RE: [PATCH] retpoline/module: Taint kernel for missing retpoline in module
From: Van De Ven, Arjan
Date: Mon Jan 15 2018 - 07:53:11 EST
> > For modules it is checked at compile time, however it cannot
> > check assembler or other non compiled objects used in the module link.
>
> It is not unlikely that most of a module's code is released as a
> binary 'blob', with only the part that needs to match the kernel ABI
> compiled on the target system.
> (This allows a single binary driver be loaded onto different Linux
> kernel versions.)
binary what? ;-)
retpoline (or lack thereof) is part of the kernel ABI at this point....
now clearly security does not matter for this (not unlikely that you have more severe issues) but warning of a mismatch is not a bad thing so that you at least know.