Received: by 2002:a05:6a10:8c0a:0:0:0:0 with SMTP id go10csp1778467pxb; Thu, 4 Mar 2021 22:24:20 -0800 (PST) X-Google-Smtp-Source: ABdhPJyrV+S82ZZwQ3nlCCzjAfYUNiQ0JXtdpSTcRIkFSvdvLgyeUCOD2NmRL5H6rwxeUL01FCeo X-Received: by 2002:a92:1a51:: with SMTP id z17mr7663971ill.295.1614925460785; Thu, 04 Mar 2021 22:24:20 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1614925460; cv=none; d=google.com; s=arc-20160816; b=qR/6WwUnVSwLrrjd/pgEC3FT/IYZu5zJgCVtW2gkKO9LThfyKWxlW7sXCDFSaCS31a itDaSmWOU+LQsAoEUiK2RpM9ARzJ06Cw3IG8PSCu3OxIqZaK2FwroIYL6nPcYsRC8Wz9 Qn8njT6KSCTbzEja+8mYvI/TgBUUcPufirOEUx4tkd9T7X5TAX4AgVhwwaqA5btb6gGp c/qe2N9mg0lM78PrnMUVXW+4425uX73eRvQFW0mTLRWBf5UkOqc0nC75N7BpoyTUVawJ ifiEljfsklMwStqh5KLDMkan3E7gN/k3kOS/yajazz5scwLiF/oiQKKyfrsZNq+hIrfM 757Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:mime-version:message-id:date:references :in-reply-to:subject:cc:to:from:dkim-signature; bh=zB20AWZCLfEBbGKQPBi/qJSelo7iqc/KSNDLZOpau2s=; b=WNPx79ECgV11B7VQ3gPJS5W1dANZygHq7OYEDmGToP8P/9Se7+BUMGaVET6G/Wwq4/ lBbc0AUqqrnC+0H4pXSRZc5c13+K3lIMRA56Ht0heey+PbQG276hmHoWEWj1MWGSogT5 IwxZpl6Ne+HmmsAZs5gbGkXQVYUTji4Q4xyY1wp69oVoY0IKIJu4TqgG7lFXBqXww/1a kP+16EJlofxyY8iaSj8SJo+UA1q1JnQCdULUKRW5Muw7rpKKRlftfmgzbeSs9qsshSbz mRyT9ipQAPcR4pzkMWGL0T6luB6e/FvvAE56XGqJyw8GmXw/1eBwKA04/PgCgXAZWDKn wgeA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@ellerman.id.au header.s=201909 header.b=W4Na6DiU; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id k18si1438401jam.96.2021.03.04.22.24.07; Thu, 04 Mar 2021 22:24:20 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@ellerman.id.au header.s=201909 header.b=W4Na6DiU; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229523AbhCEGXc (ORCPT + 99 others); Fri, 5 Mar 2021 01:23:32 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:43012 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229458AbhCEGX3 (ORCPT ); Fri, 5 Mar 2021 01:23:29 -0500 Received: from ozlabs.org (bilbo.ozlabs.org [IPv6:2401:3900:2:1::2]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id CC642C061574 for ; Thu, 4 Mar 2021 22:23:28 -0800 (PST) Received: from authenticated.ozlabs.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail.ozlabs.org (Postfix) with ESMTPSA id 4DsHjn6wf6z9sVt; Fri, 5 Mar 2021 17:23:25 +1100 (AEDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ellerman.id.au; s=201909; t=1614925406; bh=vhZ+ardqsQ5ea5DSlNBSfyBBFPtTVFoe3/Aq+lA3Wms=; h=From:To:Cc:Subject:In-Reply-To:References:Date:From; b=W4Na6DiUpEajZaPOVjPsUiELSE3AFsUzknC3uEpdrbr+GqXVXR6GB/iZbets36I8A pUnaWA+0qviuS9Pj5qwEGIlx3JYely+VBLeNBKajvLhvT+Bs2YUc5IjytsHwRsjI4p L5KSUQ7yKZ4+DG21cPtPoQOqtj5MamKnd5o0ipHWAH/+R55Uj+PNcmEKJ10w6lNZ/g f0audOESlXLc2hBgO9zFi1lnNy9gpEFWO6/DPWqqCmeEFTkLirs68osCaSu7KpzNcg XdWMF4GO8LP3EXk8EPY2ywYy8g577rJpxuqrzySILgpk1uDlqZBtgWwb9gwcY0tOEo AX7XnJJyFQlIA== From: Michael Ellerman To: Laurent Dufour , benh@kernel.crashing.org, paulus@samba.org, linuxppc-dev@lists.ozlabs.org Cc: nathanl@linux.ibm.com, cheloha@linux.ibm.com, linux-kernel@vger.kernel.org Subject: Re: [PATCH] powerpc/pseries: export LPAR security flavor in lparcfg In-Reply-To: <20210304114240.54112-1-ldufour@linux.ibm.com> References: <20210304114240.54112-1-ldufour@linux.ibm.com> Date: Fri, 05 Mar 2021 17:23:21 +1100 Message-ID: <871rcuruee.fsf@mpe.ellerman.id.au> MIME-Version: 1.0 Content-Type: text/plain Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Laurent Dufour writes: > This is helpful to read the security flavor from inside the LPAR. We already have /sys/kernel/debug/powerpc/security_features. Is that not sufficient? > Export it like this in /proc/powerpc/lparcfg: > > $ grep security_flavor /proc/powerpc/lparcfg > security_flavor=1 > > Value means: > 0 Speculative execution fully enabled > 1 Speculative execution controls to mitigate user-to-kernel attacks > 2 Speculative execution controls to mitigate user-to-kernel and > user-to-user side-channel attacks Those strings come from the FSP help, but we have no guarantee it won't mean something different in future. cheers