Re: [PATCH v5 4/5] KVM: VMX: Allow direct access to MSR_IA32_SPEC_CTRL

From: Andy Lutomirski
Date: Wed Jan 31 2018 - 17:54:02 EST




> On Jan 31, 2018, at 2:06 PM, Jim Mattson <jmattson@xxxxxxxxxx> wrote:
>
>> On Wed, Jan 31, 2018 at 1:59 PM, David Woodhouse <dwmw2@xxxxxxxxxxxxx> wrote:
>> I'm actually working on IBRS_ALL at the moment.
>>
>> I was tempted to *not* let the guests turn it off. Expose SPEC_CTRL but
>> just make it a no-op.
>
> Maybe we could convince Intel to add a LOCK bit to IA32_SPEC_CTRL like
> the one in IA32_FEATURE_CONTROL.

Please no. Some BIOS vendor is going to lock it to zero to win some silly benchmark.