Live data from Hacker News

Intel has released new CPU microcode for download

downloadcenter.intel.com

91–100 of 112 posts

Re: Intel has released new CPU microcode for download

#91
post #76

Earlier quoted context omitted.

What he said isn't wrong, this new ucode changes fencing and branching prediction semantics regardless of using the instructions added for spectre. The problem is varied. While most people should run the new ucode and pending kernel and toolchain fixes, not all must. Most businesses buy computers on rated performance, and they are about to take an unexpected performance haircut. Intel ucode isn't really optional, as…

I wonder if this will end with Intel selling a lot of new chips, or Intel having to issue massive recalls. I doubt Intel will be able to be able to get away with discount/trade-ins without some serious legal complications. I doubt we'll see entire data centers move to AMD as that would get stupid expensive. For the short term, we might see data centers order extra AMD blades and changing their provisioning systems to…

The first would set a strange precedent without some kind of good faith amends by intel, and so far they have signaled apathetic callousness. I think the legal implications haven't even begun to arise yet because large users are still scrambling to understand the impact and deal with what they have on hand. I speculate some kind of recall or prorate program will come out of it in time.

Dieselgate is the closest thing I can think of recently where a product was marketed primarily on performance that was later rescinded through mechanical and/or software clamping. I wonder if there will be any FTC action for consumers.

Separate from the above thoughts, intel was already testing customer patience with Skylake. It wasn't a substantial performance increase, but it was a substantial pricing increase. A lot of that, because, in merging the 4S (E5-4xxx) and 8S (E7) into one marketing line, a majority of users are paying big premiums for unwanted UPI scalability to get clock speed, cores, and caches they do want. They also gambled poorly on clamping I/O lanes to fight GPU, and with omnipath which is a niche at best. History will most likely judge Krzanich poorly. I expect AMD and IBM will have a good couple years coming up.

Re: Intel has released new CPU microcode for download

#92
post #76

Earlier quoted context omitted.

What he said isn't wrong, this new ucode changes fencing and branching prediction semantics regardless of using the instructions added for spectre. The problem is varied. While most people should run the new ucode and pending kernel and toolchain fixes, not all must. Most businesses buy computers on rated performance, and they are about to take an unexpected performance haircut. Intel ucode isn't really optional, as…

Doesn't the microcode expose new MSRs to control branch prediction? If you don't want to, don't clear the cache.

It's hard to make sense of what Intel are doing in the ucode since communication has been so poor, but "LFENCE terminates all previous instructions" has been variously reported, and there are rumblings that RET or conditional jumps have been changed too. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=886367#17

Intel deserves an extra pwnie award just for the way they handle ucode without changelogs.

Re: Intel has released new CPU microcode for download

#94
post #53

Earlier quoted context omitted.

I was just explained the other day on Hacker News how CPU microcode gets delivered with the Kernel. That it gets installed automatically on every boot. Why is it a separate package (which it turns out I don't have).

Debian removes binary blobs from the kernel, putting them into separate microcode and firmware packages in non-free instead. Intel places restrictions against reverse engineering the microcode, as well as it not being in the prefered original source. Both of these violate the Debian Free Software Guidelines, and thus it can only be in non-free at best.

I thought you need the microcode to boot. How can you function in a non-free OS? And I guess non-free people will have these bugs now?

Also, I have basic Ubuntu. I'm running `apt list --installed` and I don't have the microcode package in the list. Does that command not list dependencies, or am I just missing it?

Re: Intel has released new CPU microcode for download

#95

Earlier quoted context omitted.

I was just explained the other day on Hacker News how CPU microcode gets delivered with the Kernel. That it gets installed automatically on every boot. Why is it a separate package (which it turns out I don't have).

Well it is a separate package because it is fundamentally independent of the kernel. For example, your Debian system might want to use a different kernel like GNU's Hurd, kFreeBSD, or NetBSD, so by keeping those packages separate, they can easily be used interchangeably. Also if you are on an AMD system, you wouldn't want Intel microcode, but you might still want the same Linux kernel. Also another big issue issue is…

This is an excellent explanation. Thank you.

Re: Intel has released new CPU microcode for download

#96
post #92

Earlier quoted context omitted.

Doesn't the microcode expose new MSRs to control branch prediction? If you don't want to, don't clear the cache.

It's hard to make sense of what Intel are doing in the ucode since communication has been so poor, but "LFENCE terminates all previous instructions" has been variously reported, and there are rumblings that RET or conditional jumps have been changed too. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=886367#17 Intel deserves an extra pwnie award just for the way they handle ucode without changelogs.

No disagreement that reverse engineering Linux patches is not the optimal disclosure policy.

Re: Intel has released new CPU microcode for download

#97
post #31
post #17

CPU: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz Not listed :/

Note: We don't actually know what this microcode contains. It could be a bug fix for the one that came out a few days ago, a bug maybe not present on your generation of CPU

Nah, they list all the models around it, like the L5640. This is basically the same CPU with 100MHz shaved off it.

They're system-pulls off eBay, and appear to be some specialist OEM part - note they don't appear on ark, they go L5630 straight to L5640.

Re: Intel has released new CPU microcode for download

#98

Earlier quoted context omitted.

I'm running freenas on a Xeon. I'm assuming i am going to have to install something from supermicro and wait for a freenas (and freebsd) update. Is there anything else I should update?

Similarly, my primary (personal) server is an X10SL7-F with an E3-1231v3 (running FreeBSD). I'm waiting around for Supermicro but I would suggest not holding your breath. On second thought, I suppose the same goes for Asus with regard to my main workstation (Z10PE-D16/WS with a pair of E5-2620v4's). My ThinkPads are much older (T420/W530) and I'm not really expecting anything for them from Lenovo -- especially any ti…

You don't need to wait for BIOS updates to install microcode - install sysutils/devcpu-data and sysrc microcode_update_enable=YES

Re: Intel has released new CPU microcode for download

#99
post #13

Earlier quoted context omitted.

And no reverse engineering possible? I'm a bit surprised there is no enthusiast blog that tries to document intel microcode changes, but maybe I just haven't found it yet.

This might be interesting reading for you: http://inertiawar.com/microcode/ Signed with 2048-bit RSA, and probably encrypted too.

Yes! I love it, even if there were meager returns; basically identifying the algorithms for encrypting/signing the blob and that's all.

Re: Intel has released new CPU microcode for download

#100

Literally tells us nothing about what's in it. Not even a changelog. Not even a sentence hinting as to what might be in it. Incredible.

> Literally tells us nothing about what's in it. Not even a changelog. Not even a sentence hinting as to what might be in it. Incredible. They do have ./releasenote: Intel Processor Microcode Package for Linux 20180108 Release -- Updates upon 20171117 release -- IVT C0 (06-3e-04:ed) 428->42a SKL-U/Y D0 (06-4e-03:c0) ba->c2 BDW-U/Y E/F (06-3d-04:c0) 25->28 HSW-ULT Cx/Dx (06-45-01:72) 20->21 Crystalwell Cx (06-46-01:32…

I hate to say it, but I'm also finding myself scratching my head at this one. I've randomly chosen 3 separate Xeon E5 family processors that are in production, and _each time_ I look at the intel-ucode files, _absolutely none_ of the family-model-stepping outputs from lscpu/dmidecode match.

I'd guess that the format above (using HSW-ULT Cx/Dx as an example), that 01:72 means stepping 1 through 72?

Post reply on HN