From nobody Thu Sep 24 20:23:48 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=reject dis=none) header.from=citrix.com ARC-Seal: i=1; a=rsa-sha256; t=1788887749; cv=none; d=zohomail.com; s=zohoarc; b=U9mJowAL53mJaXoUx5ZOwSUUIYxkDPstOyR/Z6vMqaiy6SAld4BOo6RWCXa5yaFDfM27fpEfIf8DpUH8oMk2LubSNlret3wPa9YtvyON7WLRyZqDL16qMqOuyAbZ1/Xhi425jv43ruIw0MH49p1H5NdTdtnHG5ZQnIHTPU84Zoo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788887749; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=mJSy1oOnfZYuUJld/ZrDnUr2X+fXVk73FeNzFX3opLg=; b=nj+uylGh5BZoR9vgKLfE2FCmKQZljF6m8nA670K/6VW5msTf6QXxM5V3gsmdBDtg6XigalCmhddsRbsoamwovGdKFa2hbES6Xxi2k2cTwyXYZaR97x8kscH1Xcw/GadGSZxVIOTUNnlGS/ZTh8UCDjyuqPIAxQw2CyhBzxo/Ag8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1788887748958889.0454498323924; Tue, 8 Sep 2026 10:15:48 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1412315.1642843 (Exim 4.92) (envelope-from ) id 1x3zPv-0005Fa-Ju; Tue, 08 Sep 2026 17:15:31 +0000 Received: by outflank-mailman (output) from mailman id 1412315.1642843; Tue, 08 Sep 2026 17:15:31 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x3zPv-0005FT-Gf; Tue, 08 Sep 2026 17:15:31 +0000 Received: by outflank-mailman (input) for mailman id 1412315; Tue, 08 Sep 2026 17:15:30 +0000 Received: from mx.expurgate.net ([194.145.224.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x3zPu-0005FN-0V for xen-devel@lists.xenproject.org; Tue, 08 Sep 2026 17:15:30 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x3zPs-002MWe-VI for xen-devel@lists.xenproject.org; Tue, 08 Sep 2026 19:15:28 +0200 Received: from [10.42.69.1] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6aa042aa-e002-0a2a0a5209dd-0a2a450188d8-6 for ; Tue, 08 Sep 2026 19:15:28 +0200 Received: from [209.85.128.49] (helo=mail-wm1-f49.google.com) by tlsNG-d62444.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6aa042b0-5984-0a2a45010019-d1558031a557-3 for ; Tue, 08 Sep 2026 19:15:28 +0200 Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-495437bb891so28439045e9.1 for ; Tue, 08 Sep 2026 10:15:28 -0700 (PDT) Received: from localhost.localdomain (host-78-146-248-75.as13285.net. [78.146.248.75]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485883c6ba4sm42308095f8f.25.2026.09.08.10.15.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 08 Sep 2026 10:15:27 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=google header.d=citrix.com header.i="@citrix.com" header.h="Content-Transfer-Encoding:Content-Type:MIME-Version:Message-Id:Date:Subject:Cc:To:From" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=citrix.com; s=google; t=1788887728; x=1789492528; darn=lists.xenproject.org; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=mJSy1oOnfZYuUJld/ZrDnUr2X+fXVk73FeNzFX3opLg=; b=KdT+SCW66LbI3HcZ4msa85CuNWmEagIwIsBn95T7QLSL7L+RVuOXtf6Hef5ziREJpo 1AMGiNkB3zmPfJaW/EXXmnZhhM6SLB3j5t2SZupTDr9lmAvdn88jiArbE8u1cc25UOTC HwDml92IkKLzFodfBcGmg+6RL85LjgWqN+7rY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788887728; x=1789492528; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=mJSy1oOnfZYuUJld/ZrDnUr2X+fXVk73FeNzFX3opLg=; b=CK9SueLM8jclWXp8fKbTjXzuixuBNqingD5lu6d6/Y/PdL33LLdZnnZLoa1qUFDUSG ZrQHh0u/Wg2iDw2/YC0lqeD91/4FwlAYfK/lEzEL1Tw7NA1OVflT14H3iFS3H80r89Th VQ+YJsE0U9nD2n7L5QVv+fxIVvlbppJpDkNPXks/UvYNooKN0/00eP/l6UH/9Vsj+kxO MEDfzduF+eA1ktL/yw14T5nD1Yhjp+KIOfcjq9wmZa5acWU1ZjSbbErshgDIluUnHgsG ovFPTIV1CU8xBDjG7pDs8ZOuqnDmEx4ZtAMzJugXnmwJyaRV3VJAphJqRoK1ZTlfCj+b zH/Q== X-Gm-Message-State: AFuF++mrFA5c9CwRJIRVZoWZP52+u+MFLz4NRZ+i8o/tWv1vOek6hnRw PXGynINPZasJKyM3HeEzJmHzrPhX4S70nlvW/Zm59sqMJ2V/34MRS8DBC+jQVxARxH4Ke8upPBG Jp9JdXVw= X-Gm-Gg: AYBFou2iYGb5LP+jGwPeflAnnB9xrqTGw8rfuClPRhv4qezcxef1Xq1iyzLk6uEmWm9 mTrYAbTsE4sxq2Jz9chzkcsD7CydewRL9+MRuC7zggLmIu3IgqLsFsYno/fl5iMqoWa25OHRMVt zD4ig/Wj9/yELesqg7pHCQQ4iuoFEZpu/m0gUhVB7DsNQmr+zidxtcHMejerBi3QK4mKM4NP/Nw