Re: microcode updates and spectre variant 2

2018-01-24 Thread Justin Forbes
On Wed, Jan 24, 2018 at 12:13 PM, Chris Murphy wrote: > Intel has pulled the 20180108 microcode due to some CPUs crashing > (uncommanded reboots are a crash), and they have reverted latest > recommended to 20171117. And they appear to be recommending no longer > deploying

Re: microcode updates and spectre variant 2

2018-01-24 Thread Chris Murphy
Intel has pulled the 20180108 microcode due to some CPUs crashing (uncommanded reboots are a crash), and they have reverted latest recommended to 20171117. And they appear to be recommending no longer deploying the 20180108 microcode, but I can't tell if they are directing this to firmware oems or

Re: microcode updates and spectre variant 2

2018-01-20 Thread Chris Murphy
$ grep . /sys/devices/system/cpu/vulnerabilities/* /sys/devices/system/cpu/vulnerabilities/meltdown:Mitigation: PTI /sys/devices/system/cpu/vulnerabilities/spectre_v1:Vulnerable /sys/devices/system/cpu/vulnerabilities/spectre_v2:Mitigation: Full generic retpoline All of my machines show this

Re: microcode updates and spectre variant 2

2018-01-16 Thread Josh Boyer
On Tue, Jan 16, 2018 at 4:06 PM, Zbigniew Jędrzejewski-Szmek wrote: > On Tue, Jan 16, 2018 at 03:42:42PM -0500, Josh Boyer wrote: >> On Tue, Jan 16, 2018 at 3:36 PM, Zbigniew Jędrzejewski-Szmek >> wrote: >> > On Tue, Jan 16, 2018 at 06:54:36AM -0500, Josh

Re: microcode updates and spectre variant 2

2018-01-16 Thread Josh Boyer
On Tue, Jan 16, 2018 at 3:55 PM, Reindl Harald wrote: > > Am 16.01.2018 um 21:42 schrieb Josh Boyer: >> >> On Tue, Jan 16, 2018 at 3:36 PM, Zbigniew Jędrzejewski-Szmek >> wrote: >>> >>> On Tue, Jan 16, 2018 at 06:54:36AM -0500, Josh Boyer wrote:

Re: microcode updates and spectre variant 2

2018-01-16 Thread Zbigniew Jędrzejewski-Szmek
On Tue, Jan 16, 2018 at 03:42:42PM -0500, Josh Boyer wrote: > On Tue, Jan 16, 2018 at 3:36 PM, Zbigniew Jędrzejewski-Szmek > wrote: > > On Tue, Jan 16, 2018 at 06:54:36AM -0500, Josh Boyer wrote: > >> On Mon, Jan 15, 2018 at 12:58 PM, Chris Murphy >

Re: microcode updates and spectre variant 2

2018-01-16 Thread Josh Boyer
On Tue, Jan 16, 2018 at 3:36 PM, Zbigniew Jędrzejewski-Szmek wrote: > On Tue, Jan 16, 2018 at 06:54:36AM -0500, Josh Boyer wrote: >> On Mon, Jan 15, 2018 at 12:58 PM, Chris Murphy >> wrote: >> > If microcode is updated, but the initramfs isn't

Re: microcode updates and spectre variant 2

2018-01-16 Thread Zbigniew Jędrzejewski-Szmek
On Tue, Jan 16, 2018 at 06:54:36AM -0500, Josh Boyer wrote: > On Mon, Jan 15, 2018 at 12:58 PM, Chris Murphy > wrote: > > If microcode is updated, but the initramfs isn't regenerated, so the > > newer microcode get loaded later in the boot process once available? > > Or

Re: microcode updates and spectre variant 2

2018-01-16 Thread Josh Boyer
On Mon, Jan 15, 2018 at 12:58 PM, Chris Murphy wrote: > On Fri, Jan 12, 2018 at 2:28 PM, Chris Murphy wrote: >> On Fri, Jan 12, 2018 at 2:00 PM, Josh Boyer >> wrote: >>> On Fri, Jan 12, 2018 at 3:31 PM, Chris Murphy

