lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:	Thu, 18 Sep 2014 21:13:11 -0300
From:	Henrique de Moraes Holschuh <>
To:	"H. Peter Anvin" <>
Cc:	Chuck Ebbert <>,
	Andy Lutomirski <>,, Borislav Petkov <>
Subject: Re: x86, microcode: BUG: microcode update that changes x86_capability

On Thu, 18 Sep 2014, Henrique de Moraes Holschuh wrote:
> On Thu, 18 Sep 2014, H. Peter Anvin wrote:
> > We should, but this is also part of why we want the early ucode capability.
> Well, yes.  But that won't help the several stable and LTS distros with
> kernels without early ucode update support.

Here's a plan that might work, pending actually checking the libpthread TSX
code to make sure it keys on /proc/cpuinfo flags:

Add a cpu quirk, triggered by the Haswell cpuids, to force-disable hle on
the affected processors.

This will work around the x86_capability capability issue (which should
still be fixed, anyway), and it should also get userspace to stay away from
TSX, therefore also working around the worst issue (processes getting

This will disable the "user may ask the BIOS to keep TSX enabled"
anti-feature, though.  This drawback can be avoided, but only if a future
microcode update won't re-disable hle when the BIOS enabled it.  For now, I
suggest that we decree that "hle is toast" for the current Haswells and add
back ways to enable it for testing when we know more about it.

  "One disk to rule them all, One disk to find them. One disk to bring
  them all and in the darkness grind them. In the Land of Redmond
  where the shadows lie." -- The Silicon Valley Tarot
  Henrique Holschuh
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to
More majordomo info at
Please read the FAQ at

Powered by blists - more mailing lists