Re: [PATCH v2 11/35] x86/bugs: Restructure spectre_v1 mitigation

From: Borislav Petkov
Date: Thu Nov 14 2024 - 11:25:53 EST


On Thu, Nov 14, 2024 at 03:49:42PM +0000, Kaplan, David wrote:
> Actually looks like the existing code wasn't always consistent here. For
> srbds, ssb, and gds, it would still print a message about the system being
> vulnerable even if mitigations=off was passed. But for the others it would
> not print a message. I think I'm going to suppress the message for all
> cases, but if people feel it should be the other way, let me know.

Yeah, we probably should fix this in a pre-patch. I.e., if mitigations=off,
not issue any "Vulnerable" message because this is the "master switch", so to
speak.

Or do we want to issue a bunch of "Vulnerable" in dmesg?

I gravitate towards former because if user supplies mitigations=off, then she
probably knows what she's doing...?

Hmm.

--
Regards/Gruss,
Boris.

https://people.kernel.org/tglx/notes-about-netiquette