mirror of
https://github.com/speed47/spectre-meltdown-checker.git
synced 2026-07-22 21:11:20 +02:00
Compare commits
3 Commits
737cfe4a5f
...
test
| Author | SHA1 | Date | |
|---|---|---|---|
| 5bbffaf053 | |||
| 23ea5427b5 | |||
| cc159fe7fd |
+1
-1
@@ -186,7 +186,7 @@ if [ $ret = $READ_CPUID_RET_OK ]; then
|
|||||||
cap_ssbd='Intel SSBD'
|
cap_ssbd='Intel SSBD'
|
||||||
elif [ $ret = $READ_CPUID_RET_ERR ] && [ "$g_mode" = live ]; then
|
elif [ $ret = $READ_CPUID_RET_ERR ] && [ "$g_mode" = live ]; then
|
||||||
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
||||||
if grep ^flags "$g_procfs/cpuinfo" | grep -qw ssbd; then
|
if cpuinfo_has_flag ssbd; then
|
||||||
cap_ssbd='Intel SSBD (cpuinfo)'
|
cap_ssbd='Intel SSBD (cpuinfo)'
|
||||||
ret=$READ_CPUID_RET_OK
|
ret=$READ_CPUID_RET_OK
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -195,6 +195,14 @@ is_arch_cap_mmio_immune() {
|
|||||||
[ "$cap_sbdr_ssdp_no" = 1 ] && [ "$cap_fbsdp_no" = 1 ] && [ "$cap_psdp_no" = 1 ]
|
[ "$cap_sbdr_ssdp_no" = 1 ] && [ "$cap_fbsdp_no" = 1 ] && [ "$cap_psdp_no" = 1 ]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Whether the MMIO arch-cap immunity bits are undetermined because the
|
||||||
|
# IA32_ARCH_CAPABILITIES MSR couldn't be read (msr module unavailable or kernel
|
||||||
|
# lockdown).
|
||||||
|
# Returns: 0 if undetermined, 1 otherwise
|
||||||
|
is_arch_cap_mmio_undetermined() {
|
||||||
|
[ "$cap_sbdr_ssdp_no" = -1 ] || [ "$cap_fbsdp_no" = -1 ] || [ "$cap_psdp_no" = -1 ]
|
||||||
|
}
|
||||||
|
|
||||||
# Check whether the CPU is known to be unaffected by MMIO Stale Data (CVE-2022-21123/21125/21166)
|
# Check whether the CPU is known to be unaffected by MMIO Stale Data (CVE-2022-21123/21125/21166)
|
||||||
# Matches the kernel's NO_MMIO whitelist plus arch_cap_mmio_immune().
|
# Matches the kernel's NO_MMIO whitelist plus arch_cap_mmio_immune().
|
||||||
# Model inventory and kernel-commit history are documented in check_mmio_linux().
|
# Model inventory and kernel-commit history are documented in check_mmio_linux().
|
||||||
|
|||||||
@@ -9,7 +9,7 @@ dmesg_grep() {
|
|||||||
# dmesg truncated
|
# dmesg truncated
|
||||||
return 2
|
return 2
|
||||||
fi
|
fi
|
||||||
ret_dmesg_grep_grepped=$(dmesg 2>/dev/null | grep -E "$1" | head -n1)
|
ret_dmesg_grep_grepped=$(dmesg 2>/dev/null | grep -m 1 -E "$1")
|
||||||
# not found:
|
# not found:
|
||||||
[ -z "$ret_dmesg_grep_grepped" ] && return 1
|
[ -z "$ret_dmesg_grep_grepped" ] && return 1
|
||||||
# found, output is in $ret_dmesg_grep_grepped
|
# found, output is in $ret_dmesg_grep_grepped
|
||||||
@@ -22,3 +22,9 @@ is_coreos() {
|
|||||||
command -v coreos-install >/dev/null 2>&1 && command -v toolbox >/dev/null 2>&1 && return 0
|
command -v coreos-install >/dev/null 2>&1 && command -v toolbox >/dev/null 2>&1 && return 0
