This is the start of the stable review cycle for the 4.14.297 release. There are 34 patches in this series, all will be posted as a response to this one. If anyone has any issues with these being applied, please let me know. Responses should be made by Wed, 02 Nov 2022 07:01:32 +0000. Anything received after that time might be too late. The whole patch series can be found in one patch at: https://www.kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.14.297-rc1.gz or in the git tree and branch at: git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.14.y and the diffstat can be found below. thanks, greg k-h ------------- Pseudo-Shortlog of commits: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> Linux 4.14.297-rc1 Daniel Sneddon <daniel.sneddon@xxxxxxxxxxxxxxx> x86/speculation: Add RSB VM Exit protections Pawan Gupta <pawan.kumar.gupta@xxxxxxxxxxxxxxx> x86/bugs: Warn when "ibrs" mitigation is selected on Enhanced IBRS parts Nathan Chancellor <nathan@xxxxxxxxxx> x86/speculation: Use DECLARE_PER_CPU for x86_spec_ctrl_current Pawan Gupta <pawan.kumar.gupta@xxxxxxxxxxxxxxx> x86/speculation: Disable RRSBA behavior Pawan Gupta <pawan.kumar.gupta@xxxxxxxxxxxxxxx> x86/bugs: Add Cannon lake to RETBleed affected CPU list Andrew Cooper <andrew.cooper3@xxxxxxxxxx> x86/cpu/amd: Enumerate BTC_NO Peter Zijlstra <peterz@xxxxxxxxxxxxx> x86/common: Stamp out the stepping madness Josh Poimboeuf <jpoimboe@xxxxxxxxxx> x86/speculation: Fill RSB on vmexit for IBRS Josh Poimboeuf <jpoimboe@xxxxxxxxxx> KVM: VMX: Fix IBRS handling after vmexit Josh Poimboeuf <jpoimboe@xxxxxxxxxx> KVM: VMX: Prevent guest RSB poisoning attacks with eIBRS Josh Poimboeuf <jpoimboe@xxxxxxxxxx> x86/speculation: Remove x86_spec_ctrl_mask Josh Poimboeuf <jpoimboe@xxxxxxxxxx> x86/speculation: Use cached host SPEC_CTRL value for guest entry/exit Josh Poimboeuf <jpoimboe@xxxxxxxxxx> x86/speculation: Fix SPEC_CTRL write on SMT state change Josh Poimboeuf <jpoimboe@xxxxxxxxxx> x86/speculation: Fix firmware entry SPEC_CTRL handling Josh Poimboeuf <jpoimboe@xxxxxxxxxx> x86/speculation: Fix RSB filling with CONFIG_RETPOLINE=n Pawan Gupta <pawan.kumar.gupta@xxxxxxxxxxxxxxx> x86/speculation: Add LFENCE to RSB fill sequence Peter Zijlstra <peterz@xxxxxxxxxxxxx> x86/speculation: Change FILL_RETURN_BUFFER to work with objtool Peter Zijlstra <peterz@xxxxxxxxxxxxx> entel_idle: Disable IBRS during long idle Peter Zijlstra <peterz@xxxxxxxxxxxxx> x86/bugs: Report Intel retbleed vulnerability Peter Zijlstra <peterz@xxxxxxxxxxxxx> x86/bugs: Split spectre_v2_select_mitigation() and spectre_v2_user_select_mitigation() Pawan Gupta <pawan.kumar.gupta@xxxxxxxxxxxxxxx> x86/speculation: Add spectre_v2=ibrs option to support Kernel IBRS Peter Zijlstra <peterz@xxxxxxxxxxxxx> x86/bugs: Optimize SPEC_CTRL MSR writes Thadeu Lima de Souza Cascardo <cascardo@xxxxxxxxxxxxx> x86/entry: Add kernel IBRS implementation Peter Zijlstra <peterz@xxxxxxxxxxxxx> x86/bugs: Keep a per-CPU IA32_SPEC_CTRL value Alexandre Chartre <alexandre.chartre@xxxxxxxxxx> x86/bugs: Add AMD retbleed= boot parameter Alexandre Chartre <alexandre.chartre@xxxxxxxxxx> x86/bugs: Report AMD retbleed vulnerability Peter Zijlstra <peterz@xxxxxxxxxxxxx> x86/cpufeatures: Move RETPOLINE flags to word 11 Peter Zijlstra <peterz@xxxxxxxxxxxxx> x86/entry: Remove skip_r11rcx Mark Gross <mgross@xxxxxxxxxxxxxxx> x86/cpu: Add a steppings field to struct x86_cpu_id Thomas Gleixner <tglx@xxxxxxxxxxxxx> x86/cpu: Add consistent CPU match macros Thomas Gleixner <tglx@xxxxxxxxxxxxx> x86/devicetable: Move x86 specific macro out of generic code Ingo Molnar <mingo@xxxxxxxxxx> x86/cpufeature: Fix various quality problems in the <asm/cpu_device_hd.h> header Kan Liang <kan.liang@xxxxxxxxxxxxxxx> x86/cpufeature: Add facility to check for min microcode revisions Suraj Jitindar Singh <surajjs@xxxxxxxxxx> Revert "x86/cpu: Add a steppings field to struct x86_cpu_id" ------------- Diffstat: Documentation/admin-guide/hw-vuln/spectre.rst | 8 + Documentation/admin-guide/kernel-parameters.txt | 13 + Makefile | 4 +- arch/x86/entry/calling.h | 68 +++- arch/x86/entry/entry_32.S | 2 - arch/x86/entry/entry_64.S | 38 ++- arch/x86/entry/entry_64_compat.S | 12 +- arch/x86/include/asm/cpu_device_id.h | 168 +++++++++- arch/x86/include/asm/cpufeatures.h | 16 +- arch/x86/include/asm/intel-family.h | 6 + arch/x86/include/asm/msr-index.h | 14 + arch/x86/include/asm/nospec-branch.h | 48 +-- arch/x86/kernel/cpu/amd.c | 21 +- arch/x86/kernel/cpu/bugs.c | 415 ++++++++++++++++++++---- arch/x86/kernel/cpu/common.c | 68 ++-- arch/x86/kernel/cpu/match.c | 44 ++- arch/x86/kernel/cpu/scattered.c | 1 + arch/x86/kernel/process.c | 2 +- arch/x86/kvm/svm.c | 1 + arch/x86/kvm/vmx.c | 51 ++- drivers/base/cpu.c | 8 + drivers/cpufreq/acpi-cpufreq.c | 1 + drivers/cpufreq/amd_freq_sensitivity.c | 1 + drivers/idle/intel_idle.c | 45 ++- include/linux/cpu.h | 2 + include/linux/mod_devicetable.h | 4 +- tools/arch/x86/include/asm/cpufeatures.h | 1 + 27 files changed, 899 insertions(+), 163 deletions(-)