,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":207,"context_line":""},{"line_number":208,"context_line":"The following limitations may be removed in the future as the"},{"line_number":209,"context_line":"hardware, firmware, and various layers of software receive new"},{"line_number":210,"context_line":"features:"},{"line_number":211,"context_line":""},{"line_number":212,"context_line":"- Because of missing support in the Linux kernel, TDs cannot yet be"},{"line_number":213,"context_line":"  live-migrated or suspended. At the moment, TDs need to be fully shut down"},{"line_number":214,"context_line":"  before migrating off a Intel TDX host, e.g. if maintenance is required on the"},{"line_number":215,"context_line":"  host."},{"line_number":216,"context_line":""},{"line_number":217,"context_line":"- For security hardening purposes, TDVF limits the supported features"},{"line_number":218,"context_line":"  of the virtualized platform. As a result, some features that are normally"},{"line_number":219,"context_line":"  available to non-Intel TDX guests may not be available to TDs. For example,"},{"line_number":220,"context_line":"  TDs cannot use the scsi driver."},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"- Use of spice / VNC / serial / RDP consoles is not reliable with"},{"line_number":223,"context_line":"  Intel TDX guests in practice, even where the underlying feature"},{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."},{"line_number":226,"context_line":""},{"line_number":227,"context_line":"Permanent limitations"},{"line_number":228,"context_line":"~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":4,"id":"433ad3c3_78dc803b","line":225,"range":{"start_line":204,"start_character":1,"end_line":225,"end_character":36},"in_reply_to":"49f58f52_72c14902","updated":"2026-08-21 03:19:18.000000000","message":"yeah, not every users do live migration. honestly saying for me, if VM is booted and can be used, Nova did its job :) (I remember Kenichi and I used to joke about it that we should remove every API/operation from nova except create/delete VM :P). Migration is useful feature for many cloud but if anyone providing this TDX VM to users they know that creating VM/using it is more than enough *for now*.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"d9618f0d7116ec31daa1a31ab5118d5d3fb4e4ad","unresolved":true,"context_lines":[{"line_number":201,"context_line":""},{"line_number":202,"context_line":"Limitations"},{"line_number":203,"context_line":"-----------"},{"line_number":204,"context_line":""},{"line_number":205,"context_line":"Impermanent limitations"},{"line_number":206,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":207,"context_line":""},{"line_number":208,"context_line":"The following limitations may be removed in the future as the"},{"line_number":209,"context_line":"hardware, firmware, and various layers of software receive new"},{"line_number":210,"context_line":"features:"},{"line_number":211,"context_line":""},{"line_number":212,"context_line":"- Because of missing support in the Linux kernel, TDs cannot yet be"},{"line_number":213,"context_line":"  live-migrated or suspended. At the moment, TDs need to be fully shut down"},{"line_number":214,"context_line":"  before migrating off a Intel TDX host, e.g. if maintenance is required on the"},{"line_number":215,"context_line":"  host."},{"line_number":216,"context_line":""},{"line_number":217,"context_line":"- For security hardening purposes, TDVF limits the supported features"},{"line_number":218,"context_line":"  of the virtualized platform. As a result, some features that are normally"},{"line_number":219,"context_line":"  available to non-Intel TDX guests may not be available to TDs. For example,"},{"line_number":220,"context_line":"  TDs cannot use the scsi driver."},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"- Use of spice / VNC / serial / RDP consoles is not reliable with"},{"line_number":223,"context_line":"  Intel TDX guests in practice, even where the underlying feature"},{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."},{"line_number":226,"context_line":""},{"line_number":227,"context_line":"Permanent limitations"},{"line_number":228,"context_line":"~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":4,"id":"8debb977_9ae636a5","line":225,"range":{"start_line":204,"start_character":1,"end_line":225,"end_character":36},"in_reply_to":"639bd723_0454cd43","updated":"2026-08-22 03:03:03.000000000","message":"i cannot disagree with you about all these limitation and untested in CI. I am not strongly against of calling it experimental but only concern is when we will make it production ready and how? anyways I will leave that feature supported vs experimental call to you guys.