[MODERATED] Re: ***UNCHECKED*** Re: [PATCH v5 08/11] TAAv5 8

Josh Poimboeuf <[email protected]> Tue, 15 Oct 2019 15:00:24 -0500
Newsgroups org.kernel.lore.historical-speck
Message-ID <20191015200024.hxs4brxi7gbvmcdy@treble>
On Tue, Oct 15, 2019 at 05:32:08PM +0200, speck for Jiri Kosina wrote:
> On Tue, 15 Oct 2019, speck for Josh Poimboeuf wrote:
> 
> > > > Since all (or most?) modern Intel CPUs are vulnerable to TAA, 
> > > > defaulting to tsx=auto would effectively be the same as defaulting 
> > > > to tsx=off, right?  How does this help with regressions?
> > > 
> > > The mitigation is only needed on CPUs where verw doesn't have the buffer 
> > > clearing semantics.
> > 
> > Can you elaborate?  I have no idea what you're trying to say and how it
> > relates to my question :-)
> 
> Only those CPUs with TSX *and* with MDS_NO need TSX disabled in order to 
> protect from this issues.
> 
> The CPUs that don't enumarate MDS_NO (and therefore got ucode update with 
> verw buffer-clearing semantics) are fully mitigated against TAA by MDS 
> mitigations already.
> 
> Therefore the set of CPUs where we *really* need to turn of TSX in order 
> to protect from TAA is currently rather minimal (CascadeLake-B, 
> WhiskeyLake-V, CommitLake, CoffeeLake-R), so force-disabling on all CPUs 
> covers way bigger set of platforms than actually needed.

Maybe I'm missing something.  Isn't there going to be a ucode update for
MDS_NO parts, which does the verw buffer clearing?  In that case there's
no need to disable TSX, and instead the verw mitigation could be used,
if desired.

AFAICT, the patch allows to set the default to tsx=auto, which disables
TSX on *all* vulnerable parts, not just the MDS_NO ones.  I don't see
how that would prevent user regressions.

It sounds like maybe you're suggesting something else, that TSX should
only be disabled on vulnerable MDS_NO parts?

-- 
Josh