|
||||||
return 1
|
return 1
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Check whether /proc/cpuinfo has $1 in the flags line
|
||||||
|
# Returns: 0 if flag found, 1 otherwise
|
||||||
|
cpuinfo_has_flag() {
|
||||||
|
grep -Eq '^flags\b.+\b'"$1"'\b' "$g_procfs/cpuinfo" 2>/dev/null
|
||||||
|
}
|
||||||
|
|||||||
@@ -20,8 +20,8 @@ parse_cpu_details() {
|
|||||||
cap_avx2=0
|
cap_avx2=0
|
||||||
cap_avx512=0
|
cap_avx512=0
|
||||||
if [ -e "$g_procfs/cpuinfo" ]; then
|
if [ -e "$g_procfs/cpuinfo" ]; then
|
||||||
if grep -qw avx2 "$g_procfs/cpuinfo" 2>/dev/null; then cap_avx2=1; fi
|
if cpuinfo_has_flag avx2; then cap_avx2=1; fi
|
||||||
if grep -qw avx512 "$g_procfs/cpuinfo" 2>/dev/null; then cap_avx512=1; fi
|
if cpuinfo_has_flag avx512; then cap_avx512=1; fi
|
||||||
cpu_vendor=$(grep '^vendor_id' "$g_procfs/cpuinfo" | awk '{print $3}' | head -n1)
|
cpu_vendor=$(grep '^vendor_id' "$g_procfs/cpuinfo" | awk '{print $3}' | head -n1)
|
||||||
cpu_friendly_name=$(grep '^model name' "$g_procfs/cpuinfo" | cut -d: -f2- | head -n1 | sed -e 's/^ *//')
|
cpu_friendly_name=$(grep '^model name' "$g_procfs/cpuinfo" | cut -d: -f2- | head -n1 | sed -e 's/^ *//')
|
||||||
# ARM-style cpuinfo: parse per-core implementer/part/arch/variant/revision lists
|
# ARM-style cpuinfo: parse per-core implementer/part/arch/variant/revision lists
|
||||||
|
|||||||
@@ -513,7 +513,7 @@ check_cpu() {
|
|||||||
fi
|
fi
|
||||||
if [ -z "$cap_ibrs" ] && [ $ret = $READ_CPUID_RET_ERR ] && has_runtime; then
|
if [ -z "$cap_ibrs" ] && [ $ret = $READ_CPUID_RET_ERR ] && has_runtime; then
|
||||||
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
||||||
if grep ^flags "$g_procfs/cpuinfo" | grep -qw ibrs; then
|
if cpuinfo_has_flag ibrs; then
|
||||||
cap_ibrs='IBRS (cpuinfo)'
|
cap_ibrs='IBRS (cpuinfo)'
|
||||||
cap_spec_ctrl=1
|
cap_spec_ctrl=1
|
||||||
pstatus green YES "ibrs flag in $g_procfs/cpuinfo"
|
pstatus green YES "ibrs flag in $g_procfs/cpuinfo"
|
||||||
@@ -588,7 +588,7 @@ check_cpu() {
|
|||||||
if [ $ret = $READ_CPUID_RET_OK ]; then
|
if [ $ret = $READ_CPUID_RET_OK ]; then
|
||||||
cap_ibpb='IBPB_SUPPORT'
|
cap_ibpb='IBPB_SUPPORT'
|
||||||
pstatus green YES "IBPB_SUPPORT feature bit"
|
pstatus green YES "IBPB_SUPPORT feature bit"
|
||||||
elif [ $ret = $READ_CPUID_RET_ERR ] && has_runtime && grep ^flags "$g_procfs/cpuinfo" | grep -qw ibpb; then
|
elif [ $ret = $READ_CPUID_RET_ERR ] && has_runtime && cpuinfo_has_flag ibpb; then
|
||||||
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
||||||
cap_ibpb='IBPB (cpuinfo)'
|
cap_ibpb='IBPB (cpuinfo)'
|
||||||
pstatus green YES "ibpb flag in $g_procfs/cpuinfo"
|
pstatus green YES "ibpb flag in $g_procfs/cpuinfo"
|
||||||
@@ -661,7 +661,7 @@ check_cpu() {
|
|||||||
fi
|
fi
|
||||||
if [ -z "$cap_stibp" ] && [ $ret = $READ_CPUID_RET_ERR ] && has_runtime; then
|
if [ -z "$cap_stibp" ] && [ $ret = $READ_CPUID_RET_ERR ] && has_runtime; then
|
||||||
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
||||||
if grep ^flags "$g_procfs/cpuinfo" | grep -qw stibp; then
|
if cpuinfo_has_flag stibp; then
|
||||||
cap_stibp='STIBP (cpuinfo)'
|
cap_stibp='STIBP (cpuinfo)'
|
||||||
pstatus green YES "stibp flag in $g_procfs/cpuinfo"
|
pstatus green YES "stibp flag in $g_procfs/cpuinfo"
|
||||||
ret=$READ_CPUID_RET_OK
|
ret=$READ_CPUID_RET_OK
|
||||||
@@ -733,9 +733,9 @@ check_cpu() {
|
|||||||
|
|
||||||
if [ -z "$cap_ssbd" ] && [ "$ret24" = $READ_CPUID_RET_ERR ] && [ "$ret25" = $READ_CPUID_RET_ERR ] && has_runtime; then
|
if [ -z "$cap_ssbd" ] && [ "$ret24" = $READ_CPUID_RET_ERR ] && [ "$ret25" = $READ_CPUID_RET_ERR ] && has_runtime; then
|
||||||
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
||||||
if grep ^flags "$g_procfs/cpuinfo" | grep -qw ssbd; then
|
if cpuinfo_has_flag ssbd; then
|
||||||
cap_ssbd='SSBD (cpuinfo)'
|
cap_ssbd='SSBD (cpuinfo)'
|
||||||
elif grep ^flags "$g_procfs/cpuinfo" | grep -qw virt_ssbd; then
|
elif cpuinfo_has_flag virt_ssbd; then
|
||||||
cap_ssbd='SSBD in VIRT_SPEC_CTRL (cpuinfo)'
|
cap_ssbd='SSBD in VIRT_SPEC_CTRL (cpuinfo)'
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
@@ -795,7 +795,7 @@ check_cpu() {
|
|||||||
if [ $ret = $READ_CPUID_RET_OK ]; then
|
if [ $ret = $READ_CPUID_RET_OK ]; then
|
||||||
pstatus green YES "L1D flush feature bit"
|
pstatus green YES "L1D flush feature bit"
|
||||||
cap_l1df=1
|
cap_l1df=1
|
||||||
elif [ $ret = $READ_CPUID_RET_ERR ] && has_runtime && grep ^flags "$g_procfs/cpuinfo" | grep -qw flush_l1d; then
|
elif [ $ret = $READ_CPUID_RET_ERR ] && has_runtime && cpuinfo_has_flag flush_l1d; then
|
||||||
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
||||||
pstatus green YES "flush_l1d flag in $g_procfs/cpuinfo"
|
pstatus green YES "flush_l1d flag in $g_procfs/cpuinfo"
|
||||||
cap_l1df=1
|
cap_l1df=1
|
||||||
@@ -815,7 +815,7 @@ check_cpu() {
|
|||||||
if [ $ret = $READ_CPUID_RET_OK ]; then
|
if [ $ret = $READ_CPUID_RET_OK ]; then
|
||||||
cap_md_clear=1
|
cap_md_clear=1
|
||||||
pstatus green YES "MD_CLEAR feature bit"
|
pstatus green YES "MD_CLEAR feature bit"
|
||||||
elif [ $ret = $READ_CPUID_RET_ERR ] && has_runtime && grep ^flags "$g_procfs/cpuinfo" | grep -qw md_clear; then
|
elif [ $ret = $READ_CPUID_RET_ERR ] && has_runtime && cpuinfo_has_flag md_clear; then
|
||||||
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
||||||
cap_md_clear=1
|
cap_md_clear=1
|
||||||
pstatus green YES "md_clear flag in $g_procfs/cpuinfo"
|
pstatus green YES "md_clear flag in $g_procfs/cpuinfo"
|
||||||
@@ -885,7 +885,7 @@ check_cpu() {
|
|||||||
if [ $ret = $READ_CPUID_RET_OK ]; then
|
if [ $ret = $READ_CPUID_RET_OK ]; then
|
||||||
pstatus green YES
|
pstatus green YES
|
||||||
cap_arch_capabilities=1
|
cap_arch_capabilities=1
|
||||||
elif [ $ret = $READ_CPUID_RET_ERR ] && has_runtime && grep ^flags "$g_procfs/cpuinfo" | grep -qw arch_capabilities; then
|
elif [ $ret = $READ_CPUID_RET_ERR ] && has_runtime && cpuinfo_has_flag arch_capabilities; then
|
||||||
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
# CPUID device unavailable (e.g. in a VM): fall back to /proc/cpuinfo
|
||||||
pstatus green YES "arch_capabilities flag in $g_procfs/cpuinfo"
|
pstatus green YES "arch_capabilities flag in $g_procfs/cpuinfo"
|
||||||
cap_arch_capabilities=1
|
cap_arch_capabilities=1
|
||||||
@@ -987,8 +987,33 @@ check_cpu() {
|
|||||||
pstatus yellow NO
|
pstatus yellow NO
|
||||||
fi
|
fi
|
||||||
elif [ $ret = $READ_MSR_RET_KO ]; then
|
elif [ $ret = $READ_MSR_RET_KO ]; then
|
||||||
|
# the MSR access faulted: the register is genuinely absent, so the
|
||||||
|
# pre-seeded 0 ("not advertised") values are correct.
|
||||||
pstatus yellow NO
|
pstatus yellow NO
|
||||||
else
|
else
|
||||||
|
# RET_ERR (no msr module) or RET_LOCKDOWN (MSR reads restricted):
|
||||||
|
# CPUID told us the MSR exists but we couldn't read it, so its bits
|
||||||
|
# are undetermined, not 0. Leaving them at 0 would falsely claim the
|
||||||
|
# CPU "explicitly indicates not immune".
|
||||||
|
# Reset every arch-cap-derived value to -1 (UNKNOWN) instead.
|
||||||
|
cap_rdcl_no=-1
|
||||||
|
cap_taa_no=-1
|
||||||
|
cap_mds_no=-1
|
||||||
|
cap_ibrs_all=-1
|
||||||
|
cap_rsba=-1
|
||||||
|
cap_l1dflush_no=-1
|
||||||
|
cap_ssb_no=-1
|
||||||
|
cap_pschange_msc_no=-1
|
||||||
|
cap_tsx_ctrl_msr=-1
|
||||||
|
cap_gds_ctrl=-1
|
||||||
|
cap_gds_no=-1
|
||||||
|
cap_rfds_no=-1
|
||||||
|
cap_rfds_clear=-1
|
||||||
|
cap_its_no=-1
|
||||||
|
cap_sbdr_ssdp_no=-1
|
||||||
|
cap_fbsdp_no=-1
|
||||||
|
cap_psdp_no=-1
|
||||||
|
cap_fb_clear=-1
|
||||||
pstatus yellow UNKNOWN "$ret_read_msr_msg"
|
pstatus yellow UNKNOWN "$ret_read_msr_msg"
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -138,7 +138,7 @@ check_mds_linux() {
|
|||||||
if is_x86_kernel; then
|
if is_x86_kernel; then
|
||||||
pr_info_nol "* Kernel supports using MD_CLEAR mitigation: "
|
pr_info_nol "* Kernel supports using MD_CLEAR mitigation: "
|
||||||
kernel_md_clear_can_tell=1
|
kernel_md_clear_can_tell=1
|
||||||
if [ "$g_mode" = live ] && grep ^flags "$g_procfs/cpuinfo" | grep -qw md_clear; then
|
if [ "$g_mode" = live ] && cpuinfo_has_flag md_clear; then
|
||||||
kernel_md_clear="md_clear found in $g_procfs/cpuinfo"
|
kernel_md_clear="md_clear found in $g_procfs/cpuinfo"
|
||||||
pstatus green YES "$kernel_md_clear"
|
pstatus green YES "$kernel_md_clear"
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -6,15 +6,22 @@ check_mmio_bsd() {
|
|||||||
# the only partial defense available, and without OS-level VERW invocation it
|
# the only partial defense available, and without OS-level VERW invocation it
|
||||||
# cannot close the vulnerability.
|
# cannot close the vulnerability.
|
||||||
local unk
|
local unk
|
||||||
unk="your CPU's MMIO Stale Data status is unknown (Intel never officially assessed this CPU, its servicing period has ended)"
|
|
||||||
if ! is_cpu_affected "$cve"; then
|
if ! is_cpu_affected "$cve"; then
|
||||||
pvulnstatus "$cve" OK "your CPU vendor reported your CPU model as not affected"
|
pvulnstatus "$cve" OK "your CPU vendor reported your CPU model as not affected"
|
||||||
elif is_cpu_mmio_unknown; then
|
elif is_cpu_mmio_unknown; then
|
||||||
if [ "$opt_paranoid" = 1 ]; then
|
if is_arch_cap_mmio_undetermined; then
|
||||||
pvulnstatus "$cve" VULN "$unk, and no BSD mitigation exists"
|
# We only landed in the "unknown" bucket because the IA32_ARCH_CAPABILITIES
|
||||||
explain "There is no known mitigation for this CPU model. Even with up-to-date microcode, BSD kernels do not invoke VERW for MMIO Stale Data clearing. Only a hardware replacement can fully address this."
|
# MSR couldn't be read: the CPU might actually advertise MMIO immunity.
|
||||||
|
unk="your CPU's MMIO Stale Data status could not be determined: the IA32_ARCH_CAPABILITIES MSR (0x10a) couldn't be read"
|
||||||
|
pvulnstatus "$cve" UNK "$unk; load the cpuctl module and/or re-run as root to get a definitive answer"
|
||||||
else
|
else
|
||||||
pvulnstatus "$cve" UNK "$unk; no BSD mitigation exists in any case"
|
unk="your CPU's MMIO Stale Data status is unknown (Intel never officially assessed this CPU, its servicing period has ended)"
|
||||||
|
if [ "$opt_paranoid" = 1 ]; then
|
||||||
|
pvulnstatus "$cve" VULN "$unk, and no BSD mitigation exists"
|
||||||
|
explain "There is no known mitigation for this CPU model. Even with up-to-date microcode, BSD kernels do not invoke VERW for MMIO Stale Data clearing. Only a hardware replacement can fully address this."
|
||||||
|
else
|
||||||
|
pvulnstatus "$cve" UNK "$unk; no BSD mitigation exists in any case"
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
pvulnstatus "$cve" VULN "your CPU is affected and no BSD has implemented an MMIO Stale Data mitigation"
|
pvulnstatus "$cve" VULN "your CPU is affected and no BSD has implemented an MMIO Stale Data mitigation"
|
||||||
@@ -24,7 +31,7 @@ check_mmio_bsd() {
|
|||||||
|
|
||||||
# MMIO Stale Data (Processor MMIO Stale Data Vulnerabilities) - Linux mitigation check
|
# MMIO Stale Data (Processor MMIO Stale Data Vulnerabilities) - Linux mitigation check
|
||||||
check_mmio_linux() {
|
check_mmio_linux() {
|
||||||
local status sys_interface_available msg kernel_mmio kernel_mmio_can_tell mmio_mitigated mmio_smt_mitigated mystatus mymsg unk
|
local status sys_interface_available msg kernel_mmio kernel_mmio_can_tell kernel_mmio_unknown_aware mmio_mitigated mmio_smt_mitigated mystatus mymsg unk
|
||||||
status=UNK
|
status=UNK
|
||||||
sys_interface_available=0
|
sys_interface_available=0
|
||||||
msg=''
|
msg=''
|
||||||
@@ -166,6 +173,11 @@ check_mmio_linux() {
|
|||||||
# MMIO Stale Data is Intel-only; skip x86-specific kernel/MSR checks on non-x86 kernels
|
# MMIO Stale Data is Intel-only; skip x86-specific kernel/MSR checks on non-x86 kernels
|
||||||
kernel_mmio=''
|
kernel_mmio=''
