Concerning microcode update time in Trusty, real test (with linux-generic-lts-xenial installed): --- marat@CM01:~$ lsb_release -a No LSB modules are available. Distributor ID: Ubuntu Description: Ubuntu 14.04.5 LTS Release: 14.04 Codename: trusty
marat@CM01:~$ uname -a Linux CM01.administration.intranet.rqc.ru 4.4.0-81-generic #104~14.04.1-Ubuntu SMP Wed Jun 14 12:45:52 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux marat@CM01:~$ dmesg | nl | grep -i microcode 1 [ 0.000000] microcode: CPU0 microcode updated early to revision 0x29, date = 2013-06-12 226 [ 0.080489] microcode: CPU1 microcode updated early to revision 0x29, date = 2013-06-12 229 [ 0.083195] microcode: CPU2 microcode updated early to revision 0x29, date = 2013-06-12 230 [ 0.085331] #3<6>[ 0.085831] microcode: CPU3 microcode updated early to revision 0x29, date = 2013-06-12 670 [ 1.262792] microcode: CPU0 sig=0x206a7, pf=0x2, revision=0x29 671 [ 1.262799] microcode: CPU1 sig=0x206a7, pf=0x2, revision=0x29 672 [ 1.262836] microcode: CPU2 sig=0x206a7, pf=0x2, revision=0x29 673 [ 1.262877] microcode: CPU3 sig=0x206a7, pf=0x2, revision=0x29 674 [ 1.262960] microcode: Microcode Update Driver: v2.01 <tig...@aivazian.fsnet.co.uk>, Peter Oruba 812 [ 2.696416] [drm] Loading CAICOS Microcode --- So it's in the beginning, though not all quite 0.000000. (Last line is apparently unrelated to CPU.) As for microcode updates _from_ container, I thought it should go without saying that it must be prohibited. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1700373 Title: Please update microcode to version 20170511 on all supported platforms To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/intel-microcode/+bug/1700373/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs