Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #191703 > unrolled thread

Kernel for Spectre and Meltdown

Started byDextin Jerafmel <jerafmel@yahoo.com>
First post2018-01-29 09:10 +0100
Last post2018-01-29 10:50 +0100
Articles 20 on this page of 81 — 25 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Kernel for Spectre and Meltdown Dextin Jerafmel <jerafmel@yahoo.com> - 2018-01-29 09:10 +0100
    Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 10:00 +0100
      Re: Kernel for Spectre and Meltdown arne <sp113438@telfort.nl> - 2018-01-29 10:50 +0100
        Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 11:50 +0100
          Re: Kernel for Spectre and Meltdown arne <sp113438@telfort.nl> - 2018-01-29 13:30 +0100
      Re: Kernel for Spectre and Meltdown Jonathan Dowland <jmtd@debian.org> - 2018-01-29 10:50 +0100
      Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 11:20 +0100
        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 12:40 +0100
          Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-01-29 14:30 +0100
            Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 14:50 +0100
          Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 14:30 +0100
            Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 15:00 +0100
              Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 15:30 +0100
                Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-01-29 16:50 +0100
                  Re: Kernel for Spectre and Meltdown Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-29 17:20 +0100
                    Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 18:40 +0100
                  Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 19:10 +0100
                    Re: Kernel for Spectre and Meltdown "Thomas Schmitt" <scdbackup@gmx.net> - 2018-01-29 19:40 +0100
                      Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 20:00 +0100
                    Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 20:40 +0100
                      Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-30 22:50 +0100
                        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 23:10 +0100
                  Re: Kernel for Spectre and Meltdown Elimar Riesebieter <riesebie@lxtec.de> - 2018-01-30 16:30 +0100
                    Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 17:20 +0100
                      Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 18:00 +0100
                        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-31 14:50 +0100
            Re: Kernel for Spectre and Meltdown Carl Fink <carl@finknetwork.com> - 2018-01-29 15:50 +0100
              Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 18:40 +0100
      Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 11:30 +0100
        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 13:40 +0100
          Re: Kernel for Spectre and Meltdown Michael Stone <mstone@debian.org> - 2018-01-29 14:00 +0100
        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-29 14:10 +0100
          Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 19:20 +0100
            Re: Kernel for Spectre and Meltdown deloptes <deloptes@gmail.com> - 2018-01-29 19:40 +0100
              Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-29 20:00 +0100
          Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-30 10:50 +0100
            Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-30 12:20 +0100
              Re: Kernel for Spectre and Meltdown Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-30 14:30 +0100
                Re: Kernel for Spectre and Meltdown Gene Heskett <gheskett@shentel.net> - 2018-01-30 14:50 +0100
                Re: Kernel for Spectre and Meltdown "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2018-01-30 16:40 +0100
                Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-31 19:20 +0100
                  Re: Kernel for Spectre and Meltdown Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-31 19:30 +0100
                  Re: Kernel for Spectre and Meltdown Michael Lange <klappnase@freenet.de> - 2018-01-31 19:40 +0100
                    Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-31 23:40 +0100
                      Re: Kernel for Spectre and Meltdown Richard Hector <richard@walnut.gen.nz> - 2018-01-31 23:50 +0100
                        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-01 00:10 +0100
                          Re: Kernel for Spectre and Meltdown Richard Hector <richard@walnut.gen.nz> - 2018-02-01 00:20 +0100
                            Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-01 00:50 +0100
                Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-01 13:10 +0100
                  Re: Kernel for Spectre and Meltdown Andy Smith <andy@strugglers.net> - 2018-02-02 05:40 +0100
                    Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 09:10 +0100
                      Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-02-03 15:50 +0100
                        Re: Kernel for Spectre and Meltdown Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-02-03 16:40 +0100
                          Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 18:10 +0100
                          Re: Kernel for Spectre and Meltdown David Wright <deblis@lionunicorn.co.uk> - 2018-02-03 18:30 +0100
                            Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 23:50 +0100
                      Re: Kernel for Spectre and Meltdown David Wright <deblis@lionunicorn.co.uk> - 2018-02-03 18:20 +0100
                        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 23:10 +0100
                        Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-03 23:10 +0100
                          Re: Kernel for Spectre and Meltdown Andy Smith <andy@strugglers.net> - 2018-02-04 00:20 +0100
                            Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-04 01:10 +0100
                              Re: Kernel for Spectre and Meltdown Andy Smith <andy@strugglers.net> - 2018-02-04 16:30 +0100
                                Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-05 00:10 +0100
                                Re: Kernel for Spectre and Meltdown Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-05 00:10 +0100
                            Re: Kernel for Spectre and Meltdown rhkramer@gmail.com - 2018-02-04 05:30 +0100
      comment and new question--when do upgrades take effect  (was: Re: Kernel for Spectre and Meltdown) rhkramer@gmail.com - 2018-01-29 14:20 +0100
        Re: comment and new question--when do upgrades take effect  (was:  Re: Kernel for Spectre and Meltdown) Roberto C. Sánchez <roberto@debian.org> - 2018-01-29 14:50 +0100
        Re: comment and new question--when do upgrades take effect  (was:  Re: Kernel for Spectre and Meltdown) Joe <joe@jretrading.com> - 2018-01-29 14:50 +0100
          Re: comment and new question--when do upgrades take effect (was: Re:  Kernel for Spectre and Meltdown) Boyan Penkov <boyan.penkov@gmail.com> - 2018-01-29 15:40 +0100
            Re: comment and new question--when do upgrades take effect Richard Hector <richard@walnut.gen.nz> - 2018-01-30 00:20 +0100
              Re: comment and new question--when do upgrades take effect Boyan Penkov <boyan.penkov@gmail.com> - 2018-01-30 01:00 +0100
          Re: comment and new question--when do upgrades take effect  (was:  Re: Kernel for Spectre and Meltdown) David Wright <deblis@lionunicorn.co.uk> - 2018-01-29 17:20 +0100
        Re: comment and new question--when do upgrades take effect  (was:  Re: Kernel for Spectre and Meltdown) Andy Smith <andy@strugglers.net> - 2018-01-29 15:20 +0100
          Re: comment and new question--when do upgrades take effect Richard Owlett <rowlett@cloud85.net> - 2018-01-29 15:40 +0100
            Re: comment and new question--when do upgrades take effect Roberto C. Sánchez <roberto@debian.org> - 2018-01-29 15:40 +0100
              Re: comment and new question--when do upgrades take effect <tomas@tuxteam.de> - 2018-01-29 16:00 +0100
                Re: comment and new question--when do upgrades take effect Richard Owlett <rowlett@cloud85.net> - 2018-01-29 16:20 +0100
                  Re: comment and new question--when do upgrades take effect David Wright <deblis@lionunicorn.co.uk> - 2018-01-29 16:50 +0100
          Re: comment and new question--when do upgrades take effect (side  question) Neo <neo@spacerat.ch> - 2018-01-29 17:10 +0100
        Re: comment and new question--when do upgrades take effect  (was:  Re: Kernel for Spectre and Meltdown) Michael Lange <klappnase@freenet.de> - 2018-01-29 19:20 +0100
    Re: Kernel for Spectre and Meltdown Bastien Durel <bastien@durel.org> - 2018-01-29 10:50 +0100

