On 13/02/2018 11:53, David Woodhouse wrote: >> You have my vote. :) Really, IBRS_ALL makes no sense and it would be >> nice to know _why_ Intel is pushing something that makes no sense. > No, IBRS_ALL *does* make sense. It's not a complete fix, but it's as > much of a fix as they should shoe-horn into the generation of CPUs > which are currently going to the fabs. > > With IBRS_ALL they presumably add tags to the predictions with the VMX > mode and ring, to give complete protection against predictions being > used in a more privileged mode. Yeah, but I still don't get why they need an MSR to turn those tags on. Is it basically a chicken bit in the wrong direction? Paolo