On 05/21/2018 12:46 PM, speck for Greg KH wrote: > On Sun, May 20, 2018 at 04:59:04PM -0400, speck for Jon Masters wrote: >> * ARM. They have a new SMCC (Secure Monitor Call) interface (similar to >> the one they did for branch predictor invalidation for Spectre-v2) that >> will be wired up with kernel patches. Each of the vendors will implement >> the new SMCC in ATF (Arm Trusted Firmware) on their parts, using the >> best back-end mitigation (similar to microcode). Arm know to ping Thomas >> with those patches, yet this has not happened yet (to my knowledge), nor >> to Greg. Will has point on this in any case. He and the team are working >> hard on this. Still, I am saddened by these patches not being available >> prior to disclosure since this is not how we do things in the server >> space. But in anticipation that this would happen, I worked directly >> with Cavium (the only server-class CPU vendor with production RHEL >> support for which we need an answer tomorrow on our end) to create a >> firmware knob that can be used in the short term until this is fixed. I >> also have pinged all of the Arm server vendors to let them know I expect >> all of the SMCC wiring to be in place within the next few weeks. > > Just heard from ARM, they are going to wait a week or so and then send > patches for inclusion in 4.18 and then send some backports for the older > kernels then. The kernel patches are useless without firmware updates > and I don't know what the state of them are. For the firmware, I'm told that there's a reference ATF (Arm Trusted Firmware) in flight that implements the new SMCC. I'm aware that some of the client folks have this working. On the server side, people are waiting for Arm to release the reference to them to incorporate. One of the server vendors is not impacted at all, while three others are to differing levels, and all can implement the SMCC but may also provide more optimal per-platform fixes via the errata infrastructure. I've been working with Cavium (as the only supported platform with RHEL today - we only ship subscriptions with Tier 1 OEMs, the others you can kick the tires on but no support yet) on plans and we came to a decision that we would use the emergency knob in the short term, then give Arm a few weeks to get the ATF reference out. If they don't have that done within the next few weeks, at least for Cavium/HPE it'll be done separately implementing the SMCC as we're not waiting around. Jon. -- Computer Architect | Sent from my Fedora powered laptop