mirror of
https://github.com/speed47/spectre-meltdown-checker.git
synced 2026-09-10 12:53:58 +02:00
Compare commits
20
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d8e26423d5 | ||
|
|
32fa538ceb | ||
|
|
1b14bf4d27 | ||
|
|
d5cbaaa7c3 | ||
|
|
cc29aaba6b | ||
|
|
cb48e1ace8 | ||
|
|
96269b77df | ||
|
|
7cfb924465 | ||
|
|
ea33890c84 | ||
|
|
b8b2f8377b | ||
|
|
d7129649d2 | ||
|
|
1161089b2e | ||
|
|
dc7b92bf42 | ||
|
|
1ffa598c80 | ||
|
|
2bd3957480 | ||
|
|
44ba92635f | ||
|
|
7d9345a32f | ||
|
|
645a79846b | ||
|
|
0045d237fa | ||
|
|
3e2b6cc734 |
+5
-3
@@ -41,20 +41,22 @@ The project uses 4 branches organized in two pipelines (production and dev/test)
|
|||||||
| **`test-build`** | Monolithic test script (built artifact) | CI from `test` |
|
| **`test-build`** | Monolithic test script (built artifact) | CI from `test` |
|
||||||
| **`source`** | Production source (split files + Makefile) | Developers |
|
| **`source`** | Production source (split files + Makefile) | Developers |
|
||||||
| **`source-build`** | Monolithic test script (built artifact) | CI from `source` |
|
| **`source-build`** | Monolithic test script (built artifact) | CI from `source` |
|
||||||
| **`master`** | Monolithic production script (built artifact) | PR by developers from `source-build` |
|
| **`master`** | Monolithic production script (built artifact) | `release` workflow, synced from `source-build` |
|
||||||
|
|
||||||
- **`source`** and **`test`** contain the split source files and the Makefile. These are the branches developers commit to.
|
- **`source`** and **`test`** contain the split source files and the Makefile. These are the branches developers commit to.
|
||||||
- **`master`**, **`source-build`** and **`test-build`** contain only the monolithic `spectre-meltdown-checker.sh` built by CI. Nobody commits to these directly.
|
- **`master`**, **`source-build`** and **`test-build`** contain only the monolithic `spectre-meltdown-checker.sh` built by CI. Nobody commits to these directly.
|
||||||
- **`master`** is the preexisting production branch that users pull from. It cannot be renamed.
|
- **`master`** is the preexisting production branch that users pull from. It cannot be renamed.
|
||||||
- **`test-build`** is a testing branch that users can pull from to test pre-release versions.
|
- **`test-build`** is a testing branch that users can pull from to test pre-release versions.
|
||||||
- **`source-build`** is a preprod branch to prepare the artifact before merging to **`master`**.
|
- **`source-build`** is a preprod branch to prepare the artifact before releasing it to **`master`**. It is a build *output* branch and is never merged into `master`; instead the assembled files are copied across by the manual `release` workflow (see [RELEASE.md](RELEASE.md)), which keeps `master`'s own CI workflows untouched.
|
||||||
|
|
||||||
Typical workflow:
|
Typical workflow:
|
||||||
1. Feature/fix branches are created from `test` and merged back into `test`.
|
1. Feature/fix branches are created from `test` and merged back into `test`.
|
||||||
2. CI builds the script and pushes it to `test-build` for testing.
|
2. CI builds the script and pushes it to `test-build` for testing.
|
||||||
3. When ready for release, `test` is merged into `source`.
|
3. When ready for release, `test` is merged into `source`.
|
||||||
4. CI builds the script and pushes it to `source-build` for production.
|
4. CI builds the script and pushes it to `source-build` for production.
|
||||||
5. Developer creates a PR from `source-build` to `master`.
|
5. Developer runs the manual `release` workflow to sync `source-build`'s
|
||||||
|
assembled files onto `master` and draft a GitHub release. See
|
||||||
|
[RELEASE.md](RELEASE.md) for the full procedure.
|
||||||
|
|
||||||
## Versioning
|
## Versioning
|
||||||
|
|
||||||
|
|||||||
+86
@@ -0,0 +1,86 @@
|
|||||||
|
# Releasing
|
||||||
|
|
||||||
|
This document describes how a production release reaches the `master` branch
|
||||||
|
and how a GitHub release is published. It complements the **Branch Model**
|
||||||
|
section of [DEVELOPMENT.md](DEVELOPMENT.md).