Re: microcode updates and spectre variant 2

2018-01-16 Thread Petr Pisar
On 2018-01-15, Randy Barlow wrote: > I'm quite surprised that my PIII is getting a microcode update. It's 18 > years old! > I assume Intel simply released latest microcode for all processors they had some regardless of the Spectre bug. Probably some of them have

Re: microcode updates and spectre variant 2

2018-01-15 Thread Chris Murphy
On Fri, Jan 12, 2018 at 2:28 PM, Chris Murphy wrote: > On Fri, Jan 12, 2018 at 2:00 PM, Josh Boyer wrote: >> On Fri, Jan 12, 2018 at 3:31 PM, Chris Murphy >> wrote: >>> Koji contains

Re: microcode updates and spectre variant 2

2018-01-15 Thread Justin Forbes
On Mon, Jan 15, 2018 at 9:04 AM, Michael Cronenworth wrote: > On 01/15/2018 09:00 AM, Randy Barlow wrote: >> >> I'm quite surprised that my PIII is getting a microcode update. It's 18 >> years old! >> > > On the flip side: One of my systems has an i3-3225 (Ivy Bridge) that has

Re: microcode updates and spectre variant 2

2018-01-15 Thread Justin Forbes
On Mon, Jan 15, 2018 at 9:00 AM, Randy Barlow wrote: > On 01/12/2018 03:31 PM, Chris Murphy wrote: >> https://downloadcenter.intel.com/download/27431/Linux-Processor-Microcode-Data-File > > I'm quite surprised that my PIII is getting a microcode update. It's 18 >

Re: microcode updates and spectre variant 2

2018-01-15 Thread Michael Cronenworth
On 01/15/2018 09:00 AM, Randy Barlow wrote: I'm quite surprised that my PIII is getting a microcode update. It's 18 years old! On the flip side: One of my systems has an i3-3225 (Ivy Bridge) that has not received an update. ___ devel mailing list

Re: microcode updates and spectre variant 2

2018-01-15 Thread Randy Barlow
On 01/12/2018 03:31 PM, Chris Murphy wrote: > https://downloadcenter.intel.com/download/27431/Linux-Processor-Microcode-Data-File I'm quite surprised that my PIII is getting a microcode update. It's 18 years old! signature.asc Description: OpenPGP digital signature

Re: microcode updates and spectre variant 2

2018-01-12 Thread Chris Murphy
On Fri, Jan 12, 2018 at 2:00 PM, Josh Boyer wrote: > On Fri, Jan 12, 2018 at 3:31 PM, Chris Murphy wrote: >> Koji contains linux-firmware-20171215-82.git2451bb22.fc27 which >> contains intel-ucode from 20171117. But I don't know if this

Re: microcode updates and spectre variant 2

2018-01-12 Thread Tomasz Torcz ️
On Fri, Jan 12, 2018 at 01:31:25PM -0700, Chris Murphy wrote: > Koji contains linux-firmware-20171215-82.git2451bb22.fc27 which > contains intel-ucode from 20171117. But I don't know if this firmware > contains the microcode required to completely secure from Spectre > variant 2. > >

Re: microcode updates and spectre variant 2

2018-01-12 Thread Josh Boyer
On Fri, Jan 12, 2018 at 3:31 PM, Chris Murphy wrote: > Koji contains linux-firmware-20171215-82.git2451bb22.fc27 which > contains intel-ucode from 20171117. But I don't know if this firmware > contains the microcode required to completely secure from Spectre > variant 2.

microcode updates and spectre variant 2

2018-01-12 Thread Chris Murphy
Koji contains linux-firmware-20171215-82.git2451bb22.fc27 which contains intel-ucode from 20171117. But I don't know if this firmware contains the microcode required to completely secure from Spectre variant 2. https://access.redhat.com/articles/3311301 "This vulnerability requires both updated