From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Google-Smtp-Source: AH8x227wxBbWbzN8uDQfCch+xYLtdCmUYh6Fh567jZSfJ5rKnQY5lF1ST/GrcgluTZ/9cIfgKkMz ARC-Seal: i=1; a=rsa-sha256; t=1517309901; cv=none; d=google.com; s=arc-20160816; b=rXsz1NbdjVl0oFIMt7krYCfAwM+6Zqs1M5erbDZdtSO12xjYRoPKtOKaBbcn4s1OXQ tUKgm8ejd6dL8OJ+JPIzbH+d3HkVL5zL57DlqCIaZpmA5ZY3nLmAA/OewBj23lCm0lM3 LzxPUGQgTDfnVWH53Pwu0uv283CjTgtNAMZ7ggp//OqflVkJJcmEDvtTBeYsEirN+t6I LXOnCoB+d6lW0pgKqqLpsNjkxHTowq0EgEfVYBsOalzwoZ0inR/4WgEFp+IFGnhUq+U3 qv8fB/tqHyKvkVQaa0O/Wv4Ftpcx4Xm6cBJ9QXGLqFOaSMmbfBYFhpSybjD18/dvC8E1 AMOQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=user-agent:in-reply-to:content-disposition:mime-version:references :message-id:subject:cc:to:from:date:arc-authentication-results; bh=WWyArB4C0eXZnmwBtUlSfLq3038dHgKe9ulyu2r8kQg=; b=xUZI6VvW5nzfIOQzhv6uodZtTyizsv/oiZiLkDrgywe5+5EKT3jz6eqPoVYrDFGWN/ X1SlF6jxGd7Lzy9XSZqiVkXu/c1WWn4X0R9q1cRUw6DjSswXHrC1lqI6nDykNbwSaCc0 S/TfbR2E0JIVckKtSuvKRhOTfgseDBZIBaNZTv5tWHDmg87avzSPGP8Q1DnMsyvIwkmO hFw+PcTSVpF52MjFesUuAPrcCSngsLcBmsICHEnjGmtvKNICBM3NPQ0iEZF1D7/X3M4D 0j0lnItNGWwMxSoebmCTerYBsFXuM5RRaIC50Q1SbJpmuGMz27YNJw9AJtEp+xdwmXSR GwSg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of bp@alien8.de designates 2a01:4f8:190:11c2::b:1457 as permitted sender) smtp.mailfrom=bp@alien8.de Authentication-Results: mx.google.com; spf=pass (google.com: domain of bp@alien8.de designates 2a01:4f8:190:11c2::b:1457 as permitted sender) smtp.mailfrom=bp@alien8.de Date: Tue, 30 Jan 2018 11:58:14 +0100 From: Borislav Petkov To: David Woodhouse Cc: arjan@linux.intel.com, tglx@linutronix.de, karahmed@amazon.de, x86@kernel.org, linux-kernel@vger.kernel.org, tim.c.chen@linux.intel.com, peterz@infradead.org, pbonzini@redhat.com, ak@linux.intel.com, torvalds@linux-foundation.org, gregkh@linux-foundation.org Subject: Re: [PATCH] x86/cpuid: Fix up "virtual" IBRS/IBPB/STIBP feature bits on Intel Message-ID: <20180130105814.m5zd43dyx2o2ius2@pd.tnic> References: <1517269773-16750-1-git-send-email-dwmw@amazon.co.uk> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <1517269773-16750-1-git-send-email-dwmw@amazon.co.uk> User-Agent: NeoMutt/20170609 (1.8.3) X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-THRID: =?utf-8?q?1590972687399963990?= X-GMAIL-MSGID: =?utf-8?q?1591014747475123019?= X-Mailing-List: linux-kernel@vger.kernel.org List-ID: On Mon, Jan 29, 2018 at 11:49:33PM +0000, David Woodhouse wrote: > Despite the fact that all the other code there seems to be doing it, > just using set_cpu_cap() in early_intel_init() doesn't actually work. > > When the CPU is queried again in identify_boot_cpu(), it all gets > overwritten again. Do it in init_scattered_cpuid_features() instead. > > Turning the bits off for bad microcode can use setup_clear_cpu_cap() > to force them off for all CPUs; I was less keen on forcing the feature > bits *on* that way. > > Signed-off-by: David Woodhouse > Fixes: 2961298e ("x86/cpufeatures: Clean up Spectre v2 related CPUID flags") > --- > I feel I must be missing something. Is the rest of early_init_intel() broken too? Does that help? diff --git a/arch/x86/kernel/cpu/intel.c b/arch/x86/kernel/cpu/intel.c index 6936d14d4c77..1dd596d0a6c4 100644 --- a/arch/x86/kernel/cpu/intel.c +++ b/arch/x86/kernel/cpu/intel.c @@ -182,21 +182,21 @@ static void early_init_intel(struct cpuinfo_x86 *c) * Intel CPUs, for finer-grained selection of what's available. */ if (cpu_has(c, X86_FEATURE_SPEC_CTRL)) { - set_cpu_cap(c, X86_FEATURE_IBRS); - set_cpu_cap(c, X86_FEATURE_IBPB); + setup_force_cpu_cap(X86_FEATURE_IBRS); + setup_force_cpu_cap(X86_FEATURE_IBPB); } if (cpu_has(c, X86_FEATURE_INTEL_STIBP)) - set_cpu_cap(c, X86_FEATURE_STIBP); + setup_force_cpu_cap(X86_FEATURE_STIBP); /* Now if any of them are set, check the blacklist and clear the lot */ if ((cpu_has(c, X86_FEATURE_IBRS) || cpu_has(c, X86_FEATURE_IBPB) || cpu_has(c, X86_FEATURE_STIBP)) && bad_spectre_microcode(c)) { pr_warn("Intel Spectre v2 broken microcode detected; disabling Speculation Control\n"); - clear_cpu_cap(c, X86_FEATURE_IBRS); - clear_cpu_cap(c, X86_FEATURE_IBPB); - clear_cpu_cap(c, X86_FEATURE_STIBP); - clear_cpu_cap(c, X86_FEATURE_SPEC_CTRL); - clear_cpu_cap(c, X86_FEATURE_INTEL_STIBP); + setup_clear_cpu_cap(X86_FEATURE_IBRS); + setup_clear_cpu_cap(X86_FEATURE_IBPB); + setup_clear_cpu_cap(X86_FEATURE_STIBP); + setup_clear_cpu_cap(X86_FEATURE_SPEC_CTRL); + setup_clear_cpu_cap(X86_FEATURE_INTEL_STIBP); } /* -- Regards/Gruss, Boris. Good mailing practices for 400: avoid top-posting and trim the reply.