|
||||||
|
|
||||||
|
This file lives only on the `source`/`test` development branches. It is **not**
|
||||||
|
part of `dist/`, so it never reaches `source-build` or `master` — users who
|
||||||
|
`git clone` the `master` branch onto their servers get only the files needed to
|
||||||
|
run the tool.
|
||||||
|
|
||||||
|
## Why `master` is not a merge target
|
||||||
|
|
||||||
|
`master` plays two roles at once:
|
||||||
|
|
||||||
|
- It is the **distribution branch** — users clone it directly onto their
|
||||||
|
servers, so it must stay minimal (just the monolithic script and the few
|
||||||
|
files needed to run/build the container).
|
||||||
|
- It is the repository's **default branch**, which is the only place GitHub
|
||||||
|
runs *scheduled* workflows from. The `autoupdate`, `stale` and `vuln-watch`
|
||||||
|
workflows are therefore **master-only** and deliberately kept off the
|
||||||
|
`source`/`test` line (see commit "remove from test branch workflows that must
|
||||||
|
live on master").
|
||||||
|
|
||||||
|
`source-build` is a build **output** branch and does **not** carry those
|
||||||
|
master-only workflows (the build's `rsync --delete` strips `.github/` down to
|
||||||
|
what `source` ships). Merging the whole `source-build` tree into `master` would
|
||||||
|
therefore drag the *absence* of those workflows into `master`, producing
|
||||||
|
recurring `modify/delete` conflicts — and, worse, a clean merge could silently
|
||||||
|
delete them when they hadn't been edited since the last release.
|
||||||
|
|
||||||
|
So we never merge `source-build` into `master`. Instead we **copy only the
|
||||||
|
assembled artifact files** across, and cut GitHub releases from `master`
|
||||||
|
directly.
|
||||||
|
|
||||||
|
## The `release` workflow
|
||||||
|
|
||||||
|
`.github/workflows/release.yml` (which, like the other master-only workflows,
|
||||||
|
lives **only on `master`**) is triggered manually via `workflow_dispatch` and
|
||||||
|
offers two independent actions selected from the `action` dropdown. Run it
|
||||||
|
against the `master` branch.
|
||||||
|
|
||||||
|
### 1. `sync-from-source-build`
|
||||||
|
|
||||||
|
Copies every top-level entry on `source-build` **except `.github/`**
|
||||||
|
(`spectre-meltdown-checker.sh`, `README.md`, `doc/`, `Dockerfile`,
|
||||||
|
`docker-compose.yml`) onto `master` as a single commit, mirroring exactly
|
||||||
|
(deletions and renames included). `master`'s own `.github/` — its
|
||||||
|
master-only CI — is never touched.
|
||||||
|
|
||||||
|
The script's contents are copied byte-for-byte, so its `VERSION` (generated by
|
||||||
|
the `source-build` build) is preserved unchanged. No version bump happens here.
|
||||||
|
|
||||||
|
The job is a no-op if `master` is already up to date.
|
||||||
|
|
||||||
|
### 2. `draft-github-release`
|
||||||
|
|
||||||
|
Reads the `VERSION` from the script currently on `master`, and creates a
|
||||||
|
**draft** GitHub release tagged `v<VERSION>`, with the monolithic script
|
||||||
|
attached as an asset. Because it is a draft, **no tag is created and nothing is
|
||||||
|
published** until you press *Publish* in the Releases UI — so this step is fully
|
||||||
|
reversible.
|
||||||
|
|
||||||
|
The changelog is auto-drafted by locating the `source-build` commit whose built
|
||||||
|
`VERSION` matches the previous published release, then listing every assembled
|
||||||
|
commit since. Treat it as a starting point and edit it before publishing.
|
||||||
|
|
||||||
|
## Release procedure
|
||||||
|
|
||||||
|
1. Confirm `source-build` holds the artifact you want to release (CI is green,
|
||||||
|
version string looks right).
|
||||||
|
2. Run the **`release`** workflow on `master` with `action =
|
||||||
|
sync-from-source-build`. Review the resulting commit/diff on `master`.
|
||||||
|
3. Run the **`release`** workflow on `master` with `action =
|
||||||
|
draft-github-release`.
|
||||||
|
4. Open the draft release, review/edit the auto-generated changelog, then
|
||||||
|
**Publish** it. Publishing creates the `v<VERSION>` tag.
|
||||||
|
|
||||||
|
Steps 2 and 3 are decoupled on purpose: you can refresh `master` from
|
||||||
|
`source-build` (step 2) without cutting a formal GitHub release yet.
|
||||||
|
|
||||||
|
## Rollback
|
||||||
|
|
||||||
|
- Before publishing: delete the draft release in the UI (no tag exists yet).
|
||||||
|
- After a bad `sync-from-source-build`: `master` history is intact — revert the
|
||||||
|
sync commit with a normal `git revert` (never force-push `master`).
|
||||||
+49
-44
@@ -8,7 +8,7 @@
|
|||||||
# with X being either I for Intel, or A for AMD
|
# with X being either I for Intel, or A for AMD
|
||||||
# When the date is unknown it defaults to 20000101
|
# When the date is unknown it defaults to 20000101
|
||||||
|
|
||||||
# %%% MCEDB v349+i20260227+615b
|
# %%% MCEDB v352+i20260812+16e5
|
||||||
# I,0x00000611,0xFF,0x00000B27,19961218
|
# I,0x00000611,0xFF,0x00000B27,19961218
|
||||||
# I,0x00000612,0xFF,0x000000C6,19961210
|
# I,0x00000612,0xFF,0x000000C6,19961210
|
||||||
# I,0x00000616,0xFF,0x000000C6,19961210
|
# I,0x00000616,0xFF,0x000000C6,19961210
|
||||||
@@ -346,9 +346,9 @@
|
|||||||
# I,0x000606A0,0xFF,0x80000031,20200308
|
# I,0x000606A0,0xFF,0x80000031,20200308
|
||||||
# I,0x000606A4,0xFF,0x0B000280,20200817
|
# I,0x000606A4,0xFF,0x0B000280,20200817
|
||||||
# I,0x000606A5,0x87,0x0C0002F0,20210308
|
# I,0x000606A5,0x87,0x0C0002F0,20210308
|
||||||
# I,0x000606A6,0x87,0x0D000421,20250819
|
# I,0x000606A6,0x87,0x0D000433,20260309
|
||||||
# I,0x000606C0,0xFF,0xFD000220,20210629
|
# I,0x000606C0,0xFF,0xFD000220,20210629
|
||||||
# I,0x000606C1,0x10,0x010002F1,20250819
|
# I,0x000606C1,0x10,0x01000301,20260309
|
||||||
# I,0x000606E0,0xFF,0x0000000B,20161104
|
# I,0x000606E0,0xFF,0x0000000B,20161104
|
||||||
# I,0x000606E1,0xFF,0x00000108,20190423
|
# I,0x000606E1,0xFF,0x00000108,20190423
|
||||||
# I,0x000606E4,0xFF,0x0000000C,20190124
|
# I,0x000606E4,0xFF,0x0000000C,20190124
|
||||||
@@ -360,7 +360,7 @@
|
|||||||
# I,0x000706E2,0xFF,0x00000042,20190420
|
# I,0x000706E2,0xFF,0x00000042,20190420
|
||||||
# I,0x000706E3,0xFF,0x81000008,20181002
|
# I,0x000706E3,0xFF,0x81000008,20181002
|
||||||
# I,0x000706E4,0xFF,0x00000046,20190905
|
# I,0x000706E4,0xFF,0x00000046,20190905
|
||||||
# I,0x000706E5,0x80,0x000000CC,20250724
|
# I,0x000706E5,0x80,0x000000CE,20260212
|
||||||
# I,0x00080650,0xFF,0x00000018,20180108
|
# I,0x00080650,0xFF,0x00000018,20180108
|
||||||
# I,0x00080664,0xFF,0x4C000025,20230926
|
# I,0x00080664,0xFF,0x4C000025,20230926
|
||||||
# I,0x00080665,0xFF,0x4C000026,20240228
|
# I,0x00080665,0xFF,0x4C000026,20240228
|
||||||
@@ -380,15 +380,15 @@
|
|||||||
# I,0x000806F1,0xFF,0x800003C0,20220327
|
# I,0x000806F1,0xFF,0x800003C0,20220327
|
||||||
# I,0x000806F2,0xFF,0x8C0004E0,20211112
|
# I,0x000806F2,0xFF,0x8C0004E0,20211112
|
||||||
# I,0x000806F3,0xFF,0x8D000520,20220812
|
# I,0x000806F3,0xFF,0x8D000520,20220812
|
||||||
# I,0x000806F4,0x10,0x2C000421,20250825
|
# I,0x000806F4,0x10,0x2C000435,20260302
|
||||||
# I,0x000806F4,0x87,0x2B000661,20250825
|
# I,0x000806F4,0x87,0x2B000685,20260302
|
||||||
# I,0x000806F5,0x10,0x2C000421,20250825
|
# I,0x000806F5,0x10,0x2C000435,20260302
|
||||||
# I,0x000806F5,0x87,0x2B000661,20250825
|
# I,0x000806F5,0x87,0x2B000685,20260302
|
||||||
# I,0x000806F6,0x10,0x2C000421,20250825
|
# I,0x000806F6,0x10,0x2C000435,20260302
|
||||||
# I,0x000806F6,0x87,0x2B000661,20250825
|
# I,0x000806F6,0x87,0x2B000685,20260302
|
||||||
# I,0x000806F7,0x87,0x2B000661,20250825
|
# I,0x000806F7,0x87,0x2B000685,20260302
|
||||||
# I,0x000806F8,0x10,0x2C000421,20250825
|
# I,0x000806F8,0x10,0x2C000435,20260302
|
||||||
# I,0x000806F8,0x87,0x2B000661,20250825
|
# I,0x000806F8,0x87,0x2B000685,20260302
|
||||||
# I,0x00090660,0xFF,0x00000009,20200617
|
# I,0x00090660,0xFF,0x00000009,20200617
|
||||||
# I,0x00090661,0x01,0x0000001A,20240405
|
# I,0x00090661,0x01,0x0000001A,20240405
|
||||||
# I,0x00090670,0xFF,0x00000019,20201111
|
# I,0x00090670,0xFF,0x00000019,20201111
|
||||||
@@ -417,7 +417,7 @@
|
|||||||
# I,0x000A0660,0x80,0x00000102,20241114
|
# I,0x000A0660,0x80,0x00000102,20241114
|
||||||
# I,0x000A0661,0x80,0x00000100,20241114
|
# I,0x000A0661,0x80,0x00000100,20241114
|
||||||
# I,0x000A0670,0xFF,0x0000002C,20201124
|
# I,0x000A0670,0xFF,0x0000002C,20201124
|
||||||
# I,0x000A0671,0x02,0x00000065,20250724
|
# I,0x000A0671,0x02,0x00000066,20260212
|
||||||
# I,0x000A0680,0xFF,0x80000002,20200121
|
# I,0x000A0680,0xFF,0x80000002,20200121
|
||||||
# I,0x000A06A1,0xFF,0x00000017,20230518
|
# I,0x000A06A1,0xFF,0x00000017,20230518
|
||||||
# I,0x000A06A2,0xFF,0x00000011,20230627
|
# I,0x000A06A2,0xFF,0x00000011,20230627
|
||||||
@@ -425,39 +425,44 @@
|
|||||||
# I,0x000A06C0,0xFF,0x00000013,20230901
|
# I,0x000A06C0,0xFF,0x00000013,20230901
|
||||||
# I,0x000A06C1,0xFF,0x00000005,20231201
|
# I,0x000A06C1,0xFF,0x00000005,20231201
|
||||||
# I,0x000A06D0,0xFF,0x10000680,20240818
|
# I,0x000A06D0,0xFF,0x10000680,20240818
|
||||||
# I,0x000A06D1,0x20,0x0A000133,20251009
|
# I,0x000A06D1,0x20,0x0A000151,20260324
|
||||||
# I,0x000A06D1,0x95,0x01000405,20251031
|
# I,0x000A06D1,0x95,0x01000434,20260427
|
||||||
# I,0x000A06E1,0x97,0x01000303,20251202
|
# I,0x000A06E0,0xFF,0x80000953,20240902
|
||||||
|
# I,0x000A06E1,0x97,0x01000309,20260415
|
||||||
# I,0x000A06F0,0xFF,0x80000360,20240130
|
# I,0x000A06F0,0xFF,0x80000360,20240130
|
||||||
# I,0x000A06F3,0x01,0x03000382,20250730
|
# I,0x000A06F3,0x01,0x030003B2,20260316
|
||||||
# I,0x000B0650,0x80,0x0000000D,20250925
|
# I,0x000B0650,0x80,0x0000000E,20260115
|
||||||
# I,0x000B0664,0xFF,0x00000030,20250529
|
# I,0x000B0664,0xFF,0x00000030,20250529
|
||||||
# I,0x000B0670,0xFF,0x0000000E,20220220
|