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"a18b2cc1e942ee40bc997b62ad6e3a64a59bef2c","unresolved":true,"context_lines":[{"line_number":201,"context_line":""},{"line_number":202,"context_line":"Limitations"},{"line_number":203,"context_line":"-----------"},{"line_number":204,"context_line":""},{"line_number":205,"context_line":"Impermanent limitations"},{"line_number":206,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":207,"context_line":""},{"line_number":208,"context_line":"The following limitations may be removed in the future as the"},{"line_number":209,"context_line":"hardware, firmware, and various layers of software receive new"},{"line_number":210,"context_line":"features:"},{"line_number":211,"context_line":""},{"line_number":212,"context_line":"- Because of missing support in the Linux kernel, TDs cannot yet be"},{"line_number":213,"context_line":"  live-migrated or suspended. At the moment, TDs need to be fully shut down"},{"line_number":214,"context_line":"  before migrating off a Intel TDX host, e.g. if maintenance is required on the"},{"line_number":215,"context_line":"  host."},{"line_number":216,"context_line":""},{"line_number":217,"context_line":"- For security hardening purposes, TDVF limits the supported features"},{"line_number":218,"context_line":"  of the virtualized platform. As a result, some features that are normally"},{"line_number":219,"context_line":"  available to non-Intel TDX guests may not be available to TDs. For example,"},{"line_number":220,"context_line":"  TDs cannot use the scsi driver."},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"- Use of spice / VNC / serial / RDP consoles is not reliable with"},{"line_number":223,"context_line":"  Intel TDX guests in practice, even where the underlying feature"},{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."},{"line_number":226,"context_line":""},{"line_number":227,"context_line":"Permanent limitations"},{"line_number":228,"context_line":"~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":4,"id":"f2b1c18f_144fe392","line":225,"range":{"start_line":204,"start_character":1,"end_line":225,"end_character":36},"in_reply_to":"8debb977_9ae636a5","updated":"2026-08-24 15:03:31.000000000","message":"i think as long as we are upfront with the limiatoin and caveat about the state of it its ok to trust the operator to make the right chocie for there env so that what i care about most, being very clear about what we expect to work and what limtied set of usecase we intend to supprot and if that works for them then they can make the production or expermital call themseslves.\n\nso im not agaisnt just leaving this to the docs but just want use to be very intentional about this.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"d36e20b925972d3079a59c7cd9d310c254d6b09b","unresolved":true,"context_lines":[{"line_number":201,"context_line":""},{"line_number":202,"context_line":"Limitations"},{"line_number":203,"context_line":"-----------"},{"line_number":204,"context_line":""},{"line_number":205,"context_line":"Impermanent limitations"},{"line_number":206,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":207,"context_line":""},{"line_number":208,"context_line":"The following limitations may be removed in the future as the"},{"line_number":209,"context_line":"hardware, firmware, and various layers of software receive new"},{"line_number":210,"context_line":"features:"},{"line_number":211,"context_line":""},{"line_number":212,"context_line":"- Because of missing support in the Linux kernel, TDs cannot yet be"},{"line_number":213,"context_line":"  live-migrated or suspended. At the moment, TDs need to be fully shut down"},{"line_number":214,"context_line":"  before migrating off a Intel TDX host, e.g. if maintenance is required on the"},{"line_number":215,"context_line":"  host."},{"line_number":216,"context_line":""},{"line_number":217,"context_line":"- For security hardening purposes, TDVF limits the supported features"},{"line_number":218,"context_line":"  of the virtualized platform. As a result, some features that are normally"},{"line_number":219,"context_line":"  available to non-Intel TDX guests may not be available to TDs. For example,"},{"line_number":220,"context_line":"  TDs cannot use the scsi driver."},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"- Use of spice / VNC / serial / RDP consoles is not reliable with"},{"line_number":223,"context_line":"  Intel TDX guests in practice, even where the underlying feature"},{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."