The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: "Chang S. Bae" <chang.seok.bae@intel.com>
To: Dave Hansen <dave.hansen@intel.com>,
	"Maciej W. Rozycki" <macro@orcam.me.uk>
Cc: <linux-kernel@vger.kernel.org>, <x86@kernel.org>,
	<tglx@kernel.org>, "Ingo Molnar" <mingo@redhat.com>,
	<bp@alien8.de>, <dave.hansen@linux.intel.com>, <hpa@zytor.com>
Subject: Re: [PATCH] x86/microcode/intel: Panic on partial microcode update
Date: Mon, 27 Jul 2026 13:36:25 -0700	[thread overview]
Message-ID: <a9262015-e403-4d36-a3a9-3e29f6f49318@intel.com> (raw)
In-Reply-To: <cb805adf-c382-4bc3-b0d4-19b6426aceab@intel.com>

On 7/19/2026 8:52 AM, Dave Hansen wrote:
> 
> Chang, have you seen anything at all in the specs or from our Intel
> colleagues that makes you think that it's _dangerous_ to keep running
> rather than killing the system as soon as possible?


I double-checked with the microcode guy, and here are what I heard so far:

  * The microcode implementation makes best effort to avoid partial
    updates in the first place
  * If an update leaves any critical state, e.g. data corruption and
    serious security breach, the processor will terminate execution
    rather than relying on the OS to take action.
  * That said, no implementation can perfectly cover every possible case.
    At the same time, panicking on every partial update could be also an
    overkill. It will depend on the specific failure condition in detail.

Then, they've defined those bits seemingly intended to summary the 
condition at abstraction.

I think the first two points have played in this thread already. There 
seems to be some caution, specifically around the authentication-failure 
as per spec. Perhaps it might be reassuring if handling that case 
conservatively (unless too much complicated).

In summary, I think options are:

  1. Panic on any partial update is the most conservative and secure
     option, but it may unnecessarily disrupt systems and users
  2. Warn admins that the system has entered a taint state, assuming the
     processor handles truly unrecoverable cases itself.
  3. Different reactions - for example, panic on an authentication
     failure but warn/taint otherwise.

Thanks,
Chang

  parent reply	other threads:[~2026-07-27 20:36 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-30 19:13 [PATCH] x86/microcode/intel: Panic on partial microcode update Chang S. Bae
2026-06-30 21:38 ` Dave Hansen
2026-06-30 21:47   ` Dave Hansen
2026-06-30 23:21     ` Borislav Petkov
2026-07-01 19:02     ` Chang S. Bae
2026-07-18 22:54     ` Maciej W. Rozycki
2026-07-19 15:52       ` Dave Hansen
2026-07-23 22:42         ` Maciej W. Rozycki
2026-07-27 12:35           ` Nikolay Borisov
2026-07-28 21:53             ` Maciej W. Rozycki
2026-07-27 20:36         ` Chang S. Bae [this message]
2026-07-27 21:59           ` Sohil Mehta
2026-07-28  2:58             ` Chang S. Bae
2026-07-28 14:12               ` Dave Hansen
2026-07-28 18:56                 ` David Laight
2026-07-28 20:48                   ` Dave Hansen
2026-07-28 21:47                     ` Maciej W. Rozycki
2026-07-28 21:53                       ` Dave Hansen
2026-07-28 22:09                     ` David Laight
2026-07-08 21:18 ` [PATCH v2] x86/microcode/intel: Taint kernel on partial update Chang S. Bae
2026-07-27 11:27   ` Nikolay Borisov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=a9262015-e403-4d36-a3a9-3e29f6f49318@intel.com \
    --to=chang.seok.bae@intel.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@intel.com \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=macro@orcam.me.uk \
    --cc=mingo@redhat.com \
    --cc=tglx@kernel.org \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox