7 ms·
It appears the retpoline fixes don't work in Skylake or later (it's smart enough to speculate out of it?) and will require new support for IBRS/IBPB in the micr
by cws125 9y ago
It appears the retpoline fixes don't work in Skylake or later (it's smart enough to speculate out of it?) and will require new support for IBRS/IBPB in the microcode to mitigate.
From: https://lkml.org/lkml/2018/1/4/615 https://lkml.org/lkml/2018/1/4/615
- bpye 9y agoSeems that the new MSR results in worse perf than the retoline which is alarming. https://docs.google.com/document/u/2/d/e/2PACX-1vSMrwkaoSUBAFc6Fjd19F18c1O9pudkfAY-7lGYGOTN8mc9ul-J6pWadcAaBJZcVA7W_3jlLKRtKRbd/pub https://docs.google.com/document/u/2/d/e/2PACX-1vSMrwkaoSUBA...
- cesarb 9y agoInteresting: > Note: IBRS is not required in order to isolate branch predictions for SMM or SGX enclaves Perhaps this microcode update exposes a feature which was originally to protect these two modes? But that would mean that Intel did think about leaks through the branch predictor, only didn't make the logical leap that this could be an issue also for normal ring0/ring3...
- contrarian_ 9y agoHuh, so did Intel know about this vulnerability when they designed SGX?
- pritambaral 9y agoMaybe, maybe not. I looked around a bit and found [1]"that the Intel SGX does not clear branch history when switching from enclave mode to non-enclave mode", which suggests either that the SGX designers were unaware of the dangers of not separating branch prediction between privilege levels, or that Intel intentionally weakened SGX so as to not reveal the similar flaw in their ring0/ring3 separation. 1: https://arxiv.org/abs/1611.06952 https://arxiv.org/abs/1611.06952 (Nov '16)
- j_coder 9y agoWhat I don't understand is why the kernel patches and microcode updates are still been worked out today. They had 6 months to work on it. No secret channel to communicate with Linux Kernel developers? No coordinated effort? Last minute findings? On this thread https://lkml.org/lkml/2018/1/4/174 https://lkml.org/lkml/2018/1/4/174 looks like that the author is disclosing the info on the last minute.
- Pyxl101 9y agoI was wondering the same thing earlier. This doesn't feel like a disclosure that's had anywhere near ~6 months put into it. Did the vendors ignore the disclosure initially and begin to change tactics later in the game? Based on how certain vendors have been characterizing this in their PR, I wouldn't be surprised if they didn't take the problem seriously originally.
- mook 9y agoThe Ubuntu page that was on HN earlier [] claims that they were notified in early November. I have no idea if kernel people (as opposed to distro people) got notified earlier. []: https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAndMeltdown https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAn...
- geezerjay 9y agoIIRC Intel employs people to work on the linux kernel on behalf oh Intel. Either Intel fumbled or it isn't that easy to circumvent the problem plaging Intel's processors with a software hack.
- hinkley 9y agoOr, they were holding out hope for a workaround that didn't make the entire Cloud 20% slower and they couldn't make it work.
- yndoendo 9y agoCode for the solution and then code for performance. Direct performance coding is a bad return on investment. First prove it works and then prove it can be made better and faster ...
- gcbirzan 9y agoIntel says Broadwell or newer: https://newsroom.intel.com/wp-content/uploads/sites/11/2018/01/Intel-Analysis-of-Speculative-Execution-Side-Channels.pdf https://newsroom.intel.com/wp-content/uploads/sites/11/2018/... (page 5)