[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Openstack-security] [Bug 1777460] Re: Whitelist two more SSBD-related CPU flags for AMD ('amd-ssbd', 'amd-no-ssb')

Reviewed:  https://review.openstack.org/607296
Committed: https://git.openstack.org/cgit/openstack/nova/commit/?id=c85f5e22e1cb8afd756341517bd7284ffc8e505b
Submitter: Zuul
Branch:    stable/ocata

commit c85f5e22e1cb8afd756341517bd7284ffc8e505b
Author: Dan Smith <dansmith at redhat.com>
Date:   Mon Jun 18 14:13:29 2018 -0700

    [Stable Only] Add amd-ssbd and amd-no-ssb CPU flags
    Update the whitelist for the latest new CPU flags for mitigation
    of recent security issues.
    Change-Id: I8686a4755777c8c720c40d4111cc469676d2a5fd
    Closes-Bug: #1777460
    (cherry picked from commit f8aca778f704983bc7ebb0a75d42914fee2dac06)
    (cherry picked from commit 682ee60803c0e6a468e701282a18cee1c118c9df)

** Changed in: nova/ocata
       Status: In Progress => Fix Committed

You received this bug notification because you are a member of OpenStack
Security SIG, which is subscribed to OpenStack.

  Whitelist two more SSBD-related CPU flags for AMD ('amd-ssbd',  'amd-

Status in OpenStack Compute (nova):
  Won't Fix
Status in OpenStack Compute (nova) ocata series:
  Fix Committed
Status in OpenStack Compute (nova) pike series:
  Fix Committed
Status in OpenStack Compute (nova) queens series:
  Fix Committed

Bug description:
  In addition to the existing 'virt-ssbd', future AMD CPUs will have
  another (architectural) way to deal with SSBD (Speculative Store Bypass
  Disable), via the CPU flag: 'amd-ssbd'.

  Furthermore, future AMD CPUs also will expose a mechanism to tell the
  guest that the "Speculative Store Bypass Disable" (SSBD) is not needed
  and that the CPU is all good.  This is via the CPU flag: 'amd-no-ssb'

  In summary, two new flags are[1][2]:


  It is recommended to add the above two flags to the whitelist of Nova's
  `cpu_model_extra_flags` config attribute -- for stable branches (Queens,
  Pike and Ocata).

  For Rocky and above release, no such white-listing is required, since we
  allow free-form CPU flags[3].

      * * *

  Additional notes (from the QEMU mailing list thread[4]) related to
  performance and live migration:

    - tl;dr: On an AMD Compute node, a guest should be presented with
      'amd-ssbd', if available, in preference to 'virt-ssbd'.

      Details: Tom Lendacky from AMD writes[4] -- "The idea behind
      'virt-ssbd' was to provide an architectural method for a guest to do
      SSBD when 'amd-ssbd' isn't present.  The 'amd-ssbd' feature will use
      SPEC_CTRL which is intended to not be intercepted and will be fast.
      The use of 'virt-ssbd' will always be intercepted and therefore will
      not be as fast.  So a guest should be presented with 'amd-ssbd', if
      available, in preference to 'virt-ssbd'."

    - It is safe to use 'amd-ssbd' (it is an architectural method for
      guest to do SSBD) in a guest which can be live migrated between
      different generations/families of AMD CPU.

  [1] libvirt patch:
  [2] QEMU patch:
  [3] http://git.openstack.org/cgit/openstack/nova/commit/?id=cc27a20 --
      libvirt: Lift the restriction of choices for `cpu_model_extra_flags`
  [4] https://lists.nongnu.org/archive/html/qemu-devel/2018-06/msg02301.html

To manage notifications about this bug go to: