All of lore.kernel.org
 help / color / mirror / Atom feed
From: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
To: x86@kernel.org
Cc: David Kaplan <david.kaplan@amd.com>,
	linux-kernel@vger.kernel.org, "H. Peter Anvin" <hpa@zytor.com>,
	Josh Poimboeuf <jpoimboe@kernel.org>,
	Borislav Petkov <bp@alien8.de>
Subject: [PATCH v4 1/7] x86/retbleed: Avoid AUTO after the select step
Date: Wed, 11 Jun 2025 10:29:00 -0700	[thread overview]
Message-ID: <20250611-eibrs-fix-v4-1-5ff86cac6c61@linux.intel.com> (raw)
In-Reply-To: <20250611-eibrs-fix-v4-0-5ff86cac6c61@linux.intel.com>

Retbleed select function leaves the mitigation to AUTO in some cases.
Moreover, the update function can also set the mitigation to AUTO. This is
inconsistent with other mitigations and requires explicit handling of AUTO
at the end of update step.

Make sure a mitigation gets selected in the select step, and do not change
it to AUTO in the update step. When no mitigation can be selected leave it
to NONE, which is what AUTO was getting changed to in the end.

Suggested-by: Borislav Petkov <bp@alien8.de>
Acked-by: Borislav Petkov (AMD) <bp@alien8.de>
Signed-off-by: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
---
 arch/x86/kernel/cpu/bugs.c | 19 ++++++++++---------
 1 file changed, 10 insertions(+), 9 deletions(-)

diff --git a/arch/x86/kernel/cpu/bugs.c b/arch/x86/kernel/cpu/bugs.c
index 7f94e6a5497d9a2d312a76095e48d6b364565777..53649df2c4d66c6bd3aa34dec69af9df253bccfc 100644
--- a/arch/x86/kernel/cpu/bugs.c
+++ b/arch/x86/kernel/cpu/bugs.c
@@ -1247,6 +1247,14 @@ static void __init retbleed_select_mitigation(void)
 			retbleed_mitigation = RETBLEED_MITIGATION_IBPB;
 		else
 			retbleed_mitigation = RETBLEED_MITIGATION_NONE;
+	} else if (boot_cpu_data.x86_vendor == X86_VENDOR_INTEL) {
+		/* Final mitigation depends on spectre-v2 selection */
+		if (boot_cpu_has(X86_FEATURE_IBRS_ENHANCED))
+			retbleed_mitigation = RETBLEED_MITIGATION_EIBRS;
+		else if (boot_cpu_has(X86_FEATURE_IBRS))
+			retbleed_mitigation = RETBLEED_MITIGATION_IBRS;
+		else
+			retbleed_mitigation = RETBLEED_MITIGATION_NONE;
 	}
 }
 
@@ -1255,9 +1263,6 @@ static void __init retbleed_update_mitigation(void)
 	if (!boot_cpu_has_bug(X86_BUG_RETBLEED) || cpu_mitigations_off())
 		return;
 
-	if (retbleed_mitigation == RETBLEED_MITIGATION_NONE)
-		goto out;
-
 	/*
 	 * retbleed=stuff is only allowed on Intel.  If stuffing can't be used
 	 * then a different mitigation will be selected below.
@@ -1268,7 +1273,7 @@ static void __init retbleed_update_mitigation(void)
 	    its_mitigation == ITS_MITIGATION_RETPOLINE_STUFF) {
 		if (spectre_v2_enabled != SPECTRE_V2_RETPOLINE) {
 			pr_err("WARNING: retbleed=stuff depends on spectre_v2=retpoline\n");
-			retbleed_mitigation = RETBLEED_MITIGATION_AUTO;
+			retbleed_mitigation = RETBLEED_MITIGATION_NONE;
 		} else {
 			if (retbleed_mitigation != RETBLEED_MITIGATION_STUFF)
 				pr_info("Retbleed mitigation updated to stuffing\n");
@@ -1294,15 +1299,11 @@ static void __init retbleed_update_mitigation(void)
 			if (retbleed_mitigation != RETBLEED_MITIGATION_STUFF)
 				pr_err(RETBLEED_INTEL_MSG);
 		}
-		/* If nothing has set the mitigation yet, default to NONE. */
-		if (retbleed_mitigation == RETBLEED_MITIGATION_AUTO)
-			retbleed_mitigation = RETBLEED_MITIGATION_NONE;
 	}
-out:
+
 	pr_info("%s\n", retbleed_strings[retbleed_mitigation]);
 }
 
-
 static void __init retbleed_apply_mitigation(void)
 {
 	bool mitigate_smt = false;

-- 
2.34.1



  reply	other threads:[~2025-06-11 17:29 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-06-11 17:28 [PATCH v4 0/7] Retbleed fixes Pawan Gupta
2025-06-11 17:29 ` Pawan Gupta [this message]
2025-06-24 10:05   ` [tip: x86/bugs] x86/bugs: Avoid AUTO after the select step in the retbleed mitigation tip-bot2 for Pawan Gupta
2025-06-11 17:29 ` [PATCH v4 2/7] x86/retbleed: Simplify the =stuff checks Pawan Gupta
2025-06-24 10:05   ` [tip: x86/bugs] x86/bugs: Simplify the retbleed=stuff checks tip-bot2 for Pawan Gupta
2025-06-11 17:29 ` [PATCH v4 3/7] x86/bugs: Avoid warning when overriding return thunk Pawan Gupta
2025-06-24 10:05   ` [tip: x86/bugs] " tip-bot2 for Pawan Gupta
2025-06-11 17:29 ` [PATCH v4 4/7] x86/its: Use switch/case to apply mitigation Pawan Gupta
2025-06-24 10:05   ` [tip: x86/bugs] x86/bugs: Use switch/case in its_apply_mitigation() tip-bot2 for Pawan Gupta
2025-06-11 17:30 ` [PATCH v4 5/7] x86/retbleed: Introduce cdt_possible() Pawan Gupta
2025-06-24 10:05   ` [tip: x86/bugs] x86/bugs: " tip-bot2 for Pawan Gupta
2025-06-11 17:30 ` [PATCH v4 6/7] x86/its: Remove =stuff dependency on retbleed Pawan Gupta
2025-06-24 10:05   ` [tip: x86/bugs] x86/bugs: Remove its=stuff " tip-bot2 for Pawan Gupta
2025-06-11 17:30 ` [PATCH v4 7/7] x86/its: Allow stuffing in eIBRS+retpoline mode also Pawan Gupta
2025-06-24 10:05   ` [tip: x86/bugs] x86/bugs: Allow ITS " tip-bot2 for Pawan Gupta
2025-06-24 12:23   ` tip-bot2 for Pawan Gupta
2025-06-22 16:01 ` [PATCH v4 0/7] Retbleed fixes Borislav Petkov
2025-06-23 18:35   ` Pawan Gupta
2025-06-24 14:53     ` Borislav Petkov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250611-eibrs-fix-v4-1-5ff86cac6c61@linux.intel.com \
    --to=pawan.kumar.gupta@linux.intel.com \
    --cc=bp@alien8.de \
    --cc=david.kaplan@amd.com \
    --cc=hpa@zytor.com \
    --cc=jpoimboe@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.