From: Thomas Gleixner <tglx@linutronix.de>
To: Tom Lendacky <thomas.lendacky@amd.com>
Cc: Andrew Cooper <andrew.cooper3@citrix.com>,
bp@alien8.de, dwmw@amazon.co.uk, gregkh@linux-foundation.org,
pjt@google.com, mingo@kernel.org, linux-kernel@vger.kernel.org,
hpa@zytor.com, tim.c.chen@linux.intel.com,
torvalds@linux-foundation.org, peterz@infradead.org,
dave.hansen@intel.com, linux-tip-commits@vger.kernel.org
Subject: Re: [tip:x86/pti] x86/cpu/AMD: Use LFENCE_RDTSC instead of MFENCE_RDTSC
Date: Mon, 8 Jan 2018 21:57:19 +0100 (CET) [thread overview]
Message-ID: <alpine.DEB.2.20.1801082155380.2253@nanos> (raw)
In-Reply-To: <b950e80b-e3a7-3395-8f22-74adbe91965d@amd.com>
On Mon, 8 Jan 2018, Tom Lendacky wrote:
> So now I'm also concerned about setting the retpoline method and using
> LFENCE as the speculation barrier. If we go back to the original
> statement:
>
> - the hypervisor did not set the LFENCE to serializing on the host
> - the hypervisor does not allow writing MSR_AMD64_DE_CFG
>
> It looks like I'll need to attempt to write MSR_AMD64_DE_CFG and then read
> it back checking for whether MSR_F10H_DECFG_LFENCE_SERIALIZE has been set.
> If the MSR can be read and the bit is set, then I can set RETPOLINE_AMD
> (once those patches go in) and LFENCE_RDTSC. Otherwise, set (only)
> MFENCE_RDTSC. This also means we need to use MFENCE as the speculation
> barrier instead of LFENCE in this situation (another alternative added to
> the __nospec_barrier() implementation).
>
> Does that sound right? Or does the "cannot prove that you run on bare
> metal" mess this all up?
I think that covers it. If the hypervisor would be trapping the read and
then lying on the bit being set while it's not, that's really nothing you
should care about at all.
Thanks,
tglx
next prev parent reply other threads:[~2018-01-08 20:57 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-01-05 16:07 [PATCH v1 0/3] x86/cpu/AMD: Make LFENCE a serializing instruction on AMD Tom Lendacky
2018-01-05 16:07 ` [PATCH v1 1/3] x86/cpu/AMD: Make LFENCE a serializing instruction Tom Lendacky
2018-01-05 16:35 ` Brian Gerst
2018-01-05 16:36 ` Tom Lendacky
2018-01-06 21:05 ` [tip:x86/pti] " tip-bot for Tom Lendacky
2018-01-05 16:07 ` [PATCH v1 2/3] x86/cpu/AMD: Use LFENCE_RDTSC instead of MFENCE_RDTSC Tom Lendacky
2018-01-06 21:06 ` [tip:x86/pti] " tip-bot for Tom Lendacky
2018-01-08 10:08 ` Thomas Gleixner
2018-01-08 10:23 ` Woodhouse, David
2018-01-08 10:25 ` Thomas Gleixner
2018-01-08 10:40 ` Andrew Cooper
2018-01-08 11:10 ` Thomas Gleixner
2018-01-08 14:47 ` Tom Lendacky
2018-01-08 14:54 ` Andrew Cooper
2018-01-08 16:48 ` Dr. David Alan Gilbert
2018-01-08 17:01 ` Paolo Bonzini
2018-01-08 17:39 ` Tom Lendacky
2018-01-08 17:42 ` Paolo Bonzini
2018-01-17 17:21 ` Tom Lendacky
2018-01-17 17:53 ` Paolo Bonzini
2018-01-08 15:02 ` David Woodhouse
2018-01-08 15:15 ` Thomas Gleixner
2018-01-08 17:31 ` Tom Lendacky
2018-01-08 20:57 ` Thomas Gleixner [this message]
2018-01-05 16:08 ` [PATCH v1 3/3] x86/msr: Remove now unused definition of MFENCE_RDTSC feature Tom Lendacky
2018-01-06 21:06 ` [tip:x86/pti] " tip-bot for Tom Lendacky
2018-01-05 16:56 ` [PATCH v1 0/3] x86/cpu/AMD: Make LFENCE a serializing instruction on AMD Borislav Petkov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=alpine.DEB.2.20.1801082155380.2253@nanos \
--to=tglx@linutronix.de \
--cc=andrew.cooper3@citrix.com \
--cc=bp@alien8.de \
--cc=dave.hansen@intel.com \
--cc=dwmw@amazon.co.uk \
--cc=gregkh@linux-foundation.org \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-tip-commits@vger.kernel.org \
--cc=mingo@kernel.org \
--cc=peterz@infradead.org \
--cc=pjt@google.com \
--cc=thomas.lendacky@amd.com \
--cc=tim.c.chen@linux.intel.com \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®