From owner-freebsd-stable@freebsd.org Sun Feb 18 16:50:24 2018 Return-Path: Delivered-To: freebsd-stable@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 4EB0CF17961 for ; Sun, 18 Feb 2018 16:50:24 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: from mail-wm0-x233.google.com (mail-wm0-x233.google.com [IPv6:2a00:1450:400c:c09::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id C4E7B7F57A for ; Sun, 18 Feb 2018 16:50:23 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: by mail-wm0-x233.google.com with SMTP id t74so11144004wme.3 for ; Sun, 18 Feb 2018 08:50:23 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardenedbsd-org.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=tqw+heApmxLfVV1/ZLxoi40iuXrN+4LR012X/bWAg8E=; b=OEW7ye38YjjGGkv2eyJOTNxfg6Zwsacl+Z3jHfcAi+3pUvoSPzPaLWbpo1s2OwRuPk Tc6zOVitcXZew/Tp935M9RBPwQi7OLCo3wjbaXdyBX0GkKVYqf+Hmg/cxAN3JyWypmJF CCm5jY+LIGtC/d14rgX6Z4G51BA1TSlicA86gPErd49cUCSc/qsIr3AKmH6E8lQc9FIH QJrHnvYIGzNaaxY4yNG152mC1W9SikkOb8VBvniJeunf1i2tywzaY2fMoC3IEj2DenK9 tBNat9QqxJ60MryJ6erx6/fKmofCf3bYOBLN/DsICBQg5lKGedH1KMaz4v9AXwTNVjzm wPoQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=tqw+heApmxLfVV1/ZLxoi40iuXrN+4LR012X/bWAg8E=; b=Dc6YDXDtaV3/BKOWHjQbB2yBHkjOw411eV3dB7JPtFdSyogjC4DxHgzQZdQvVn6lN/ CZFpQ1kVaKgJzMKC3z66rSvurHAiJoSOXy/K+jWbPhK4fkxWXfVODZ20I4zV1dySXUvo 7ybH+IK84bRDC0sorSeA4b/cROXwPTcc/lzIEumjjN6B9Lz5wUZyzAY6BqL0M+nCgSmD dEVjXNIAUYeJieSIE+hlhFiwo1naPqbMFCQS2geLc280/wYdZkBjdX9F1I1/1TgDv/FN omplrnbWSSMzbKDqe3uHveYqws+FXpysVTC1hIst3e1GQYb3+G51vbMDQBp7rp2X515a 3tmg== X-Gm-Message-State: APf1xPB+1bl1n4CgBOk9NojMvkyr/HzEQ1QWlobtGGsXV5qv65MdKys/ 6Fitb+u+LU9bCwSWcv9YCC4DY/Gy0EM= X-Google-Smtp-Source: AH8x2245/QTa+yCevCbHRZa7eWl2qOupkdWIofs5H021J5vVq7X5qhPNF5EnCwC2oDh4MG3qiUtV1A== X-Received: by 10.28.55.81 with SMTP id e78mr10106084wma.50.1518972621920; Sun, 18 Feb 2018 08:50:21 -0800 (PST) Received: from mutt-hbsd ([192.42.116.13]) by smtp.gmail.com with ESMTPSA id w14sm16565905wmf.32.2018.02.18.08.50.15 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Sun, 18 Feb 2018 08:50:20 -0800 (PST) Date: Sun, 18 Feb 2018 11:50:01 -0500 From: Shawn Webb To: David Marec Cc: freebsd-stable@freebsd.org Subject: Re: stable/11 r329462 - Meltdown/Spectre MFC questions Message-ID: <20180218165001.whbmonks7fq27mgq@mutt-hbsd> References: <20180217194726.GA79666@icarus.home.lan> <58099107-bc04-8ad9-3909-16bf5297dd2b@davenulle.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="lqdufu4v222lgprr" Content-Disposition: inline In-Reply-To: <58099107-bc04-8ad9-3909-16bf5297dd2b@davenulle.org> X-Operating-System: FreeBSD mutt-hbsd 12.0-CURRENT FreeBSD 12.0-CURRENT X-PGP-Key: http://pgp.mit.edu/pks/lookup?op=vindex&search=0x6A84658F52456EEE User-Agent: NeoMutt/20171215 X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 18 Feb 2018 16:50:24 -0000 --lqdufu4v222lgprr Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sun, Feb 18, 2018 at 05:04:55PM +0100, David Marec wrote: > On 17.02.2018 20:47, Jeremy Chadwick wrote: > > hw.ibrs_disable > > - Description: Disable Indirect Branch Restricted Speculation > > - Loader tunable and sysctl tunable (read-write) > > - Integer > > - Default value: unsure. Variable declaration has 1 but > > SYSCTL_PROC() macro has 0. > >=20 >=20 >=20 > Strange thing is that tweaking `hw.ibrs_disable` has no effect on > `hw.ibrs_active` on my side. Did you install the latest Intel microcode update? Thanks, --=20 Shawn Webb Cofounder and Security Engineer HardenedBSD Tor-ified Signal: +1 443-546-8752 GPG Key ID: 0x6A84658F52456EEE GPG Key Fingerprint: 2ABA B6BD EF6A F486 BE89 3D9E 6A84 658F 5245 6EEE --lqdufu4v222lgprr Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEKrq2ve9q9Ia+iT2eaoRlj1JFbu4FAlqJrrQACgkQaoRlj1JF bu721xAAvuGIXR88q68u0gQRERDgCiUQoKO210+uTdu9JDfPSELD3O4w9eD8DPhm UdX3blBT8cz56f/kVoRhV/og8m4sp2RqJL+qBru2gg8APryugjiAvRFhlG0JVfnf 89gxEAx8aUmNbNW3c5U++kJZTMjE8TKUTZahxc1KaBsujFglQP+r37aCz7wvd+k6 A9dgmG/BqG4bs1VlA9iXt0MhFhq3ttt2KcUKR61DEtdaRV4QZMgHIKcljloAvaCv jKehvZ5gPtd+U4RaB8Yae1zmiHV3EJY2YIKZ0g141RyPpIbq6FXbiluGYgFBpCS6 MWS8wN/ip+VCx3R8Oqz9mp0Q5kgwfVwy1C+Gypkht8iuez33kwyJQv32BwwE5RVh 50Qvn2iugRzkxbj7p0P+hcc1VxLaJOukIPHd4OEwGhXS9vG3A5xGCkf8W2m6HkmL +CtQhroD5Rm1t5qtlB4fW0PatLLL57liMKg1Qk8IZDDYAuYQOKsVbkuWVBJRcVGP 8MdmDQ3lu6BzRg3jShI1UpqICLtZBtop0vsbERtMcmoE4idp4XYnqMAhy1p0+D/p MtUXXCAl6iW399/I+XQAcRhBC24XAsaok8VoDBp13iEzjJu9jPuBKSX/U0q4Tzj8 bmndISWEZHPmR9tMT7hsoj63eUZVVFM7/Q162XpJtWeZCIm/c50= =NV5L -----END PGP SIGNATURE----- --lqdufu4v222lgprr--