From nobody Sat Jul 25 02:12:51 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 682033AFB11; Mon, 20 Jul 2026 18:11:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784571094; cv=none; b=nD20ye2LvI5LvITfCFngJFtRoR7HBasw69lkphP6pGRIAxGADRgT3SMhov9Q3k8R2QP4pC5vngBTMOb51OXJ4NkTwE8EpUyoQR4dl0Fp4WoiSFOrI64k/+BY7E9KWpTrq0g2JIT4VvvOXy54ACt+qK40G2/qeSWvKzg+K1YMFxI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784571094; c=relaxed/simple; bh=hWvysDIieXL9mJ6Lkn+lMeVgiV0G9aJSgJtsgZ89+oE=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=AwB/v/NWq5CgAbfZp0CCLE8Qp2EalXLs6zaaNldZWzRnDcsal5EXPUhyZ7sAUyaifkDtBaCdhXafCqWGvx1zTOtNEURJRE2YVwcMDaqKlp0R3V6rMTm9DL9xKloigA/YdIdFAyACFeHBlC8hN8QyVtfr5LPnByJBbkQmm9rk0LY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=Sb+FtrQn; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=PlNwHoaJ; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="Sb+FtrQn"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="PlNwHoaJ" Date: Mon, 20 Jul 2026 18:11:28 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1784571090; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=cHYfhHL9eM6kLniAh2TLl9m//FxHTYlV6dZpSoZeh2Y=; b=Sb+FtrQnTOFYN4IuPbN7qxuqbmfUcERDuJqWtoTS7E5NqMKJ70I2VLF0XnoMUtgmiZzG7W bbVHTnqzf8M4hF8aDXOuGG/mcgQ8y64GiIIKkfxFGq8FF+wf7r021E97bGfDiVhi1z+GxQ p5nPj045wnGV8HP8m9Rf5yf8IkhS07DA+wWfbhCYBQBTm2ooFhavxCmCnWRyS4qAAuPahT 6SZ+WSePQAK2NFtc1d3DSJ+Y8TTPhvzvqmUIo+K+SbXgSZvsv58jTN83/p1w5QfjZ8QLd9 C0WrS4/QT05ywliKVK3iA9/XA6IWPiLaU8lD54j8URZ8TFGnP8AYuhoKPltzzg== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1784571090; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=cHYfhHL9eM6kLniAh2TLl9m//FxHTYlV6dZpSoZeh2Y=; b=PlNwHoaJ7a06q40CcuY1IoYg3xbZyU8/bWL+JNGuZ3UrbV4TCylxrQJ+UqRJLv8wxZyWxy px6fRf0Oc5Ww/3AA== From: "tip-bot2 for Pawan Gupta" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: x86/cpu] x86/bugs: Don't use cpu-type matching in cpu_vuln_blacklist Cc: Pawan Gupta , "Borislav Petkov (AMD)" , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20260708-cpu-type-vuln-v1-1-85c1d3c704db@linux.intel.com> References: <20260708-cpu-type-vuln-v1-1-85c1d3c704db@linux.intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <178457108840.2943223.16476212060051435385.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the x86/cpu branch of tip: Commit-ID: a4c714fe9746bf5a434bb798b26ebba278b798c1 Gitweb: https://git.kernel.org/tip/a4c714fe9746bf5a434bb798b26ebba27= 8b798c1 Author: Pawan Gupta AuthorDate: Wed, 08 Jul 2026 11:40:14 -07:00 Committer: Borislav Petkov (AMD) CommitterDate: Mon, 20 Jul 2026 10:04:45 -07:00 x86/bugs: Don't use cpu-type matching in cpu_vuln_blacklist Thomas Gleixner pointed out that cpu-type is a per-CPU property while hybrid is a system property; conflating the two in the CPU matching infrastructure= is wrong. Currently, on a hybrid system x86_match_cpu() matches any cpu-type. This works if the intent is to find the possibility of a cpu-type in a syst= em. But fails if matching for the cpu-type of a given CPU. Borislav posted a cleanup here: https://lore.kernel.org/all/20260703193222.GFakgORjvxwnZTPRnI@fat_crate.l= ocal