Page 2 of 5 — ← Prev page 1 [2] 3 4 5  Next page →


#191791

FromMichael Lange <klappnase@freenet.de>
Date2018-01-30 22:50 +0100
Message-ID<vdLWV-7vj-1@gated-at.bofh.it>
In reply to#191782
On Tue, 30 Jan 2018 19:14:36 +0000
Michael Fothergill <michael.fothergill@gmail.com> wrote:

> 
> I am not really so sure what the correct dosage ought to be now.

Maybe just stick with the booze... ;-)

scnr

Michael


.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

Fascinating is a word I use for the unexpected.
		-- Spock, "The Squire of Gothos", stardate 2124.5

[toc] | [prev] | [next] | [standalone]


#191793

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-30 23:10 +0100
Message-ID<vdMgh-7RI-1@gated-at.bofh.it>
In reply to#191791

[Multipart message — attachments visible in raw view] — view raw

On 30 January 2018 at 21:45, Michael Lange <klappnase@freenet.de> wrote:

> On Tue, 30 Jan 2018 19:14:36 +0000
> Michael Fothergill <michael.fothergill@gmail.com> wrote:
>
> >
> > I am not really so sure what the correct dosage ought to be now.
>
> Maybe just stick with the booze... ;-)
>
> scnr
>
> Michael
>

​It's OK.  As it turns out, I don't drink but it is still funny......

Cheers

MF​


>
>
> .-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.
>
> Fascinating is a word I use for the unexpected.
>                 -- Spock, "The Squire of Gothos", stardate 2124.5
>
>

[toc] | [prev] | [next] | [standalone]


#191771

FromElimar Riesebieter <riesebie@lxtec.de>
Date2018-01-30 16:30 +0100
Message-ID<vdG1c-3EN-7@gated-at.bofh.it>
In reply to#191740
* rhkramer@gmail.com <rhkramer@gmail.com> [2018-01-29 10:47 -0500]:

[...] 
> On the other hand, if I download kernel source, I would need GCC, and a 
> version that is sufficient for the code.

One can check the compiler version the running kernel is built with
by:

$ cat /proc/version
Linux version 4.14.15-toy-lxtec-amd64 (riesebie@toy) (gcc version 7.3.0 (Debian 7.3.0-1)) #1 SMP Tue Jan 30 14:20:49 CET 2018
                                                      ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

Elimar
-- 
  You cannot propel yourself forward by
  patting yourself on the back.

[toc] | [prev] | [next] | [standalone]


#191773

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-30 17:20 +0100
Message-ID<vdGNA-4cp-3@gated-at.bofh.it>
In reply to#191771

[Multipart message — attachments visible in raw view] — view raw

On 30 January 2018 at 15:23, Elimar Riesebieter <riesebie@lxtec.de> wrote:

> * rhkramer@gmail.com <rhkramer@gmail.com> [2018-01-29 10:47 -0500]:
>
> [...]
> > On the other hand, if I download kernel source, I would need GCC, and a
> > version that is sufficient for the code.
>
> One can check the compiler version the running kernel is built with
> by:
>
> $ cat /proc/version
> Linux version 4.14.15-toy-lxtec-amd64 (riesebie@toy) (gcc version 7.3.0
> (Debian 7.3.0-1)) #1 SMP Tue Jan 30 14:20:49 CET 2018
>

​That is a very useful command.

I ran it myself.

djt /home/mikef/spectre-meltdown-checker # cat /proc/version
Linux version 4.14.14-gentoo (root@djt) (gcc version 7.2.0 (Gentoo
7.2.0-r1)) #1 SMP Tue Jan 23 13:06:23 GMT 2018

Here is a bit of the output from the spectre patch checker:


​* Mitigation 2
  * Kernel compiled with retpoline option:  YES
  * Kernel compiled with a retpoline-aware compiler:  NO  (kernel reports
minimal retpoline compilation)
  * Retpoline enabled:  YES
> STATUS:  VULNERABLE  (Vulnerable: Minimal AMD ASM retpoline)

​As can be seen here, the compiler I used to create this kernel was not
recent enough to make retpoline work.

Since I now have gcc 7.3 installed I will do kernel upgrade in a little
while and see if I can change the NO in

  "* Kernel compiled with a retpoline-aware compiler:  NO  (kernel reports
minimal retpoline compilation)"

to YES.....

I think it will work.

Cheers MF




​






>
> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>
> Elimar
> --
>   You cannot propel yourself forward by
>   patting yourself on the back.
>
>

[toc] | [prev] | [next] | [standalone]


#191774

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-30 18:00 +0100
Message-ID<vdHqh-4r9-7@gated-at.bofh.it>
In reply to#191773

[Multipart message — attachments visible in raw view] — view raw

On 30 January 2018 at 16:02, Michael Fothergill <
michael.fothergill@gmail.com> wrote:

>
>
> On 30 January 2018 at 15:23, Elimar Riesebieter <riesebie@lxtec.de> wrote:
>
>> * rhkramer@gmail.com <rhkramer@gmail.com> [2018-01-29 10:47 -0500]:
>>
>> [...]
>> > On the other hand, if I download kernel source, I would need GCC, and a
>> > version that is sufficient for the code.
>>
>> One can check the compiler version the running kernel is built with
>> by:
>>
>> $ cat /proc/version
>> Linux version 4.14.15-toy-lxtec-amd64 (riesebie@toy) (gcc version 7.3.0
>> (Debian 7.3.0-1)) #1 SMP Tue Jan 30 14:20:49 CET 2018
>>
>
> ​That is a very useful command.
>
> I ran it myself.
>
> djt /home/mikef/spectre-meltdown-checker # cat /proc/version
> Linux version 4.14.14-gentoo (root@djt) (gcc version 7.2.0 (Gentoo
> 7.2.0-r1)) #1 SMP Tue Jan 23 13:06:23 GMT 2018
>
> Here is a bit of the output from the spectre patch checker:
>
>
> ​* Mitigation 2
>   * Kernel compiled with retpoline option:  YES
>   * Kernel compiled with a retpoline-aware compiler:  NO  (kernel reports
> minimal retpoline compilation)
>   * Retpoline enabled:  YES
> > STATUS:  VULNERABLE  (Vulnerable: Minimal AMD ASM retpoline)
>
> ​As can be seen here, the compiler I used to create this kernel was not
> recent enough to make retpoline work.
>
> Since I now have gcc 7.3 installed I will do kernel upgrade in a little
> while and see if I can change the NO in
>
>   "* Kernel compiled with a retpoline-aware compiler:  NO  (kernel reports
> minimal retpoline compilation)"
>
> to YES.....
>
> I think it will work.
>
> Cheers MF
>

​I just ran the kernel rebuild:

djt /home/mikef # cat /proc/version
Linux version 4.14.15-gentoo (root@djt) (gcc version 7.3.0 (Gentoo 7.3.0))
#1 SMP Tue Jan 30 16:22:47 GMT 2018

and now the spectre kernel checker says the following:

* Mitigation 2
  * Kernel compiled with retpoline option:  YES
  * Kernel compiled with a retpoline-aware compiler:  YES  (kernel reports
full retpoline compilation)
  * Retpoline enabled:  YES
> STATUS:  NOT VULNERABLE  (Mitigation: Full AMD retpoline)

New kernels are going to appear soon with fancier fixes for spectre
vulnerabilities if I understand it correctly.

I can now install them right away; and if I want I can downgrade gentoo
testing to gentoo stable and do the very same thing.

Cheers

MF



​


>
>
>
>
> ​
>
>
>
>
>
>
>>
>> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>>
>> Elimar
>> --
>>   You cannot propel yourself forward by
>>   patting yourself on the back.
>>
>>
>

[toc] | [prev] | [next] | [standalone]


#191801

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-31 14:50 +0100
Message-ID<ve0VY-Hl-9@gated-at.bofh.it>
In reply to#191774

[Multipart message — attachments visible in raw view] — view raw

On 30 January 2018 at 16:36, Michael Fothergill <
michael.fothergill@gmail.com> wrote:

>
>
> On 30 January 2018 at 16:02, Michael Fothergill <
> michael.fothergill@gmail.com> wrote:
>
>>
>>
>> On 30 January 2018 at 15:23, Elimar Riesebieter <riesebie@lxtec.de>
>> wrote:
>>
>>> * rhkramer@gmail.com <rhkramer@gmail.com> [2018-01-29 10:47 -0500]:
>>>
>>> [...]
>>> > On the other hand, if I download kernel source, I would need GCC, and a
>>> > version that is sufficient for the code.
>>>
>>> One can check the compiler version the running kernel is built with
>>> by:
>>>
>>> $ cat /proc/version
>>> Linux version 4.14.15-toy-lxtec-amd64 (riesebie@toy) (gcc version 7.3.0
>>> (Debian 7.3.0-1)) #1 SMP Tue Jan 30 14:20:49 CET 2018
>>>
>>
>> ​That is a very useful command.
>>
>> I ran it myself.
>>
>> djt /home/mikef/spectre-meltdown-checker # cat /proc/version
>> Linux version 4.14.14-gentoo (root@djt) (gcc version 7.2.0 (Gentoo
>> 7.2.0-r1)) #1 SMP Tue Jan 23 13:06:23 GMT 2018
>>
>> Here is a bit of the output from the spectre patch checker:
>>
>>
>> ​* Mitigation 2
>>   * Kernel compiled with retpoline option:  YES
>>   * Kernel compiled with a retpoline-aware compiler:  NO  (kernel reports
>> minimal retpoline compilation)
>>   * Retpoline enabled:  YES
>> > STATUS:  VULNERABLE  (Vulnerable: Minimal AMD ASM retpoline)
>>
>> ​As can be seen here, the compiler I used to create this kernel was not
>> recent enough to make retpoline work.
>>
>> Since I now have gcc 7.3 installed I will do kernel upgrade in a little
>> while and see if I can change the NO in
>>
>>   "* Kernel compiled with a retpoline-aware compiler:  NO  (kernel
>> reports minimal retpoline compilation)"
>>
>> to YES.....
>>
>> I think it will work.
>>
>> Cheers MF
>>
>
> ​I just ran the kernel rebuild:
>
> djt /home/mikef # cat /proc/version
> Linux version 4.14.15-gentoo (root@djt) (gcc version 7.3.0 (Gentoo
> 7.3.0)) #1 SMP Tue Jan 30 16:22:47 GMT 2018
>
> and now the spectre kernel checker says the following:
>
> * Mitigation 2
>   * Kernel compiled with retpoline option:  YES
>   * Kernel compiled with a retpoline-aware compiler:  YES  (kernel reports
> full retpoline compilation)
>   * Retpoline enabled:  YES
> > STATUS:  NOT VULNERABLE  (Mitigation: Full AMD retpoline)
>
> New kernels are going to appear soon with fancier fixes for spectre
> vulnerabilities if I understand it correctly.
>
> I can now install them right away; and if I want I can downgrade gentoo
> testing to gentoo stable and do the very same thing.
>
> Cheers
>
> MF
>

​It has occured to me that two distributions of linux could be useful for
the spectre kernel patches right now.

One is sabayon and the other is calculate linux.

Both are gentoo based distributions.  For a new linux user, I think they
could have some advantages over e.g. gentoo itself.

Both come with installers so you will avoid the funny learning curve
involved in gentoo installs.

Sabayon has its own binary package installer called equo (its answer to apt
in debian). AFAICT, you
can avoid installing kernels with emerge (compiling them) if you want; you
have a choice.

I think, but I am not 100% sure that you can take the ebuild file for
kernel 4.15 from the gentoo kernel source site and install it directly in
sabayon.
Calculate linux is similar but does not have the equo package installer.

I notice that it seems Fedora have made kernels with the spectre patch
available. Whether they run in the equivalent of the stable version of the
distribution I am not sure.

Cheers

MF











​



>
>
>
> ​
>
>
>>
>>
>>
>>
>> ​
>>
>>
>>
>>
>>
>>
>>>
>>> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>>>
>>> Elimar
>>> --
>>>   You cannot propel yourself forward by
>>>   patting yourself on the back.
>>>
>>>
>>
>

[toc] | [prev] | [next] | [standalone]


#191737

FromCarl Fink <carl@finknetwork.com>
Date2018-01-29 15:50 +0100
Message-ID<vdiUW-5xM-9@gated-at.bofh.it>
In reply to#191725
On Mon, Jan 29, 2018 at 02:28:06PM +0100, deloptes wrote:

> My conclusion to this Spectre and Meltdown hysteria is, that a single
> machine in a secure environment is not exactly endangered.
> People should better take care of their mobile devices, especially phones
> and tablets, where you need neither Spectre nor Meltdown to compromise.

Be fair: you also don't need Spectre or Meldtdown to compromise Linux-based
computers.  Somethings as simple as going a week between installing security
upgrades can do it.
-- 
Carl Fink                           nitpicking@nitpicking.com 

Read my blog at blog.nitpicking.com.  Reviews!  Observations!
Stupid mistakes you can correct!

[toc] | [prev] | [next] | [standalone]


#191746

Fromdeloptes <deloptes@gmail.com>
Date2018-01-29 18:40 +0100
Message-ID<vdlzr-7hH-5@gated-at.bofh.it>
In reply to#191737
Carl Fink wrote:

> Be fair: you also don't need Spectre or Meldtdown to compromise
> Linux-based computers.  Somethings as simple as going a week between
> installing security upgrades can do it.

well - at least that's not so easy as windows or android with compromised
security in mind

[toc] | [prev] | [next] | [standalone]


#191713

FromMichael Lange <klappnase@freenet.de>
Date2018-01-29 11:30 +0100
Message-ID<vdeRk-2XQ-1@gated-at.bofh.it>
In reply to#191704
Hi,

On Mon, 29 Jan 2018 08:35:58 +0000
Michael Fothergill <michael.fothergill@gmail.com> wrote:

> ​Your need to upgrade to unstable (Debian Sid).  Then you need to get
> the latest kernel from the kernel.org website.
> You also need to install GCC7 in sid which will give you version 7.3.0
> at present.  That is a new enough compiler to be able to properly
> install the spectre and meltdown fixes.

The "meltdown fix" (a.k.a. page tables isolation) is already included in
Stretch's 4.9 kernel.

> Then you need to run the spectre/meltdown checker which you can get
> from a github site and run locally on your box to know it's really
> installed properly.
> AFAICT at present running a kernel with spectre and meltdown protection
> means running debian in the opposite way it is usually billed as to the
> outside world ie unstable for quite some time.

That's not entirely true, you can run Debian Stable / Stretch with a
kernel that was compiled on Sid with gcc-7.3, however it is true that for
now there is no such kernel available for Stretch out-of-the-box and even
installing the latest gcc-7 compiler packages from sid on a Stretch
system is, if possible at all, probably not trivial.

I assume that most likely someone is working on an update to gcc-6 that
will make it possible to compile the latest "spectre fix" into the kernel
with Stretch's default compiler and we will have to wait until that is
done.

I think it is likely though, that a kernel with that fix will be
available soon in the "experimental" suite and could be installed
manually on Stretch.

