Live data from Hacker News

Intel has released new CPU microcode for download

downloadcenter.intel.com

101–110 of 112 posts

Re: Intel has released new CPU microcode for download

#101

Literally tells us nothing about what's in it. Not even a changelog. Not even a sentence hinting as to what might be in it. Incredible.

> Literally tells us nothing about what's in it. Not even a changelog. Not even a sentence hinting as to what might be in it. Incredible. They do have ./releasenote: Intel Processor Microcode Package for Linux 20180108 Release -- Updates upon 20171117 release -- IVT C0 (06-3e-04:ed) 428->42a SKL-U/Y D0 (06-4e-03:c0) ba->c2 BDW-U/Y E/F (06-3d-04:c0) 25->28 HSW-ULT Cx/Dx (06-45-01:72) 20->21 Crystalwell Cx (06-46-01:32…

These are the updates, sorted by microcode update date, with a cursory look at the generation:

sig 0x000406e3, pf_mask 0xc0, 2017-11-16, rev 0x00c2, size 99328 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=263907 Skylake Core

sig 0x000506e3, pf_mask 0x36, 2017-11-16, rev 0x00c2, size 99328 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=329443 Skylake Core & Xeon

sig 0x000306f4, pf_mask 0x80, 2017-11-17, rev 0x0010, size 17408 Haswell-EX

sig 0x00040671, pf_mask 0x22, 2017-11-17, rev 0x001b, size 13312 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=263793 Broadwell Core

sig 0x000306d4, pf_mask 0xc0, 2017-11-17, rev 0x0028, size 18432 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=198356 Broadwell Core

sig 0x000306f2, pf_mask 0x6f, 2017-11-17, rev 0x003b, size 33792 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=198386 Haswell Core & Xeon

sig 0x00040661, pf_mask 0x32, 2017-11-20, rev 0x0018, size 25600 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=263777 Crystal Well Core

sig 0x00040651, pf_mask 0x72, 2017-11-20, rev 0x0021, size 22528 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=263761 Haswell Core

sig 0x000306c3, pf_mask 0x32, 2017-11-20, rev 0x0023, size 23552 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=198339 Haswell Core & Xeon

sig 0x000306e4, pf_mask 0xed, 2017-12-01, rev 0x042a, size 15360 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=198372 Ivy Bridge Core & Xeon

sig 0x00050654, pf_mask 0xb7, 2017-12-08, rev 0x200003c, size 27648 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=329300 Skylake Core

sig 0x00050662, pf_mask 0x10, 2017-12-16, rev 0x0014, size 31744 Broadwell

sig 0x00050663, pf_mask 0x10, 2017-12-16, rev 0x7000011, size 22528 Broadwell

sig 0x000706a1, pf_mask 0x01, 2017-12-26, rev 0x0022, size 73728 Gemini Lake

sig 0x000906ea, pf_mask 0x22, 2018-01-04, rev 0x0080, size 97280 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=591594 Coffee Lake Core

sig 0x000806e9, pf_mask 0xc0, 2018-01-04, rev 0x0080, size 98304 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=526057 Kaby Lake Core

sig 0x000806ea, pf_mask 0xc0, 2018-01-04, rev 0x0080, size 98304 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=526058 Kaby Lake Core

sig 0x000906e9, pf_mask 0x2a, 2018-01-04, rev 0x0080, size 98304 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=591593 Kaby Lake Core & Xeon

sig 0x000906eb, pf_mask 0x02, 2018-01-04, rev 0x0080, size 98304 http://www.cpu-world.com/cgi-bin/CPUID.pl?&SIGNATURE=591595 Coffee Lake

I believe the oldest processors in the list are the Ivy Bridge sig=0x306e4. That includes E5-xxxx v2 Xeons, circa 2013.

Re: Intel has released new CPU microcode for download

#102
post #86

Earlier quoted context omitted.

I thought you were joking and had a close look at the list. Turns out you're absolutely right! Intel® Pentium® Processor 100 MHz, 50 MHz FSB Intel® Pentium® Processor 120 MHz, 60 MHz FSB Intel® Pentium® Processor 150 MHz, 60 MHz FSB Intel® Pentium® Processor 75 MHz, 50 MHz FSB Intel® Pentium® Processor 90 MHz, 60 MHz FSB

I wouldn't be so quick to say that. it's the cumulatively package including all microcodes. Thus it applies to the listed CPUs. Without having a look, you cannot say which one got an update and which CPU didn't.

Practically though, I downloaded the microcode from the link for my 2009 era i7 920 Family 6 Model 1A stepping 5 CPU (Bloomfield) and applied it to my AMI BIOS and the tool gave the date as 2013 AND after rebooting the Powershell Get-SpeculationControlSettings command shows I do not have the hardware microcode support.

For those interested I used the instructions here -> https://www.delidded.com/how-to-update-cpu-microcode-in-ami-... and to get my family/model/stepping I used https://www.intel.com/content/www/us/en/support/articles/000...

