Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #191703 > unrolled thread

Kernel for Spectre and Meltdown

Started byDextin Jerafmel <jerafmel@yahoo.com>
First post2018-01-29 09:10 +0100
Last post2018-01-29 10:50 +0100
Articles 20 on this page of 81 — 25 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Kernel for Spectre and Meltdown Dextin Jerafmel <jerafmel@yahoo.com> - 2018-01-29 09:10 +0100
    Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 10:00 +0100
      Re: Kernel for Spectre and Meltdown arne <sp113438@telfort.nl> - 2018-01-29 10:50 +0100
        Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 11:50 +0100
          Re: Kernel for Spectre and Meltdown arne <sp113438@telfort.nl> - 2018-01-29 13:30 +0100
      Re: Kernel for Spectre and Meltdown Jonathan Dowland <jmtd@debian.org> - 2018-01-29 10:50 +0100
      Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 11:20 +0100
        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 12:40 +0100
          Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-01-29 14:30 +0100
            Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 14:50 +0100
          Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 14:30 +0100
            Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 15:00 +0100
              Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 15:30 +0100
                Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-01-29 16:50 +0100
                  Re: Kernel for Spectre and Meltdown Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-29 17:20 +0100
                    Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 18:40 +0100
                  Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 19:10 +0100
                    Re: Kernel for Spectre and Meltdown "Thomas Schmitt" <scdbackup@gmx.net> - 2018-01-29 19:40 +0100
                      Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 20:00 +0100
                    Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 20:40 +0100
                      Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-30 22:50 +0100
                        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 23:10 +0100
                  Re: Kernel for Spectre and Meltdown Elimar Riesebieter <riesebie@lxtec.de> - 2018-01-30 16:30 +0100
                    Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 17:20 +0100
                      Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 18:00 +0100
                        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-31 14:50 +0100
            Re: Kernel for Spectre and Meltdown Carl Fink <carl@finknetwork.com> - 2018-01-29 15:50 +0100
              Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 18:40 +0100
      Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 11:30 +0100
        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 13:40 +0100
          Re: Kernel for Spectre and Meltdown Michael Stone <mstone@debian.org> - 2018-01-29 14:00 +0100
        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 14:10 +0100
          Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 19:20 +0100
            Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 19:40 +0100
              Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 20:00 +0100
          Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 10:50 +0100
            Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-30 12:20 +0100
              Re: Kernel for Spectre and Meltdown Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-30 14:30 +0100
                Re: Kernel for Spectre and Meltdown Gene Heskett <gheskett@shentel.net> - 2018-01-30 14:50 +0100
                Re: Kernel for Spectre and Meltdown "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2018-01-30 16:40 +0100
                Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-31 19:20 +0100
                  Re: Kernel for Spectre and Meltdown Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-31 19:30 +0100
                  Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-31 19:40 +0100
                    Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-31 23:40 +0100
                      Re: Kernel for Spectre and Meltdown Richard Hector <richard@walnut.gen.nz> - 2018-01-31 23:50 +0100
                        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-01 00:10 +0100
                          Re: Kernel for Spectre and Meltdown Richard Hector <richard@walnut.gen.nz> - 2018-02-01 00:20 +0100
                            Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-01 00:50 +0100
                Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-01 13:10 +0100
                  Re: Kernel for Spectre and Meltdown Andy Smith <andy@strugglers.net> - 2018-02-02 05:40 +0100
                    Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 09:10 +0100
                      Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-02-03 15:50 +0100
                        Re: Kernel for Spectre and Meltdown Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-02-03 16:40 +0100
                          Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 18:10 +0100
                          Re: Kernel for Spectre and Meltdown David Wright <deblis@lionunicorn.co.uk> - 2018-02-03 18:30 +0100
                            Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 23:50 +0100
                      Re: Kernel for Spectre and Meltdown David Wright <deblis@lionunicorn.co.uk> - 2018-02-03 18:20 +0100
                        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 23:10 +0100
                        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 23:10 +0100
                          Re: Kernel for Spectre and Meltdown Andy Smith <andy@strugglers.net> - 2018-02-04 00:20 +0100
                            Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-04 01:10 +0100
                              Re: Kernel for Spectre and Meltdown Andy Smith <andy@strugglers.net> - 2018-02-04 16:30 +0100
                                Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-05 00:10 +0100
                                Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-05 00:10 +0100
                            Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-02-04 05:30 +0100
      comment and new question--when do upgrades take effect  (was: Re: Kernel for Spectre and Meltdown) rhkramer@gmail.com - 2018-01-29 14:20 +0100
        Re: comment and new question--when do upgrades take effect  (was:  Re: Kernel for Spectre and Meltdown) Roberto C. Sánchez <roberto@debian.org> - 2018-01-29 14:50 +0100
        Re: comment and new question--when do upgrades take effect  (was:  Re: Kernel for Spectre and Meltdown) Joe <joe@jretrading.com> - 2018-01-29 14:50 +0100
          Re: comment and new question--when do upgrades take effect (was: Re:  Kernel for Spectre and Meltdown) Boyan Penkov <boyan.penkov@gmail.com> - 2018-01-29 15:40 +0100
            Re: comment and new question--when do upgrades take effect Richard Hector <richard@walnut.gen.nz> - 2018-01-30 00:20 +0100
              Re: comment and new question--when do upgrades take effect Boyan Penkov <boyan.penkov@gmail.com> - 2018-01-30 01:00 +0100
          Re: comment and new question--when do upgrades take effect  (was:  Re: Kernel for Spectre and Meltdown) David Wright <deblis@lionunicorn.co.uk> - 2018-01-29 17:20 +0100
        Re: comment and new question--when do upgrades take effect  (was:  Re: Kernel for Spectre and Meltdown) Andy Smith <andy@strugglers.net> - 2018-01-29 15:20 +0100
          Re: comment and new question--when do upgrades take effect Richard Owlett <rowlett@cloud85.net> - 2018-01-29 15:40 +0100
            Re: comment and new question--when do upgrades take effect Roberto C. Sánchez <roberto@debian.org> - 2018-01-29 15:40 +0100
              Re: comment and new question--when do upgrades take effect <tomas@tuxteam.de> - 2018-01-29 16:00 +0100
                Re: comment and new question--when do upgrades take effect Richard Owlett <rowlett@cloud85.net> - 2018-01-29 16:20 +0100
                  Re: comment and new question--when do upgrades take effect David Wright <deblis@lionunicorn.co.uk> - 2018-01-29 16:50 +0100
          Re: comment and new question--when do upgrades take effect (side  question) Neo <neo@spacerat.ch> - 2018-01-29 17:10 +0100
        Re: comment and new question--when do upgrades take effect  (was:  Re: Kernel for Spectre and Meltdown) Michael Lange <klappnase@freenet.de> - 2018-01-29 19:20 +0100
    Re: Kernel for Spectre and Meltdown Bastien Durel <bastien@durel.org> - 2018-01-29 10:50 +0100

Page 1 of 5  [1] 2 3 4 5  Next page →


#191703 — Kernel for Spectre and Meltdown

FromDextin Jerafmel <jerafmel@yahoo.com>
Date2018-01-29 09:10 +0100
SubjectKernel for Spectre and Meltdown
Message-ID<vdcFP-1G3-1@gated-at.bofh.it>
Hello

I've installed Debian 9.3 about one and a half month ago . I'm newbie to Linux world
My Kernel was 4.9.0.3 at the first of installation . After upgrading ( sudo apt upgrade ) it becomes 4.9.0.4
But in Your site You've mentioned Kernel for Debian Stretch is 4.9.65 and You updated it for Spectre and Meltdown bugs
I tried to search for available Kernel images but there isn't any newer Kernel than 4.9.0.5

Please guide me

Thanks a lot

[toc] | [next] | [standalone]


#191704

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-29 10:00 +0100
Message-ID<vddsd-1Zm-1@gated-at.bofh.it>
In reply to#191703

[Multipart message — attachments visible in raw view] — view raw

On 29 January 2018 at 07:52, Dextin Jerafmel <jerafmel@yahoo.com> wrote:

> Hello
>
> I've installed Debian 9.3 about one and a half month ago . I'm newbie to
> Linux world
> My Kernel was 4.9.0.3 at the first of installation . After upgrading (
> sudo apt upgrade ) it becomes 4.9.0.4
> But in Your site You've mentioned Kernel for Debian Stretch is 4.9.65 and
> You updated it for Spectre and Meltdown bugs
> I tried to search for available Kernel images but there isn't any newer
> Kernel than 4.9.0.5
>
> Please guide me
>

​Your need to upgrade to unstable (Debian Sid).  Then you need to get the
latest kernel from the kernel.org website.
You also need to install GCC7 in sid which will give you version 7.3.0 at
present.  That is a new enough compiler to be able to properly install the
spectre and meltdown fixes.
Then you need to run the spectre/meltdown checker which you can get from a
github site and run locally on your box to know it's really installed
properly.
AFAICT at present running a kernel with spectre and meltdown protection
means running debian in the opposite way it is usually billed as to the
outside world ie unstable for quite some time.

Eventually gcc 7.3 could become available in buster/testing but I don't
know when.

I think gentoo is  a good distribution to try in the current security
vulnerability situation.  It is good for kernel compilations and
modifications etc.

Running gcc 7.3 is as easy in gentoo stable is it is gentoo testing.  The
ebuild is there now and the latest version binunits (2.30) is getting
readied.  I have installed
gcc 7.3 on it and soon I will uprade the kernel shortly.  New kernels are
in the pipeline that will have more spectre fixes added.

I will fire them all in to my gentoo  install soon like a deck of cards.

Cheers

Regards

Michael Fothergill



​


>
> Thanks a lot
>
>

[toc] | [prev] | [next] | [standalone]


#191707

Fromarne <sp113438@telfort.nl>
Date2018-01-29 10:50 +0100
Message-ID<vdeeB-2vu-3@gated-at.bofh.it>
In reply to#191704
On Mon, 29 Jan 2018 08:35:58 +0000
Michael Fothergill <michael.fothergill@gmail.com> wrote:
 
> 
> ​Your need to upgrade to unstable (Debian Sid).  Then you need to get
> the latest kernel from the kernel.org website.
> You also need to install GCC7 in sid which will give you version
> 7.3.0 at present.  That is a new enough compiler to be able to
> properly install the spectre and meltdown fixes.
> Then you need to run the spectre/meltdown checker which you can get
> from a github site and run locally on your box to know it's really
> installed properly.

sudo install spectre-meltdown-checker
sudo spectre-meltdown-checker

works at least in stretch.

[toc] | [prev] | [next] | [standalone]


#191714

FromMichael Lange <klappnase@freenet.de>
Date2018-01-29 11:50 +0100
Message-ID<vdfaF-35w-5@gated-at.bofh.it>
In reply to#191707
On Mon, 29 Jan 2018 10:48:27 +0100
arne <sp113438@telfort.nl> wrote:

> sudo install spectre-meltdown-checker
> sudo spectre-meltdown-checker
> 
> works at least in stretch.

Seems like stretch-backports must be enabled for that, though.

Regards

Michael


.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

You speak of courage.  Obviously you do not know the difference between
courage and foolhardiness.  Always it is the brave ones who die, the
soldiers.
		-- Kor, the Klingon Commander, "Errand of Mercy",
		   stardate 3201.7

[toc] | [prev] | [next] | [standalone]


#191718

Fromarne <sp113438@telfort.nl>
Date2018-01-29 13:30 +0100
Message-ID<vdgJs-4b4-9@gated-at.bofh.it>
In reply to#191714
> > sudo install spectre-meltdown-checker
> > sudo spectre-meltdown-checker
> > 
> > works at least in stretch.  
> 
> Seems like stretch-backports must be enabled for that, though.


You are right. I forgot to check.

[toc] | [prev] | [next] | [standalone]


#191708

FromJonathan Dowland <jmtd@debian.org>
Date2018-01-29 10:50 +0100
Message-ID<vdeeB-2vu-7@gated-at.bofh.it>
In reply to#191704
On Mon, Jan 29, 2018 at 08:35:58AM +0000, Michael Fothergill wrote:
>​Your need to upgrade to unstable (Debian Sid).  Then you need to get the
>latest kernel from the kernel.org website.

This is not good advice to a beginner.

>You also need to install GCC7 in sid which will give you version 7.3.0 at
>present.  That is a new enough compiler to be able to properly install the
>spectre and meltdown fixes.
>Then you need to run the spectre/meltdown checker which you can get from a
>github site and run locally on your box to know it's really installed
>properly.

spectre-meltdown-checker is packaged (in sid), this is a better route to
get the script as it is (or will be) adjusted to work properly on a
Debian system.

-- 

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland
⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net
⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


#191712

Fromdeloptes <deloptes@gmail.com>
Date2018-01-29 11:20 +0100
Message-ID<vdeHE-2Uy-11@gated-at.bofh.it>
In reply to#191704
Michael Fothergill wrote:

> Your need to upgrade to unstable (Debian Sid).  Then you need to get the
> latest kernel from the kernel.org website.

worst BS ever seen - DON'T LISTEN TO THIS PLEASE

Michael, please stop writing such things in public

regards

[toc] | [prev] | [next] | [standalone]


#191716

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-29 12:40 +0100
Message-ID<vdfX4-3Cf-13@gated-at.bofh.it>
In reply to#191712

[Multipart message — attachments visible in raw view] — view raw

On 29 January 2018 at 10:10, deloptes <deloptes@gmail.com> wrote:

> Michael Fothergill wrote:
>
> > Your need to upgrade to unstable (Debian Sid).  Then you need to get the
> > latest kernel from the kernel.org website.
>
> worst BS ever seen - DON'T LISTEN TO THIS PLEASE
>
> Michael, please stop writing such things in public
>

​I accept that are some kernels that you could run in stable apparently
that address the security issue etc.
I apologise for inaccuracy there.
But perhaps not all of what I posted is BS.

Cheers

MF​


>
> regards
>
>

[toc] | [prev] | [next] | [standalone]


#191724

Fromrhkramer@gmail.com
Date2018-01-29 14:30 +0100
Message-ID<vdhFv-4LX-3@gated-at.bofh.it>
In reply to#191716
On Monday, January 29, 2018 06:22:50 AM Michael Fothergill wrote:
> ​I accept that are some kernels that you could run in stable apparently
> that address the security issue etc.

I'd go a step further--it's not some (random) kernels that you could run, but 
it is the updated kernels (now, and unless a regression, going forward) that 
will have the fix(es) and will run "automatically" (perhaps after a reboot).

[toc] | [prev] | [next] | [standalone]


#191728

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-29 14:50 +0100
Message-ID<vdhYS-4U8-3@gated-at.bofh.it>
In reply to#191724

[Multipart message — attachments visible in raw view] — view raw

On 29 January 2018 at 13:26, <rhkramer@gmail.com> wrote:

> On Monday, January 29, 2018 06:22:50 AM Michael Fothergill wrote:
> > ​I accept that are some kernels that you could run in stable apparently
> > that address the security issue etc.
>

​Do they work on spectre as well as meltdown?
Sorry for not replying on the site by mistake.

Regards

MF​



>
> I'd go a step further--it's not some (random) kernels that you could run,
> but
> it is the updated kernels (now, and unless a regression, going forward)
> that
> will have the fix(es) and will run "automatically" (perhaps after a
> reboot).
>
>
>

[toc] | [prev] | [next] | [standalone]


#191725

Fromdeloptes <deloptes@gmail.com>
Date2018-01-29 14:30 +0100
Message-ID<vdhFv-4LX-7@gated-at.bofh.it>
In reply to#191716
Michael Fothergill wrote:

> I accept that are some kernels that you could run in stable apparently
> that address the security issue etc.
> I apologise for inaccuracy there.
> But perhaps not all of what I posted is BS.

You can run any kernel in stable

I just build 4.14

make oldconfig
make -j4 deb-pkg

what has gcc7 to do with the patches is unclear to me, but I admit I have
never worried about.

My conclusion to this Spectre and Meltdown hysteria is, that a single
machine in a secure environment is not exactly endangered.
People should better take care of their mobile devices, especially phones
and tablets, where you need neither Spectre nor Meltdown to compromise.

regards

[toc] | [prev] | [next] | [standalone]


#191730

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-29 15:00 +0100
Message-ID<vdi8y-4Zs-3@gated-at.bofh.it>
In reply to#191725

[Multipart message — attachments visible in raw view] — view raw

On 29 January 2018 at 13:28, deloptes <deloptes@gmail.com> wrote:

> Michael Fothergill wrote:
>
> > I accept that are some kernels that you could run in stable apparently
> > that address the security issue etc.
> > I apologise for inaccuracy there.
> > But perhaps not all of what I posted is BS.
>
> You can run any kernel in stable
>
> I just build 4.14
>
> make oldconfig
> make -j4 deb-pkg
>
> what has gcc7 to do with the patches is unclear to me, but I admit I have
> never worried about.
>

​I thought you had to have gcc7 because it included a backport of some code
used in GCC 8 that was needed to allow e.g. the spectre fix to work
properly.........

If you could use any compiler to do it then earlier my post truly would be
BS.​


​Cheers

MF​

>
> My conclusion to this Spectre and Meltdown hysteria is, that a single
> machine in a secure environment is not exactly endangered.
> People should better take care of their mobile devices, especially phones
> and tablets, where you need neither Spectre nor Meltdown to compromise.
>
> regards
>
>

[toc] | [prev] | [next] | [standalone]


#191733

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-29 15:30 +0100
Message-ID<vdiBz-5p3-3@gated-at.bofh.it>
In reply to#191730

[Multipart message — attachments visible in raw view] — view raw

On 29 January 2018 at 13:35, Michael Fothergill <
michael.fothergill@gmail.com> wrote:

>
>
> On 29 January 2018 at 13:28, deloptes <deloptes@gmail.com> wrote:
>
>> Michael Fothergill wrote:
>>
>> > I accept that are some kernels that you could run in stable apparently
>> > that address the security issue etc.
>> > I apologise for inaccuracy there.
>> > But perhaps not all of what I posted is BS.
>>
>> You can run any kernel in stable
>>
>> I just build 4.14
>>
>> make oldconfig
>> make -j4 deb-pkg
>>
>> what has gcc7 to do with the patches is unclear to me, but I admit I have
>> never worried about.
>>
>
> ​I thought you had to have gcc7 because it included a backport of some
> code used in GCC 8 that was needed to allow e.g. the spectre fix to work
> properly.........
>
> If you could use any compiler to do it then earlier my post truly would be
> BS.​
>

PS as I understand (correct me if I am wrong)  the compiler needs to be GCC
7.3.0 or greater (I believe the 7.2 rc2 also works); if you used a compiler
earlier that you would get a kernel that works OK in very respect except
the for spectre fix itself.

The spectre-meltdown checker  if you ran it (as I did in gentoo with the
7.2.1 compiler or whatever it was) said that the compiler I used was not
capable of properly installing the spectre fix so it was not enabled.

GCC 7.3.0 is now available in Debian sid.

Cheers

MF  ​


>
>
> ​Cheers
>
> MF​
>
>>
>> My conclusion to this Spectre and Meltdown hysteria is, that a single
>> machine in a secure environment is not exactly endangered.
>> People should better take care of their mobile devices, especially phones
>> and tablets, where you need neither Spectre nor Meltdown to compromise.
>>
>> regards
>>
>>
>

[toc] | [prev] | [next] | [standalone]


#191740

Fromrhkramer@gmail.com
Date2018-01-29 16:50 +0100
Message-ID<vdjQZ-69x-1@gated-at.bofh.it>
In reply to#191733
On Monday, January 29, 2018 09:06:13 AM Michael Fothergill wrote:
> On 29 January 2018 at 13:35, Michael Fothergill <
> 
> michael.fothergill@gmail.com> wrote:
> >> what has gcc7 to do with the patches is unclear to me, but I admit I
> >> have never worried about.
> > 
> > ​I thought you had to have gcc7 because it included a backport of some
> > code used in GCC 8 that was needed to allow e.g. the spectre fix to work
> > properly.........
> > 
> > If you could use any compiler to do it then earlier my post truly would
> > be BS.​
> 
> PS as I understand (correct me if I am wrong)  the compiler needs to be GCC
> 7.3.0 or greater (I believe the 7.2 rc2 also works); if you used a compiler
> earlier that you would get a kernel that works OK in very respect except
> the for spectre fix itself.

Again, checking / confirming my understanding, if you download a kernel image 
(which is normal for me), there is no need for me to have any version of GCC 
as the image is pre-compiled.

On the other hand, if I download kernel source, I would need GCC, and a 
version that is sufficient for the code.

I have only compiled the kernel a few times, all a long time ago (12 to 15 
years?), on the advice of members of my local LUG, and maybe as a learning 
experience.  It is far from necessary for most of us.  (Some members of the 
LUG seemed to think it was imperative, and maybe it is for older smaller 
machines or maybe to squeeze the very last little bit of efficiency out of the 
system.)

[toc] | [prev] | [next] | [standalone]


#191744

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2018-01-29 17:20 +0100
Message-ID<vdkk1-6Al-7@gated-at.bofh.it>
In reply to#191740
On Mon, Jan 29, 2018 at 10:47:57AM -0500, rhkramer@gmail.com wrote:
> Again, checking / confirming my understanding, if you download a kernel image 
> (which is normal for me), there is no need for me to have any version of GCC 
> as the image is pre-compiled.
> 
> On the other hand, if I download kernel source, I would need GCC, and a 
> version that is sufficient for the code.

All correct.  (Plus several additional development packages, not just gcc.)

> I have only compiled the kernel a few times, all a long time ago (12 to 15 
> years?), on the advice of members of my local LUG, and maybe as a learning 
> experience.  It is far from necessary for most of us.  (Some members of the 
> LUG seemed to think it was imperative, and maybe it is for older smaller 
> machines or maybe to squeeze the very last little bit of efficiency out of the 
> system.)

Before Linux 2.6 (or thereabouts), compiling one's own kernel was a much
more common event.  Certainly it wasn't required for ordinary use, but
hardware was much less powerful back then, so a leaner kernel tuned
exactly for the target system was sometimes desirable.

With Linux 2.6, things started to change.  The Linux developers
acknowledged that the source code they were releasing wasn't really
"stable" in the sense that end users expected; the distributions (Red Hat,
Debian, et al.) were the ones doing the final stabilization and patching.

Also, the number of configuration questions one had to answer before
compiling a kernel started to balloon out of control.

This was also the time when initramfs/initrd images started to be used,
at least by Debian.  My understanding of this is only partial, but it
seems that the initrd allows some adjustments of the kernel for the
target system (installation of driver modules, firmware) which may
previously have required a reconfiguration and recompilation.

Hardware was also becoming more powerful, as one would expect.  More RAM
meant less pressure to produce minimalist kernel images.

All of these things put together meant that for most users, Debian's
kernel images were good enough that they didn't feel a need to build
their own kernels.

[toc] | [prev] | [next] | [standalone]


#191747

Fromdeloptes <deloptes@gmail.com>
Date2018-01-29 18:40 +0100
Message-ID<vdlzs-7hH-9@gated-at.bofh.it>
In reply to#191744
Greg Wooledge wrote:

> Hardware was also becoming more powerful, as one would expect.  More RAM
> meant less pressure to produce minimalist kernel images.
> 
> All of these things put together meant that for most users, Debian's
> kernel images were good enough that they didn't feel a need to build
> their own kernels.

+ disk space got cheeper, so one could compile all drivers, install them and
don't care and let initrd make skript pick up what is needed to load at
boot - the rest would stay there and be loaded (later triggers in udev) if
needed.

[toc] | [prev] | [next] | [standalone]


#191748

FromMichael Lange <klappnase@freenet.de>
Date2018-01-29 19:10 +0100
Message-ID<vdm2u-7Ky-25@gated-at.bofh.it>
In reply to#191740
On Mon, 29 Jan 2018 10:47:57 -0500
rhkramer@gmail.com wrote:

> Again, checking / confirming my understanding, if you download a kernel
> image (which is normal for me), there is no need for me to have any
> version of GCC as the image is pre-compiled.

Sure.

> 
> On the other hand, if I download kernel source, I would need GCC, and a 
> version that is sufficient for the code.

That is point here, at least as far as I understood for that new "spectre
fix" one needs a compiler that is "retpoline-aware" (as the
"checker"-script calls it, whatever that means) and currently this is only
true for gcc >= 7.3. So if you compile the kernel on Stretch with gcc-6
this "retpoline" fix will not work.

Regards

Michael


.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

Earth -- mother of the most beautiful women in the universe.
		-- Apollo, "Who Mourns for Adonais?" stardate 3468.1

[toc] | [prev] | [next] | [standalone]


#191753

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2018-01-29 19:40 +0100
Message-ID<vdmvw-7VI-39@gated-at.bofh.it>
In reply to#191748
Hi,

Michael Lange wrote:
> compiler that is "retpoline-aware" (as the
> "checker"-script calls it, whatever that means)

The term was coined by Google engineers

  https://support.google.com/faqs/answer/7625886
  "The name “retpoline” is a portmanteau of “return” and “trampoline.”
   It is a trampoline construct constructed using return operations which
   also figuratively ensures that any associated speculative execution
   will “bounce” endlessly.  

   (If it brings you any amusement: imagine speculative execution as an
    overly energetic 7-year old that we must now build a warehouse of
    trampolines around.)"

It is worthwhile to read this early description of Spectre, which they
call "Variant 2" or "CVE-2017-5715".

Retpoline is on the first view useless effort for the CPU, so i guess
a compiler must be kept from optimizing it away.
The goal is to prevent speculative execution of code at addresses
which the attacker seeded into the branch prediction table of the CPU.


Have a nice day :)

Thomas

[toc] | [prev] | [next] | [standalone]


#191754

FromMichael Lange <klappnase@freenet.de>
Date2018-01-29 20:00 +0100
Message-ID<vdmOS-83T-7@gated-at.bofh.it>
In reply to#191753
On Mon, 29 Jan 2018 19:29:19 +0100
"Thomas Schmitt" <scdbackup@gmx.net> wrote:

> Hi,
> 
> Michael Lange wrote:
> > compiler that is "retpoline-aware" (as the
> > "checker"-script calls it, whatever that means)
> 
> The term was coined by Google engineers
> 
>   https://support.google.com/faqs/answer/7625886
>   "The name “retpoline” is a portmanteau of “return” and “trampoline.”
>    It is a trampoline construct constructed using return operations
> which also figuratively ensures that any associated speculative
> execution will “bounce” endlessly.  
> 
>    (If it brings you any amusement: imagine speculative execution as an
>     overly energetic 7-year old that we must now build a warehouse of
>     trampolines around.)"

Thanks, very well explained for technically limited people like me.
And this also explains why they made the common name of their fix sound
so similar to "Ritalin" :)

Regards

Michael


.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

Men will always be men -- no matter where they are.
		-- Harry Mudd, "Mudd's Women", stardate 1329.8

[toc] | [prev] | [next] | [standalone]


#191782

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-30 20:40 +0100
Message-ID<vdJV9-69s-31@gated-at.bofh.it>
In reply to#191748

[Multipart message — attachments visible in raw view] — view raw

On 29 January 2018 at 18:02, Michael Lange <klappnase@freenet.de> wrote:

> On Mon, 29 Jan 2018 10:47:57 -0500
> rhkramer@gmail.com wrote:
>
> > Again, checking / confirming my understanding, if you download a kernel
> > image (which is normal for me), there is no need for me to have any
> > version of GCC as the image is pre-compiled.
>
> Sure.
>
> >
> > On the other hand, if I download kernel source, I would need GCC, and a
> > version that is sufficient for the code.
>
> That is point here, at least as far as I understood for that new "spectre
> fix" one needs a compiler that is "retpoline-aware" (as the
> "checker"-script calls it, whatever that means) and currently this is only
> true for gcc >= 7.3. So if you compile the kernel on Stretch with gcc-6
> this "retpoline" fix will not work.
>

​For me, the realisation of this felt as if a person had drunk too much
alcohol the night before,
and woke the next morning with a hangover.

After groping around in the medicine cabinet and finding the alka seltzer
one would realise that they
needed to take two tablets not just one to recover and face the reality of
the moment.

One could perhaps argue that the fact that one could use a live
distribution to run sid
and produce a kernel that could be ported to stretch plus the fact that some
kernels that address only the meltdown problem are knocking around in
stretch
etc might make one feel that perhaps one alka seltzer tablet might suffice
instead of two here.

Perhaps otherwise.

I am not really so sure what the correct dosage ought to be now.

Cheers

MF



>
> Regards
>
> Michael
>
>
> .-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.
>
> Earth -- mother of the most beautiful women in the universe.
>                 -- Apollo, "Who Mourns for Adonais?" stardate 3468.1
>
>

[toc] | [prev] | [next] | [standalone]


Page 1 of 5  [1] 2 3 4 5  Next page →

Back to top | Article view | linux.debian.user


csiph-web