Received: by 2002:ab2:69cc:0:b0:1f4:be93:e15a with SMTP id n12csp87509lqp; Fri, 12 Apr 2024 11:11:00 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCXXcYoMOu6lVjPHswbG6BkqTpJCeJ9I2idpTBjk2KFU7ts93pdAIn5qVycE2wraHy8KGyNwmoGXQReD3xJNPh81NQJ1FliDw+l4lCK5xw== X-Google-Smtp-Source: AGHT+IH0PV20DkWx4Ll2j9XX4eAFQEVTc9tMv6ShYmuqm1RkZrwzA+KGtvAIT2d6q88rg0HP9zf2 X-Received: by 2002:ad4:4f23:0:b0:69b:5445:6ab0 with SMTP id fc3-20020ad44f23000000b0069b54456ab0mr4087312qvb.46.1712945459950; Fri, 12 Apr 2024 11:10:59 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1712945459; cv=pass; d=google.com; s=arc-20160816; b=IJ0HLs0He6gh24MXFUXChRkErKCiA2j5T5VGk9jssi+1WQ+0mbw0eu890bvrz/lZyz 5azUtpJAAbPUFibMWb+HTCvHZTz+rNQHHPY/D1JQ1wHxEwzwAPbAxsBv7/z/mCJBjW5/ kZGIB0JRFfZhW9BwHjWO2I3dDZRW5oZAlYfBHa0BIDj3IADYtsSxyI0pkqS6qlCix0Qg EE7RxCgZKYbq4VxcgScx4KthKfNQWCBPm8P/PvIsjvn2FreimfbqbprXnw9okN0vLhzw VkQAZYnNQ08qcq2wvYv8ZUUOz+5pa0GyomP8qnAZNUQzgTGcibT1DYvSPWbO5dxwiCQp fsGw== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:in-reply-to:message-id :date:subject:cc:to:from:dkim-signature; bh=BZ0n2vDYCwEQgjxXNg8h7Lt6MhFHAKHI61Oew1Jmlg0=; fh=D1drUkjhd6cQ461FGcgjExl1O+jZ7EhaGJAtOyxVAPQ=; b=euRwQVw16h+Ut/bNrGFLPjTBvnLHlwQouExdEV8QZVmZV7XmfrrJ91FsXu9ErhAoK+ Pi2qWDtgTTgN0oZ4E7qz+/w69KQEw6XexFODWsvi2ckFfhGVJfl6pqo+nRyFifFw9zva fW39IuvgxkxufwKQl3zB2/pKBwpd8rC1haS/KwKkD7zudeWjZE/CB86lf38nvnlhHhTV QEEPWoQy0/wYIUPteIW+DqTZOp5KA/9udW2Ps7CVzohWHDhW5AXGbYmLFQCPcZr0rXZl PLTBiPsGr8SltmyhAKOGaHP6wp3OpHkvuZ3sVfdVmy4DNw5Dce6TzXszkFOiV0HWC8Dp uN1A==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=PnwENq27; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-143178-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.199.223 as permitted sender) smtp.mailfrom="linux-kernel+bounces-143178-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from ny.mirrors.kernel.org (ny.mirrors.kernel.org. [147.75.199.223]) by mx.google.com with ESMTPS id j9-20020ad453a9000000b0069b516a51f5si3131511qvv.254.2024.04.12.11.10.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 12 Apr 2024 11:10:59 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-143178-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.199.223 as permitted sender) client-ip=147.75.199.223; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=PnwENq27; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-143178-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.199.223 as permitted sender) smtp.mailfrom="linux-kernel+bounces-143178-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ny.mirrors.kernel.org (Postfix) with ESMTPS id 9170F1C222DA for ; Fri, 12 Apr 2024 18:10:59 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id E7A2914F10A; Fri, 12 Apr 2024 18:10:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="PnwENq27" Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 18A2814EC60 for ; Fri, 12 Apr 2024 18:10:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1712945441; cv=none; b=IPDJ+gMD+XiMTnHoIeLAz9Gg8bGrZNHte4ngiWC16K9lRZOLbNo0fUxQ1i8KssrEw3BY8uSve4pjw0AiJ4V8P6dkEi1y67zlu9JImh7Evn8uxM+c/dTC614RWLh+LBEu7WYHo8P/72N5AhvOUWG52b2pnyH8R5ZvKqlMEQYXCI0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1712945441; c=relaxed/simple; bh=8NZHE1tS6vfknLA1oyfYTojtWsl+OR5G87hXz6y9g5w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XZa94evWT7J3q+dbcwETrF4lHO/azj7xPfn8bKAe56d6CxC7M7+VB7/uSZiIX3+OODLMP2cFaIFFDu8r1KUbpopjPTDiusZ5wTvVzdioVbOzOuFhsU5/5eVQ90RIvp06tVKUvIMVYqYNiw5NoTQAf2q/OGq4JrxsDTapt+zZ5H8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=PnwENq27; arc=none smtp.client-ip=10.30.226.201 Received: by smtp.kernel.org (Postfix) with ESMTPSA id F1F87C32786; Fri, 12 Apr 2024 18:10:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1712945440; bh=8NZHE1tS6vfknLA1oyfYTojtWsl+OR5G87hXz6y9g5w=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=PnwENq27GKTELnxMvUoZ8+jmsfhQy+Q+870u2mG+IiA2sxv9jwNwy0ZkRJfumNfzx 3d1B8SJxdFwUOsKNTKUN/uMa3pWhiedeB8rsef/NXyBB+YWDSn61LvWxfEQnC7FWEY MGBsdg8MP2ho3zIApifLmNSoqT6+Q3kwZ4adtY/BeJrtXGo4MAG29w2G854hUnYfdU uoAZ1I5wDYekZYh3wPLAD/VOIIPA1ruYqu36mHVow5EfY0MZGMicreYJyAq8KEwV8a JRRRUFUwqaZDCZCnmQcy+X8JAvrr7l7gQRLVXY+pFxc1zuCZHZEph3e02MRj5aAUkw N7SfiULmO+Jsg== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, Linus Torvalds , Daniel Sneddon , Pawan Gupta , Thomas Gleixner , Alexandre Chartre , Konrad Rzeszutek Wilk , Peter Zijlstra , Greg Kroah-Hartman , Sean Christopherson , Andrew Cooper , Dave Hansen , Nikolay Borisov , KP Singh , Waiman Long , Borislav Petkov , Ingo Molnar Subject: [PATCH 2/3] x86/bugs: Fix BHI retpoline check Date: Fri, 12 Apr 2024 11:10:33 -0700 Message-ID: X-Mailer: git-send-email 2.44.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Confusingly, X86_FEATURE_RETPOLINE doesn't mean retpolines are enabled, as it also includes the original "AMD retpoline" which isn't a retpoline at all. Also replace cpu_feature_enabled() with boot_cpu_has() because this is before alternatives are patched and cpu_feature_enabled()'s fallback path is slower than plain old boot_cpu_has(). Fixes: ec9404e40e8f ("x86/bhi: Add BHI mitigation knob") Signed-off-by: Josh Poimboeuf --- arch/x86/kernel/cpu/bugs.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/arch/x86/kernel/cpu/bugs.c b/arch/x86/kernel/cpu/bugs.c index dcb97cc2758f..e827613c9e39 100644 --- a/arch/x86/kernel/cpu/bugs.c +++ b/arch/x86/kernel/cpu/bugs.c @@ -1652,7 +1652,8 @@ static void __init bhi_select_mitigation(void) return; /* Retpoline mitigates against BHI unless the CPU has RRSBA behavior */ - if (cpu_feature_enabled(X86_FEATURE_RETPOLINE)) { + if (boot_cpu_has(X86_FEATURE_RETPOLINE) && + !boot_cpu_has(X86_FEATURE_RETPOLINE_LFENCE)) { spec_ctrl_disable_kernel_rrsba(); if (rrsba_disabled) return; @@ -2833,11 +2834,13 @@ static const char *spectre_bhi_state(void) { if (!boot_cpu_has_bug(X86_BUG_BHI)) return "; BHI: Not affected"; - else if (boot_cpu_has(X86_FEATURE_CLEAR_BHB_HW)) + else if (boot_cpu_has(X86_FEATURE_CLEAR_BHB_HW)) return "; BHI: BHI_DIS_S"; - else if (boot_cpu_has(X86_FEATURE_CLEAR_BHB_LOOP)) + else if (boot_cpu_has(X86_FEATURE_CLEAR_BHB_LOOP)) return "; BHI: SW loop, KVM: SW loop"; - else if (boot_cpu_has(X86_FEATURE_RETPOLINE) && rrsba_disabled) + else if (boot_cpu_has(X86_FEATURE_RETPOLINE) && + !boot_cpu_has(X86_FEATURE_RETPOLINE_LFENCE) && + rrsba_disabled) return "; BHI: Retpoline"; else if (boot_cpu_has(X86_FEATURE_CLEAR_BHB_LOOP_ON_VMEXIT)) return "; BHI: Vulnerable, KVM: SW loop"; -- 2.44.0