android_kernel_motorola_sm6375/arch/x86
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Josh Poimboeuf 398beb5677 UPSTREAM: x86/speculation: Warn about eIBRS + LFENCE + Unprivileged eBPF + SMT
commit 0de05d056afdb00eca8c7bbb0c79a3438daf700c upstream.

The commit

   44a3918c8245 ("x86/speculation: Include unprivileged eBPF status in Spectre v2 mitigation reporting")

added a warning for the "eIBRS + unprivileged eBPF" combination, which
has been shown to be vulnerable against Spectre v2 BHB-based attacks.

However, there's no warning about the "eIBRS + LFENCE retpoline +
unprivileged eBPF" combo. The LFENCE adds more protection by shortening
the speculation window after a mispredicted branch. That makes an attack
significantly more difficult, even with unprivileged eBPF. So at least
for now the logic doesn't warn about that combination.

But if you then add SMT into the mix, the SMT attack angle weakens the
effectiveness of the LFENCE considerably.

So extend the "eIBRS + unprivileged eBPF" warning to also include the
"eIBRS + LFENCE + unprivileged eBPF + SMT" case.

  [ bp: Massage commit message. ]

Bug: 215557547
Suggested-by: Alyssa Milburn <alyssa.milburn@linux.intel.com>
Signed-off-by: Josh Poimboeuf <jpoimboe@redhat.com>
Signed-off-by: Borislav Petkov <bp@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I1d99e035c6fc53fac367b0423056dc75237ed430
2022-03-14 12:47:14 +01:00
..
boot x86/boot: Add .text.* to setup.ld 2021-06-16 11:59:38 +02:00
configs ANDROID: GKI: Enable CONFIG_SERIAL_8250_RUNTIME_UARTS=0 2022-02-11 09:39:11 +00:00
crypto BACKPORT: crypto: arch - conditionalize crypto api in arch glue for lib code 2021-10-23 19:32:27 -07:00
entry This is the 5.4.90 stable release 2021-01-17 15:43:22 +01:00
events This is the 5.4.152 stable release 2021-10-09 14:57:08 +02:00
hyperv x86/hyperv: Protect set_hv_tscchange_cb() against getting preempted 2021-11-17 09:48:33 +01:00
ia32
include UPSTREAM: x86/speculation: Add eIBRS + Retpoline options 2022-03-14 12:47:08 +01:00
kernel UPSTREAM: x86/speculation: Warn about eIBRS + LFENCE + Unprivileged eBPF + SMT 2022-03-14 12:47:14 +01:00
kvm This is the 5.4.160 stable release 2021-11-17 10:19:21 +01:00
lib x86/msr: Fix wr/rdmsr_safe_regs_on_cpu() prototypes 2021-05-22 11:38:27 +02:00
math-emu x86: math-emu: Fix up 'cmp' insn for clang ias 2020-07-29 10:18:40 +02:00
mm This is the 5.4.160 stable release 2021-11-17 10:19:21 +01:00
net bpf: Introduce BPF nospec instruction for mitigating Spectre v4 2021-09-15 09:47:38 +02:00
oprofile
pci UPSTREAM: x86/pci: Fix the function type for check_reserved_t 2022-01-14 19:05:02 +00:00
platform x86/platform/olpc: Correct ifdef symbol to intended CONFIG_OLPC_XO15_SCI 2021-10-13 10:08:20 +02:00
power This is the 5.4.90 stable release 2021-01-17 15:43:22 +01:00
purgatory
ras
realmode x86/asm/32: Add ENDs to some functions and relabel with SYM_CODE_* 2021-01-17 14:05:30 +01:00
tools This is the 5.4.142 stable release 2021-08-27 16:27:13 +02:00
um
video
xen xen/x86: fix PV trap handling on secondary processors 2021-09-30 10:09:21 +02:00
.gitignore
Kbuild
Kconfig This is the 5.4.155 stable release 2021-10-20 12:35:49 +02:00
Kconfig.cpu
Kconfig.debug
Makefile This is the 5.4.118 stable release 2021-05-11 16:56:33 +02:00
Makefile.um
Makefile_32.cpu
OWNERS ANDROID: Add OWNERS files referring to the respective android-mainline OWNERS 2021-04-01 13:45:14 +00:00