From nobody Fri Dec 19 19:04:57 2025 Received: from NAM11-CO1-obe.outbound.protection.outlook.com (mail-co1nam11on2073.outbound.protection.outlook.com [40.107.220.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2C511203718 for ; Wed, 8 Jan 2025 20:25:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=40.107.220.73 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736367947; cv=fail; b=ZxnL4E3VBDZKmMD2BlV7o6IjPt6ENhpMWZYTQdobSC0qMLfTE2AHFcWJsmbq5ydOlcL6Q62oG3N2naaoM4X79je+S0/e2Sn2+LSVOjbu8NiTnfEvqv1zji47nuA/EptsraMAiV/8JGXDYJNeyiD6bZB3MQcc0e4agntLLdVxGt8= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736367947; c=relaxed/simple; bh=avAw8EIsDIE6XQgigzLjWbZozHQOpY3xIXbqF3fxdsM=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=nuUAlXKWtwr2I0saRB2c9TZgkw+WlFpljBKDOfXGh/yEpAhjRcriOP+0YI7hBGIRBy84MQMykK6RQ8N8YSXbhyD/5FwQsxPnOeYi4xAsOoThyDApFkZTngOBp7bbk56CAaq3OUdOE52lZt7vFtQsYdWmxhprjLEqioUQODUyTnU= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=jSH6axeI; arc=fail smtp.client-ip=40.107.220.73 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="jSH6axeI" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Mpn3WNI/V93n3fvuP6X57YqU9n6IfM7OEnaC3+6au57w+1K9380RkARzEBeeuCa5PNXQW0ZO1bx0pI5esxgPtyxNJpTa8k6H3qLCLzhMtTzinzZdAybdKZy26X1odJfOyoOYX9dNeCGi6jb8tSfPeudbj7uWGOevwIGDl+ROVDwzFCH0Z7X0J7l3uaIZAyZ1vIscQzJ7OQbgdJhl99w4CqAEMm77P6A5ed28zicQMT2Bg6XcPj932G5gCU4w5Q2+w13/BXJU+5gfeIYwONYRmhUVjVFYPNyjwoMaesVC0u3NgsOhozydguajzBzQKnWqqpfDfJJFByr8KpWItjppUQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=GJK25JRucbSw2LClsYVBB1SxjqIbZiZ5J8q+AXQQXGY=; b=I4L5MCjQXHCM0a3ZHYub3U9lXEgteRjSOsosVcHJ60WJvtMTriR5WVYeUM2Eo8yO+nUu39eIhtQaQm+0w906jvfV1HK/WQC4pfkKIKnyaQ7LnSUenm6vpotmddEsousJ5UBtdhKhdwXl+0oqiew+cV/6H8SnQwzTMPBiUQmbiFdavEzztOFCn2q6oBv3KP6fQ8a54AC2yS/x3js11mRCYDSAQYZnBrBFs8XB//ncB8JvD12CBfBpH863HjzF5A+JxYoGwptHTQP1M1v1s5hts+/2bReuFhe3d55MH7QLKtGg9/3atOtKztO3jvIH84S+kUVkcEpPCQbx7spqSXBDXw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=linutronix.de smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=GJK25JRucbSw2LClsYVBB1SxjqIbZiZ5J8q+AXQQXGY=; b=jSH6axeIPxdRjb1sCffVc+756ez7py2nuI6pRM6oaiRX6NLD+qmi+UWigWRy5QsuVVhW/Aak+d5ePhm8XyoQeffTgANVvtt9zOEUb6pOWRL8Fhdov5KgzIi0u4Vy3IPW2bAZza3aK9e4a+inQHCZbf988zd9N+pnK2E+pYwZEDc= Received: from BL0PR02CA0096.namprd02.prod.outlook.com (2603:10b6:208:51::37) by MN2PR12MB4439.namprd12.prod.outlook.com (2603:10b6:208:262::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8335.10; Wed, 8 Jan 2025 20:25:42 +0000 Received: from DS3PEPF000099DB.namprd04.prod.outlook.com (2603:10b6:208:51:cafe::1f) by BL0PR02CA0096.outlook.office365.com (2603:10b6:208:51::37) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.20.8093.23 via Frontend Transport; Wed, 8 Jan 2025 20:25:42 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 165.204.84.17) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=amd.com; Received-SPF: Pass (protection.outlook.com: domain of amd.com designates 165.204.84.17 as permitted sender) receiver=protection.outlook.com; client-ip=165.204.84.17; helo=SATLEXMB04.amd.com; pr=C Received: from SATLEXMB04.amd.com (165.204.84.17) by DS3PEPF000099DB.mail.protection.outlook.com (10.167.17.197) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.20.8335.7 via Frontend Transport; Wed, 8 Jan 2025 20:25:42 +0000 Received: from tiny.amd.com (10.180.168.240) by SATLEXMB04.amd.com (10.181.40.145) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.39; Wed, 8 Jan 2025 14:25:39 -0600 From: David Kaplan To: Thomas Gleixner , Borislav Petkov , Peter Zijlstra , Josh Poimboeuf , Pawan Gupta , Ingo Molnar , Dave Hansen , , "H . Peter Anvin" CC: Subject: [PATCH v3 07/35] x86/bugs: Restructure rfds mitigation Date: Wed, 8 Jan 2025 14:24:47 -0600 Message-ID: <20250108202515.385902-8-david.kaplan@amd.