From: Greg KH <gregkh@linuxfoundation.org>
To: speck@linutronix.de
Subject: [MODERATED] Re: [patch V3 9/9] MDS basics 9
Date: Fri, 22 Feb 2019 15:44:37 +0100 [thread overview]
Message-ID: <20190222144437.GA14171@kroah.com> (raw)
In-Reply-To: <alpine.DEB.2.21.1902221131260.1777@nanos.tec.linutronix.de>
On Fri, Feb 22, 2019 at 11:38:36AM +0100, speck for Thomas Gleixner wrote:
> On Fri, 22 Feb 2019, speck for Greg KH wrote:
> > On Fri, Feb 22, 2019 at 12:44:40AM +0100, speck for Thomas Gleixner wrote:
> > > static void mds_select_mitigation(void)
> > > @@ -236,12 +237,12 @@ static void mds_select_mitigation(void)
> > > break;
> > > case MDS_MITIGATION_AUTO:
> > > case MDS_MITIGATION_FULL:
> > > - if (boot_cpu_has(X86_FEATURE_MD_CLEAR)) {
> > > + case MDS_MITIGATION_VMWERV:
> > > + if (boot_cpu_has(X86_FEATURE_MD_CLEAR))
> > > mds_mitigation = MDS_MITIGATION_FULL;
> > > - static_branch_enable(&mds_user_clear);
> > > - } else {
> > > - mds_mitigation = MDS_MITIGATION_OFF;
> > > - }
> > > + else
> > > + mds_mitigation = MDS_MITIGATION_VMWERV;
> > > + static_branch_enable(&mds_user_clear);
> >
> > So did we just loose the ability at "auto" to turn this off if present,
> > because we really do not know if we can turn it off automatically?
> >
> > Or am I reading this code wrong?
> >
> > Should there be a new usespace command line option for "vmwerv"?
>
> I'd prefer not. So the logic here is:
>
> if CPU not affected:
> do nothing
>
> if 'off':
> do nothing
>
> if 'auto' or 'full':
> enable VERW
>
> The latter has two variants:
>
> 1) cpuid MD_CLEAR is set
>
> Switches the internal mode to FULL and VERW provides real protection.
>
> 2) cpuid MD_CLEAR is not set
>
> Switches the internal mode to VMWERV, issues VERW which protects or
> not. If microcode is not updated the VERW wastes a few cpu cycles
> pointlessly.
>
> The internal state is there so the dmesg/sysfs output reflects the
> protection state real vs. lottery.
Ok, thanks, that makes more sense. That might want to go into the
documentation somewhere :)
thanks,
greg k-h
next prev parent reply other threads:[~2019-02-22 14:44 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-02-21 23:44 [patch V3 0/9] MDS basics 0 Thomas Gleixner
2019-02-21 23:44 ` [patch V3 1/9] MDS basics 1 Thomas Gleixner
2019-02-22 6:53 ` [MODERATED] " Greg KH
2019-02-22 7:30 ` Borislav Petkov
2019-02-21 23:44 ` [patch V3 2/9] MDS basics 2 Thomas Gleixner
2019-02-21 23:44 ` [patch V3 3/9] MDS basics 3 Thomas Gleixner
2019-02-21 23:44 ` [patch V3 4/9] MDS basics 4 Thomas Gleixner
2019-02-22 6:58 ` [MODERATED] " Greg KH
2019-02-22 10:44 ` Thomas Gleixner
2019-02-22 14:36 ` [MODERATED] " Greg KH
2019-02-22 22:38 ` Thomas Gleixner
2019-02-22 7:45 ` [MODERATED] Encrypted Message Jon Masters
2019-02-22 17:16 ` [MODERATED] " Linus Torvalds
2019-02-22 17:40 ` Thomas Gleixner
2019-02-22 7:50 ` [MODERATED] Re: [patch V3 4/9] MDS basics 4 Borislav Petkov
2019-02-21 23:44 ` [patch V3 5/9] MDS basics 5 Thomas Gleixner
2019-02-22 0:46 ` [MODERATED] " Andrew Cooper
2019-02-22 7:00 ` Thomas Gleixner
2019-02-22 9:20 ` [MODERATED] " Peter Zijlstra
2019-02-22 10:23 ` Thomas Gleixner
2019-02-21 23:44 ` [patch V3 6/9] MDS basics 6 Thomas Gleixner
2019-02-21 23:44 ` [patch V3 7/9] MDS basics 7 Thomas Gleixner
2019-02-22 7:08 ` [MODERATED] " Greg KH
2019-02-21 23:44 ` [patch V3 8/9] MDS basics 8 Thomas Gleixner
2019-02-22 7:14 ` [MODERATED] " Greg KH
2019-02-22 8:55 ` Borislav Petkov
2019-02-21 23:44 ` [patch V3 9/9] MDS basics 9 Thomas Gleixner
2019-02-22 7:50 ` [MODERATED] " Greg KH
2019-02-22 10:38 ` Thomas Gleixner
2019-02-22 14:44 ` Greg KH [this message]
2019-02-22 15:53 ` [MODERATED] Re: " Borislav Petkov
2019-02-22 15:54 ` [MODERATED] " Borislav Petkov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20190222144437.GA14171@kroah.com \
--to=gregkh@linuxfoundation.org \
--cc=speck@linutronix.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.