From: Stefano Brivio <sbrivio@redhat.com>
To: Eric Biggers <ebiggers@kernel.org>
Cc: x86@kernel.org, linux-kernel@vger.kernel.org,
linux-raid@vger.kernel.org, Christoph Hellwig <hch@infradead.org>,
linux-crypto@vger.kernel.org,
Herbert Xu <herbert@gondor.apana.org.au>,
Taehee Yoo <ap420073@gmail.com>,
netfilter-devel@vger.kernel.org,
Pablo Neira Ayuso <pablo@netfilter.org>,
Florian Westphal <fw@strlen.de>, Phil Sutter <phil@nwl.cc>,
stable@vger.kernel.org
Subject: Re: [PATCH 6/6] netfilter: nft_set_pipapo_avx2: add missing vzeroupper
Date: Sun, 16 Aug 2026 12:38:41 +0200 (CEST) [thread overview]
Message-ID: <20260816123839.3670e5c3@elisabeth> (raw)
In-Reply-To: <20260815205750.169336-7-ebiggers@kernel.org>
Eric, thanks for taking care of this.
The patch looks good to me, I just have two questions:
On Sat, 15 Aug 2026 13:57:50 -0700
Eric Biggers <ebiggers@kernel.org> wrote:
> Since pipapo_get_avx2() uses YMM registers, execute vzeroupper before
> returning from it. This is needed to avoid degrading the performance of
> any later SSE code that may happen to be executed.
Out of curiosity: was this prompted by some observed latency spike in
execution of SSE code, or it's just meant to satisfy the recommendation
from AMD and Intel to use it while transitioning from AVX to SSE modes?
> Fixes: 7400b063969b ("nft_set_pipapo: Introduce AVX2-based lookup implementation")
> Cc: stable@vger.kernel.org
Is this really stable material? Skipping vzeroupper might have a
performance impact, but it's not an issue for correctness.
The main reason why I'm asking is that, while vzeroupper might look
harmless and obviously safe, it actually caused CVE-2023-20593
("ZenBleed") on AMD Zen 2.
I expect systems receiving stable kernel updates to also run the
patched microcode by now, so I'm not overly concerned in any case.
--
Stefano
next prev parent reply other threads:[~2026-08-16 10:38 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-15 20:57 [PATCH 0/6] x86: add missing vzeroupper instructions Eric Biggers
2026-08-15 20:57 ` [PATCH 1/6] xor: add missing vzeroupper to AVX code Eric Biggers
2026-08-15 20:57 ` [PATCH 2/6] raid6: add missing vzeroupper to AVX2 code Eric Biggers
2026-08-15 20:57 ` [PATCH 3/6] raid6: add missing vzeroupper to AVX-512 code Eric Biggers
2026-08-15 20:57 ` [PATCH 4/6] crypto: x86/aria - add missing vzeroupper in AVX2 code Eric Biggers
2026-08-15 20:57 ` [PATCH 5/6] crypto: x86/aria - add missing vzeroupper in AVX-512 code Eric Biggers
2026-08-15 20:57 ` [PATCH 6/6] netfilter: nft_set_pipapo_avx2: add missing vzeroupper Eric Biggers
2026-08-16 10:38 ` Stefano Brivio [this message]
2026-08-16 17:15 ` Eric Biggers
2026-08-16 15:14 ` [PATCH 0/6] x86: add missing vzeroupper instructions David Laight
2026-08-16 17:31 ` Eric Biggers
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260816123839.3670e5c3@elisabeth \
--to=sbrivio@redhat.com \
--cc=ap420073@gmail.com \
--cc=ebiggers@kernel.org \
--cc=fw@strlen.de \
--cc=hch@infradead.org \
--cc=herbert@gondor.apana.org.au \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-raid@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
--cc=phil@nwl.cc \
--cc=stable@vger.kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).