To make way for the cleanup stop matching cpu-type in cpu_vuln_blacklist. RFDS is the only user, so drop the VULNBL_INTEL_TYPE entries and fold their RFDS bit into the base Alder Lake (0x97) and Raptor Lake (0xB7) blacklist entries. For now open-code cpu-type check in vulnerable_to_rfds(). In the future, if more vulnerabilities need cpu-type matching a helper can be adde= d. No functional change intended. Fixes: 722fa0dba74f ("x86/rfds: Exclude P-only parts from the RFDS affected= list") Signed-off-by: Pawan Gupta Signed-off-by: Borislav Petkov (AMD) Link: https://patch.msgid.link/20260708-cpu-type-vuln-v1-1-85c1d3c704db@lin= ux.intel.com --- arch/x86/kernel/cpu/common.c | 25 +++++++++++++++++-------- 1 file changed, 17 insertions(+), 8 deletions(-) diff --git a/arch/x86/kernel/cpu/common.c b/arch/x86/kernel/cpu/common.c index a3df21d..b381261 100644 --- a/arch/x86/kernel/cpu/common.c +++ b/arch/x86/kernel/cpu/common.c @@ -1251,9 +1251,6 @@ static const __initconst struct x86_cpu_id cpu_vuln_w= hitelist[] =3D { #define VULNBL_INTEL_STEPS(vfm, max_stepping, issues) \ X86_MATCH_VFM_STEPS(vfm, X86_STEP_MIN, max_stepping, issues) =20 -#define VULNBL_INTEL_TYPE(vfm, cpu_type, issues) \ - X86_MATCH_VFM_CPU_TYPE(vfm, INTEL_CPU_TYPE_##cpu_type, issues) - #define VULNBL_AMD(family, blacklist) \ VULNBL(AMD, family, X86_MODEL_ANY, blacklist) =20 @@ -1316,11 +1313,9 @@ static const struct x86_cpu_id cpu_vuln_blacklist[] = __initconst =3D { VULNBL_INTEL_STEPS(INTEL_TIGERLAKE, X86_STEP_MAX, GDS | ITS | ITS_NA= TIVE_ONLY), VULNBL_INTEL_STEPS(INTEL_LAKEFIELD, X86_STEP_MAX, MMIO | MMIO_SBDS |= RETBLEED), VULNBL_INTEL_STEPS(INTEL_ROCKETLAKE, X86_STEP_MAX, MMIO | RETBLEED |= GDS | ITS | ITS_NATIVE_ONLY), - VULNBL_INTEL_TYPE(INTEL_ALDERLAKE, ATOM, RFDS | VMSCAPE), - VULNBL_INTEL_STEPS(INTEL_ALDERLAKE, X86_STEP_MAX, VMSCAPE), + VULNBL_INTEL_STEPS(INTEL_ALDERLAKE, X86_STEP_MAX, RFDS | VMSCAPE), VULNBL_INTEL_STEPS(INTEL_ALDERLAKE_L, X86_STEP_MAX, RFDS | VMSCAPE), - VULNBL_INTEL_TYPE(INTEL_RAPTORLAKE, ATOM, RFDS | VMSCAPE), - VULNBL_INTEL_STEPS(INTEL_RAPTORLAKE, X86_STEP_MAX, VMSCAPE), + VULNBL_INTEL_STEPS(INTEL_RAPTORLAKE, X86_STEP_MAX, RFDS | VMSCAPE), VULNBL_INTEL_STEPS(INTEL_RAPTORLAKE_P, X86_STEP_MAX, RFDS | VMSCAPE), VULNBL_INTEL_STEPS(INTEL_RAPTORLAKE_S, X86_STEP_MAX, RFDS | VMSCAPE), VULNBL_INTEL_STEPS(INTEL_METEORLAKE_L, X86_STEP_MAX, VMSCAPE), @@ -1388,7 +1383,21 @@ static bool __init vulnerable_to_rfds(u64 x86_arch_c= ap_msr) return true; =20 /* Only consult the blacklist when there is no enumeration: */ - return cpu_matches(cpu_vuln_blacklist, RFDS); + if (!cpu_matches(cpu_vuln_blacklist, RFDS)) + return false; + + /* + * ADL and RPL are affected only if they have Atom CPUs. Hybrids have + * both Core and Atom CPUs. Mark unaffected when Atom CPUs are not + * present. + */ + if ((boot_cpu_data.x86_model =3D=3D 0x97 || + boot_cpu_data.x86_model =3D=3D 0xB7) && + boot_cpu_data.topo.intel_type !=3D INTEL_CPU_TYPE_ATOM && + !boot_cpu_has(X86_FEATURE_HYBRID_CPU)) + return false; + + return true; } =20 static bool __init vulnerable_to_its(u64 x86_arch_cap_msr)