Re: Intel has released new CPU microcode for download

#103
I opened a request on Intel's Community Site requesting microcode changelog documentation. Hopefully I'll get an answer.

https://communities.intel.com/message/518872#518872

Please do click the "I have the same question" button on that thread. Hopefully if it gets enough heat Intel will answer our questions.

As best I can tell at the moment these changes are necessary in order to enable the IBRS and IBPB changes that are currently being discussed on LKML. AFAIK, IBRS and IBPB mitigate against Spectre V2 performance regressions that are introduced with the retpoline changes.

Re: Intel has released new CPU microcode for download

#104
I downloaded this microcode from the link and got the latest BIOS for my Asus motherboard. I found my CPU family/model/stepping using https://www.intel.com/content/www/us/en/support/articles/000...

I used a tool and instructions from https://www.delidded.com/how-to-update-cpu-microcode-in-ami-... to update my AMI BIOS. It recognized the microcode and added it to the list. Unfortunately, the tool showed my microcode as having a date of 2013 even if it was listed and included in the download. So I have to wait for updated microcode I assume. I flashed it anyway. Post boot tests showed I was not protected by microcode... I have a Bloomfield CPU.

This technique will probably work for someone else with a newer CPU.

Re: Intel has released new CPU microcode for download

#105
post #53

Earlier quoted context omitted.

Debian removes binary blobs from the kernel, putting them into separate microcode and firmware packages in non-free instead. Intel places restrictions against reverse engineering the microcode, as well as it not being in the prefered original source. Both of these violate the Debian Free Software Guidelines, and thus it can only be in non-free at best.

I thought you need the microcode to boot. How can you function in a non-free OS? And I guess non-free people will have these bugs now? Also, I have basic Ubuntu. I'm running `apt list --installed` and I don't have the microcode package in the list. Does that command not list dependencies, or am I just missing it?

The CPU has a built-in baseline microcode that it uses on every boot (runtime microcode updates are not persistent), OSes don't need to necessarily update it, but they can.

Re: Intel has released new CPU microcode for download

#106

Earlier quoted context omitted.

I'm running freenas on a Xeon. I'm assuming i am going to have to install something from supermicro and wait for a freenas (and freebsd) update. Is there anything else I should update?

Similarly, my primary (personal) server is an X10SL7-F with an E3-1231v3 (running FreeBSD). I'm waiting around for Supermicro but I would suggest not holding your breath. On second thought, I suppose the same goes for Asus with regard to my main workstation (Z10PE-D16/WS with a pair of E5-2620v4's). My ThinkPads are much older (T420/W530) and I'm not really expecting anything for them from Lenovo -- especially any ti…

Supermoto bios updates: https://www.supermicro.com/support/security_Intel-SA-00088.c...

Re: Intel has released new CPU microcode for download

#107

Earlier quoted context omitted.

I was just explained the other day on Hacker News how CPU microcode gets delivered with the Kernel. That it gets installed automatically on every boot. Why is it a separate package (which it turns out I don't have).

Well it is a separate package because it is fundamentally independent of the kernel. For example, your Debian system might want to use a different kernel like GNU's Hurd, kFreeBSD, or NetBSD, so by keeping those packages separate, they can easily be used interchangeably. Also if you are on an AMD system, you wouldn't want Intel microcode, but you might still want the same Linux kernel. Also another big issue issue is…

Does this mean that my Ubuntu installation runs stock Intel microcode? It means I actually have to know about this, and then go out of my way and know how to install it? Or should it be installed by default on Ubuntu? Because the package called `intel-microcode` isn't installed for me now.

Re: Intel has released new CPU microcode for download

#108

Earlier quoted context omitted.

> Literally tells us nothing about what's in it. Not even a changelog. Not even a sentence hinting as to what might be in it. Incredible. They do have ./releasenote: Intel Processor Microcode Package for Linux 20180108 Release -- Updates upon 20171117 release -- IVT C0 (06-3e-04:ed) 428->42a SKL-U/Y D0 (06-4e-03:c0) ba->c2 BDW-U/Y E/F (06-3d-04:c0) 25->28 HSW-ULT Cx/Dx (06-45-01:72) 20->21 Crystalwell Cx (06-46-01:32…

I hate to say it, but I'm also finding myself scratching my head at this one. I've randomly chosen 3 separate Xeon E5 family processors that are in production, and _each time_ I look at the intel-ucode files, _absolutely none_ of the family-model-stepping outputs from lscpu/dmidecode match. I'd guess that the format above (using HSW-ULT Cx/Dx as an example), that 01:72 means stepping 1 through 72?

Just an update in case that someone is experiencing something similar.

1.) If using RHEL, most likely the latest microcode updated offered via RHEL entitlements will contain the requisite updates.

2.) Slapping myself over this one(!), but the family, model, and stepping ID's need to be changed to hex. I confirmed this via inspecting a node which was patched using the latest updates (kernel & microcode) from RHEL; I am now able to verify that the majority of the microcode offered by Intel appears to be ready to go.

Post reply on HN