mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Henrique de Moraes Holschuh <hmh@hmh.eng.br>
To: Borislav Petkov <bp@suse.de>
Cc: "Luck, Tony" <tony.luck@intel.com>,
	Andi Kleen <andi@firstfloor.org>, Ashok Raj <ashok.raj@intel.com>,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2] x86/mce: Include the PPIN in machine check records when it is available
Date: Wed, 23 Nov 2016 11:29:51 -0200	[thread overview]
Message-ID: <20161123132951.GA9373@khazad-dum.debian.net> (raw)
In-Reply-To: <20161123114855.njguoaygp3qnbkia@pd.tnic>

On Wed, 23 Nov 2016, Borislav Petkov wrote:
> +		/* if PPIN is disabled, but not locked, try to enable: */
> +		if (!(val & 3ul)) {
> +			wrmsrl_safe(MSR_PPIN_CTL,  val | 2ul);
> +			rdmsrl_safe(MSR_PPIN_CTL, &val);
> +		}

Actually, since this thing is supposed to be opt-in [through UEFI
config] for a good reason (privacy), IMHO it would make more sense to:

1. Assuming we can do it, always lock it when it is found to be unlocked
   at kernel boot.

2. Not attempt to change its state from disabled to enabled *unless*
   given a command line parameter authorizing it.  A kconfig-based
   solution for default+command line override would also work well IMHO,
   if it makes more sense.

This would keep the feature opt-in as it is supposed to be, while making
it "safer" on firmware that leaves it unlocked after boot, and would
still allow owners of systems that leave it unlocked to change its
state at boot.  Everyone ends up happy...

-- 
  Henrique Holschuh

  reply	other threads:[~2016-11-23 13:29 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-11-18  0:35 [PATCH 2/2] mcelog: Print " Luck, Tony
2016-11-18  0:35 ` [PATCH 1/2] x86/mce: Include " Luck, Tony
2016-11-18 13:00   ` Borislav Petkov
2016-11-18 16:42     ` Luck, Tony
2016-11-18 17:02     ` Andi Kleen
2016-11-18 17:45       ` Borislav Petkov
2016-11-18 17:48       ` [PATCH v2] " Luck, Tony
2016-11-23 11:48         ` Borislav Petkov
2016-11-23 13:29           ` Henrique de Moraes Holschuh [this message]
2016-11-23 13:37             ` Borislav Petkov
2016-11-23 14:05               ` Borislav Petkov
2016-11-23 16:42                 ` Tony Luck
2016-11-23 16:55                   ` Borislav Petkov
2016-11-23 17:29               ` Henrique de Moraes Holschuh
2016-11-23 20:56                 ` Tony Luck
2016-11-24 11:20                   ` Henrique de Moraes Holschuh
2016-11-23 15:58           ` [tip:ras/core] x86/mce: Include the PPIN in MCE records when available tip-bot for Tony Luck

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20161123132951.GA9373@khazad-dum.debian.net \
    --to=hmh@hmh.eng.br \
    --cc=andi@firstfloor.org \
    --cc=ashok.raj@intel.com \
    --cc=bp@suse.de \
    --cc=linux-kernel@vger.kernel.org \
    --cc=tony.luck@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®