From: "Chang S. Bae" <chang.seok.bae@intel.com>
To: Dave Hansen <dave.hansen@intel.com>,
"Maciej W. Rozycki" <macro@orcam.me.uk>
Cc: <linux-kernel@vger.kernel.org>, <x86@kernel.org>,
<tglx@kernel.org>, "Ingo Molnar" <mingo@redhat.com>,
<bp@alien8.de>, <dave.hansen@linux.intel.com>, <hpa@zytor.com>
Subject: Re: [PATCH] x86/microcode/intel: Panic on partial microcode update
Date: Mon, 27 Jul 2026 13:36:25 -0700 [thread overview]
Message-ID: <a9262015-e403-4d36-a3a9-3e29f6f49318@intel.com> (raw)
In-Reply-To: <cb805adf-c382-4bc3-b0d4-19b6426aceab@intel.com>
On 7/19/2026 8:52 AM, Dave Hansen wrote:
>
> Chang, have you seen anything at all in the specs or from our Intel
> colleagues that makes you think that it's _dangerous_ to keep running
> rather than killing the system as soon as possible?
I double-checked with the microcode guy, and here are what I heard so far:
* The microcode implementation makes best effort to avoid partial
updates in the first place
* If an update leaves any critical state, e.g. data corruption and
serious security breach, the processor will terminate execution
rather than relying on the OS to take action.
* That said, no implementation can perfectly cover every possible case.
At the same time, panicking on every partial update could be also an
overkill. It will depend on the specific failure condition in detail.
Then, they've defined those bits seemingly intended to summary the
condition at abstraction.
I think the first two points have played in this thread already. There
seems to be some caution, specifically around the authentication-failure
as per spec. Perhaps it might be reassuring if handling that case
conservatively (unless too much complicated).
In summary, I think options are:
1. Panic on any partial update is the most conservative and secure
option, but it may unnecessarily disrupt systems and users
2. Warn admins that the system has entered a taint state, assuming the
processor handles truly unrecoverable cases itself.
3. Different reactions - for example, panic on an authentication
failure but warn/taint otherwise.
Thanks,
Chang
next prev parent reply other threads:[~2026-07-27 20:36 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-30 19:13 [PATCH] x86/microcode/intel: Panic on partial microcode update Chang S. Bae
2026-06-30 21:38 ` Dave Hansen
2026-06-30 21:47 ` Dave Hansen
2026-06-30 23:21 ` Borislav Petkov
2026-07-01 19:02 ` Chang S. Bae
2026-07-18 22:54 ` Maciej W. Rozycki
2026-07-19 15:52 ` Dave Hansen
2026-07-23 22:42 ` Maciej W. Rozycki
2026-07-27 12:35 ` Nikolay Borisov
2026-07-28 21:53 ` Maciej W. Rozycki
2026-07-27 20:36 ` Chang S. Bae [this message]
2026-07-27 21:59 ` Sohil Mehta
2026-07-28 2:58 ` Chang S. Bae
2026-07-28 14:12 ` Dave Hansen
2026-07-28 18:56 ` David Laight
2026-07-28 20:48 ` Dave Hansen
2026-07-28 21:47 ` Maciej W. Rozycki
2026-07-28 21:53 ` Dave Hansen
2026-07-28 22:09 ` David Laight
2026-07-08 21:18 ` [PATCH v2] x86/microcode/intel: Taint kernel on partial update Chang S. Bae
2026-07-27 11:27 ` Nikolay Borisov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a9262015-e403-4d36-a3a9-3e29f6f49318@intel.com \
--to=chang.seok.bae@intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=macro@orcam.me.uk \
--cc=mingo@redhat.com \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox