-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Update fingerprint for AMD #5472
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Manciukic
merged 2 commits into
firecracker-microvm:main
from
zulinx86:update_fingerprint
Oct 8, 2025
Merged
Update fingerprint for AMD #5472
Manciukic
merged 2 commits into
firecracker-microvm:main
from
zulinx86:update_fingerprint
Oct 8, 2025
+22
−49
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
12aa10c
to
d809488
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #5472 +/- ##
==========================================
- Coverage 82.79% 82.78% -0.01%
==========================================
Files 263 263
Lines 27223 27223
==========================================
- Hits 22538 22537 -1
- Misses 4685 4686 +1
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Manciukic
approved these changes
Oct 8, 2025
The kernel patch [1] passed through CPUID.0x80000021:EAX[5] (VERW_CLEAR) to tell guests that the microcode is applied and the memory form of the VERW instruction can be used to clear the microarchitectural data structures necessary to mitigate TSA-L1 and TSA-SQ. Thanks to it, we can drop the exception for vulnerabilities sysfs check inside guest. In addition to the VERW_CLEAR bit passthrough, the kernel also started always setting CPUID.0x80000021:EAX[9] (NO_SMM_CTL_MSR) since SMM_CTL MSR is not available for KVM guests. [1]: amazonlinux/linux@8d1e0db Signed-off-by: Takahiro Itazuri <[email protected]>
KVM added support for CPUID leaf 0x80000021 [1] and synthesized TSA_{SQ,L1}_NO bits on ECX [2]. However, the second patch has a bug where TSA_{SQ,L1}_NO bits are 1st and 2nd bits [3] but exposed as 11th and 12th bits. This bug happened because it used to be software-defined word (not hardware-defined). Recently, the kernel added another bit (X86_FWEATURE_IBPB_EXIT_TO_USER) for VMScape that is not a hardware- defined bit but a software-defined bit. We update the fingerprints for now to make the fingerprint test pass, but will fix the bug. So we'll need to update again once the fix arrives. [1]: amazonlinux/linux@6457a8c [2]: amazonlinux/linux@6fea1a4 [3]: https://www.amd.com/content/dam/amd/en/documents/resources/bulletin/technical-guidance-for-mitigating-transient-scheduler-attacks.pdf [4]: amazonlinux/linux@ac60717 Signed-off-by: Takahiro Itazuri <[email protected]>
d809488
to
df253f1
Compare
Manciukic
approved these changes
Oct 8, 2025
JackThomson2
approved these changes
Oct 8, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Changes / Reason
See commit messages.
License Acceptance
By submitting this pull request, I confirm that my contribution is made under
the terms of the Apache 2.0 license. For more information on following Developer
Certificate of Origin and signing off your commits, please check
CONTRIBUTING.md
.PR Checklist
tools/devtool checkbuild --all
to verify that the PR passesbuild checks on all supported architectures.
tools/devtool checkstyle
to verify that the PR passes theautomated style checks.
how they are solving the problem in a clear and encompassing way.
[ ] I have updated any relevant documentation (both in code and in the docs)in the PR.
[ ] I have mentioned all user-facing changes inCHANGELOG.md
.[ ] If a specific issue led to this PR, this PR closes the issue.[ ] When making API changes, I have followed theRunbook for Firecracker API changes.
integration tests.
[ ] I have linked an issue to every newTODO
.rust-vmm
.