From: Dave Hansen <dave.hansen@intel.com>
To: Borislav Petkov <bp@alien8.de>, KP Singh <kpsingh@kernel.org>,
Andrew Cooper <andrew.cooper3@citrix.com>
Cc: "Josh Poimboeuf" <jpoimboe@kernel.org>,
linux-kernel@vger.kernel.org, pjt@google.com, evn@google.com,
tglx@linutronix.de, mingo@redhat.com,
dave.hansen@linux.intel.com, x86@kernel.org, hpa@zytor.com,
peterz@infradead.org, pawan.kumar.gupta@linux.intel.com,
kim.phillips@amd.com, alexandre.chartre@oracle.com,
daniel.sneddon@linux.intel.com,
"José Oliveira" <joseloliveira11@gmail.com>,
"Rodrigo Branco" <rodrigo@kernelhacking.com>,
"Alexandra Sandulescu" <aesa@google.com>,
"Jim Mattson" <jmattson@google.com>
Subject: Re: [PATCH RESEND] x86/speculation: Fix user-mode spectre-v2 protection with KERNEL_IBRS
Date: Mon, 20 Feb 2023 07:38:49 -0800 [thread overview]
Message-ID: <4996fd95-49bf-71bb-7071-6050b60529c1@intel.com> (raw)
In-Reply-To: <Y/OETPFTJbGtCADM@zn.tnic>
On 2/20/23 06:31, Borislav Petkov wrote:
> This above probably wants to say that you need to write 1 on CPL change
> because it has a flushing behavior of killing user prediction entries.
Right. The naive way of looking at IBRS is that setting IBRS=1
mitigates spectre-v2. But, as the documentation says, just _leaving_ it
set to 1 is not good enough. It must be actively rewritten in order to
get the strongest semantics.
It's still rather early in the morning, but I'm also quite confused
about what exactly the problem is here. The patch and the changelog
aren't especially clear. I'll need to stare at it with a cup of coffee
before I can give any coherent better suggestions, though.
next prev parent reply other threads:[~2023-02-20 15:39 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-02-20 12:01 KP Singh
2023-02-20 12:13 ` Josh Poimboeuf
2023-02-20 12:20 ` KP Singh
2023-02-20 12:34 ` KP Singh
2023-02-20 14:31 ` Borislav Petkov
2023-02-20 15:38 ` Dave Hansen [this message]
2023-02-20 19:57 ` Andrew Cooper
2023-02-20 21:10 ` Borislav Petkov
2023-02-20 23:01 ` KP Singh
2023-02-20 23:30 ` Andrew Cooper
2023-02-20 23:45 ` KP Singh
2023-02-21 18:52 ` KP Singh
2023-02-21 10:59 ` Borislav Petkov
2023-02-20 16:34 ` Josh Poimboeuf
2023-02-20 17:46 ` Borislav Petkov
2023-02-20 17:59 ` Josh Poimboeuf
2023-02-20 18:01 ` KP Singh
2023-02-20 18:22 ` Borislav Petkov
2023-02-20 18:44 ` KP Singh
2023-02-20 18:51 ` Borislav Petkov
2023-02-20 18:56 ` KP Singh
2023-02-20 19:02 ` Borislav Petkov
2023-02-20 19:10 ` KP Singh
2023-02-20 18:27 ` [PATCH] x86/bugs: Allow STIBP with IBRS Josh Poimboeuf
2023-02-20 18:33 ` KP Singh
2023-02-20 18:59 ` Josh Poimboeuf
2023-02-20 19:04 ` KP Singh
2023-02-20 19:19 ` Josh Poimboeuf
2023-02-20 18:34 ` Borislav Petkov
2023-02-20 19:09 ` Josh Poimboeuf
2023-02-20 19:16 ` KP Singh
2023-02-20 19:35 ` Josh Poimboeuf
2023-02-20 19:38 ` KP Singh
2023-02-20 19:20 ` Borislav Petkov
2023-02-22 1:20 ` Pawan Gupta
2023-02-22 1:26 ` KP Singh
2023-02-22 1:38 ` Pawan Gupta
2023-02-27 19:59 ` [tip: x86/urgent] x86/speculation: Allow enabling STIBP with legacy IBRS tip-bot2 for KP Singh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4996fd95-49bf-71bb-7071-6050b60529c1@intel.com \
--to=dave.hansen@intel.com \
--cc=aesa@google.com \
--cc=alexandre.chartre@oracle.com \
--cc=andrew.cooper3@citrix.com \
--cc=bp@alien8.de \
--cc=daniel.sneddon@linux.intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=evn@google.com \
--cc=hpa@zytor.com \
--cc=jmattson@google.com \
--cc=joseloliveira11@gmail.com \
--cc=jpoimboe@kernel.org \
--cc=kim.phillips@amd.com \
--cc=kpsingh@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=pawan.kumar.gupta@linux.intel.com \
--cc=peterz@infradead.org \
--cc=pjt@google.com \
--cc=rodrigo@kernelhacking.com \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®