},{"line_number":226,"context_line":""},{"line_number":227,"context_line":"Permanent limitations"},{"line_number":228,"context_line":"~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":4,"id":"49f58f52_72c14902","line":225,"range":{"start_line":204,"start_character":1,"end_line":225,"end_character":36},"in_reply_to":"c1de9478_5f134918","updated":"2026-08-19 08:27:16.000000000","message":"I don\u0027t think that live migration should be considered as a blocker since it is a standard limitation of the technology and AMD SEV has the same limitation.\n\nvirtio-scsi limitation comes from the firmware being hardened. The same firmware can be built with SCSI support if required, it is just that the most commonly distributed version doesn\u0027t include it.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":true,"context_lines":[{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."},{"line_number":226,"context_line":""},{"line_number":227,"context_line":"Permanent limitations"},{"line_number":228,"context_line":"~~~~~~~~~~~~~~~~~~~~~"},{"line_number":229,"context_line":""},{"line_number":230,"context_line":"The following limitations are expected long-term:"}],"source_content_type":"text/x-rst","patch_set":4,"id":"f8a24641_f8c81974","line":227,"range":{"start_line":227,"start_character":0,"end_line":227,"end_character":21},"updated":"2026-08-21 03:19:18.000000000","message":"can we add the secure boot limitation also and ask users not to request os_secure_boot in image/flavor.","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"d9618f0d7116ec31daa1a31ab5118d5d3fb4e4ad","unresolved":false,"context_lines":[{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."},{"line_number":226,"context_line":""},{"line_number":227,"context_line":"Permanent limitations"},{"line_number":228,"context_line":"~~~~~~~~~~~~~~~~~~~~~"},{"line_number":229,"context_line":""},{"line_number":230,"context_line":"The following limitations are expected long-term:"}],"source_content_type":"text/x-rst","patch_set":4,"id":"e22f2a7a_317ee038","line":227,"range":{"start_line":227,"start_character":0,"end_line":227,"end_character":21},"in_reply_to":"57cae1b6_b9a0068a","updated":"2026-08-22 03:03:03.000000000","message":"Done","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"542046038da9f50bab69dc4ca6e07dd9c0a017de","unresolved":true,"context_lines":[{"line_number":224,"context_line":"  is nominally supported. Do not depend on console access being"},{"line_number":225,"context_line":"  available for Intel TDX instances."},{"line_number":226,"context_line":""},{"line_number":227,"context_line":"Permanent limitations"},{"line_number":228,"context_line":"~~~~~~~~~~~~~~~~~~~~~"},{"line_number":229,"context_line":""},{"line_number":230,"context_line":"The following limitations are expected long-term:"}],"source_content_type":"text/x-rst","patch_set":4,"id":"57cae1b6_b9a0068a","line":227,"range":{"start_line":227,"start_character":0,"end_line":227,"end_character":21},"in_reply_to":"f8a24641_f8c81974","updated":"2026-08-21 14:59:49.000000000","message":"See #144 comment","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":true,"context_lines":[{"line_number":239,"context_line":"Non-limitations"},{"line_number":240,"context_line":"~~~~~~~~~~~~~~~~"},{"line_number":241,"context_line":""},{"line_number":242,"context_line":"For the sake of eliminating any doubt, the following actions are *not*"},{"line_number":243,"context_line":"expected to be limited when Intel TDX is used:"},{"line_number":244,"context_line":""},{"line_number":245,"context_line":"- Cold migration and shelve, since the guest is powered off before the"},{"line_number":246,"context_line":"  operation and no protected TD runtime state needs to be preserved."}],"source_content_type":"text/x-rst","patch_set":4,"id":"369d1644_48d787e5","line":243,"range":{"start_line":242,"start_character":43,"end_line":243,"end_character":46},"updated":"2026-08-21 03:19:18.000000000","message":"...following actions are expected to work when Intel TDX is used:\n\nshould we say that we have not tested those and if any of it does not work, please file the bug? or if you have tested those then fine and good to add \u0027tested\u0027 word in the first statement","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"d9618f0d7116ec31daa1a31ab5118d5d3fb4e4ad","unresolved":false,"context_lines":[{"line_number":239,"context_line":"Non-limitations"},{"line_number":240,"context_line":"~~~~~~~~~~~~~~~~"},{"line_number":241,"context_line":""},{"line_number":242,"context_line":"For the sake of eliminating any doubt, the following actions are *not*"},{"line_number":243,"context_line":"expected to be limited when Intel TDX is used:"},{"line_number":244,"context_line":""},{"line_number":245,"context_line":"- Cold migration and shelve, since the guest is powered off before the"},{"line_number":246,"context_line":"  operation and no protected TD runtime state needs to be preserved."