From mboxrd@z Thu Jan 1 00:00:00 1970 Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752997AbeAFLuH (ORCPT + 1 other); Sat, 6 Jan 2018 06:50:07 -0500 Received: from smtp-fw-9102.amazon.com ([207.171.184.29]:30928 "EHLO smtp-fw-9102.amazon.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752905AbeAFLuD (ORCPT ); Sat, 6 Jan 2018 06:50:03 -0500 X-IronPort-AV: E=Sophos;i="5.46,321,1511827200"; d="scan'208";a="584537221" From: David Woodhouse To: Andi Kleen Cc: Paul Turner , LKML , Linus Torvalds , Greg Kroah-Hartman , Tim Chen , Dave Hansen , tglx@linutronix.de, Kees Cook , Rik van Riel , Peter Zijlstra , Andy Lutomirski , Jiri Kosina , gnomes@lxorguk.ukuu.org.uk Subject: [PATCH v5 10/12] x86/retpoline: Add boot time option to disable retpoline Date: Sat, 6 Jan 2018 11:49:32 +0000 Message-Id: <1515239374-23361-11-git-send-email-dwmw@amazon.co.uk> X-Mailer: git-send-email 2.7.4 In-Reply-To: <1515239374-23361-1-git-send-email-dwmw@amazon.co.uk> References: <1515239374-23361-1-git-send-email-dwmw@amazon.co.uk> Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Return-Path: From: Andi Kleen Add a noretpoline option boot to disable retpoline and patch out the extra sequences. It cannot patch out the jumps to the thunk functions from code generated by the compiler, but those thunks turn into a single indirect branch now. Signed-off-by: Andi Kleen Signed-off-by: David Woodhouse --- Documentation/admin-guide/kernel-parameters.txt | 3 +++ arch/x86/kernel/cpu/intel.c | 11 +++++++++++ 2 files changed, 14 insertions(+) diff --git a/Documentation/admin-guide/kernel-parameters.txt b/Documentation/admin-guide/kernel-parameters.txt index 520fdec..f30f9b4 100644 --- a/Documentation/admin-guide/kernel-parameters.txt +++ b/Documentation/admin-guide/kernel-parameters.txt @@ -2596,6 +2596,9 @@ nohugeiomap [KNL,x86] Disable kernel huge I/O mappings. + noretpoline [X86] Disable the retpoline kernel indirect branch speculation + workarounds. System may allow data leaks with this option. + nosmt [KNL,S390] Disable symmetric multithreading (SMT). Equivalent to smt=1. diff --git a/arch/x86/kernel/cpu/intel.c b/arch/x86/kernel/cpu/intel.c index b720dac..35e123e 100644 --- a/arch/x86/kernel/cpu/intel.c +++ b/arch/x86/kernel/cpu/intel.c @@ -31,6 +31,17 @@ #include #endif +#ifdef RETPOLINE +static int __init noretpoline_setup(char *__unused) +{ + pr_info("Retpoline runtime disabled\n"); + setup_clear_cpu_cap(X86_FEATURE_RETPOLINE); + setup_clear_cpu_cap(X86_FEATURE_RETPOLINE_AMD); + return 1; +} +__setup("noretpoline", noretpoline_setup); +#endif + /* * Just in case our CPU detection goes bad, or you have a weird system, * allow a way to override the automatic disabling of MPX. -- 2.7.4