Regards

Michael

.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

After a time, you may find that "having" is not so pleasing a thing,
after all, as "wanting."  It is not logical, but it is often true.
		-- Spock, "Amok Time", stardate 3372.7

[toc] | [prev] | [next] | [standalone]


#191719

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-29 13:40 +0100
Message-ID<vdgT8-4fk-11@gated-at.bofh.it>
In reply to#191713

[Multipart message — attachments visible in raw view] — view raw

On 29 January 2018 at 10:17, Michael Lange <klappnase@freenet.de> wrote:

> Hi,
>
> On Mon, 29 Jan 2018 08:35:58 +0000
> Michael Fothergill <michael.fothergill@gmail.com> wrote:
>
> > ​Your need to upgrade to unstable (Debian Sid).  Then you need to get
> > the latest kernel from the kernel.org website.
> > You also need to install GCC7 in sid which will give you version 7.3.0
> > at present.  That is a new enough compiler to be able to properly
> > install the spectre and meltdown fixes.
>
> The "meltdown fix" (a.k.a. page tables isolation) is already included in
> Stretch's 4.9 kernel.
>

​Yes, that is true.  If the OP was running an Intel box than that really
would be useful to them.
So I should have mentioned it to them.  But, to be fair the OP specifically
mentioned that
they were interested in fixes to the meltdown and spectre vulnerabilities
ie both problems not just one of them.


Cheers

MF
​


>
> > Then you need to run the spectre/meltdown checker which you can get
> > from a github site and run locally on your box to know it's really
> > installed properly.
> > AFAICT at present running a kernel with spectre and meltdown protection
> > means running debian in the opposite way it is usually billed as to the
> > outside world ie unstable for quite some time.
>
> That's not entirely true, you can run Debian Stable / Stretch with a
> kernel that was compiled on Sid with gcc-7.3, however it is true that for
> now there is no such kernel available for Stretch out-of-the-box and even
> installing the latest gcc-7 compiler packages from sid on a Stretch
> system is, if possible at all, probably not trivial.
>
> I assume that most likely someone is working on an update to gcc-6 that
> will make it possible to compile the latest "spectre fix" into the kernel
> with Stretch's default compiler and we will have to wait until that is
> done.
>
> I think it is likely though, that a kernel with that fix will be
> available soon in the "experimental" suite and could be installed
> manually on Stretch.
>
> Regards
>
> Michael
>
> .-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.
>
> After a time, you may find that "having" is not so pleasing a thing,
> after all, as "wanting."  It is not logical, but it is often true.
>                 -- Spock, "Amok Time", stardate 3372.7
>
>

[toc] | [prev] | [next] | [standalone]


#191720

FromMichael Stone <mstone@debian.org>
Date2018-01-29 14:00 +0100
Message-ID<vdhct-4mR-1@gated-at.bofh.it>
In reply to#191719
On Mon, Jan 29, 2018 at 12:20:17PM +0000, Michael Fothergill wrote:
>So I should have mentioned it to them.  But, to be fair the OP specifically
>mentioned that
>they were interested in fixes to the meltdown and spectre vulnerabilities ie
>both problems not just one of them.

Well, to be fair, it would have been really good to point out that the 
best strategy would be to wait for the bugs to be worked out rather than 
haring off into frantically rebuilding kernels. 

Mike Stone

[toc] | [prev] | [next] | [standalone]


#191721

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-29 14:10 +0100
Message-ID<vdhma-4Fi-7@gated-at.bofh.it>
In reply to#191713

[Multipart message — attachments visible in raw view] — view raw

On 29 January 2018 at 10:17, Michael Lange <klappnase@freenet.de> wrote:

> Hi,
>
> On Mon, 29 Jan 2018 08:35:58 +0000
> Michael Fothergill <michael.fothergill@gmail.com> wrote:
>
> > ​Your need to upgrade to unstable (Debian Sid).  Then you need to get
> > the latest kernel from the kernel.org website.
> > You also need to install GCC7 in sid which will give you version 7.3.0
> > at present.  That is a new enough compiler to be able to properly
> > install the spectre and meltdown fixes.
>
> The "meltdown fix" (a.k.a. page tables isolation) is already included in
> Stretch's 4.9 kernel.
>
> > Then you need to run the spectre/meltdown checker which you can get
> > from a github site and run locally on your box to know it's really
> > installed properly.
> > AFAICT at present running a kernel with spectre and meltdown protection
> > means running debian in the opposite way it is usually billed as to the
> > outside world ie unstable for quite some time.
>
> That's not entirely true, you can run Debian Stable / Stretch with a
> kernel that was compiled on Sid with gcc-7.3, however it is true that for
> now there is no such kernel available for Stretch out-of-the-box and even
> installing the latest gcc-7 compiler packages from sid on a Stretch
> system is, if possible at all, probably not trivial.
>

​That is pretty much what I had been led to believe already except
for the part where you suggest that a kernel compiled in Sid could
apparently
be used in stable.  Again, if that would be true I should have mentioned it
to the OP; sorry about that.
Apart from that it makes me think that what I posted was perhaps not BS
after all.......

