From: Arjan van de Ven <arjan@linux.intel.com>
To: Linus Torvalds <torvalds@linux-foundation.org>,
Jiri Kosina <jikos@kernel.org>
Cc: Thomas Gleixner <tglx@linutronix.de>,
Peter Zijlstra <peterz@infradead.org>,
Josh Poimboeuf <jpoimboe@redhat.com>,
Andrea Arcangeli <aarcange@redhat.com>,
David Woodhouse <dwmw@amazon.co.uk>,
Andi Kleen <ak@linux.intel.com>,
Tim Chen <tim.c.chen@linux.intel.com>,
"Schaufler, Casey" <casey.schaufler@intel.com>,
Linux List Kernel Mailing <linux-kernel@vger.kernel.org>,
the arch/x86 maintainers <x86@kernel.org>,
"stable@vger.kernel.org" <stable@vger.kernel.org>
Subject: Re: Re: STIBP by default.. Revert?
Date: Mon, 19 Nov 2018 07:04:19 +0800 [thread overview]
Message-ID: <51127fd4-5dcc-b2b9-4873-72098d2a77d9@linux.intel.com> (raw)
In-Reply-To: <CAHk-=whH2daKsZTqVPb-G9mJ1g15XMse7j-9YqN+yBYk7M9=Dw@mail.gmail.com>
On 11/19/2018 6:00 AM, Linus Torvalds wrote:
> On Sun, Nov 18, 2018 at 1:49 PM Jiri Kosina <jikos@kernel.org> wrote:
>>
>>> So why do that STIBP slow-down by default when the people who *really*
>>> care already disabled SMT?
>>
>> BTW for them, there is no impact at all.
>
> Right. People who really care about security and are anal about it do
> not see *any* advantage of the patch.
In the documentation, AMD officially recommends against this by default, and I can
speak for Intel that our position is that as well: this really must not be on by default.
STIBP and its friends are there as tools, and were created early on as big hammers because
that is all that one can add in a microcode update.. expensive big hammers.
In some ways it's analogous to the "disable caches" bit in CR0. sure it's there as a big hammer,
but you don't set that always just because caches could be used for a side channel
Using these tools much more surgically is fine, if a paranoid task wants it for example,
or when you know you are doing a hard core security transition. But always on? Yikes.
next prev parent reply other threads:[~2018-11-18 23:04 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-11-18 20:36 Linus Torvalds
2018-11-18 21:49 ` Jiri Kosina
2018-11-18 21:59 ` Willy Tarreau
2018-11-18 22:00 ` Linus Torvalds
2018-11-18 22:17 ` Jiri Kosina
2018-11-18 22:35 ` Dave Hansen
2018-11-18 22:36 ` Tony Luck
2018-11-18 22:36 ` Linus Torvalds
2018-11-18 22:55 ` Tim Chen
2018-11-18 23:56 ` Andi Kleen
2018-11-18 22:40 ` Tim Chen
2018-11-18 23:58 ` Andi Kleen
2018-11-19 3:48 ` Willy Tarreau
2018-11-19 12:49 ` Thomas Gleixner
2018-11-18 23:01 ` Jiri Kosina
2018-11-18 23:04 ` Arjan van de Ven [this message]
2018-11-20 15:27 ` Jiri Kosina
2018-11-20 23:43 ` Arjan van de Ven
2018-11-19 8:38 ` Ingo Molnar
2018-11-19 8:43 ` Jiri Kosina
2018-11-20 15:20 ` Jiri Kosina
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=51127fd4-5dcc-b2b9-4873-72098d2a77d9@linux.intel.com \
--to=arjan@linux.intel.com \
--cc=aarcange@redhat.com \
--cc=ak@linux.intel.com \
--cc=casey.schaufler@intel.com \
--cc=dwmw@amazon.co.uk \
--cc=jikos@kernel.org \
--cc=jpoimboe@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=peterz@infradead.org \
--cc=stable@vger.kernel.org \
--cc=tglx@linutronix.de \
--cc=tim.c.chen@linux.intel.com \
--cc=torvalds@linux-foundation.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome