On Sun, Jan 21, 2018 at 03:56:55PM +0100, Borislav Petkov wrote: > Also, blacklisting microcode for early loading will become an ugly dance > so I'd like to avoid it if possible. > > Thus, it would be much much easier if dracut/initrd creation thing > already filters those blacklisted blobs by looking at the revision in > the header. Which is much easier. That wouldn't be enough; AFAIU there's people with this stuff already flashed in their BIOS. So the kernel needs to deal with it one way or another.