|
||||||
kernel_mmio_can_tell=0
|
kernel_mmio_can_tell=0
|
||||||
|
# Whether this kernel implements the X86_BUG_MMIO_UNKNOWN distinction, i.e. can
|
||||||
|
# report "Unknown: No mitigations" for CPUs Intel never assessed. Only such kernels
|
||||||
|
# emit a *trustworthy* "Not affected": they would have said "Unknown" instead if the
|
||||||
|
# CPU were in the unknown bucket. Detected by the presence of the literal sysfs string in the kernel image.
|
||||||
|
kernel_mmio_unknown_aware=0
|
||||||
if is_x86_kernel; then
|
if is_x86_kernel; then
|
||||||
pr_info_nol "* Kernel supports MMIO Stale Data mitigation: "
|
pr_info_nol "* Kernel supports MMIO Stale Data mitigation: "
|
||||||
kernel_mmio_can_tell=1
|
kernel_mmio_can_tell=1
|
||||||
@@ -176,6 +188,10 @@ check_mmio_linux() {
|
|||||||
kernel_mmio='found MMIO Stale Data mitigation evidence in kernel image'
|
kernel_mmio='found MMIO Stale Data mitigation evidence in kernel image'
|
||||||
pstatus green YES "$kernel_mmio"
|
pstatus green YES "$kernel_mmio"
|
||||||
fi
|
fi
|
||||||
|
if [ -z "$g_kernel_err" ] && grep -qF 'Unknown: No mitigations' "$g_kernel" 2>/dev/null; then
|
||||||
|
pr_debug "mmio: kernel image knows the 'Unknown: No mitigations' state (X86_BUG_MMIO_UNKNOWN-aware)"
|
||||||
|
kernel_mmio_unknown_aware=1
|
||||||
|
fi
|
||||||
if [ -z "$kernel_mmio" ] && [ -n "$opt_config" ] && grep -q '^CONFIG_MITIGATION_MMIO_STALE_DATA=y' "$opt_config"; then
|
if [ -z "$kernel_mmio" ] && [ -n "$opt_config" ] && grep -q '^CONFIG_MITIGATION_MMIO_STALE_DATA=y' "$opt_config"; then
|
||||||
kernel_mmio='found MMIO Stale Data mitigation config option enabled'
|
kernel_mmio='found MMIO Stale Data mitigation config option enabled'
|
||||||
pstatus green YES "$kernel_mmio"
|
pstatus green YES "$kernel_mmio"
|
||||||
@@ -241,12 +257,32 @@ check_mmio_linux() {
|
|||||||
# Bypass the normal sysfs reconciliation: sysfs reports "Unknown: No mitigations"
|
# Bypass the normal sysfs reconciliation: sysfs reports "Unknown: No mitigations"
|
||||||
# only on v6.0-v6.15. On earlier and on v6.16+ kernels it wrongly says "Not affected"
|
# only on v6.0-v6.15. On earlier and on v6.16+ kernels it wrongly says "Not affected"
|
||||||
# for these CPUs (which predate FB_CLEAR microcode and Intel's affected-processor list).
|
# for these CPUs (which predate FB_CLEAR microcode and Intel's affected-processor list).
|
||||||
unk="your CPU's MMIO Stale Data status is unknown (Intel never officially assessed this CPU, its servicing period has ended)"
|
if is_arch_cap_mmio_undetermined; then
|
||||||
if [ "$opt_paranoid" = 1 ]; then
|
# We landed in the "unknown" bucket only because the IA32_ARCH_CAPABILITIES
|
||||||
pvulnstatus "$cve" VULN "$unk, and no mitigation is available"
|
# MSR couldn't be read from userspace (no msr module, or kernel lockdown under
|
||||||
explain "There is no known mitigation for this CPU model. Intel ended its servicing period without evaluating whether it is affected by MMIO Stale Data vulnerabilities, so no FB_CLEAR-capable microcode was released. Consider replacing affected hardware."
