From: Kim Phillips <kim.phillips@amd.com>
To: <linux-kernel@vger.kernel.org>, <kvm@vger.kernel.org>,
<linux-coco@lists.linux.dev>, <x86@kernel.org>
Cc: Sean Christopherson <seanjc@google.com>,
Paolo Bonzini <pbonzini@redhat.com>,
K Prateek Nayak <kprateek.nayak@amd.com>,
"Nikunj A Dadhania" <nikunj@amd.com>,
Tom Lendacky <thomas.lendacky@amd.com>,
"Michael Roth" <michael.roth@amd.com>,
Borislav Petkov <borislav.petkov@amd.com>,
Borislav Petkov <bp@alien8.de>, Naveen Rao <naveen.rao@amd.com>,
David Kaplan <david.kaplan@amd.com>,
Pawan Gupta <pawan.kumar.gupta@linux.intel.com>,
"Dave Hansen" <dave.hansen@linux.intel.com>,
Kim Phillips <kim.phillips@amd.com>, <stable@kernel.org>
Subject: [PATCH v4 03/10] cpu/bugs: Fall back to AutoIBRS when retpoline unavailable on SNP CPUs
Date: Tue, 4 Aug 2026 18:56:04 -0500 [thread overview]
Message-ID: <20260804235611.4053375-4-kim.phillips@amd.com> (raw)
In-Reply-To: <20260804235611.4053375-1-kim.phillips@amd.com>
When the kernel is compiled without CONFIG_MITIGATION_RETPOLINE,
spectre_v2_select_retpoline() returns SPECTRE_V2_NONE, leaving SNP
hosts with AutoIBRS completely unmitigated against Spectre v2 in the
default/auto case.
Since SNP CPUs have AutoIBRS available, fall back to SPECTRE_V2_EIBRS
rather than leaving the system unmitigated. The preceding commit already
enables AutoIBRS (and sets X86_FEATURE_IBRS_ENHANCED) on SNP parts, so no
additional feature-bit fixup is needed here; only the mitigation
selection changes when retpoline is unavailable.
Fixes: acaa4b5c4c85 ("x86/speculation: Do not enable Automatic IBRS if SEV-SNP is enabled")
Cc: stable@kernel.org
Signed-off-by: Kim Phillips <kim.phillips@amd.com>
Assisted-by: ClaudeCode:claude-opus-4-7
---
arch/x86/kernel/cpu/bugs.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/arch/x86/kernel/cpu/bugs.c b/arch/x86/kernel/cpu/bugs.c
index a813a98ac5bd..6a036b509f0b 100644
--- a/arch/x86/kernel/cpu/bugs.c
+++ b/arch/x86/kernel/cpu/bugs.c
@@ -2204,6 +2204,15 @@ static void __init spectre_v2_select_mitigation(void)
}
spectre_v2_enabled = spectre_v2_select_retpoline();
+ /*
+ * If retpoline is unavailable (e.g. built without
+ * CONFIG_MITIGATION_RETPOLINE), fall back to eIBRS on
+ * AutoIBRS-capable parts rather than leaving SNP hosts
+ * unmitigated.
+ */
+ if (spectre_v2_enabled == SPECTRE_V2_NONE &&
+ boot_cpu_has(X86_FEATURE_AUTOIBRS))
+ spectre_v2_enabled = SPECTRE_V2_EIBRS;
break;
case SPECTRE_V2_CMD_RETPOLINE_LFENCE:
--
2.43.0
next prev parent reply other threads:[~2026-08-04 23:57 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 23:56 [PATCH v4 00/10] KVM: SEV: Add support for IBPB-on-Entry and BTB Isolation Kim Phillips
2026-08-04 23:56 ` [PATCH v4 01/10] x86/bugs: Only log missing retpoline when it's actually the missing mitigation Kim Phillips
2026-08-05 0:44 ` Borislav Petkov
2026-08-05 14:51 ` Kim Phillips
2026-08-05 22:49 ` Borislav Petkov
2026-08-06 20:12 ` Kim Phillips
2026-08-07 5:44 ` Borislav Petkov
2026-08-10 23:21 ` Kim Phillips
2026-08-11 0:48 ` Borislav Petkov
2026-08-04 23:56 ` [PATCH v4 02/10] cpu/bugs: Allow forcing Automatic IBRS with SNP active using spectre_v2=eibrs Kim Phillips
2026-08-04 23:56 ` Kim Phillips [this message]
2026-08-04 23:56 ` [PATCH v4 04/10] cpu/bugs: Allow spectre_v2=ibrs on x86 vendors other than Intel Kim Phillips
2026-08-04 23:56 ` [PATCH v4 05/10] KVM: SEV: Define SVM_SEV_FEAT_* flags using BIT_ULL() Kim Phillips
2026-08-04 23:56 ` [PATCH v4 06/10] KVM: selftests: sev_init2: Use BIT_ULL for VMSA feature bit definition Kim Phillips
2026-08-04 23:56 ` [PATCH v4 07/10] KVM: SEV: Disallow setting SNP-only features for non-SNP guests via a single mask Kim Phillips
2026-08-04 23:56 ` [PATCH v4 08/10] KVM: SEV: Advertise SVM_SEV_FEAT_SNP_ACTIVE Kim Phillips
2026-08-04 23:56 ` [PATCH v4 09/10] KVM: SEV: Add support for IBPB-on-Entry Kim Phillips
2026-08-04 23:56 ` [PATCH v4 10/10] KVM: SEV: Add support for SNP BTB Isolation Kim Phillips
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260804235611.4053375-4-kim.phillips@amd.com \
--to=kim.phillips@amd.com \
--cc=borislav.petkov@amd.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=david.kaplan@amd.com \
--cc=kprateek.nayak@amd.com \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=michael.roth@amd.com \
--cc=naveen.rao@amd.com \
--cc=nikunj@amd.com \
--cc=pawan.kumar.gupta@linux.intel.com \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=stable@kernel.org \
--cc=thomas.lendacky@amd.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.