[MODERATED] Re: [PATCH 3/9] TAA 3

Borislav Petkov <[email protected]>
Newsgroups org.kernel.lore.historical-speck
Message-ID <[email protected]>
On Thu, Oct 24, 2019 at 10:30:15AM -0500, speck for Josh Poimboeuf wrote:
> This still needs details about when 'tsx=off' does and doesn't work.
> 
> The above makes it sound like it's off for all CPUs, when in fact it's
> only off for newer MDS_NO CPUs.

How does that sound (and that is being mentioned somewhere in all the
text but here it is important to have):

			off     - Disable TSX on the system. (Note that this
				option takes effect only on newer CPUs which are
				not vulnerable to MDS, i.e., have
				MSR_IA32_ARCH_CAPABILITIES.MDS_NO=1 and which get
				the new IA32_TSX_CTRL MSR through a microcode
				update. This new MSR allows for the reliable
				deactivation of the TSX functionality.)

> It should also perhaps describe the risks associated with tsx=on.  While
> there are mitigations for all known issues (i.e., the tsx_async_abort=
> option), TSX has been known to be an accelerator for several previous
> speculation-related CVEs, and so there may be unknown security risks
> associated with leaving it enabled.

You've basically said it nicely already:

"Although there are mitigations for all known security vulnerabilities,
TSX has been known to be an accelerator for several previous
speculation-related CVEs, and so there may be unknown security risks
associated with leaving it enabled."

ACK?

-- 
Regards/Gruss,
    Boris.

SUSE Software Solutions Germany GmbH, GF: Felix Imendörffer, HRB 36809, AG Nürnberg
--
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.