[MODERATED] Re: [PATCH 8/9] TAA 8

Pawan Gupta <[email protected]>
Newsgroups org.kernel.lore.historical-speck
Message-ID <[email protected]>
> > > > +For the affected platforms below table indicates the mitigation status for the
> > > > +combinations of CPUID bit MD_CLEAR and IA32_ARCH_CAPABILITIES MSR bits MDS_NO
> > > > +and TSX_CTRL_MSR.
> > > > +
> > > > +  =======  =========  =============  ========================================
> > > > +  MDS_NO   MD_CLEAR   TSX_CTRL_MSR   Status
> > > > +  =======  =========  =============  ========================================
> > > > +    0          0            0        Vulnerable (needs ucode)
> > > > +    0          1            0        MDS and TAA mitigated via VERW
> > > > +    1          1            0        MDS fixed, TAA vulnerable if TSX enabled
> > > > +                                     because MD_CLEAR has no meaning and
> > > > +                                     VERW is not guaranteed to clear buffers
> > > 
> > > (needs ucode) ?
> > 
> > Will there even be microcode for those to beef up VERW?
> 
> This might be a question for Intel, but I assumed this is the case where
> the new microcode on the MDS_NO parts would enable the VERW buffer
> clearing.

That is correct.

> > > > +If the microcode is available and the TSX is disabled on the host, attacks
> > > > +are prevented in a virtualized environment as well, even if the VMs do not
> > > > +explicitly enable the mitigation.
> > > 
> > > What's the effect on VM security if TSX is enabled and the host TAA
> > > mitigation is also enabled?
> > 
> > Same as in the !VM case, I'd assume. tsx_async_abort=full,nosmt should
> > give you full mitigation.
> 
> Right, the effects of the host mitigation options on the guest would be
> useful here.

When TSX is enabled on host part 6/9 exports MDS_NO=0 to VMs, so that
VMs deploy MDS mitigation which also mitigates TAA.

> > > > +Mitigation strategy
> > > > +-------------------
> > > > +
> > > > +a) TSX disable - one of the mitigations is to disable TSX. A new MSR
> > > > +IA32_TSX_CTRL will be available in future and current processors after
> > > 
> > > which processors?
> > 
> > The MDS_NO=1 and future parts, I guess.
> 
> Right, that should be clarified.

This is correct, list of MDS_NO=1 parts shared earlier, and the future parts.

Thanks,
Pawan
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.