}],"source_content_type":"text/x-rst","patch_set":4,"id":"48301cf0_ead12d3b","line":243,"range":{"start_line":242,"start_character":43,"end_line":243,"end_character":46},"in_reply_to":"369d1644_48d787e5","updated":"2026-08-22 03:03:03.000000000","message":"Done","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"a18b2cc1e942ee40bc997b62ad6e3a64a59bef2c","unresolved":false,"context_lines":[{"line_number":73,"context_line":"     ``hw_machine_type`` on the image when a feature such as Intel TDX"},{"line_number":74,"context_line":"     requires a specific machine type, and to treat this config option"},{"line_number":75,"context_line":"     as a fallback rather than the primary mechanism, testing carefully"},{"line_number":76,"context_line":"     before applying it beyond a single host or aggregate."},{"line_number":77,"context_line":""},{"line_number":78,"context_line":"- Configure :oslo.config:option:`libvirt.num_intel_tdx_guests` to represent"},{"line_number":79,"context_line":"  the number of guests a Intel TDX-capable compute node can host concurrently"}],"source_content_type":"text/x-rst","patch_set":6,"id":"31d448d9_5dfdb349","line":76,"updated":"2026-08-24 15:03:31.000000000","message":"+1","commit_id":"51928db00915238e60df98b2cb0eb4c296a6f273"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"a18b2cc1e942ee40bc997b62ad6e3a64a59bef2c","unresolved":true,"context_lines":[{"line_number":189,"context_line":"    At the time of writing, the default Unix socket path is:"},{"line_number":190,"context_line":"    ``/var/run/tdx-qgs/qgs.socket``"},{"line_number":191,"context_line":""},{"line_number":192,"context_line":"Operators must install and enable QGS on every Intel TDX-capable"},{"line_number":193,"context_line":"compute host as part of host setup, before it is added to the compute"},{"line_number":194,"context_line":"plane. This is a manual, host-level step. Nova does not deploy,"},{"line_number":195,"context_line":"manage the lifecycle of, or health-check the QGS on the operator\u0027s"},{"line_number":196,"context_line":"behalf."},{"line_number":197,"context_line":""},{"line_number":198,"context_line":".. note::"},{"line_number":199,"context_line":""}],"source_content_type":"text/x-rst","patch_set":6,"id":"52fcf2f0_78899dd2","line":196,"range":{"start_line":192,"start_character":0,"end_line":196,"end_character":7},"updated":"2026-08-24 15:03:31.000000000","message":"nit: this implies that it required for TDX to work but that is adressed by the note\n\ni woudl be tempeted to invert the two and move this into the node and put the note content here \n\n```\nhe QGS only affects whether a TD Quote can be generated. It has no\n    bearing on whether a TD starts or continues running, nor does it\n    affect the confidentiality or integrity provided by Intel TDX. A\n    host with a missing or broken QGS will still successfully boot TDs.\n    Conversely, successfully launching a TD does not guarantee that attestation\n    is functioning correctly.\n    ```","commit_id":"51928db00915238e60df98b2cb0eb4c296a6f273"}],"releasenotes/notes/bp-intel-tdx-libvirt-support-90b5fc0efde4135c.yaml":[{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"13df8492b326f2e3ecc74da5cc651171fdb7bc5b","unresolved":true,"context_lines":[{"line_number":7,"context_line":"    Usage of Intel TDX for memory encryption can be required either via"},{"line_number":8,"context_line":"    a flavor which has the ``hw:mem_encryption_model`` extra spec set to"},{"line_number":9,"context_line":"    ``intel-tdx``, or via an image which has the ``hw_mem_encryption_model``"},{"line_number":10,"context_line":"    property set to ``intel-tdx``."}],"source_content_type":"text/x-yaml","patch_set":4,"id":"1b6be721_4542a6e3","line":10,"range":{"start_line":10,"start_character":0,"end_line":10,"end_character":34},"updated":"2026-08-21 03:19:18.000000000","message":"good to add the ref to the doc you are adding in this change. that can be a good ref to read who ever find it in releasenotes","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"884edaffa550c6f534a41839ec3c344cddd5dab7","unresolved":false,"context_lines":[{"line_number":7,"context_line":"    Usage of Intel TDX for memory encryption can be required either via"},{"line_number":8,"context_line":"    a flavor which has the ``hw:mem_encryption_model`` extra spec set to"},{"line_number":9,"context_line":"    ``intel-tdx``, or via an image which has the ``hw_mem_encryption_model``"},{"line_number":10,"context_line":"    property set to ``intel-tdx``."}],"source_content_type":"text/x-yaml","patch_set":4,"id":"e2f90c0a_417bf25d","line":10,"range":{"start_line":10,"start_character":0,"end_line":10,"end_character":34},"in_reply_to":"1b6be721_4542a6e3","updated":"2026-08-21 13:44:46.000000000","message":"Done","commit_id":"432ec45fd18f090d0b2ff8a29fba937b026b058a"}]}
