From nobody Sun Feb 8 16:34:33 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 310C825E46F; Wed, 9 Apr 2025 11:44:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1744199067; cv=none; b=ttT0Wv5JyzdwtLJ4Je/kvGLt9M+z5uFd6TMtABS0/+7+tEIxh5eayqmT31V1SComww0q4rq32xUuQrLNXZyd1i2o6xSKMELtCSEU12UxDUUARjEyp+CXSxp1acUK2dEBqyA54cyrsHluIC1/6eQvxOUF6VMaGA/d2aMifiPBr1s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1744199067; c=relaxed/simple; bh=1zuuKfq8Fb2gUxCOT5nm7PjF4ClnVz1Kne9wx5wdnT0=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=udYVg2zSoK+q9h+IQk6vfMb+c/W4ZB2IfbtPVYQ/t2erHMxglPAaV5M9tECdb3v/uIVkwiGhjcVI/CFf0LjH63dsevKVL0P0Otqe//G/kUUlWeYWchg9gqmqVs6eyJhl24Jzezzn2Y5ivOa77NXTN+JyxlTkJ/jrTp0LReMblPk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=Y232yHbM; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=vAAqV43m; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="Y232yHbM"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="vAAqV43m" Date: Wed, 09 Apr 2025 11:44:24 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1744199064; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=aNLd30xIMik6LI+ehTepOf+SXmSqYObNycz8f+vXaSs=; b=Y232yHbM85VIXm1W2J/wuLZVh7K+mXVEW0jNxFbzU6rJ/B3F2xc4P0dPbOwkVllcsKD0Rq Rk1SbwTULgfoBwHQsH8lCaI6TtZLTMDEqUGDW/+sn/3ehTuwjR4JHU9ojBEeYF1yY2woE9 sHgbNJQcRpaVgFBV2KUjKrMHkEhC5EdZTtNr3Y0iBGHrmEOuIQXpFOL6tBK6ftujYoo3Vd By11TEP1IcRAjDEF7jkxO9SzX9lkv8qoKq5nQGiHGHYSjfbLk59dQa7bJIYIeEVW4lQjgk tJdxPW35wYoQOe01x+ucgP1pMdkdqCFAlWYIhnSbeQsOfklnGjIxwOpUF+Fa+Q== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1744199064; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=aNLd30xIMik6LI+ehTepOf+SXmSqYObNycz8f+vXaSs=; b=vAAqV43mrKlQPRdNS43ODnevcrAKb+oq8Biy6PHdWmiyDukNqnPJDB6jL0oFekzdbbZJn4 Bx4ZQ4Iae8y6C/AQ== From: "tip-bot2 for Josh Poimboeuf" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: x86/urgent] x86/bugs: Don't fill RSB on VMEXIT with eIBRS+retpoline Cc: Pawan Gupta , Josh Poimboeuf , Ingo Molnar , Amit Shah , Nikolay Borisov , Paolo Bonzini , Vitaly Kuznetsov , Sean Christopherson , David Woodhouse , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <84a1226e5c9e2698eae1b5ade861f1b8bf3677dc.1744148254.git.jpoimboe@kernel.org> References: <84a1226e5c9e2698eae1b5ade861f1b8bf3677dc.1744148254.git.jpoimboe@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <174419906403.31282.6211937821580800684.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the x86/urgent branch of tip: Commit-ID: 18bae0dfec15b24ec14ca17dc18603372f5f254f Gitweb: https://git.kernel.org/tip/18bae0dfec15b24ec14ca17dc18603372= f5f254f Author: Josh Poimboeuf AuthorDate: Tue, 08 Apr 2025 14:47:33 -07:00 Committer: Ingo Molnar CommitterDate: Wed, 09 Apr 2025 12:41:55 +02:00 x86/bugs: Don't fill RSB on VMEXIT with eIBRS+retpoline eIBRS protects against guest->host RSB underflow/poisoning attacks. Adding retpoline to the mix doesn't change that. Retpoline has a balanced CALL/RET anyway. So the current full RSB filling on VMEXIT with eIBRS+retpoline is overkill. Disable it or do the VMEXIT_LITE mitigation if needed. Suggested-by: Pawan Gupta Signed-off-by: Josh Poimboeuf Signed-off-by: Ingo Molnar Reviewed-by: Pawan Gupta Reviewed-by: Amit Shah Reviewed-by: Nikolay Borisov Cc: Paolo Bonzini Cc: Vitaly Kuznetsov Cc: Sean Christopherson Cc: David Woodhouse Link: https://lore.kernel.org/r/84a1226e5c9e2698eae1b5ade861f1b8bf3677dc.17= 44148254.git.jpoimboe@kernel.org --- arch/x86/kernel/cpu/bugs.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/arch/x86/kernel/cpu/bugs.c b/arch/x86/kernel/cpu/bugs.c index 9926509..a10b37b 100644 --- a/arch/x86/kernel/cpu/bugs.c +++ b/arch/x86/kernel/cpu/bugs.c @@ -1617,20 +1617,20 @@ static void __init spectre_v2_determine_rsb_fill_ty= pe_at_vmexit(enum spectre_v2_ case SPECTRE_V2_NONE: return; =20 - case SPECTRE_V2_EIBRS_LFENCE: case SPECTRE_V2_EIBRS: + case SPECTRE_V2_EIBRS_LFENCE: + case SPECTRE_V2_EIBRS_RETPOLINE: if (boot_cpu_has_bug(X86_BUG_EIBRS_PBRSB)) { - setup_force_cpu_cap(X86_FEATURE_RSB_VMEXIT_LITE); pr_info("Spectre v2 / PBRSB-eIBRS: Retire a single CALL on VMEXIT\n"); + setup_force_cpu_cap(X86_FEATURE_RSB_VMEXIT_LITE); } return; =20 - case SPECTRE_V2_EIBRS_RETPOLINE: case SPECTRE_V2_RETPOLINE: case SPECTRE_V2_LFENCE: case SPECTRE_V2_IBRS: - setup_force_cpu_cap(X86_FEATURE_RSB_VMEXIT); pr_info("Spectre v2 / SpectreRSB : Filling RSB on VMEXIT\n"); + setup_force_cpu_cap(X86_FEATURE_RSB_VMEXIT); return; }