Live data from Hacker News

Meltdown and Spectre Linux kernel status

kroah.com

141–150 of 186 posts

Re: Meltdown and Spectre Linux kernel status

#141
So if you're running a ARM64 chromebook, the answer appears to be: get fukt.

"For the 4.4 and 4.9 LTS kernels, odds are these patches will never get merged into them, due to the large number of prerequisite patches required. All of those prerequisite patches have been long merged and tested in the android-common kernels, so I think it is a better idea to just rely on those kernel branches instead of the LTS release for ARM systems at this point in time."

Great. Into the trash it goes.

Re: Meltdown and Spectre Linux kernel status

#142
What bothers me is the lack of confirmation on the microcode updates (other than 'soon') – apparently they're out there[1], but Intel's own package has yet to be updated[2]. The 20171215 update carried by some distros only seems to cover HSX/BDX/SKX, so does that mean regular HSW/BDW/SKL users are screwed, are they covered by the 20171117 update, or are the new microcodes simply not ready for all models yet?

Of course, the microcode updates are meaningless without the corresponding kernel patches, but apparently only RHEL and SLES were deemed worthy of receiving those ahead of time, having already rolled them out while Linus and co are left scrambling to integrate the IBRS and retpoline code dumps after the fact.

[1] https://tracker.debian.org/news/899110 [2] https://downloadcenter.intel.com/download/27337/Linux-Proces...

Re: Meltdown and Spectre Linux kernel status

#143
post #136
post #111

Earlier quoted context omitted.

No, one does not need to read in between the lines for that, either. One can simply read the lines. Far from everyone being "just focussed on the technical issues", the questions over the share dealings have made the news in the papers, from The Australian to The Irish Times .

Insider trading happens all the time. But usually you don't read about it in the news. So that the Intel CEO's insider trading got him in trouble shows there's someone fighting against him. Thus, no that's not the full story. I know it's hard to accept but the official scape goat is rarely the trouble maker. Or do you believe that the 2008 crisis was just the doing of that one banker that got jailed?

The 2008 crisis was an emergent systemic risk. (Similar to Spectre) But Meltdown is Intel's fuckup, and the insider trading is on Krzanich. And naturally anyone is happy to point that out, even if they sort of fucked up by implementing speculative execution and thus allowed Spectre on their platform.

Or it can be simply someone that noticed this unusual sale, and saw the circumstances ripe for a bit of naked shorting.

Re: Meltdown and Spectre Linux kernel status

#144
post #99

Earlier quoted context omitted.

I'm not pointing at Debian. I think it is even possible to run Jessie with a current kernel, (which is quite cool) but I haven't tried it. I just upgraded all machines to Stretch and called it a day. I just did the apt-get update; apt-get upgrade dance in a hurry yesterday and thought I might be good. My post was more a reminder to everyone not be lulled into a false sense of security...

I run (many) jessie systems with 4.9 kernels (still haven't made a 4.14 configuration). No problem at all.

You might want to bite the bullet and upgrade from 4.9, because the patches for 4.9 are not so rock solid: https://news.ycombinator.com/item?id=16087736

Re: Meltdown and Spectre Linux kernel status

#145
post #103

Earlier quoted context omitted.

So, there is NO kernel update available for Ubuntu 16.04 at this time.

4.4.110 is available (and patched) right now from kernel.org . Compile it yourself and you'll be safe(r).

Better to recommend something from here: http://kernel.ubuntu.com/~kernel-ppa/mainline/ (especially the daily is relevant now)

Re: Meltdown and Spectre Linux kernel status

#146

Earlier quoted context omitted.

Almost all Linux Mint users "piggy back" on top of the most recent Ubuntu Long Term Support (LTS) release. Currently the most recent Ubuntu LTS is 16.04 and by default it uses the 4.4 Linux kernel. There are patches for the 4.4 kernel from the kernel.org team and the Ubuntu team are testing and integrating these patches. The most recent updates from the Ubuntu team about Meltdown and Spectre is available from this UR…

So, there is NO kernel update available for Ubuntu 16.04 at this time.

http://kernel.ubuntu.com/~kernel-ppa/mainline/daily/

Re: Meltdown and Spectre Linux kernel status

#148

Earlier quoted context omitted.

There's such a thing called: 'embargo period', wherein CVEs are (in most cases) responsibly disclosed to various parties---including several Linux distributions---much ahead than the general public, to coordinate security errata. So you can be assured that Red Hat coordinates with upstream. It also has a serious "Upstream First" policy (with sensible exceptions, of course). As to whether Red Hat has kernel developers…

I really dislike the term "responsible disclosure" in this context. I might consider it responsible to notify a software vendor about a vulnerability in their software so they have a chance to issue a fix to their customers before the rest of the world finds out. But this situation is different. These vulnerabilities affect everyone, and only a special few were allowed to prepare in advance. That's just preferential…

The lay public, aka everyone, isn't considered to be experts in this domain to address the issues. Hence, they disclosed to top tier OS distributions and partners.

It's similar to the Recalls of Takanas airbags in this regard. The manufacturers are informed and they tell us the consumer to bring in our cars. I'm not qualified to replace an explosive airbag, even though I drive a car daily as a lay person.

Re: Meltdown and Spectre Linux kernel status

#149

Earlier quoted context omitted.

I get the irony, but if you could magically visualize the entire internet security threat matrix, this would fall so far down the list and his other work is so high in terms of impact, that it would absolutely no sense for him to take even one minute away from his other activities to address this.

Yes, hence my question. I have tried to setup a HTTPS service and it seems incredibly complicated if you have your own domain name. Even with lets encrypt, if you are using github pages for hosting but your own custom domain, you are out of luck. The point is not that he is not serious about security, point is, it is too hard to get normal security correct. And I am not talking about "cryptography is hard". I am talk…

What question?

Re: Meltdown and Spectre Linux kernel status

#150

Earlier quoted context omitted.

Ubuntu and BSD still have no fixes. It indeed seems like a preferrential disclosure. Plus no 2nd-tier cloud providers like DO were notified.

It will be pretty unfortunate if it turns out that the projects that maintain a kernel (FreeBSD, various others) only received notification at Christmas, while various Linux distros (who have to deal with packaging, release, QA but not developing their own kernel patch since that comes from upstream) got a long warning period. It seems that way... Looking forward to reading about how this played out when the dust set…

There is basically no independent upstream (other than a handful of people). Essentially all the kernel developers work for the companies that have distros plus organizations like Intel, Qualcomm, etc. that do a lot of device enablement.
Post reply on HN