Re: tip/master falls off NOP cliff with KPTI under KVM

From: Woodhouse, David
Date: Wed Jan 10 2018 - 17:57:42 EST


On Thu, 2018-01-11 at 01:34 +0300, Alexey Dobriyan wrote:
>
> Bisection points to
>
> ÂÂÂÂÂÂÂÂf3433c1010c6af61c9897f0f0447f81b991feac1 is the first bad commit
> ÂÂÂÂÂÂÂÂcommit f3433c1010c6af61c9897f0f0447f81b991feac1
> ÂÂÂÂÂÂÂÂAuthor: David Woodhouse <dwmw@xxxxxxxxxxxx>
> ÂÂÂÂÂÂÂÂDate:ÂÂ Tue Jan 9 14:43:11 2018 +0000
>
> ÂÂÂÂÂÂÂÂÂÂÂ x86/retpoline/entry: Convert entry assembler indirect jumps

Thanks. We've fixed the underlying problem with the alternatives
mechanism, *and* changed the retpoline code not to actually rely on
said fix.

> RETPOLINE is enabled but build system is reporting that compiler doesn't
> support it (Gentoo 6.4.0 p1.1)
>
> Disabling CONFIG_RETPOLINE fixes boot.
>
> And build system reports that "system may be insecure" even if RETPOLINE
> is disabled.

That's odd. The warning is *inside* 'ifdef CONFIG_RETPOLINE'...

Attachment: smime.p7s
Description: S/MIME cryptographic signature