3 ms·
Binary packaging systems download microcode.dat (a text blob containing microcode) from Intel during the build process. Microcode.dat gets converted into an ini
by twr 10y ago
Binary packaging systems download microcode.dat (a text blob containing microcode) from Intel during the build process. Microcode.dat gets converted into an initramfs image that supplies the new microcode early in the system boot. Users download the built binary package, which then modifies the boot parameters of their system.
So normally only the build servers contact Intel. Source-based distributions may. But even then the source files are verified with cryptographic hashes (which are in turn signed by the maintainers' private keys).
Edit: I may have misread your question. I thought you were asking by implication if the microcode blob is pulled after the install. If not, then: No. Updates happen when the package manager decides.
https://www.kernel.org/doc/Documentation/x86/early-microcode.txt https://www.kernel.org/doc/Documentation/x86/early-microcode...
https://gitlab.com/iucode-tool/iucode-tool https://gitlab.com/iucode-tool/iucode-tool
https://downloadcenter.intel.com/download/26400/Linux-Processor-Microcode-Data-File https://downloadcenter.intel.com/download/26400/Linux-Proces...