|
# Secure Boot): the CPU might actually advertise MMIO immunity
|
||||||
|
# through FBSDP_NO/PSDP_NO/SBDR_SSDP_NO, but we can't read it, however the kernel can.
|
||||||
|
#
|
||||||
|
# We can trust a sysfs "Not affected" only if this kernel is X86_BUG_MMIO_UNKNOWN-aware:
|
||||||
|
# such a kernel would have reported "Unknown: No mitigations" instead if the CPU were in
|
||||||
|
# the unknown bucket, so "Not affected" genuinely means arch-cap immune.
|
||||||
|
# On kernels that lack that distinction, a "Not affected" is not trustworthy for these CPUs,
|
||||||
|
# so we keep UNK.
|
||||||
|
if [ "$g_mode" = live ] && [ "$sys_interface_available" = 1 ] &&
|
||||||
|
[ "$kernel_mmio_unknown_aware" = 1 ] && [ "$status" = OK ]; then
|
||||||
|
pvulnstatus "$cve" OK "your kernel reports your CPU as not affected, and this kernel distinguishes the MMIO 'unknown' state, so its verdict is trustworthy (we couldn't read the IA32_ARCH_CAPABILITIES MSR ourselves)"
|
||||||
|
else
|
||||||
|
unk="your CPU's MMIO Stale Data status could not be determined: the IA32_ARCH_CAPABILITIES MSR (0x10a) couldn't be read"
|
||||||
|
pvulnstatus "$cve" UNK "$unk; load the msr module and/or disable kernel lockdown, then re-run as root to get a definitive answer"
|
||||||
|
fi
|
||||||
else
|
else
|
||||||
pvulnstatus "$cve" UNK "$unk; no mitigation is available in any case"
|
unk="your CPU's MMIO Stale Data status is unknown (Intel never officially assessed this CPU, its servicing period has ended)"
|
||||||
|
if [ "$opt_paranoid" = 1 ]; then
|
||||||
|
pvulnstatus "$cve" VULN "$unk, and no mitigation is available"
|
||||||
|
explain "There is no known mitigation for this CPU model. Intel ended its servicing period without evaluating whether it is affected by MMIO Stale Data vulnerabilities, so no FB_CLEAR-capable microcode was released."
|
||||||
|
else
|
||||||
|
pvulnstatus "$cve" UNK "$unk; no mitigation is available in any case"
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
if [ "$opt_sysfs_only" != 1 ]; then
|
if [ "$opt_sysfs_only" != 1 ]; then
|
||||||
|
|||||||
@@ -306,7 +306,7 @@ check_CVE_2017_5715_linux() {
|
|||||||
# which in that case means ibrs is supported *and* enabled for kernel & user
|
# which in that case means ibrs is supported *and* enabled for kernel & user
|
||||||
# as per the ibrs patch series v3
|
# as per the ibrs patch series v3
|
||||||
if [ -z "$g_ibrs_supported" ]; then
|
if [ -z "$g_ibrs_supported" ]; then
|
||||||
if grep ^flags "$g_procfs/cpuinfo" | grep -qw spec_ctrl_ibrs; then
|
if cpuinfo_has_flag spec_ctrl_ibrs; then
|
||||||
pr_debug "ibrs: found spec_ctrl_ibrs flag in $g_procfs/cpuinfo"
|
pr_debug "ibrs: found spec_ctrl_ibrs flag in $g_procfs/cpuinfo"
|
||||||
g_ibrs_supported="spec_ctrl_ibrs flag in $g_procfs/cpuinfo"
|
g_ibrs_supported="spec_ctrl_ibrs flag in $g_procfs/cpuinfo"
|
||||||
# enabled=2 -> kernel & user
|
# enabled=2 -> kernel & user
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
pti_performance_check() {
|
pti_performance_check() {
|
||||||
local ret pcid invpcid
|
local ret pcid invpcid
|
||||||
pr_info_nol " * Reduced performance impact of PTI: "
|
pr_info_nol " * Reduced performance impact of PTI: "
|
||||||