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20250108202515.385902-1-david.kaplan@amd.com> References: <20250108202515.385902-1-david.kaplan@amd.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: SATLEXMB04.amd.com (10.181.40.145) To SATLEXMB04.amd.com (10.181.40.145) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DS3PEPF000099DB:EE_|MN2PR12MB4439:EE_ X-MS-Office365-Filtering-Correlation-Id: 09c3e4b1-c17e-4e61-b226-08dd30229fe7 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|376014|36860700013|1800799024|7416014|82310400026; X-Microsoft-Antispam-Message-Info: =?us-ascii?Q?vxOZa/l2M3+8r6bB0bG+Vt3iqC4RaFNW8QDxnlKQJKMtTAn9Ifh9vcDhjg0T?= =?us-ascii?Q?I5nooJ+CgSgkyu7pWSIMUQcj4y0bIy7xKn6zG3FqWRhzu0uZSew8Zfo3EUrt?= =?us-ascii?Q?PNIqmI17izY+yGS6AZkPqQvLbTR3p+UeTCscR/d7I6CZEjjcQEUo34QmrxJI?= =?us-ascii?Q?5WfQlEUv0KxT5TVTD8H7LtKMkUYHhs1KvUpHZklRR2ZPamgyvFoaHgeRMeCl?= =?us-ascii?Q?4wTNqs5Kj3x+5n45brc3XfGIBEdvDQE5nxCkSCi9aZVlJ5UGqHPa2+QU9ZZy?= =?us-ascii?Q?wSpzVpLzPucRFeNXxaMSQtPYJoW+4PTzVwZqZQ3WHaIJDOqnmZAky9H97TUX?= =?us-ascii?Q?pZKY4KTZfwZLQFAPF2BZRTEZCsCF09UkHnK45Q56qIEYkjstVlTrHwILqL1h?= =?us-ascii?Q?f4Q5IX0IP8u+eUP1p7rmoMmOBaMjQLcCwc73saFUGTd05GdGILBfDqxYleIR?= =?us-ascii?Q?TcNGhyxn5JOZAac+fvy9AeldeyhpK5U4Z9+glNhedJ1UvTCAy4vxcCNSyjEU?= =?us-ascii?Q?ZTgEuhRSEgWcZ5nVmaD8aPYSn74eTyg8z7E1H83Yco1DUUxTRRdHRUBkfMzv?= =?us-ascii?Q?+IkFrctfJMsU+CzX8DP43Vz1fuFWfly+ZPFxjrfBRJSeKVlWsa+AdHHGPI1V?= =?us-ascii?Q?zuY34+F+35xMVC1bi/RvlNAJtUFEHBaSr76v1/C8bSCIyb7KRRXdq/+Nq7k0?= =?us-ascii?Q?wpXOhA8n+LNd1Oq5FjufHTs7e7PljtgilkQ3KTn0sbY+bLW3K+bpzdW9yL69?= =?us-ascii?Q?8ZryUv6k5fi9qWoKUqILFiQ/bNptn9Wg5FFwLFqNIpjY1CRHnxeEG1o/ewUz?= =?us-ascii?Q?QvtPtO6qO0xP0A5KX7AUKX1ZD10Rr+gv1z4gOctCKXvTebKn+63Y6suN4d3A?= =?us-ascii?Q?zuoE0QH5nL613pYFLIDwceqiPqQaMdc2aGLXwwxvsrEAup6A57n8+AOydTTs?= =?us-ascii?Q?pZAVA1cwsM6K4XORqaBhdhoGbpR3Kle3MeQ0e83PKbR2jvRemrg7y+Swsh6p?= =?us-ascii?Q?jBnUQ2wAh2uzgM0C5Jk7/RIo71jhcpWL2fZMW8cXDQ7Pvm0JjC6tFkmodSz5?= =?us-ascii?Q?y+19cZpZSYqh/WT/UAoubLp8gL15IBWv0glrGYLtDRL3LIRplPswXCiN5YsI?= =?us-ascii?Q?0nmkUAuXzKf8jWLQKy+cOjZzGWiXeOxL6lCLkY1o0wHj4hhvxERaHB46QgnE?= =?us-ascii?Q?4BeVjsXkBq8/mu5dp3hevxhtAYlSDW4NiAA+1TTPublyJk3dCxW62lYjl/Ps?= =?us-ascii?Q?LWJCozStKjOU7p5bTm03bajHSI9TGdLUN55OH9bi8SRFKgAM4JP+bviOfgIt?= =?us-ascii?Q?A2r5hUQs+mFMSnkXF4LYfVDCcjFz+68h1cOfvcKnMYc+tWZgQaICcwyMx1NG?= =?us-ascii?Q?xpfumjBB5K9qwHlZWTWGjQ0MSyb5PTI7o9DXc0BZwEiqAQmRYQqSHWY2Op1S?= =?us-ascii?Q?OdMooeVC5/2RdMUzNxDMJRGNnzONZq4jJIunA9oPnuzsz2w3mk6CwVecT3eJ?= =?us-ascii?Q?ZZAEW020CC8/RV0=3D?= X-Forefront-Antispam-Report: CIP:165.204.84.17;CTRY:US;LANG:en;SCL:1;SRV:;IPV:CAL;SFV:NSPM;H:SATLEXMB04.amd.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230040)(376014)(36860700013)(1800799024)(7416014)(82310400026);DIR:OUT;SFP:1101; X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 08 Jan 2025 20:25:42.5167 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 09c3e4b1-c17e-4e61-b226-08dd30229fe7 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[165.204.84.17];Helo=[SATLEXMB04.amd.com] X-MS-Exchange-CrossTenant-AuthSource: DS3PEPF000099DB.