mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: David Kaplan <david.kaplan@amd.com>
To: Thomas Gleixner <tglx@linutronix.de>,
	Borislav Petkov <bp@alien8.de>,
	Peter Zijlstra <peterz@infradead.org>,
	Josh Poimboeuf <jpoimboe@kernel.org>,
	Pawan Gupta <pawan.kumar.gupta@linux.intel.com>,
	Ingo Molnar <mingo@redhat.com>,
	Dave Hansen <dave.hansen@linux.intel.com>, <x86@kernel.org>,
	"H . Peter Anvin" <hpa@zytor.com>
Cc: <linux-kernel@vger.kernel.org>
Subject: [PATCH v6 00/21] Attack vector controls (part 2)
Date: Mon, 7 Jul 2025 13:32:55 -0500	[thread overview]
Message-ID: <20250707183316.1349127-1-david.kaplan@amd.com> (raw)

This is an updated version of the second half of the attack vector
series which adds new attack vector command line options designed to make
it easier to control which CPU mitigations are enabled.

The first half of this series focused on bugs.c restructuring and was
merged on May 2.  Link:
https://lore.kernel.org/all/20250418161721.1855190-1-david.kaplan@amd.com/

Attack vector options are designed to make it easier to select appropriate
mitigations based on the usage of the system.  While many users may not be
intimately familiar with the details of these CPU vulnerabilities, they are
likely better able to understand the intended usage of their system.  As a
result, unneeded mitigations may be disabled, allowing users to recoup more
performance.  New documentation is included with recommendations on what to
consider when choosing which attack vectors to enable/disable.

In this series, attack vector options are chosen using the mitigations=
command line.  Attack vectors may be individually disabled such as
'mitigations=auto;no_user_kernel,no_user_user'.  The 'mitigations=off'
option is equivalent to disabling all attack vectors.  'mitigations=off'
therefore disables all mitigations, unless bug-specific command line
options are used to re-enable some.

Note that this patch series does not change any of the existing
mitigation defaults.

Changes in v6:
   - Added ITS attack vector support
   - Removed new BHI user->kernel only mitigation (can be added later if
     desired)

Changes in v5:
   - Updated table layout in documentation file
   - Minor clean up

David Kaplan (21):
  Documentation/x86: Document new attack vector controls
  cpu: Define attack vectors
  x86/Kconfig: Add arch attack vector support
  x86/bugs: Define attack vectors relevant for each bug
  x86/bugs: Add attack vector controls for MDS
  x86/bugs: Add attack vector controls for TAA
  x86/bugs: Add attack vector controls for MMIO
  x86/bugs: Add attack vector controls for RFDS
  x86/bugs: Add attack vector controls for SRBDS
  x86/bugs: Add attack vector controls for GDS
  x86/bugs: Add attack vector controls for spectre_v1
  x86/bugs: Add attack vector controls for retbleed
  x86/bugs: Add attack vector controls for spectre_v2_user
  x86/bugs: Add attack vector controls for BHI
  x86/bugs: Add attack vector controls for spectre_v2
  x86/bugs: Add attack vector controls for L1TF
  x86/bugs: Add attack vector controls for SRSO
  x86/bugs: Add attack vector controls for ITS
  x86/pti: Add attack vector controls for PTI
  x86/bugs: Print enabled attack vectors
  cpu: Show attack vectors in sysfs

 .../hw-vuln/attack_vector_controls.rst        | 237 +++++++++++++++
 Documentation/admin-guide/hw-vuln/index.rst   |   1 +
 .../admin-guide/kernel-parameters.txt         |   4 +
 arch/Kconfig                                  |   3 +
 arch/x86/Kconfig                              |   1 +
 arch/x86/kernel/cpu/bugs.c                    | 269 ++++++++++++++----
 arch/x86/mm/pti.c                             |   4 +-
 drivers/base/cpu.c                            |  67 +++++
 include/linux/cpu.h                           |  21 ++
 kernel/cpu.c                                  | 130 ++++++++-
 10 files changed, 668 insertions(+), 69 deletions(-)
 create mode 100644 Documentation/admin-guide/hw-vuln/attack_vector_controls.rst


base-commit: f339770f60d9c3312133cfe6a349476848d9b128
-- 
2.34.1


             reply	other threads:[~2025-07-07 18:33 UTC|newest]

Thread overview: 50+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-07-07 18:32 David Kaplan [this message]
2025-07-07 18:32 ` [PATCH v6 01/21] Documentation/x86: Document new attack vector controls David Kaplan
2025-07-09 15:57   ` [PATCH v7 01/22] " David Kaplan
2025-07-11 16:09     ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:32 ` [PATCH v6 02/21] cpu: Define attack vectors David Kaplan
2025-07-10 10:42   ` Borislav Petkov
2025-07-10 14:02     ` Kaplan, David
2025-07-10 15:17       ` Borislav Petkov
2025-07-10 15:22         ` Kaplan, David
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:32 ` [PATCH v6 03/21] x86/Kconfig: Add arch attack vector support David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:32 ` [PATCH v6 04/21] x86/bugs: Define attack vectors relevant for each bug David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 05/21] x86/bugs: Add attack vector controls for MDS David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 06/21] x86/bugs: Add attack vector controls for TAA David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 07/21] x86/bugs: Add attack vector controls for MMIO David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 08/21] x86/bugs: Add attack vector controls for RFDS David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 09/21] x86/bugs: Add attack vector controls for SRBDS David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 10/21] x86/bugs: Add attack vector controls for GDS David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 11/21] x86/bugs: Add attack vector controls for spectre_v1 David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 12/21] x86/bugs: Add attack vector controls for retbleed David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 13/21] x86/bugs: Add attack vector controls for spectre_v2_user David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 14/21] x86/bugs: Add attack vector controls for BHI David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 15/21] x86/bugs: Add attack vector controls for spectre_v2 David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 16/21] x86/bugs: Add attack vector controls for L1TF David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 17/21] x86/bugs: Add attack vector controls for SRSO David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 18/21] x86/bugs: Add attack vector controls for ITS David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 19/21] x86/pti: Add attack vector controls for PTI David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 20/21] x86/bugs: Print enabled attack vectors David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan
2025-07-07 18:33 ` [PATCH v6 21/21] cpu: Show attack vectors in sysfs David Kaplan
2025-07-09 18:47   ` Borislav Petkov
2025-07-09 15:58 ` [PATCH v7 19/22] x86/bugs: Add attack vector controls for TSA David Kaplan
2025-07-11 16:09   ` [tip: x86/bugs] " tip-bot2 for David Kaplan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250707183316.1349127-1-david.kaplan@amd.com \
    --to=david.kaplan@amd.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=jpoimboe@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=pawan.kumar.gupta@linux.intel.com \
    --cc=peterz@infradead.org \
    --cc=tglx@linutronix.de \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®