# I,0x000B0670,0xFF,0x0000000E,20220220
|
||||||
# I,0x000B0671,0x32,0x00000133,20251008
|
# I,0x000B0671,0x36,0x00000137,20260218
|
||||||
# I,0x000B0674,0x32,0x00000133,20251008
|
# I,0x000B0674,0x36,0x00000137,20260218
|
||||||
# I,0x000B06A2,0xE0,0x00006134,20251008
|
# I,0x000B06A2,0xE0,0x00006134,20251008
|
||||||
# I,0x000B06A3,0xE0,0x00006134,20251008
|
# I,0x000B06A3,0xE0,0x00006134,20251008
|
||||||
# I,0x000B06A8,0xE0,0x00006134,20251008
|
# I,0x000B06A8,0xE0,0x00006134,20251008
|
||||||
# I,0x000B06D0,0xFF,0x0000001A,20240610
|
# I,0x000B06D0,0xFF,0x0000001A,20240610
|
||||||
# I,0x000B06D1,0x80,0x00000125,20250828
|
# I,0x000B06D1,0x80,0x00000128,20260219
|
||||||
# I,0x000B06E0,0x19,0x00000021,20250912
|
# I,0x000B06E0,0x19,0x00000021,20250912
|
||||||
# I,0x000B06F2,0x07,0x0000003E,20251012
|
# I,0x000B06F2,0x07,0x0000003E,20251012
|
||||||
# I,0x000B06F5,0x07,0x0000003E,20251012
|
# I,0x000B06F5,0x07,0x0000003E,20251012
|
||||||
# I,0x000B06F6,0x07,0x0000003E,20251012
|
# I,0x000B06F6,0x07,0x0000003E,20251012
|
||||||
# I,0x000B06F7,0x07,0x0000003E,20251012
|
# I,0x000B06F7,0x07,0x0000003E,20251012
|
||||||
# I,0x000C0652,0x82,0x0000011B,20250803
|
# I,0x000C0652,0x82,0x00000122,20260218
|
||||||
# I,0x000C0660,0xFF,0x00000018,20240516
|
# I,0x000C0660,0xFF,0x00000018,20240516
|
||||||
# I,0x000C0662,0x82,0x0000011B,20250803
|
# I,0x000C0662,0x82,0x00000122,20260218
|
||||||
# I,0x000C0664,0x82,0x0000011B,20250803
|
# I,0x000C0664,0x82,0x00000122,20260218
|
||||||
# I,0x000C06A2,0x82,0x0000011B,20250803
|
# I,0x000C06A2,0x82,0x00000122,20260218
|
||||||
# I,0x000C06C0,0xFF,0x00000012,20250325
|
# I,0x000C06C0,0xFF,0x00000012,20250325
|
||||||
# I,0x000C06C1,0xFF,0x00000115,20251203
|
# I,0x000C06C1,0x94,0x0000011C,20260420
|
||||||
# I,0x000C06C2,0xFF,0x00000115,20251203
|
# I,0x000C06C2,0x94,0x0000011C,20260420
|
||||||
# I,0x000C06C3,0xFF,0x00000115,20251203
|
# I,0x000C06C3,0x94,0x0000011C,20260420
|
||||||
# I,0x000C06F1,0x87,0x210002D3,20250825
|
# I,0x000C06F1,0x87,0x210002F4,20260302
|
||||||
# I,0x000C06F2,0x87,0x210002D3,20250825
|
# I,0x000C06F2,0x87,0x210002F4,20260302
|
||||||
# I,0x000D0670,0xFF,0x00000003,20250825
|
# I,0x000D0650,0xC0,0x0000000C,20260520
|
||||||
# I,0x000D06D0,0xFF,0x00000340,20250807
|
# I,0x000D0651,0xC0,0x0000000C,20260520
|
||||||
|
# I,0x000D0670,0x36,0x00000137,20260218
|
||||||
|
# I,0x000D06D0,0xFF,0x10000401,20260212
|
||||||
|
# I,0x000D06D1,0xFF,0x01000151,20260630
|
||||||
|
# I,0x000E0652,0x94,0x0000011C,20260420
|
||||||
# I,0x00FF0671,0xFF,0x0000010E,20220907
|
# I,0x00FF0671,0xFF,0x0000010E,20220907
|
||||||
# I,0x00FF0672,0xFF,0x0000000D,20210816
|
# I,0x00FF0672,0xFF,0x0000000D,20210816
|
||||||
# I,0x00FF0675,0xFF,0x0000000D,20210816
|
# I,0x00FF0675,0xFF,0x0000000D,20210816
|
||||||
@@ -554,13 +559,13 @@
|
|||||||
# A,0x00880F40,0xFF,0x08804005,20210312
|
# A,0x00880F40,0xFF,0x08804005,20210312
|
||||||
# A,0x00890F00,0xFF,0x08900007,20200921
|
# A,0x00890F00,0xFF,0x08900007,20200921
|
||||||
# A,0x00890F01,0xFF,0x08900103,20201105
|
# A,0x00890F01,0xFF,0x08900103,20201105
|
||||||
# A,0x00890F02,0xFF,0x08900203,20230915
|
# A,0x00890F02,0xFF,0x08900208,20241219
|
||||||
# A,0x00890F10,0xFF,0x08901003,20230919
|
# A,0x00890F10,0xFF,0x08901003,20230919
|
||||||
# A,0x008A0F00,0xFF,0x08A0000B,20241125
|
# A,0x008A0F00,0xFF,0x08A0000B,20241125
|
||||||
# A,0x00A00F00,0xFF,0x0A000033,20200413
|
# A,0x00A00F00,0xFF,0x0A000033,20200413
|
||||||
# A,0x00A00F10,0xFF,0x0A00107A,20240226
|
# A,0x00A00F10,0xFF,0x0A00107A,20240226
|
||||||
# A,0x00A00F11,0xFF,0x0A0011DE,20250418
|
# A,0x00A00F11,0xFF,0x0A0011DF,20260312
|
||||||
# A,0x00A00F12,0xFF,0x0A001247,20250327
|
# A,0x00A00F12,0xFF,0x0A00124B,20260305
|
||||||
# A,0x00A00F80,0xFF,0x0A008005,20230707
|
# A,0x00A00F80,0xFF,0x0A008005,20230707
|
||||||
# A,0x00A00F82,0xFF,0x0A00820F,20241111
|
# A,0x00A00F82,0xFF,0x0A00820F,20241111
|
||||||
# A,0x00A10F00,0xFF,0x0A10004B,20220309
|
# A,0x00A10F00,0xFF,0x0A10004B,20220309
|
||||||
@@ -599,15 +604,15 @@
|
|||||||
# A,0x00B00F00,0xFF,0x0B00004D,20240318
|
# A,0x00B00F00,0xFF,0x0B00004D,20240318
|
||||||
# A,0x00B00F10,0xFF,0x0B001016,20240318
|
# A,0x00B00F10,0xFF,0x0B001016,20240318
|
||||||
# A,0x00B00F20,0xFF,0x0B002032,20241003
|
# A,0x00B00F20,0xFF,0x0B002032,20241003
|
||||||
# A,0x00B00F21,0xFF,0x0B002161,20251105
|
# A,0x00B00F21,0xFF,0x0B002175,20260528
|
||||||
# A,0x00B00F80,0xFF,0x0B008011,20241211
|
# A,0x00B00F80,0xFF,0x0B008011,20241211
|
||||||
# A,0x00B00F81,0xFF,0x0B008121,20251020
|
# A,0x00B00F81,0xFF,0x0B008124,20260408
|
||||||
# A,0x00B10F00,0xFF,0x0B10000F,20240320
|
# A,0x00B10F00,0xFF,0x0B10000F,20240320
|
||||||
# A,0x00B10F10,0xFF,0x0B101058,20251105
|
# A,0x00B10F10,0xFF,0x0B101066,20260528
|
||||||
# A,0x00B20F40,0xFF,0x0B204037,20251019
|
# A,0x00B20F40,0xFF,0x0B20403C,20260330
|
||||||
# A,0x00B40F00,0xFF,0x0B400034,20240318
|
# A,0x00B40F00,0xFF,0x0B400034,20240318
|
||||||
# A,0x00B40F40,0xFF,0x0B404035,20251020
|
# A,0x00B40F40,0xFF,0x0B40403B,20260620
|
||||||
# A,0x00B40F41,0xFF,0x0B404108,20251020
|
# A,0x00B40F41,0xFF,0x0B40410E,20260620
|
||||||
# A,0x00B60F00,0xFF,0x0B600037,20251019
|
# A,0x00B60F00,0xFF,0x0B60003C,20260401
|
||||||
# A,0x00B60F80,0xFF,0x0B608038,20251019
|
# A,0x00B60F80,0xFF,0x0B608040,20260703
|
||||||
# A,0x00B70F00,0xFF,0x0B700037,20251019
|
# A,0x00B70F00,0xFF,0x0B700037,20251019
|
||||||
|
|||||||
@@ -72,6 +72,7 @@
|
|||||||
readonly INTEL_FAM6_ARROWLAKE_U=$((0xB5))
|
readonly INTEL_FAM6_ARROWLAKE_U=$((0xB5))
|
||||||
readonly INTEL_FAM6_LUNARLAKE_M=$((0xBD)) # /* Lion Cove / Skymont */
|
readonly INTEL_FAM6_LUNARLAKE_M=$((0xBD)) # /* Lion Cove / Skymont */
|
||||||
readonly INTEL_FAM6_PANTHERLAKE_L=$((0xCC)) # /* Cougar Cove / Darkmont */
|
readonly INTEL_FAM6_PANTHERLAKE_L=$((0xCC)) # /* Cougar Cove / Darkmont */
|
||||||
|
readonly INTEL_FAM6_PANTHERLAKE_R=$((0xE5)) # /* Cougar Cove / Darkmont */
|
||||||
readonly INTEL_FAM6_WILDCATLAKE_L=$((0xD5))
|
readonly INTEL_FAM6_WILDCATLAKE_L=$((0xD5))
|
||||||
readonly INTEL_FAM18_NOVALAKE=$((0x01)) # /* Coyote Cove / Arctic Wolf */
|
readonly INTEL_FAM18_NOVALAKE=$((0x01)) # /* Coyote Cove / Arctic Wolf */
|
||||||
readonly INTEL_FAM18_NOVALAKE_L=$((0x03)) # /* Coyote Cove / Arctic Wolf */
|
readonly INTEL_FAM18_NOVALAKE_L=$((0x03)) # /* Coyote Cove / Arctic Wolf */
|
||||||
|
|||||||
@@ -562,6 +562,7 @@ is_cpu_affected() {
|
|||||||
06-c5-02/82,0000011b
|
06-c5-02/82,0000011b
|
||||||
06-c6-02/82,0000011b
|
06-c6-02/82,0000011b
|
||||||
06-bd-01/80,00000125
|
06-bd-01/80,00000125
|
||||||
|
06-55-07/bf,05003901
|
||||||
06-55-0b/bf,07002b01
|
06-55-0b/bf,07002b01
|
||||||
06-8f-07/87,2b000661
|
06-8f-07/87,2b000661
|
||||||
06-8f-08/87,2b000661
|
06-8f-08/87,2b000661
|
||||||
@@ -724,9 +725,9 @@ is_cpu_affected() {
|
|||||||
if [ -n "$cpupart" ] && [ -n "$cpuarch" ]; then
|
if [ -n "$cpupart" ] && [ -n "$cpuarch" ]; then
|
||||||
# Cortex-R7 and Cortex-R8 are real-time and only used in medical devices or such
|
# Cortex-R7 and Cortex-R8 are real-time and only used in medical devices or such
|
||||||
# I can't find their CPU part number, but it's probably not that useful anyway
|
# I can't find their CPU part number, but it's probably not that useful anyway
|
||||||
# model R7 R8 A8 A9 A12 A15 A17 A57 A72 A73 A75 A76 A77 Neoverse-N1 Neoverse-V1 Neoverse-N1 Neoverse-V2
|
# model R7 R8 A8 A9 A12 A15 A17 A57 A72 A73 A75 A76 A77 Neoverse-N1 Neoverse-V1 Neoverse-N1 Neoverse-V2 Neoverse-V3 Neoverse-V3AE
|
||||||
# part ? ? c08 c09 c0d c0f c0e d07 d08 d09 d0a d0b d0d d0c d40 d49 d4f
|
# part ? ? c08 c09 c0d c0f c0e d07 d08 d09 d0a d0b d0d d0c d40 d49 d4f d84 d83
|
||||||
# arch 7? 7? 7 7 7 7 7 8 8 8 8 8 8 8 8 8 8
|
# arch 7? 7? 7 7 7 7 7 8 8 8 8 8 8 8 8 8 8 8 8
|
||||||
#
|
#
|
||||||
# Whitelist identified non-affected processors, use vulnerability information from
|
# Whitelist identified non-affected processors, use vulnerability information from
|
||||||
# https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
|
# https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
|
||||||
@@ -777,13 +778,13 @@ is_cpu_affected() {
|
|||||||
_infer_immune variant3a
|
_infer_immune variant3a
|
||||||
_set_vuln variant4
|
_set_vuln variant4
|
