[Discuss] Help needed in trying to figure out how the various Meltdown and Spectre mitigations fit together
Alan W. Irwin
irwin at beluga.phys.uvic.ca
Wed Jan 17 12:31:30 PST 2018
Hi guys:
For the new hardware buy I am considering (referred to in another
thread), I have decided to go with an AMD Ryzen 7 1700 8-core, 64GB
DDR4 hardware package, but I am still deciding about who I get to
build this beast, and when I actually go ahead with this. To help
decide that timing, I need some help trying to figure out how the
various Meltdown and Spectre mitigations all fit together.
According to
<https://www.phoronix.com/scan.php?page=news_item&px=AMD-Is-Vulnerable-Variant-2>
and other sources AMD still feels their chips are not vulnerable to
the Meltdown issue that plagues Intel chips, but AMD chips are apparently
vulnerable to Spectre (just like Intel chips). Apparently mitigation of the AMD Spectre
chip issue requires firmware patches (just coming out for AMD), propagation
of those to motherboard manufacturers, and eventually BIOS reflashing
by computer buyers, but Linux users will also require software updates. For
example, from the above article we have this statement:
"The Retpoline Linux patches continue to be worked on but have yet to
be mainlined. It's looking like Retpoline will likely land for Linux
4.16. There are also needed LLVM / GCC patches too, which have yet to
land but hopefully will still make it for the upcoming GCC 8.0
release."
What I don't understand is if the firmware patches are a fix for the
fundamental AMD chip design flaw (i.e., that speculative execution can
occur without checking at the right time that the programme is allowed
access to that particular memory being accessed by the speculative
execution) why are Linux kernel and especially gcc changes required in
addition? Does this mean that the AMD firmware patches are just
workarounds for the fundamental issue and therefore need additional
help from OS and compiler?
Here are some further related questions concerning how these firmware,
kernel, and compiler changes all fit together:
* Will the planned Linux kernel and gcc changes completely protect me (albeit
with a modest decrease in speed) even if I
don't get the BIOS upgrade?
* Assuming all of AMD, the motherboard manufacturer, and my computer
builder are competent is there any chance that the actual reflashing
process done by the computer builder to upgrade the BIOS (say a year
from now) could turn my nice new computer into a brick?
* If so, would it be a better idea to put off the computer buy for a
year or so until all the remaining firmware, Linux kernel, and gcc
updates are sorted out?
Alan
__________________________
Alan W. Irwin
Astronomical research affiliation with Department of Physics and Astronomy,
University of Victoria (astrowww.phys.uvic.ca).
Programming affiliations with the FreeEOS equation-of-state
implementation for stellar interiors (freeeos.sf.net); the Time
Ephemerides project (timeephem.sf.net); PLplot scientific plotting
software package (plplot.sf.net); the libLASi project
(unifont.org/lasi); the Loads of Linux Links project (loll.sf.net);
and the Linux Brochure Project (lbproject.sf.net).
__________________________
Linux-powered Science
__________________________
More information about the Discuss
mailing list