Re: [Xen-devel] [PATCH 3/6] x86/AMD: Rework XSA-9 / Erratum 121 handling entirely

2019-01-09 Thread Jan Beulich
>>> On 28.12.18 at 13:39, wrote: > There are multiple problems: > > * The opt_allow_unsafe < 0 logic is dead since 2012 (c/s 0c7a6966511 >"x86-64: refine the XSA-9 fix"). Not really, no, the more that said commit only introduced it. Please pay attention to the description saying "by means o

Re: [Xen-devel] [PATCH 3/6] x86/AMD: Rework XSA-9 / Erratum 121 handling entirely

2018-12-28 Thread Andrew Cooper
On 28/12/2018 15:26, Roger Pau Monné wrote: > On Fri, Dec 28, 2018 at 12:39:33PM +, Andrew Cooper wrote: >> There are multiple problems: >> >> * The opt_allow_unsafe < 0 logic is dead since 2012 (c/s 0c7a6966511 >>"x86-64: refine the XSA-9 fix"). >> * Given that opt_allow_unsafe was delib

Re: [Xen-devel] [PATCH 3/6] x86/AMD: Rework XSA-9 / Erratum 121 handling entirely

2018-12-28 Thread Roger Pau Monné
On Fri, Dec 28, 2018 at 12:39:33PM +, Andrew Cooper wrote: > There are multiple problems: > > * The opt_allow_unsafe < 0 logic is dead since 2012 (c/s 0c7a6966511 >"x86-64: refine the XSA-9 fix"). > * Given that opt_allow_unsafe was deliberately intended not to be >specific to #121 a

[Xen-devel] [PATCH 3/6] x86/AMD: Rework XSA-9 / Erratum 121 handling entirely

2018-12-28 Thread Andrew Cooper
There are multiple problems: * The opt_allow_unsafe < 0 logic is dead since 2012 (c/s 0c7a6966511 "x86-64: refine the XSA-9 fix"). * Given that opt_allow_unsafe was deliberately intended not to be specific to #121 alone, setting it to true for the not-affected case will cause a security