||||||
pr_debug "checking cpu$i: armv8 A76/A77/NeoverseN1 non affected to variant 2, 3 & 3a"
|
pr_debug "checking cpu$i: armv8 A76/A77/NeoverseN1 non affected to variant 2, 3 & 3a"
|
||||||
elif [ "$cpuarch" = 8 ] && echo "$cpupart" | grep -q -w -e 0xd40 -e 0xd49 -e 0xd4f; then
|
elif [ "$cpuarch" = 8 ] && echo "$cpupart" | grep -q -w -e 0xd40 -e 0xd49 -e 0xd4f -e 0xd84 -e 0xd83; then
|
||||||
_set_vuln variant1
|
_set_vuln variant1
|
||||||
_infer_immune variant2
|
_infer_immune variant2
|
||||||
_infer_immune variant3
|
_infer_immune variant3
|
||||||
_infer_immune variant3a
|
_infer_immune variant3a
|
||||||
_infer_immune variant4
|
_infer_immune variant4
|
||||||
pr_debug "checking cpu$i: armv8 NeoverseN2/V1/V2 non affected to variant 2, 3, 3a & 4"
|
pr_debug "checking cpu$i: armv8 NeoverseN2/V1/V2/V3/V3AE non affected to variant 2, 3, 3a & 4"
|
||||||
elif [ "$cpuarch" -le 7 ] || { [ "$cpuarch" = 8 ] && [ $((cpupart)) -lt $((0xd07)) ]; }; then
|
elif [ "$cpuarch" -le 7 ] || { [ "$cpuarch" = 8 ] && [ $((cpupart)) -lt $((0xd07)) ]; }; then
|
||||||
_infer_immune variant1
|
_infer_immune variant1
|
||||||
_infer_immune variant2
|
_infer_immune variant2
|
||||||
@@ -844,14 +845,14 @@ is_cpu_affected() {
|
|||||||
# - arm64 (CVE-2020-13844): Cortex-A32/A34/A35/A53/A57/A72/A73 confirmed affected,
|
# - arm64 (CVE-2020-13844): Cortex-A32/A34/A35/A53/A57/A72/A73 confirmed affected,
|
||||||
# and broadly all speculative Armv8-A cores. No kernel mitigation merged.
|
# and broadly all speculative Armv8-A cores. No kernel mitigation merged.
|
||||||
# Part numbers: A32=0xd01 A34=0xd02 A53=0xd03 A35=0xd04 A57=0xd07 A72=0xd08 A73=0xd09
|
# Part numbers: A32=0xd01 A34=0xd02 A53=0xd03 A35=0xd04 A57=0xd07 A72=0xd08 A73=0xd09
|
||||||
# Plus later speculative cores: A75=0xd0a A76=0xd0b A77=0xd0d N1=0xd0c V1=0xd40 N2=0xd49 V2=0xd4f
|
# Plus later speculative cores: A75=0xd0a A76=0xd0b A77=0xd0d N1=0xd0c V1=0xd40 N2=0xd49 V2=0xd4f V3=0xd84 V3AE=0xd83
|
||||||
if is_intel || is_amd; then
|
if is_intel || is_amd; then
|
||||||
_infer_vuln sls
|
_infer_vuln sls
|
||||||
elif [ "$cpu_vendor" = ARM ]; then
|
elif [ "$cpu_vendor" = ARM ]; then
|
||||||
for cpupart in $cpu_part_list; do
|
for cpupart in $cpu_part_list; do
|
||||||
if echo "$cpupart" | grep -q -w -e 0xd01 -e 0xd02 -e 0xd03 -e 0xd04 \
|
if echo "$cpupart" | grep -q -w -e 0xd01 -e 0xd02 -e 0xd03 -e 0xd04 \
|
||||||
-e 0xd07 -e 0xd08 -e 0xd09 -e 0xd0a -e 0xd0b -e 0xd0c -e 0xd0d \
|
-e 0xd07 -e 0xd08 -e 0xd09 -e 0xd0a -e 0xd0b -e 0xd0c -e 0xd0d \
|
||||||
-e 0xd40 -e 0xd49 -e 0xd4f; then
|
-e 0xd40 -e 0xd49 -e 0xd4f -e 0xd84 -e 0xd83; then
|
||||||
_set_vuln sls
|
_set_vuln sls
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
|||||||
Reference in New Issue
Block a user