[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PULL 5/5] docs: add note about stibp CPU feature for spect
From: |
Eduardo Habkost |
Subject: |
[Qemu-devel] [PULL 5/5] docs: add note about stibp CPU feature for spectre v2 |
Date: |
Thu, 21 Mar 2019 16:36:00 -0300 |
From: Daniel P. Berrangé <address@hidden>
While the stibp CPU feature is not commonly used by guest OS for spectre
mitigation due to its performance impact, it is none the less best
practice to expose it to all guest OS. This allows the guest OS to
decide whether to make use or it.
Signed-off-by: Daniel P. Berrangé <address@hidden>
Message-Id: <address@hidden>
Signed-off-by: Eduardo Habkost <address@hidden>
---
docs/qemu-cpu-models.texi | 22 ++++++++++++++++++++++
1 file changed, 22 insertions(+)
diff --git a/docs/qemu-cpu-models.texi b/docs/qemu-cpu-models.texi
index 0ce528806d..23c11dc86f 100644
--- a/docs/qemu-cpu-models.texi
+++ b/docs/qemu-cpu-models.texi
@@ -168,6 +168,17 @@ Requires the host CPU microcode to support this feature
before it
can be used for guest CPUs.
address@hidden @code{stibp}
+
+Required to enable stronger Spectre v2 (CVE-2017-5715) fixes in some
+operating systems.
+
+Must be explicitly turned on for all Intel CPU models.
+
+Requires the host CPU microcode to support this feature before it
+can be used for guest CPUs.
+
+
@item @code{ssbd}
Required to enable the CVE-2018-3639 fix
@@ -258,6 +269,17 @@ Requires the host CPU microcode to support this feature
before it
can be used for guest CPUs.
address@hidden @code{stibp}
+
+Required to enable stronger Spectre v2 (CVE-2017-5715) fixes in some
+operating systems.
+
+Must be explicitly turned on for all AMD CPU models.
+
+Requires the host CPU microcode to support this feature before it
+can be used for guest CPUs.
+
+
@item @code{virt-ssbd}
Required to enable the CVE-2018-3639 fix
--
2.18.0.rc1.1.g3f1ff2140
- [Qemu-devel] [PULL 0/5] x86 queue for -rc1, Eduardo Habkost, 2019/03/21
- [Qemu-devel] [PULL 1/5] i386: kvm: Disable arch_capabilities if MSR can't be set, Eduardo Habkost, 2019/03/21
- [Qemu-devel] [PULL 2/5] i386: Make arch_capabilities migratable, Eduardo Habkost, 2019/03/21
- [Qemu-devel] [PULL 3/5] i386: Disable OSPKE on CPU model definitions, Eduardo Habkost, 2019/03/21
- [Qemu-devel] [PULL 4/5] docs: clarify that spec-ctrl is only needed for Spectre v2, Eduardo Habkost, 2019/03/21
- [Qemu-devel] [PULL 5/5] docs: add note about stibp CPU feature for spectre v2,
Eduardo Habkost <=
- Re: [Qemu-devel] [PULL 0/5] x86 queue for -rc1, Peter Maydell, 2019/03/22