Re: [PATCH] x86: add hintable NOPs emulation

From: Kees Cook
Date: Wed Aug 20 2025 - 22:01:03 EST




On August 20, 2025 3:01:30 AM PDT, Marcos Del Sol Vives <marcos@xxxxxxxx> wrote:
>El 20/08/2025 a las 11:55, Borislav Petkov escribió:
>> On Wed, Aug 20, 2025 at 11:51:27AM +0200, Marcos Del Sol Vives wrote:
>>> I mean, they should know what they need to recompile if they want to, not
>>> just that their machine is having a bug triggered by some binary.
>>
>> And what's stopping you from writing a proper error message explaining that?
>>
>> And issuing that error message *exactly once* instead of flooding dmesg for no
>> good reason?
>
>Please define "once". Once per what? Per boot? Per executable? Per process?
>
>Once per boot would mean they'd need to reboot to see if any other executables
>are affected. Per executable AFAIK there are no facilities to do that, and the
>closest is per process which is what it's currently being done (again, like
>IOPL emulation which was already deemed okay a couple years ago and merged
>into the kernel)

If they want to see them again, just:

echo 1 >/sys/kernel/debug/clear_warn_once


--
Kees Cook