brBM7qIpfgrW0OCyG5Ftv8qzo69bKAq/W6sd+AXx2D2SMEtFMaHc1EmHXeM5EzJHmNA+x84xpMI DbrBZT4c9xF1zvB2BtSX5fZx0fBEWkIzXyBKb9lf7hAjWoUMxEqCAY1YVM0Ds39h26iRlxui/iI cO7yvcy9Pxm9KDZ3rPD6Husln2EBTyZlCBFLt/DTEpyConozX2MdjPZ6lTiLl+J+LqeGvX4WbT7 DH0QtHEMBkH9iYsQKVVbHqzUAwy9n3JkZr86nweNimMLTERb14GMtFYMoGgBFFfHAb1gYfvqIaW JRu1YGSJwnX4u2tbCBnZ0cLmfNuY2LmpOxEXbs= X-Received: by 2002:a05:600c:74a:b0:49d:10b8:7e05 with SMTP id 5b1f17b1804b1-49d10b87ec4mr104627155e9.19.1788887727994; Tue, 08 Sep 2026 10:15:27 -0700 (PDT) From: Andrew Cooper To: Xen-devel Cc: Andrew Cooper , Jan Beulich , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Teddy Astie Subject: [PATCH v3] x86/ucode: Work around Granite Rapids erraturm GNR98 Date: Tue, 8 Sep 2026 18:15:25 +0100 Message-Id: <20260908171525.3196765-1-andrew.cooper3@citrix.com> X-Mailer: git-send-email 2.39.5 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-d62444/1788887728-BE07B757-E7476D12/0/0 X-purgate-type: clean X-purgate-size: 3179 X-ZohoMail-DKIM: pass (identity @citrix.com) X-ZM-MESSAGEID: 1788887750801158500 Block loads which are known to hang the system. Signed-off-by: Andrew Cooper Reviewed-by: Roger Pau Monn=C3=A9 Reviewed-by: Teddy Astie --- CC: Jan Beulich CC: Roger Pau Monn=C3=A9 CC: Teddy Astie A more complete solution is in the works, but it's taken 4 months to get th= is much published... v3: * Double XENLOG_WARNING v2: * Correct the sign of the cpu_sig->rev check. * Expand the comment to explain why we are not following what GNR98 says. --- xen/arch/x86/cpu/microcode/intel.c | 40 ++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) diff --git a/xen/arch/x86/cpu/microcode/intel.c b/xen/arch/x86/cpu/microcod= e/intel.c index c45b00c6b033..86cbfb798160 100644 --- a/xen/arch/x86/cpu/microcode/intel.c +++ b/xen/arch/x86/cpu/microcode/intel.c @@ -27,6 +27,7 @@ #include #include =20 +#include #include #include #include @@ -273,6 +274,44 @@ static bool microcode_fits_cpu(const struct microcode_= patch *mc) return false; } =20 +static bool microcode_safe_to_load(const struct microcode_patch *mc) +{ + struct cpu_signature *cpu_sig =3D &this_cpu(cpu_sig); + + /* + * Treat pre-production as always safe - anyone using pre-production + * microcode knows what they are doing, and can keep any resulting pie= ces. + */ + if ( (int)cpu_sig->rev < 0 || mc->rev < 0 ) + return true; + + /* + * GNR98 states that Granite Rapids systems hang when loading new ucod= e on + * sufficiently old firmware. GNR101 retroactively states that one uc= ode + * had an incorrect minimum revision field, in light of discovering GN= R98. + * + * Both are incomplete statements of the problem. + * + * At the time of writing (August 2026), the believed safe sequence is: + * 0x01000370 -> [0x01000380...0x010003f3] -> 0x01000405 -> any later + * + * Disallow known-unsafe loads while permitting believed-safe loads. = For + * GNR, this allows multi-hop loading to get up to the latest. + */ + if ( boot_cpu_data.vfm =3D=3D INTEL_GRANITERAPIDS_X && + boot_cpu_data.stepping =3D=3D 1 && (cpu_sig->pf & 0x95) && + ((cpu_sig->rev < 0x01000380 && mc->rev >=3D 0x01000405) || + (cpu_sig->rev < 0x01000405 && mc->rev > 0x01000405)) ) + { + printk_once(XENLOG_WARNING "microcode: Granite Rapids erratum GNR9= 8 detected. Skipping ucode 0x%08x\n" + XENLOG_WARNING "microcode: Firmware update recommended= \n", + mc->rev); + return false; + } + + return true; +} + static int cf_check intel_compare( const struct microcode_patch *old, const struct microcode_patch *new) { @@ -365,6 +404,7 @@ static struct microcode_patch *cf_check intel_ucode_par= se( * one with higher revision. */ if ( microcode_fits_cpu(mc) && + microcode_safe_to_load(mc) && (!saved || compare_revisions(saved->rev, mc->rev) =3D=3D NEW_= UCODE) ) saved =3D mc; =20 --=20 2.39.5