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR12MB4439 Content-Type: text/plain; charset="utf-8" Restructure rfds mitigation to use select/update/apply functions to create consistent vulnerability handling. Signed-off-by: David Kaplan --- arch/x86/kernel/cpu/bugs.c | 33 ++++++++++++++++++++++++++------- 1 file changed, 26 insertions(+), 7 deletions(-) diff --git a/arch/x86/kernel/cpu/bugs.c b/arch/x86/kernel/cpu/bugs.c index a8da097ab2d5..871b9f93b714 100644 --- a/arch/x86/kernel/cpu/bugs.c +++ b/arch/x86/kernel/cpu/bugs.c @@ -70,6 +70,9 @@ static void __init taa_apply_mitigation(void); static void __init mmio_select_mitigation(void); static void __init mmio_update_mitigation(void); static void __init mmio_apply_mitigation(void); +static void __init rfds_select_mitigation(void); +static void __init rfds_update_mitigation(void); +static void __init rfds_apply_mitigation(void); static void __init srbds_select_mitigation(void); static void __init l1d_flush_select_mitigation(void); static void __init srso_select_mitigation(void); @@ -193,6 +196,7 @@ void __init cpu_select_mitigations(void) mds_select_mitigation(); taa_select_mitigation(); mmio_select_mitigation(); + rfds_select_mitigation(); md_clear_select_mitigation(); srbds_select_mitigation(); l1d_flush_select_mitigation(); @@ -211,10 +215,12 @@ void __init cpu_select_mitigations(void) mds_update_mitigation(); taa_update_mitigation(); mmio_update_mitigation(); + rfds_update_mitigation(); =20 mds_apply_mitigation(); taa_apply_mitigation(); mmio_apply_mitigation(); + rfds_apply_mitigation(); } =20 /* @@ -607,9 +613,6 @@ static int __init mmio_stale_data_parse_cmdline(char *s= tr) } early_param("mmio_stale_data", mmio_stale_data_parse_cmdline); =20 -#undef pr_fmt -#define pr_fmt(fmt) "Register File Data Sampling: " fmt - static const char * const rfds_strings[] =3D { [RFDS_MITIGATION_OFF] =3D "Vulnerable", [RFDS_MITIGATION_VERW] =3D "Mitigation: Clear Register File", @@ -627,11 +630,28 @@ static void __init rfds_select_mitigation(void) =20 if (rfds_mitigation =3D=3D RFDS_MITIGATION_AUTO) rfds_mitigation =3D RFDS_MITIGATION_VERW; +} =20 - if (x86_arch_cap_msr & ARCH_CAP_RFDS_CLEAR) +static void __init rfds_update_mitigation(void) +{ + if (!boot_cpu_has_bug(X86_BUG_RFDS) || cpu_mitigations_off()) + return; + + if (verw_mitigation_enabled()) + rfds_mitigation =3D RFDS_MITIGATION_VERW; + + if (rfds_mitigation =3D=3D RFDS_MITIGATION_VERW) { + if (!(x86_arch_cap_msr & ARCH_CAP_RFDS_CLEAR)) + rfds_mitigation =3D RFDS_MITIGATION_UCODE_NEEDED; + } + + pr_info("Register File Data Sampling: %s\n", rfds_strings[rfds_mitigation= ]); +} + +static void __init rfds_apply_mitigation(void) +{ + if (rfds_mitigation =3D=3D RFDS_MITIGATION_VERW) setup_force_cpu_cap(X86_FEATURE_CLEAR_CPU_BUF); - else - rfds_mitigation =3D RFDS_MITIGATION_UCODE_NEEDED; } =20 static __init int rfds_parse_cmdline(char *str) @@ -704,7 +724,6 @@ static void __init md_clear_update_mitigation(void) =20 static void __init md_clear_select_mitigation(void) { - rfds_select_mitigation(); =20 /* * As these mitigations are inter-related and rely on VERW instruction --=20 2.34.1