[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-10-04 Thread Andrew Cloke
** Changed in: ubuntu-power-systems Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1832622 Title: QEMU - count cache flush Spectre v2 mitiga

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-05 Thread Launchpad Bug Tracker
This bug was fixed in the package qemu - 1:2.11+dfsg-1ubuntu7.18 --- qemu (1:2.11+dfsg-1ubuntu7.18) bionic; urgency=medium * d/p/ubuntu/lp-1832622-*: count cache flush Spectre v2 mitigation for ppc64 (LP: #1832622) * d/p/ubuntu/lp-1840745-*: add amd ssbd / no-ssbd features (LP

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-05 Thread Launchpad Bug Tracker
This bug was fixed in the package qemu - 1:3.1+dfsg-2ubuntu3.4 --- qemu (1:3.1+dfsg-2ubuntu3.4) disco; urgency=medium * d/p/ubuntu/lp-1832622-*: count cache flush Spectre v2 mitigation for ppc64 (LP: #1832622) * d/p/ubuntu/lp-1836154-*: add HW CPU model for newer s390x machine

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-04 Thread Christian Ehrhardt 
After discussing this with the Team I really think it is ok to release this. As stated before we confirmed: - that on a good kernel the fix works - the fix doesn't break features if not running on the new kernel - the fix is confirmed to get in the kernel soon (this kernel cycle) In addition relea

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-04 Thread Christian Ehrhardt 
Thanks a lot Fabiano! So I summarize: - #7 is in no way a degradation to #4: - all cap-ibs= modes are failing on that before and after - that means the new qemu didn't break anything in that regard - #9 confirms that as soon as we have a fixed kernel under that new disco-qemu it will work for

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-04 Thread Fabiano Rosas
Here is test #9 (#8 is the same as #4 from my previous tests. And not of much help since Disco-updates QEMU (v=1:3.1+dfsg-2ubuntu3.3) does not have cap-ibs=workaround): *** 9- Bionic-proposed kernel + Disco-proposed QEMU $ uname -r; qemu-system-ppc64 --version | head -n 1 4.15.0-60-generic QE

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-04 Thread Fabiano Rosas
That is the effect of the lack of "2b57ecd0208f KVM: PPC: Book3S: Add count cache flush parameters to kvmppc_get_cpu_char()" in Disco. QEMU checks for KVM_PPC_CPU_BEHAV_FLUSH_COUNT_CACHE which is introduced in the above commit: (From lp-1832622-0002-target-ppc-spapr-Add-workaround-option-to- SPAP

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-04 Thread Christian Ehrhardt 
Thanks a lot faro...@br.ibm.com. Especially for noting the known firmware featues influencing this in your case and then combining cap-ibs=workaround,cap-ccf-assist=on to prove the new features work. I see that cap-ccf-assist=on can be used and successfully grants the guest [0.00] count-

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-03 Thread Andrew Cloke
** Changed in: ubuntu-power-systems Status: Confirmed => Fix Committed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1832622 Title: QEMU - count cache flush Spectre v2 mitigatio

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-03 Thread Khaled El Mously
** Changed in: linux (Ubuntu Disco) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1832622 Title: QEMU - count cache flush Spectre v2 mitigat

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-02 Thread Christian Ehrhardt 
Per my Tests we already know that on DD2.0 HW things are fine, you can't enable CCF which is expected, but it doesn't break formerly working cases there. And I'm not sure if there is DD2.3 HW in the wild already. Furthermore I was in contact with Leonardo yesterday, he is working with the Authors

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-02 Thread Kleber Sacilotto de Souza
** Changed in: linux (Ubuntu Disco) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1832622 Title: QEMU - count cache flush Spectre v2 mitigation

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-02 Thread Juerg Haefliger
Confirmed that the Disco kernel is only missing 2b57ecd0208f ("KVM: PPC: Book3S: Add count cache flush parameters to kvmppc_get_cpu_char()") from the patchset referenced in bug 1822870. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-02 Thread Andrew Cloke
Bumping priority up to high after discussions with IBM. ** Changed in: ubuntu-power-systems Importance: Medium => High -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1832622 Title: Q

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-02 Thread Christian Ehrhardt 
I think I found the missing kernel bit. As reported it needs: 2b57ecd0208f KVM: PPC: Book3S: Add count cache flush parameters to kvmppc_get_cpu_char() Which was brought into Bionic/Cosmic already as part of bug LP1822870. This is only needed when I'd be on new HW/FW Bionic: $ grep -Hrn KVM_PPC

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-02 Thread Christian Ehrhardt 
Back in bug 1822870 it was reported that the Disco kernel is only missing 92edf8df which is still applied to Disco these days. Maybe due to that 2b57ecd0208f was lost. @Kernel Team - could you go through all changes that made up bug 1822870 and ensure whatever is missing will be added to Disco? -

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-02 Thread Christian Ehrhardt 
Lacking better options I gave this some extra testing on a pre DD2.3 P9 box. revision: 2.2 (pvr 004e 1202) I though at least CCF=off I should be able to test with these chips and that worked fine. Summary: - the new versions make cap-ibs=fixed-ibs work on DD2.2 - CCF=off works with Bionic

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-09-01 Thread Christian Ehrhardt 
FYI - the related autopkgtest issues would now be resolved. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1832622 Title: QEMU - count cache flush Spectre v2 mitigation (CVE) (required

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-08-30 Thread Frank Heimes
May I ask which kernel was used while testing on disco - was is the kernel from main/updates or proposed (5.0.0.27)? -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1832622 Title: QEMU -

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-08-30 Thread Andrew Cloke
** Changed in: ubuntu-power-systems Status: Fix Committed => Confirmed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1832622 Title: QEMU - count cache flush Spectre v2 mitigatio

[Kernel-packages] [Bug 1832622] Re: QEMU - count cache flush Spectre v2 mitigation (CVE) (required for POWER9 DD2.3)

2019-08-30 Thread Christian Ehrhardt 
** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu Disco) Status: New => Confirmed ** Changed in: linux (Ubuntu Disco) Importance: Undecided => High ** No longer affects: linux (Ubuntu Cosmic) ** No longer affects: linux (Ubuntu Eo