All of lore.kernel.org
 help / color / mirror / Atom feed
From: Borislav Petkov <bp@suse.de>
To: speck@linutronix.de
Subject: [MODERATED] Re: GPZv4
Date: Tue, 17 Apr 2018 22:37:17 +0200	[thread overview]
Message-ID: <20180417203717.GF3890@pd.tnic> (raw)
In-Reply-To: <476c3e0b-dde6-6e6b-2054-6e71fa2c396b@redhat.com>

On Tue, Apr 17, 2018 at 03:56:55PM -0400, speck for Jon Masters wrote:
> Let's make sure we're talking about the right thing when we talk about
> things being on or off. I usually always talk about a performance
> feature being on or off, not a mitigation. Therefore, I read the above
> as "MD is off by default", meaning the performance feature is disabled.

I mean the opposite. MD is enabled, as it is the default setting
normally, on any CPU that has MD. So the performance feature remains
enabled.

> This is our current thinking. However, AMD disagree with this and prefer
> to leave the feature enabled by default.

Yes.

> That would mean having to (at a minimum) address all of the userspace
> exposure with prctl(), seccomp(), or other interfaces, and get that
> all done within the next month. For the actual browsers, sure, there
> will be process isolation updates.

Yes. Paranoid people can boot with mdd=on - meaning "memory
disambiguation disable - on"

   [ and yap, if anything, we very very quickly need to agree on one
     terminology and stick with it because the confusion will be insane...
   ]

or, in your suggested nomenclature, ssb=off.

The finer-grained stuff we can do in parallel.

> So can you clarify what you meant by "off on AMD" by default?

AFAIK, AMD wants MD on by default, i.e., unchanged from the current
setting. The user who wants to buy into the perf hit and is paranoid
will be able to disable MD and thus enable the mitigation.

-- 
Regards/Gruss,
    Boris.

SUSE Linux GmbH, GF: Felix Imendörffer, Jane Smithard, Graham Norton, HRB 21284 (AG Nürnberg)
-- 

  reply	other threads:[~2018-04-17 20:37 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-04-17 18:26 [MODERATED] GPZv4 Jon Masters
2018-04-17 19:31 ` [MODERATED] GPZv4 Borislav Petkov
2018-04-17 19:56   ` Jon Masters
2018-04-17 20:37     ` Borislav Petkov [this message]
2018-04-17 21:03       ` Jon Masters
2018-04-17 21:20         ` Borislav Petkov
2018-04-17 21:22         ` GPZv4 Thomas Gleixner
2018-04-17 21:25           ` [MODERATED] GPZv4 Jiri Kosina
2018-04-17 21:38             ` Jon Masters
2018-04-17 21:43               ` Jiri Kosina
2018-04-17 22:01                 ` GPZv4 Thomas Gleixner
2018-04-17 22:02                   ` [MODERATED] GPZv4 Jon Masters
2018-04-18  2:48                     ` Konrad Rzeszutek Wilk
2018-04-18  3:44                       ` Jon Masters
2018-04-18  4:09                         ` Jon Masters
2018-04-18  4:18                           ` Jon Masters
2018-04-18  4:56                         ` Jon Masters
2018-04-18  7:06                         ` Jon Masters
2018-04-18  8:54                       ` GPZv4 Thomas Gleixner
2018-04-18 13:22                         ` [MODERATED] GPZv4 Jon Masters
2018-04-18 14:04                           ` GPZv4 Thomas Gleixner
2018-04-18 14:07                             ` [MODERATED] GPZv4 Jon Masters
2018-04-18 14:52                               ` Konrad Rzeszutek Wilk
2018-04-18 15:02                                 ` Jon Masters
2018-04-18 21:12                                   ` Konrad Rzeszutek Wilk
2018-04-18 21:20                                     ` Jon Masters
2018-04-17 21:36           ` Jon Masters

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20180417203717.GF3890@pd.tnic \
    --to=bp@suse.de \
    --cc=speck@linutronix.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.