if [ -e "$g_procfs/cpuinfo" ] && grep ^flags "$g_procfs/cpuinfo" | grep -qw pcid; then
|
if cpuinfo_has_flag pcid; then
|
||||||
pcid=1
|
pcid=1
|
||||||
else
|
else
|
||||||
read_cpuid 0x1 0x0 "$ECX" 17 1 1
|
read_cpuid 0x1 0x0 "$ECX" 17 1 1
|
||||||
@@ -21,7 +21,7 @@ pti_performance_check() {
|
|||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ -e "$g_procfs/cpuinfo" ] && grep ^flags "$g_procfs/cpuinfo" | grep -qw invpcid; then
|
if cpuinfo_has_flag invpcid; then
|
||||||
invpcid=1
|
invpcid=1
|
||||||
else
|
else
|
||||||
read_cpuid 0x7 0x0 "$EBX" 10 1 1
|
read_cpuid 0x7 0x0 "$EBX" 10 1 1
|
||||||
@@ -110,11 +110,11 @@ check_CVE_2017_5754_linux() {
|
|||||||
dmesg_grep="$dmesg_grep|x86/pti: Unmapping kernel while in userspace"
|
dmesg_grep="$dmesg_grep|x86/pti: Unmapping kernel while in userspace"
|
||||||
# aarch64
|
# aarch64
|
||||||
dmesg_grep="$dmesg_grep|CPU features: detected( feature)?: Kernel page table isolation \(KPTI\)"
|
dmesg_grep="$dmesg_grep|CPU features: detected( feature)?: Kernel page table isolation \(KPTI\)"
|
||||||
if grep ^flags "$g_procfs/cpuinfo" | grep -qw pti; then
|
if cpuinfo_has_flag pti; then
|
||||||
# vanilla PTI patch sets the 'pti' flag in cpuinfo
|
# vanilla PTI patch sets the 'pti' flag in cpuinfo
|
||||||
pr_debug "kpti_enabled: found 'pti' flag in $g_procfs/cpuinfo"
|
pr_debug "kpti_enabled: found 'pti' flag in $g_procfs/cpuinfo"
|
||||||
kpti_enabled=1
|
kpti_enabled=1
|
||||||
elif grep ^flags "$g_procfs/cpuinfo" | grep -qw kaiser; then
|
elif cpuinfo_has_flag kaiser; then
|
||||||
# kernel line 4.9 sets the 'kaiser' flag in cpuinfo
|
# kernel line 4.9 sets the 'kaiser' flag in cpuinfo
|
||||||
pr_debug "kpti_enabled: found 'kaiser' flag in $g_procfs/cpuinfo"
|
pr_debug "kpti_enabled: found 'kaiser' flag in $g_procfs/cpuinfo"
|
||||||
kpti_enabled=1
|
kpti_enabled=1
|
||||||
|
|||||||
@@ -89,7 +89,7 @@ check_CVE_2018_3646_linux() {
|
|||||||
|
|
||||||
pr_info "* Mitigation 2"
|
pr_info "* Mitigation 2"
|
||||||
pr_info_nol " * L1D flush is supported by kernel: "
|
pr_info_nol " * L1D flush is supported by kernel: "
|
||||||
if [ "$g_mode" = live ] && grep -qw flush_l1d "$g_procfs/cpuinfo"; then
|
if [ "$g_mode" = live ] && cpuinfo_has_flag flush_l1d; then
|
||||||
l1d_kernel="found flush_l1d in $g_procfs/cpuinfo"
|
l1d_kernel="found flush_l1d in $g_procfs/cpuinfo"
|
||||||
fi
|
fi
|
||||||
if [ -z "$l1d_kernel" ]; then
|
if [ -z "$l1d_kernel" ]; then
|
||||||
@@ -162,7 +162,7 @@ check_CVE_2018_3646_linux() {
|
|||||||
|
|
||||||
pr_info_nol " * Hardware-backed L1D flush supported: "
|
pr_info_nol " * Hardware-backed L1D flush supported: "
|
||||||
if [ "$g_mode" = live ]; then
|
if [ "$g_mode" = live ]; then
|
||||||
if grep -qw flush_l1d "$g_procfs/cpuinfo" || [ -n "$l1d_xen_hardware" ]; then
|
if cpuinfo_has_flag flush_l1d || [ -n "$l1d_xen_hardware" ]; then
|
||||||
pstatus green YES "performance impact of the mitigation will be greatly reduced"
|
pstatus green YES "performance impact of the mitigation will be greatly reduced"
|
||||||
else
|
else
|
||||||
pstatus blue NO "flush will be done in software, this is slower"
|
pstatus blue NO "flush will be done in software, this is slower"
|
||||||
|
|||||||
Reference in New Issue
Block a user