Received: by 2002:a05:7412:6592:b0:d7:7d3a:4fe2 with SMTP id m18csp2544507rdg; Mon, 14 Aug 2023 06:07:55 -0700 (PDT) X-Google-Smtp-Source: AGHT+IETFWsPpZtX4fEMMvKkRrkE9NWycEO7h6v6fHaBPoflr1kTshl1QTv+ZHsMcm3P6K/lrXik X-Received: by 2002:a05:6512:3c83:b0:4fe:af1:c3ae with SMTP id h3-20020a0565123c8300b004fe0af1c3aemr8093657lfv.15.1692018475238; Mon, 14 Aug 2023 06:07:55 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1692018475; cv=none; d=google.com; s=arc-20160816; b=dblYDq0hSAQYS3PuT1s72Avxx1GimsZODTkIyXxxlS6qdxkWuUwzzpY5MuaEcWqx9i WXvfA7vTXhPkINKrLhWN00ctTF7YEhT964QYOZDSMlvmFmZ2GHi/MtPLOCGWg9NcGJgE kUVM9ggpOqA0PMhfQhfl7JoLkuTHwcOxoO57WjZjHt7yUAqvanICr5mXPCMYU686INuv spkLO+T+HzGKcTtyKkBig/Vml2SvB+pxWBAVcAkNuzJlFdM3oTUF0Vbv1t6Kyk3J+Z9F cVnb0jaWjZh3iFHK1558y5iIS+WgFxBFh0MfbBJ6DOBySzDGnJm+VBlzUF4n5ZVgFZeo JNiQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=oeHBEWvonmkHqTzAX1tmL+zX2cqupv+iys/IhcfXR1g=; fh=NIq3Pz1UcmJpt2r0gz0jiQ2MfKPc0s/xua1GLeoP6hY=; b=DIFkJR+L6cwGQR49v8jC1ElKvY0XZiP4clxxD+w222/R8uqROkMS8z3bTDqeD6qF+O qGNVA7//U7gupTZiWlgpuNFvvRwcfZnlVeg/aeYQGmvo+gmPnIRImpUSFuZ3VPTSCgmo hB/0xIeOwuJ3D6wNjdTBXpcKeXaI1WJ2gfhGcF78S2+r7cGAJDuaNF33fQpxLq6pU8eL 45ieHw4igWEP7jxFYhU9cNAZ9snmIhgpB4IBD5dqNIPBd35gJMeVlczkT++7V/Zd6dva X6cj3TW+5AOebialKcrFtaWNzrSZBNuEB4b6TkFrbY/N4APFqpNRbC1nIgFbiW2+SdYf EeHg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@alien8.de header.s=alien8 header.b=JOyHu5eA; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=alien8.de Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id e22-20020a056402089600b0052567e6585dsi1355919edy.72.2023.08.14.06.07.29; Mon, 14 Aug 2023 06:07:55 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@alien8.de header.s=alien8 header.b=JOyHu5eA; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=alien8.de Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230451AbjHNMxN (ORCPT + 99 others); Mon, 14 Aug 2023 08:53:13 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:60988 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231214AbjHNMxG (ORCPT ); Mon, 14 Aug 2023 08:53:06 -0400 Received: from mail.alien8.de (mail.alien8.de [IPv6:2a01:4f9:3051:3f93::2]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 3C3E194 for ; Mon, 14 Aug 2023 05:53:05 -0700 (PDT) Received: from localhost (localhost.localdomain [127.0.0.1]) by mail.alien8.de (SuperMail on ZX Spectrum 128k) with ESMTP id E391040E0196; Mon, 14 Aug 2023 12:53:02 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at mail.alien8.de Authentication-Results: mail.alien8.de (amavisd-new); dkim=pass (4096-bit key) header.d=alien8.de Received: from mail.alien8.de ([127.0.0.1]) by localhost (mail.alien8.de [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id BCRUEbTkMEpH; Mon, 14 Aug 2023 12:53:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alien8.de; s=alien8; t=1692017580; bh=oeHBEWvonmkHqTzAX1tmL+zX2cqupv+iys/IhcfXR1g=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=JOyHu5eAylFUYjlPBZDNIL+aLmF7Ir+QT6smawT1RSNJaN08dDVDOSkopkL1fB70B T9ANIWWELol5Hd/LIsbFVPHNNit1JyrrlVodez32nLrI5Zk5lP0xtYPv7afpM+F71S U+vkXV58ayxvWR6zKtJ6PkpvHbEbMyN7yFIATjxEglXWKwQuL8Hhjg6PF2bH2a1J5A yL9kRjEeunoeZsGgv4OiG8Bqr7Lwfu1Qa5/6JjxTAGa5jbEr5HEv1l5OhB5tYBjfHw zn8dtzy43UzpGZ7eHRKekmGtkxZBATRxV63qA03rQ2o9rBWRdZjm2Og5ztvadYWJvF EdqPPOuS04jw7x1iN699MYXVDLz1TkBaTVQFm5YNY3TmLpSNs0AQJmWxhOvGRdPRPf iG6JiB3z97DdwsAibUJlrB4PyXHow0r0XdaMaSXaFMH2kmi5fKPj8GDrluOs2wijMS ezIqXW1V/SS4GJ4PgzLmchFYfDFogSzu1NluYociKeNWQdpwv25o3cgAgZx+sAaBcS Y8WepRi5Kn3tQhv8WWkKAuonM23N+bWlBbEzw6M7RsexP9naW5tgxpWNQTySuETrsJ 5EnrKf6ScE2PbQyCLQRdBpzLR9rbEVsnKLgFW0LbBAczepeQnkFwhoDKPps+5DMt4n lmgnAe8eZ3BHOMqgpLCd9D/o= Received: from zn.tnic (pd9530d32.dip0.t-ipconnect.de [217.83.13.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail.alien8.de (SuperMail on ZX Spectrum 128k) with ESMTPSA id 76AC340E0195; Mon, 14 Aug 2023 12:52:55 +0000 (UTC) Date: Mon, 14 Aug 2023 14:52:49 +0200 From: Borislav Petkov To: Rainer Fiebig Cc: Xi Ruoyao , x86@kernel.org, linux-kernel@vger.kernel.org, Ken Moffat Subject: Re: Does srso safe RET mitigation require microcode update? Message-ID: <20230814125249.GCZNojoW8pC+ToOews@fat_crate.local> References: <79c179acaa6ec4e1cf112ae2dfce8370694a5089.camel@xry111.site> <20230814091012.GAZNnvdD6JX/4E679D@fat_crate.local> <0338eb8b-6b60-313c-e6eb-faca071c5227@mailbox.org> <20230814101134.GBZNn91uTmNImxRDXr@fat_crate.local> <9294eeed-e354-48e3-a0fe-8f917074ef8f@mailbox.org> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <9294eeed-e354-48e3-a0fe-8f917074ef8f@mailbox.org> X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Aug 14, 2023 at 01:21:01PM +0200, Rainer Fiebig wrote: > OK, thanks. So I think a reasonable approach for ordinary users would > be to update to the latest (LTS-) kernel, use the defaults for the > mitigations and update to the new AGESA when available. Yap, pretty much. -- Regards/Gruss, Boris. https://people.kernel.org/tglx/notes-about-netiquette