Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #191703 > unrolled thread
| Started by | Dextin Jerafmel <jerafmel@yahoo.com> |
|---|---|
| First post | 2018-01-29 09:10 +0100 |
| Last post | 2018-01-29 10:50 +0100 |
| Articles | 20 on this page of 81 — 25 participants |
Back to article view | Back to linux.debian.user
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Kernel for Spectre and Meltdown Dextin Jerafmel <jerafmel@yahoo.com> - 2018-01-29 09:10 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 10:00 +0100
Re: Kernel for Spectre and Meltdown arne <sp113438@telfort.nl> - 2018-01-29 10:50 +0100
Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 11:50 +0100
Re: Kernel for Spectre and Meltdown arne <sp113438@telfort.nl> - 2018-01-29 13:30 +0100
Re: Kernel for Spectre and Meltdown Jonathan Dowland <jmtd@debian.org> - 2018-01-29 10:50 +0100
Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 11:20 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 12:40 +0100
Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-01-29 14:30 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 14:50 +0100
Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 14:30 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 15:00 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 15:30 +0100
Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-01-29 16:50 +0100
Re: Kernel for Spectre and Meltdown Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-29 17:20 +0100
Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 18:40 +0100
Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 19:10 +0100
Re: Kernel for Spectre and Meltdown "Thomas Schmitt" <scdbackup@gmx.net> - 2018-01-29 19:40 +0100
Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 20:00 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 20:40 +0100
Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-30 22:50 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 23:10 +0100
Re: Kernel for Spectre and Meltdown Elimar Riesebieter <riesebie@lxtec.de> - 2018-01-30 16:30 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 17:20 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 18:00 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-31 14:50 +0100
Re: Kernel for Spectre and Meltdown Carl Fink <carl@finknetwork.com> - 2018-01-29 15:50 +0100
Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 18:40 +0100
Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 11:30 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 13:40 +0100
Re: Kernel for Spectre and Meltdown Michael Stone <mstone@debian.org> - 2018-01-29 14:00 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 14:10 +0100
Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 19:20 +0100
Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 19:40 +0100
Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 20:00 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 10:50 +0100
Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-30 12:20 +0100
Re: Kernel for Spectre and Meltdown Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-30 14:30 +0100
Re: Kernel for Spectre and Meltdown Gene Heskett <gheskett@shentel.net> - 2018-01-30 14:50 +0100
Re: Kernel for Spectre and Meltdown "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2018-01-30 16:40 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-31 19:20 +0100
Re: Kernel for Spectre and Meltdown Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-31 19:30 +0100
Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-31 19:40 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-31 23:40 +0100
Re: Kernel for Spectre and Meltdown Richard Hector <richard@walnut.gen.nz> - 2018-01-31 23:50 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-01 00:10 +0100
Re: Kernel for Spectre and Meltdown Richard Hector <richard@walnut.gen.nz> - 2018-02-01 00:20 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-01 00:50 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-01 13:10 +0100
Re: Kernel for Spectre and Meltdown Andy Smith <andy@strugglers.net> - 2018-02-02 05:40 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 09:10 +0100
Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-02-03 15:50 +0100
Re: Kernel for Spectre and Meltdown Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-02-03 16:40 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 18:10 +0100
Re: Kernel for Spectre and Meltdown David Wright <deblis@lionunicorn.co.uk> - 2018-02-03 18:30 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 23:50 +0100
Re: Kernel for Spectre and Meltdown David Wright <deblis@lionunicorn.co.uk> - 2018-02-03 18:20 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 23:10 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 23:10 +0100
Re: Kernel for Spectre and Meltdown Andy Smith <andy@strugglers.net> - 2018-02-04 00:20 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-04 01:10 +0100
Re: Kernel for Spectre and Meltdown Andy Smith <andy@strugglers.net> - 2018-02-04 16:30 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-05 00:10 +0100
Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-05 00:10 +0100
Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-02-04 05:30 +0100
comment and new question--when do upgrades take effect (was: Re: Kernel for Spectre and Meltdown) rhkramer@gmail.com - 2018-01-29 14:20 +0100
Re: comment and new question--when do upgrades take effect (was: Re: Kernel for Spectre and Meltdown) Roberto C. Sánchez <roberto@debian.org> - 2018-01-29 14:50 +0100
Re: comment and new question--when do upgrades take effect (was: Re: Kernel for Spectre and Meltdown) Joe <joe@jretrading.com> - 2018-01-29 14:50 +0100
Re: comment and new question--when do upgrades take effect (was: Re: Kernel for Spectre and Meltdown) Boyan Penkov <boyan.penkov@gmail.com> - 2018-01-29 15:40 +0100
Re: comment and new question--when do upgrades take effect Richard Hector <richard@walnut.gen.nz> - 2018-01-30 00:20 +0100
Re: comment and new question--when do upgrades take effect Boyan Penkov <boyan.penkov@gmail.com> - 2018-01-30 01:00 +0100
Re: comment and new question--when do upgrades take effect (was: Re: Kernel for Spectre and Meltdown) David Wright <deblis@lionunicorn.co.uk> - 2018-01-29 17:20 +0100
Re: comment and new question--when do upgrades take effect (was: Re: Kernel for Spectre and Meltdown) Andy Smith <andy@strugglers.net> - 2018-01-29 15:20 +0100
Re: comment and new question--when do upgrades take effect Richard Owlett <rowlett@cloud85.net> - 2018-01-29 15:40 +0100
Re: comment and new question--when do upgrades take effect Roberto C. Sánchez <roberto@debian.org> - 2018-01-29 15:40 +0100
Re: comment and new question--when do upgrades take effect <tomas@tuxteam.de> - 2018-01-29 16:00 +0100
Re: comment and new question--when do upgrades take effect Richard Owlett <rowlett@cloud85.net> - 2018-01-29 16:20 +0100
Re: comment and new question--when do upgrades take effect David Wright <deblis@lionunicorn.co.uk> - 2018-01-29 16:50 +0100
Re: comment and new question--when do upgrades take effect (side question) Neo <neo@spacerat.ch> - 2018-01-29 17:10 +0100
Re: comment and new question--when do upgrades take effect (was: Re: Kernel for Spectre and Meltdown) Michael Lange <klappnase@freenet.de> - 2018-01-29 19:20 +0100
Re: Kernel for Spectre and Meltdown Bastien Durel <bastien@durel.org> - 2018-01-29 10:50 +0100
Page 2 of 5 — ← Prev page 1 [2] 3 4 5 Next page →
| From | Michael Lange <klappnase@freenet.de> |
|---|---|
| Date | 2018-01-30 22:50 +0100 |
| Message-ID | <vdLWV-7vj-1@gated-at.bofh.it> |
| In reply to | #191782 |
On Tue, 30 Jan 2018 19:14:36 +0000 Michael Fothergill <michael.fothergill@gmail.com> wrote: > > I am not really so sure what the correct dosage ought to be now. Maybe just stick with the booze... ;-) scnr Michael .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. Fascinating is a word I use for the unexpected. -- Spock, "The Squire of Gothos", stardate 2124.5
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-01-30 23:10 +0100 |
| Message-ID | <vdMgh-7RI-1@gated-at.bofh.it> |
| In reply to | #191791 |
[Multipart message — attachments visible in raw view] — view raw
On 30 January 2018 at 21:45, Michael Lange <klappnase@freenet.de> wrote: > On Tue, 30 Jan 2018 19:14:36 +0000 > Michael Fothergill <michael.fothergill@gmail.com> wrote: > > > > > I am not really so sure what the correct dosage ought to be now. > > Maybe just stick with the booze... ;-) > > scnr > > Michael > It's OK. As it turns out, I don't drink but it is still funny...... Cheers MF > > > .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. > > Fascinating is a word I use for the unexpected. > -- Spock, "The Squire of Gothos", stardate 2124.5 > >
[toc] | [prev] | [next] | [standalone]
| From | Elimar Riesebieter <riesebie@lxtec.de> |
|---|---|
| Date | 2018-01-30 16:30 +0100 |
| Message-ID | <vdG1c-3EN-7@gated-at.bofh.it> |
| In reply to | #191740 |
* rhkramer@gmail.com <rhkramer@gmail.com> [2018-01-29 10:47 -0500]:
[...]
> On the other hand, if I download kernel source, I would need GCC, and a
> version that is sufficient for the code.
One can check the compiler version the running kernel is built with
by:
$ cat /proc/version
Linux version 4.14.15-toy-lxtec-amd64 (riesebie@toy) (gcc version 7.3.0 (Debian 7.3.0-1)) #1 SMP Tue Jan 30 14:20:49 CET 2018
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Elimar
--
You cannot propel yourself forward by
patting yourself on the back.
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-01-30 17:20 +0100 |
| Message-ID | <vdGNA-4cp-3@gated-at.bofh.it> |
| In reply to | #191771 |
[Multipart message — attachments visible in raw view] — view raw
On 30 January 2018 at 15:23, Elimar Riesebieter <riesebie@lxtec.de> wrote: > * rhkramer@gmail.com <rhkramer@gmail.com> [2018-01-29 10:47 -0500]: > > [...] > > On the other hand, if I download kernel source, I would need GCC, and a > > version that is sufficient for the code. > > One can check the compiler version the running kernel is built with > by: > > $ cat /proc/version > Linux version 4.14.15-toy-lxtec-amd64 (riesebie@toy) (gcc version 7.3.0 > (Debian 7.3.0-1)) #1 SMP Tue Jan 30 14:20:49 CET 2018 > That is a very useful command. I ran it myself. djt /home/mikef/spectre-meltdown-checker # cat /proc/version Linux version 4.14.14-gentoo (root@djt) (gcc version 7.2.0 (Gentoo 7.2.0-r1)) #1 SMP Tue Jan 23 13:06:23 GMT 2018 Here is a bit of the output from the spectre patch checker: * Mitigation 2 * Kernel compiled with retpoline option: YES * Kernel compiled with a retpoline-aware compiler: NO (kernel reports minimal retpoline compilation) * Retpoline enabled: YES > STATUS: VULNERABLE (Vulnerable: Minimal AMD ASM retpoline) As can be seen here, the compiler I used to create this kernel was not recent enough to make retpoline work. Since I now have gcc 7.3 installed I will do kernel upgrade in a little while and see if I can change the NO in "* Kernel compiled with a retpoline-aware compiler: NO (kernel reports minimal retpoline compilation)" to YES..... I think it will work. Cheers MF > > ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ > > Elimar > -- > You cannot propel yourself forward by > patting yourself on the back. > >
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-01-30 18:00 +0100 |
| Message-ID | <vdHqh-4r9-7@gated-at.bofh.it> |
| In reply to | #191773 |
[Multipart message — attachments visible in raw view] — view raw
On 30 January 2018 at 16:02, Michael Fothergill < michael.fothergill@gmail.com> wrote: > > > On 30 January 2018 at 15:23, Elimar Riesebieter <riesebie@lxtec.de> wrote: > >> * rhkramer@gmail.com <rhkramer@gmail.com> [2018-01-29 10:47 -0500]: >> >> [...] >> > On the other hand, if I download kernel source, I would need GCC, and a >> > version that is sufficient for the code. >> >> One can check the compiler version the running kernel is built with >> by: >> >> $ cat /proc/version >> Linux version 4.14.15-toy-lxtec-amd64 (riesebie@toy) (gcc version 7.3.0 >> (Debian 7.3.0-1)) #1 SMP Tue Jan 30 14:20:49 CET 2018 >> > > That is a very useful command. > > I ran it myself. > > djt /home/mikef/spectre-meltdown-checker # cat /proc/version > Linux version 4.14.14-gentoo (root@djt) (gcc version 7.2.0 (Gentoo > 7.2.0-r1)) #1 SMP Tue Jan 23 13:06:23 GMT 2018 > > Here is a bit of the output from the spectre patch checker: > > > * Mitigation 2 > * Kernel compiled with retpoline option: YES > * Kernel compiled with a retpoline-aware compiler: NO (kernel reports > minimal retpoline compilation) > * Retpoline enabled: YES > > STATUS: VULNERABLE (Vulnerable: Minimal AMD ASM retpoline) > > As can be seen here, the compiler I used to create this kernel was not > recent enough to make retpoline work. > > Since I now have gcc 7.3 installed I will do kernel upgrade in a little > while and see if I can change the NO in > > "* Kernel compiled with a retpoline-aware compiler: NO (kernel reports > minimal retpoline compilation)" > > to YES..... > > I think it will work. > > Cheers MF > I just ran the kernel rebuild: djt /home/mikef # cat /proc/version Linux version 4.14.15-gentoo (root@djt) (gcc version 7.3.0 (Gentoo 7.3.0)) #1 SMP Tue Jan 30 16:22:47 GMT 2018 and now the spectre kernel checker says the following: * Mitigation 2 * Kernel compiled with retpoline option: YES * Kernel compiled with a retpoline-aware compiler: YES (kernel reports full retpoline compilation) * Retpoline enabled: YES > STATUS: NOT VULNERABLE (Mitigation: Full AMD retpoline) New kernels are going to appear soon with fancier fixes for spectre vulnerabilities if I understand it correctly. I can now install them right away; and if I want I can downgrade gentoo testing to gentoo stable and do the very same thing. Cheers MF > > > > > > > > > > > >> >> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ >> >> Elimar >> -- >> You cannot propel yourself forward by >> patting yourself on the back. >> >> >
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-01-31 14:50 +0100 |
| Message-ID | <ve0VY-Hl-9@gated-at.bofh.it> |
| In reply to | #191774 |
[Multipart message — attachments visible in raw view] — view raw
On 30 January 2018 at 16:36, Michael Fothergill < michael.fothergill@gmail.com> wrote: > > > On 30 January 2018 at 16:02, Michael Fothergill < > michael.fothergill@gmail.com> wrote: > >> >> >> On 30 January 2018 at 15:23, Elimar Riesebieter <riesebie@lxtec.de> >> wrote: >> >>> * rhkramer@gmail.com <rhkramer@gmail.com> [2018-01-29 10:47 -0500]: >>> >>> [...] >>> > On the other hand, if I download kernel source, I would need GCC, and a >>> > version that is sufficient for the code. >>> >>> One can check the compiler version the running kernel is built with >>> by: >>> >>> $ cat /proc/version >>> Linux version 4.14.15-toy-lxtec-amd64 (riesebie@toy) (gcc version 7.3.0 >>> (Debian 7.3.0-1)) #1 SMP Tue Jan 30 14:20:49 CET 2018 >>> >> >> That is a very useful command. >> >> I ran it myself. >> >> djt /home/mikef/spectre-meltdown-checker # cat /proc/version >> Linux version 4.14.14-gentoo (root@djt) (gcc version 7.2.0 (Gentoo >> 7.2.0-r1)) #1 SMP Tue Jan 23 13:06:23 GMT 2018 >> >> Here is a bit of the output from the spectre patch checker: >> >> >> * Mitigation 2 >> * Kernel compiled with retpoline option: YES >> * Kernel compiled with a retpoline-aware compiler: NO (kernel reports >> minimal retpoline compilation) >> * Retpoline enabled: YES >> > STATUS: VULNERABLE (Vulnerable: Minimal AMD ASM retpoline) >> >> As can be seen here, the compiler I used to create this kernel was not >> recent enough to make retpoline work. >> >> Since I now have gcc 7.3 installed I will do kernel upgrade in a little >> while and see if I can change the NO in >> >> "* Kernel compiled with a retpoline-aware compiler: NO (kernel >> reports minimal retpoline compilation)" >> >> to YES..... >> >> I think it will work. >> >> Cheers MF >> > > I just ran the kernel rebuild: > > djt /home/mikef # cat /proc/version > Linux version 4.14.15-gentoo (root@djt) (gcc version 7.3.0 (Gentoo > 7.3.0)) #1 SMP Tue Jan 30 16:22:47 GMT 2018 > > and now the spectre kernel checker says the following: > > * Mitigation 2 > * Kernel compiled with retpoline option: YES > * Kernel compiled with a retpoline-aware compiler: YES (kernel reports > full retpoline compilation) > * Retpoline enabled: YES > > STATUS: NOT VULNERABLE (Mitigation: Full AMD retpoline) > > New kernels are going to appear soon with fancier fixes for spectre > vulnerabilities if I understand it correctly. > > I can now install them right away; and if I want I can downgrade gentoo > testing to gentoo stable and do the very same thing. > > Cheers > > MF > It has occured to me that two distributions of linux could be useful for the spectre kernel patches right now. One is sabayon and the other is calculate linux. Both are gentoo based distributions. For a new linux user, I think they could have some advantages over e.g. gentoo itself. Both come with installers so you will avoid the funny learning curve involved in gentoo installs. Sabayon has its own binary package installer called equo (its answer to apt in debian). AFAICT, you can avoid installing kernels with emerge (compiling them) if you want; you have a choice. I think, but I am not 100% sure that you can take the ebuild file for kernel 4.15 from the gentoo kernel source site and install it directly in sabayon. Calculate linux is similar but does not have the equo package installer. I notice that it seems Fedora have made kernels with the spectre patch available. Whether they run in the equivalent of the stable version of the distribution I am not sure. Cheers MF > > > > > > >> >> >> >> >> >> >> >> >> >> >> >>> >>> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ >>> >>> Elimar >>> -- >>> You cannot propel yourself forward by >>> patting yourself on the back. >>> >>> >> >
[toc] | [prev] | [next] | [standalone]
| From | Carl Fink <carl@finknetwork.com> |
|---|---|
| Date | 2018-01-29 15:50 +0100 |
| Message-ID | <vdiUW-5xM-9@gated-at.bofh.it> |
| In reply to | #191725 |
On Mon, Jan 29, 2018 at 02:28:06PM +0100, deloptes wrote: > My conclusion to this Spectre and Meltdown hysteria is, that a single > machine in a secure environment is not exactly endangered. > People should better take care of their mobile devices, especially phones > and tablets, where you need neither Spectre nor Meltdown to compromise. Be fair: you also don't need Spectre or Meldtdown to compromise Linux-based computers. Somethings as simple as going a week between installing security upgrades can do it. -- Carl Fink nitpicking@nitpicking.com Read my blog at blog.nitpicking.com. Reviews! Observations! Stupid mistakes you can correct!
[toc] | [prev] | [next] | [standalone]
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Date | 2018-01-29 18:40 +0100 |
| Message-ID | <vdlzr-7hH-5@gated-at.bofh.it> |
| In reply to | #191737 |
Carl Fink wrote: > Be fair: you also don't need Spectre or Meldtdown to compromise > Linux-based computers. Somethings as simple as going a week between > installing security upgrades can do it. well - at least that's not so easy as windows or android with compromised security in mind
[toc] | [prev] | [next] | [standalone]
| From | Michael Lange <klappnase@freenet.de> |
|---|---|
| Date | 2018-01-29 11:30 +0100 |
| Message-ID | <vdeRk-2XQ-1@gated-at.bofh.it> |
| In reply to | #191704 |
Hi, On Mon, 29 Jan 2018 08:35:58 +0000 Michael Fothergill <michael.fothergill@gmail.com> wrote: > Your need to upgrade to unstable (Debian Sid). Then you need to get > the latest kernel from the kernel.org website. > You also need to install GCC7 in sid which will give you version 7.3.0 > at present. That is a new enough compiler to be able to properly > install the spectre and meltdown fixes. The "meltdown fix" (a.k.a. page tables isolation) is already included in Stretch's 4.9 kernel. > Then you need to run the spectre/meltdown checker which you can get > from a github site and run locally on your box to know it's really > installed properly. > AFAICT at present running a kernel with spectre and meltdown protection > means running debian in the opposite way it is usually billed as to the > outside world ie unstable for quite some time. That's not entirely true, you can run Debian Stable / Stretch with a kernel that was compiled on Sid with gcc-7.3, however it is true that for now there is no such kernel available for Stretch out-of-the-box and even installing the latest gcc-7 compiler packages from sid on a Stretch system is, if possible at all, probably not trivial. I assume that most likely someone is working on an update to gcc-6 that will make it possible to compile the latest "spectre fix" into the kernel with Stretch's default compiler and we will have to wait until that is done. I think it is likely though, that a kernel with that fix will be available soon in the "experimental" suite and could be installed manually on Stretch. Regards Michael .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. After a time, you may find that "having" is not so pleasing a thing, after all, as "wanting." It is not logical, but it is often true. -- Spock, "Amok Time", stardate 3372.7
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-01-29 13:40 +0100 |
| Message-ID | <vdgT8-4fk-11@gated-at.bofh.it> |
| In reply to | #191713 |
[Multipart message — attachments visible in raw view] — view raw
On 29 January 2018 at 10:17, Michael Lange <klappnase@freenet.de> wrote: > Hi, > > On Mon, 29 Jan 2018 08:35:58 +0000 > Michael Fothergill <michael.fothergill@gmail.com> wrote: > > > Your need to upgrade to unstable (Debian Sid). Then you need to get > > the latest kernel from the kernel.org website. > > You also need to install GCC7 in sid which will give you version 7.3.0 > > at present. That is a new enough compiler to be able to properly > > install the spectre and meltdown fixes. > > The "meltdown fix" (a.k.a. page tables isolation) is already included in > Stretch's 4.9 kernel. > Yes, that is true. If the OP was running an Intel box than that really would be useful to them. So I should have mentioned it to them. But, to be fair the OP specifically mentioned that they were interested in fixes to the meltdown and spectre vulnerabilities ie both problems not just one of them. Cheers MF > > > Then you need to run the spectre/meltdown checker which you can get > > from a github site and run locally on your box to know it's really > > installed properly. > > AFAICT at present running a kernel with spectre and meltdown protection > > means running debian in the opposite way it is usually billed as to the > > outside world ie unstable for quite some time. > > That's not entirely true, you can run Debian Stable / Stretch with a > kernel that was compiled on Sid with gcc-7.3, however it is true that for > now there is no such kernel available for Stretch out-of-the-box and even > installing the latest gcc-7 compiler packages from sid on a Stretch > system is, if possible at all, probably not trivial. > > I assume that most likely someone is working on an update to gcc-6 that > will make it possible to compile the latest "spectre fix" into the kernel > with Stretch's default compiler and we will have to wait until that is > done. > > I think it is likely though, that a kernel with that fix will be > available soon in the "experimental" suite and could be installed > manually on Stretch. > > Regards > > Michael > > .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. > > After a time, you may find that "having" is not so pleasing a thing, > after all, as "wanting." It is not logical, but it is often true. > -- Spock, "Amok Time", stardate 3372.7 > >
[toc] | [prev] | [next] | [standalone]
| From | Michael Stone <mstone@debian.org> |
|---|---|
| Date | 2018-01-29 14:00 +0100 |
| Message-ID | <vdhct-4mR-1@gated-at.bofh.it> |
| In reply to | #191719 |
On Mon, Jan 29, 2018 at 12:20:17PM +0000, Michael Fothergill wrote: >So I should have mentioned it to them. But, to be fair the OP specifically >mentioned that >they were interested in fixes to the meltdown and spectre vulnerabilities ie >both problems not just one of them. Well, to be fair, it would have been really good to point out that the best strategy would be to wait for the bugs to be worked out rather than haring off into frantically rebuilding kernels. Mike Stone
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-01-29 14:10 +0100 |
| Message-ID | <vdhma-4Fi-7@gated-at.bofh.it> |
| In reply to | #191713 |
[Multipart message — attachments visible in raw view] — view raw
On 29 January 2018 at 10:17, Michael Lange <klappnase@freenet.de> wrote: > Hi, > > On Mon, 29 Jan 2018 08:35:58 +0000 > Michael Fothergill <michael.fothergill@gmail.com> wrote: > > > Your need to upgrade to unstable (Debian Sid). Then you need to get > > the latest kernel from the kernel.org website. > > You also need to install GCC7 in sid which will give you version 7.3.0 > > at present. That is a new enough compiler to be able to properly > > install the spectre and meltdown fixes. > > The "meltdown fix" (a.k.a. page tables isolation) is already included in > Stretch's 4.9 kernel. > > > Then you need to run the spectre/meltdown checker which you can get > > from a github site and run locally on your box to know it's really > > installed properly. > > AFAICT at present running a kernel with spectre and meltdown protection > > means running debian in the opposite way it is usually billed as to the > > outside world ie unstable for quite some time. > > That's not entirely true, you can run Debian Stable / Stretch with a > kernel that was compiled on Sid with gcc-7.3, however it is true that for > now there is no such kernel available for Stretch out-of-the-box and even > installing the latest gcc-7 compiler packages from sid on a Stretch > system is, if possible at all, probably not trivial. > That is pretty much what I had been led to believe already except for the part where you suggest that a kernel compiled in Sid could apparently be used in stable. Again, if that would be true I should have mentioned it to the OP; sorry about that. Apart from that it makes me think that what I posted was perhaps not BS after all....... Cheers MF > > I assume that most likely someone is working on an update to gcc-6 that > will make it possible to compile the latest "spectre fix" into the kernel > with Stretch's default compiler and we will have to wait until that is > done. > > I think it is likely though, that a kernel with that fix will be > available soon in the "experimental" suite and could be installed > manually on Stretch. > > > Regards > > Michael > > .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. > > After a time, you may find that "having" is not so pleasing a thing, > after all, as "wanting." It is not logical, but it is often true. > -- Spock, "Amok Time", stardate 3372.7 > >
[toc] | [prev] | [next] | [standalone]
| From | Michael Lange <klappnase@freenet.de> |
|---|---|
| Date | 2018-01-29 19:20 +0100 |
| Message-ID | <vdmca-7NQ-5@gated-at.bofh.it> |
| In reply to | #191721 |
On Mon, 29 Jan 2018 12:49:19 +0000 Michael Fothergill <michael.fothergill@gmail.com> wrote: > > That is pretty much what I had been led to believe already except > for the part where you suggest that a kernel compiled in Sid could > apparently > be used in stable. Again, if that would be true I should have > mentioned it to the OP; sorry about that. > Apart from that it makes me think that what I posted was perhaps not BS > after all....... It works here :) I believe that deloptes' rather harsh comment referred to your suggestion that the OP should upgrade to Sid rather than to anything else you wrote. Regards Michael .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. Our way is peace. -- Septimus, the Son Worshiper, "Bread and Circuses", stardate 4040.7.
[toc] | [prev] | [next] | [standalone]
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Date | 2018-01-29 19:40 +0100 |
| Message-ID | <vdmvw-7VI-37@gated-at.bofh.it> |
| In reply to | #191750 |
Michael Lange wrote: > I believe that deloptes' rather harsh comment referred to your > suggestion that the OP should upgrade to Sid rather than to anything else > you wrote. yes indeed - thats true in fact you can setup sid with debootstrap, chroot to it, build your kernel there and install on your stretch box. there are some side effects though. Last time I did something like this, when installing VMware, it told me that it needs the proper compiler, to compile the modules. I like simple things as true genius of nature is simple. (well there are still different levels of simple) regards
[toc] | [prev] | [next] | [standalone]
| From | Michael Lange <klappnase@freenet.de> |
|---|---|
| Date | 2018-01-29 20:00 +0100 |
| Message-ID | <vdmOS-83T-9@gated-at.bofh.it> |
| In reply to | #191752 |
On Mon, 29 Jan 2018 19:33:27 +0100 deloptes <deloptes@gmail.com> wrote: > Michael Lange wrote: > > > I believe that deloptes' rather harsh comment referred to your > > suggestion that the OP should upgrade to Sid rather than to anything > > else you wrote. > > yes indeed - thats true > > in fact you can setup sid with debootstrap, chroot to it, build your > kernel there and install on your stretch box. there are some side > effects though. Last time I did something like this, when installing > VMware, it told me that it needs the proper compiler, to compile the > modules. I never tried, but I think probably one could even start a live Sid environment, mount one's hard drive on /mnt and then compile the kernel. Regards Michael .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. Dammit Jim, I'm an actor, not a doctor.
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-01-30 10:50 +0100 |
| Message-ID | <vdAI9-8u-1@gated-at.bofh.it> |
| In reply to | #191721 |
[Multipart message — attachments visible in raw view] — view raw
On 29 January 2018 at 12:49, Michael Fothergill < michael.fothergill@gmail.com> wrote: > > > On 29 January 2018 at 10:17, Michael Lange <klappnase@freenet.de> wrote: > >> Hi, >> >> On Mon, 29 Jan 2018 08:35:58 +0000 >> Michael Fothergill <michael.fothergill@gmail.com> wrote: >> >> > Your need to upgrade to unstable (Debian Sid). Then you need to get >> > the latest kernel from the kernel.org website. >> > You also need to install GCC7 in sid which will give you version 7.3.0 >> > at present. That is a new enough compiler to be able to properly >> > install the spectre and meltdown fixes. >> >> The "meltdown fix" (a.k.a. page tables isolation) is already included in >> Stretch's 4.9 kernel. >> >> > Then you need to run the spectre/meltdown checker which you can get >> > from a github site and run locally on your box to know it's really >> > installed properly. >> > AFAICT at present running a kernel with spectre and meltdown protection >> > means running debian in the opposite way it is usually billed as to the >> > outside world ie unstable for quite some time. >> >> That's not entirely true, you can run Debian Stable / Stretch with a >> kernel that was compiled on Sid with gcc-7.3, however it is true that for >> now there is no such kernel available for Stretch out-of-the-box and even >> installing the latest gcc-7 compiler packages from sid on a Stretch >> system is, if possible at all, probably not trivial. >> > In the recent MVE thread , I had asked if I could compile the spectre fix kernel in Sid and move to buster (I thought moving down to stretch would likely not be practical). The response from Greg was the following: On Thu, Jan 25, 2018 at 12:36:46PM +0000, Michael Fothergill wrote: > If I become sid and install the kernel correctly, could I go back to being > just buster (sounds like an energy drink) and carry on using the new kernel? No. ******************* At that point I really did seem that: 1. I had no choice but to become sid/unstable here. 2. I would have to remain being sid for some considerable time running this new fangled kernel. And so would anyone else trying to address the spectre problem including new users, as far as I could then. I was interested specifically in the spectre fix because as an AMD user meltdown is not a vulnerability for me which the spectre-meltdown-checker reminds you of when you run it. I then put up a post saying "well I guess I am going to have to upgrade to sid then" or something similar. The silence was deafening. So I went ahead and installed GCC 8 (because GCC 7.3 hadn't quite been ported into sid at that point) and tried to compile the new spectre fix kernel. I now see that maybe the kernel could be more portable once created than it seemed then to me. as has been pointed out above that the OP really ought to have been made aware of. Cheers MF > > That is pretty much what I had been led to believe already except > for the part where you suggest that a kernel compiled in Sid could > apparently > be used in stable. Again, if that would be true I should have mentioned > it to the OP; sorry about that. > Apart from that it makes me think that what I posted was perhaps not BS > after all....... > > Cheers > > MF > > > >> >> I assume that most likely someone is working on an update to gcc-6 that >> will make it possible to compile the latest "spectre fix" into the kernel >> with Stretch's default compiler and we will have to wait until that is >> done. >> >> I think it is likely though, that a kernel with that fix will be >> available soon in the "experimental" suite and could be installed >> manually on Stretch. >> > > > > > >> >> Regards >> >> Michael >> >> .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. >> >> After a time, you may find that "having" is not so pleasing a thing, >> after all, as "wanting." It is not logical, but it is often true. >> -- Spock, "Amok Time", stardate 3372.7 >> >> >
[toc] | [prev] | [next] | [standalone]
| From | Michael Lange <klappnase@freenet.de> |
|---|---|
| Date | 2018-01-30 12:20 +0100 |
| Message-ID | <vdC7f-1cY-5@gated-at.bofh.it> |
| In reply to | #191763 |
On Tue, 30 Jan 2018 09:31:01 +0000 Michael Fothergill <michael.fothergill@gmail.com> wrote: > In the recent MVE thread , I had asked if I could compile the spectre > fix kernel in Sid and move to buster (I thought moving down to > stretch would likely not be practical). > > The response from Greg was the following: > > On Thu, Jan 25, 2018 at 12:36:46PM +0000, Michael Fothergill wrote: > > If I become sid and install the kernel correctly, could I go back to > being > > just buster (sounds like an energy drink) and carry on using the new > kernel? > > No. > > ******************* > > At that point I really did seem that: > > 1. I had no choice but to become sid/unstable here. I can only guess of course, I think probably they figured you would upgrade your system to Sid, then compile a kernel and then *downgrade* the system again to buster. The answer to that would clearly be "no". But running a kernel compiled on a *different* Sid system on buster or stretch is an entirely different thing of course. Regards Michael .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. It [being a Vulcan] means to adopt a philosophy, a way of life which is logical and beneficial. We cannot disregard that philosophy merely for personal gain, no matter how important that gain might be. -- Spock, "Journey to Babel", stardate 3842.4
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2018-01-30 14:30 +0100 |
| Message-ID | <vdE93-2sX-1@gated-at.bofh.it> |
| In reply to | #191767 |
On Tue, Jan 30, 2018 at 12:13:47PM +0100, Michael Lange wrote: > Michael Fothergill <michael.fothergill@gmail.com> wrote: > > The response from Greg was the following: > > > > On Thu, Jan 25, 2018 at 12:36:46PM +0000, Michael Fothergill wrote: > > > If I become sid and install the kernel correctly, could I go back to > > being > > > just buster (sounds like an energy drink) and carry on using the new > > kernel? > > > > No. > > > > ******************* > > > > At that point I really did seem that: > > > > 1. I had no choice but to become sid/unstable here. > > I can only guess of course, I think probably they figured you would > upgrade your system to Sid, then compile a kernel and then *downgrade* > the system again to buster. The answer to that would clearly be "no". > But running a kernel compiled on a *different* Sid system on buster or > stretch is an entirely different thing of course. Yes, that's correct. If you actually "become sid" (upgrade your whole system to sid), there is no going back. But you can set up a *separate* system (either an entirely new box, or a chroot into which you debootstrap sid, or a virtual machine, or a container, or whatever other fancy thing the kids are using these days), build a kernel .deb package there, *copy* that package to your buster system, and install it. Or you can do what most of us are doing: wait for the Debian security team (and, really, for the entire *world*) to figure out how best to approach, mitigate, and/or solve the issues. Meanwhile, I would recommend not letting random people get shell access to your critical systems. Near as I can tell, exploiting a Spectre-type CPU vulnerability requires the ability to install and execute a program of the attacker's creation on the target system. If you don't have users logging in and running commands, then you probably don't have to worry so much about this. Unless I'm completely missing something. (If you have users issuing commands on your system through some other vector, like a PHP web-app exploit, then that's a bigger issue you should address directly.)
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2018-01-30 14:50 +0100 |
| Message-ID | <vdEsp-2zv-1@gated-at.bofh.it> |
| In reply to | #191769 |
On Tuesday 30 January 2018 08:22:18 Greg Wooledge wrote: > On Tue, Jan 30, 2018 at 12:13:47PM +0100, Michael Lange wrote: > > Michael Fothergill <michael.fothergill@gmail.com> wrote: > > > The response from Greg was the following: > > > > > > On Thu, Jan 25, 2018 at 12:36:46PM +0000, Michael Fothergill wrote: > > > > If I become sid and install the kernel correctly, could I go > > > > back to > > > > > > being > > > > > > > just buster (sounds like an energy drink) and carry on using the > > > > new > > > > > > kernel? > > > > > > No. > > > > > > ******************* > > > > > > At that point I really did seem that: > > > > > > 1. I had no choice but to become sid/unstable here. > > > > I can only guess of course, I think probably they figured you would > > upgrade your system to Sid, then compile a kernel and then > > *downgrade* the system again to buster. The answer to that would > > clearly be "no". But running a kernel compiled on a *different* Sid > > system on buster or stretch is an entirely different thing of > > course. > > Yes, that's correct. If you actually "become sid" (upgrade your whole > system to sid), there is no going back. > > But you can set up a *separate* system (either an entirely new box, > or a chroot into which you debootstrap sid, or a virtual machine, or a > container, or whatever other fancy thing the kids are using these > days), build a kernel .deb package there, *copy* that package to your > buster system, and install it. > > Or you can do what most of us are doing: wait for the Debian security > team (and, really, for the entire *world*) to figure out how best to > approach, mitigate, and/or solve the issues. > > Meanwhile, I would recommend not letting random people get shell > access to your critical systems. Near as I can tell, exploiting a > Spectre-type CPU vulnerability requires the ability to install and > execute a program of the attacker's creation on the target system. If > you don't have users logging in and running commands, then you > probably don't have to worry so much about this. Unless I'm > completely missing something. > > (If you have users issuing commands on your system through some other > vector, like a PHP web-app exploit, then that's a bigger issue you > should address directly.) Running apache2 to serve up my web page, see sig, apache2 doesn't have access to a lot of its plugins, file browsing and pulling is all thats allowed, and thats only done via a NAT rule in dd-wrt to direct that port number only to this machine, should I be worried? -- Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | "tv.debian@googlemail.com" <tv.debian@googlemail.com> |
|---|---|
| Date | 2018-01-30 16:40 +0100 |
| Message-ID | <vdGaR-3HO-1@gated-at.bofh.it> |
| In reply to | #191769 |
On 30/01/2018 18:52, Greg Wooledge wrote: > On Tue, Jan 30, 2018 at 12:13:47PM +0100, Michael Lange wrote: >> Michael Fothergill <michael.fothergill@gmail.com> wrote: >>> The response from Greg was the following: >>> >>> On Thu, Jan 25, 2018 at 12:36:46PM +0000, Michael Fothergill wrote: >>>> If I become sid and install the kernel correctly, could I go back to >>> being >>>> just buster (sounds like an energy drink) and carry on using the new >>> kernel? >>> >>> No. >>> >>> ******************* >>> >>> At that point I really did seem that: >>> >>> 1. I had no choice but to become sid/unstable here. >> >> I can only guess of course, I think probably they figured you would >> upgrade your system to Sid, then compile a kernel and then *downgrade* >> the system again to buster. The answer to that would clearly be "no". >> But running a kernel compiled on a *different* Sid system on buster or >> stretch is an entirely different thing of course. > > Yes, that's correct. If you actually "become sid" (upgrade your whole > system to sid), there is no going back. > > But you can set up a *separate* system (either an entirely new box, > or a chroot into which you debootstrap sid, or a virtual machine, or a > container, or whatever other fancy thing the kids are using these days), > build a kernel .deb package there, *copy* that package to your buster > system, and install it. > > Or you can do what most of us are doing: wait for the Debian security > team (and, really, for the entire *world*) to figure out how best to > approach, mitigate, and/or solve the issues. > > Meanwhile, I would recommend not letting random people get shell access > to your critical systems. Near as I can tell, exploiting a Spectre-type > CPU vulnerability requires the ability to install and execute a program > of the attacker's creation on the target system. If you don't have > users logging in and running commands, then you probably don't have to > worry so much about this. Unless I'm completely missing something. > > (If you have users issuing commands on your system through some other > vector, like a PHP web-app exploit, then that's a bigger issue you > should address directly.) > It should be possible to exploit Spectre via javascript, the prominent web browsers (G.Chrome/Chromium and Firefox) have already applied mitigation for this scenario. For G.Chrome/Chromium you can also use an experimental flag do harden site isolation (at the cost of memory consumption). But you can be sure the clever kids in their basements, the mafia networks and the state sponsored rogue agencies are hard at work trying to find novelty use for these new pathways to our systems. So patch, update, and be careful what emailed link you click on (hint: none). In Debian we are lucky as far as I can judge, Stable received a backport of the Kaiser/kpti patches, and Sid has retpolined kernel and patched gcc (but still vulnerable to Spectre 1 just as everybody else on the planet). On Stable and Backport kernel you are covered for Meltdown (for Intel cpu) but still vulnerable to Spectre. That will be the case as long as the gcc patches are not backported, or the Debian deities decide to break the taboo and issue a kernel and gcc bump for Stable, unlikely. In Testing you are following Sid, remember there is no official security support for Testing outside of the very end of the pre-stable release freeze period. So you can cherry-pick what you want from Sid, or wait for the migration to naturally happen (if it has not happened yet, I don't know). The cpu microcode side of things is a lot murkier, Intel is going back and forth with crappy code that crashes some systems, and the decision to apply or not those microcode updates is a tricky one. As for board vendors they don't seem to scramble to send updates out... In any case right now there is no cause for alarm for the general public (IMHO), that may change if a working javascript exploit surfaces but it isn't here yet. If you are hosting virtual systems for distrusted clients (aren't they all) then you need to weight your options seriously, keeping in mind that when an efficient exploit surfaces it will be too late to patch. All of the above is just my attempt at offering a synthesis of my experience, I am not working for US-CERT and I am not a DD, so you can ignore all of the above and go find out for yourself (the best way®).
[toc] | [prev] | [next] | [standalone]
Page 2 of 5 — ← Prev page 1 [2] 3 4 5 Next page →
Back to top | Article view | linux.debian.user
csiph-web