Cheers

MF​



>
> I assume that most likely someone is working on an update to gcc-6 that
> will make it possible to compile the latest "spectre fix" into the kernel
> with Stretch's default compiler and we will have to wait until that is
> done.
>
> I think it is likely though, that a kernel with that fix will be
> available soon in the "experimental" suite and could be installed
> manually on Stretch.
>

​



>
> Regards
>
> Michael
>
> .-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.
>
> After a time, you may find that "having" is not so pleasing a thing,
> after all, as "wanting."  It is not logical, but it is often true.
>                 -- Spock, "Amok Time", stardate 3372.7
>
>

[toc] | [prev] | [next] | [standalone]


#191750

FromMichael Lange <klappnase@freenet.de>
Date2018-01-29 19:20 +0100
Message-ID<vdmca-7NQ-5@gated-at.bofh.it>
In reply to#191721
On Mon, 29 Jan 2018 12:49:19 +0000
Michael Fothergill <michael.fothergill@gmail.com> wrote:

> 
> ​That is pretty much what I had been led to believe already except
> for the part where you suggest that a kernel compiled in Sid could
> apparently
> be used in stable.  Again, if that would be true I should have
> mentioned it to the OP; sorry about that.
> Apart from that it makes me think that what I posted was perhaps not BS
> after all.......

It works here :)
I believe that deloptes' rather harsh comment referred to your
suggestion that the OP should upgrade to Sid rather than to anything else
you wrote. 

Regards

Michael

.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

Our way is peace.
		-- Septimus, the Son Worshiper, "Bread and Circuses",
		   stardate 4040.7.

[toc] | [prev] | [next] | [standalone]


#191752

Fromdeloptes <deloptes@gmail.com>
Date2018-01-29 19:40 +0100
Message-ID<vdmvw-7VI-37@gated-at.bofh.it>
In reply to#191750
Michael Lange wrote:

> I believe that deloptes' rather harsh comment referred to your
> suggestion that the OP should upgrade to Sid rather than to anything else
> you wrote.

yes indeed - thats true

in fact you can setup sid with debootstrap, chroot to it, build your kernel
there and install on your stretch box. there are some side effects though.
Last time I did something like this, when installing VMware, it told me
that it needs the proper compiler, to compile the modules.

I like simple things as true genius of nature is simple. (well there are
still different levels of simple)

regards

[toc] | [prev] | [next] | [standalone]


#191755

FromMichael Lange <klappnase@freenet.de>
Date2018-01-29 20:00 +0100
Message-ID<vdmOS-83T-9@gated-at.bofh.it>
In reply to#191752
On Mon, 29 Jan 2018 19:33:27 +0100
deloptes <deloptes@gmail.com> wrote:

> Michael Lange wrote:
> 
> > I believe that deloptes' rather harsh comment referred to your
> > suggestion that the OP should upgrade to Sid rather than to anything
> > else you wrote.
> 
> yes indeed - thats true
> 
> in fact you can setup sid with debootstrap, chroot to it, build your
> kernel there and install on your stretch box. there are some side
> effects though. Last time I did something like this, when installing
> VMware, it told me that it needs the proper compiler, to compile the
> modules.

I never tried, but I think probably one could even start a live Sid
environment, mount one's hard drive on /mnt and then compile the kernel.

Regards

Michael


.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

Dammit Jim, I'm an actor, not a doctor.

[toc] | [prev] | [next] | [standalone]


#191763

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-01-30 10:50 +0100
Message-ID<vdAI9-8u-1@gated-at.bofh.it>
In reply to#191721

[Multipart message — attachments visible in raw view] — view raw

On 29 January 2018 at 12:49, Michael Fothergill <
michael.fothergill@gmail.com> wrote:

>
>
> On 29 January 2018 at 10:17, Michael Lange <klappnase@freenet.de> wrote:
>
>> Hi,
>>
>> On Mon, 29 Jan 2018 08:35:58 +0000
>> Michael Fothergill <michael.fothergill@gmail.com> wrote:
>>
>> > ​Your need to upgrade to unstable (Debian Sid).  Then you need to get
>> > the latest kernel from the kernel.org website.
>> > You also need to install GCC7 in sid which will give you version 7.3.0
>> > at present.  That is a new enough compiler to be able to properly
>> > install the spectre and meltdown fixes.
>>
>> The "meltdown fix" (a.k.a. page tables isolation) is already included in
>> Stretch's 4.9 kernel.
>>
>> > Then you need to run the spectre/meltdown checker which you can get
>> > from a github site and run locally on your box to know it's really
>> > installed properly.
>> > AFAICT at present running a kernel with spectre and meltdown protection
>> > means running debian in the opposite way it is usually billed as to the
>> > outside world ie unstable for quite some time.
>>
>> That's not entirely true, you can run Debian Stable / Stretch with a
>> kernel that was compiled on Sid with gcc-7.3, however it is true that for
>> now there is no such kernel available for Stretch out-of-the-box and even
>> installing the latest gcc-7 compiler packages from sid on a Stretch
>> system is, if possible at all, probably not trivial.
>>
>
​In the recent MVE thread , I had asked if I could compile the spectre fix
kernel in Sid and move to buster (I thought moving down to
stretch would likely not be practical).

The response from Greg was the following:

On Thu, Jan 25, 2018 at 12:36:46PM +0000, Michael Fothergill wrote:
> ​If I become sid and install the kernel correctly, could I go back to
being
> just buster (sounds like an energy drink) and carry on using the new
kernel?

No.

*******************

At that point I really did seem that:

1. I had no choice but to become sid/unstable here.

​2. I would have to remain being sid for some considerable time running
this new fangled kernel.

And so would  anyone else trying to address the spectre problem including
new users, as far as I could then.

I was interested specifically in the spectre fix because as an AMD user
meltdown is not a vulnerability for me which the spectre-meltdown-checker
reminds you
of when you run it.

I then put up a post saying "well I guess I am going to have to upgrade to
sid then" or something similar.

The silence was deafening.

So I went ahead and installed GCC 8 (because GCC 7.3 hadn't quite been
ported into sid at that point) and tried to compile ​the new spectre fix
kernel.

​I now see that maybe the kernel could be more portable once created than
it seemed then to me. as has been pointed out above that the OP really
ought to have
been made aware of.

Cheers

MF​



>
> ​That is pretty much what I had been led to believe already except
> for the part where you suggest that a kernel compiled in Sid could
> apparently
> be used in stable.  Again, if that would be true I should have mentioned
> it to the OP; sorry about that.
> Apart from that it makes me think that what I posted was perhaps not BS
> after all.......
>
> Cheers
>
> MF​
>
>
>
>>
>> I assume that most likely someone is working on an update to gcc-6 that
>> will make it possible to compile the latest "spectre fix" into the kernel
>> with Stretch's default compiler and we will have to wait until that is
>> done.
>>
>> I think it is likely though, that a kernel with that fix will be
>> available soon in the "experimental" suite and could be installed
>> manually on Stretch.
>>
>
> ​
>
>
>
>>
>> Regards
>>
>> Michael
>>
>> .-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.
>>
>> After a time, you may find that "having" is not so pleasing a thing,
>> after all, as "wanting."  It is not logical, but it is often true.
>>                 -- Spock, "Amok Time", stardate 3372.7
>>
>>
>

[toc] | [prev] | [next] | [standalone]


#191767

FromMichael Lange <klappnase@freenet.de>
Date2018-01-30 12:20 +0100
Message-ID<vdC7f-1cY-5@gated-at.bofh.it>
In reply to#191763
On Tue, 30 Jan 2018 09:31:01 +0000
Michael Fothergill <michael.fothergill@gmail.com> wrote:

> ​In the recent MVE thread , I had asked if I could compile the spectre
> fix kernel in Sid and move to buster (I thought moving down to
> stretch would likely not be practical).
> 
> The response from Greg was the following:
> 
> On Thu, Jan 25, 2018 at 12:36:46PM +0000, Michael Fothergill wrote:
> > ​If I become sid and install the kernel correctly, could I go back to
> being
> > just buster (sounds like an energy drink) and carry on using the new
> kernel?
> 
> No.
> 
> *******************
> 
> At that point I really did seem that:
> 
> 1. I had no choice but to become sid/unstable here.

I can only guess of course, I think probably they figured you would
upgrade your system to Sid, then compile a kernel and then *downgrade*
the system again to buster. The answer to that would clearly be "no". 
But running a kernel compiled on a *different* Sid system on buster or
stretch is an entirely different thing of course.

Regards

Michael


.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

It [being a Vulcan] means to adopt a philosophy, a way of life which is
logical and beneficial.  We cannot disregard that philosophy merely for
personal gain, no matter how important that gain might be.
		-- Spock, "Journey to Babel", stardate 3842.4

[toc] | [prev] | [next] | [standalone]


#191769

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2018-01-30 14:30 +0100
Message-ID<vdE93-2sX-1@gated-at.bofh.it>
In reply to#191767
On Tue, Jan 30, 2018 at 12:13:47PM +0100, Michael Lange wrote:
> Michael Fothergill <michael.fothergill@gmail.com> wrote:
> > The response from Greg was the following:
> > 
> > On Thu, Jan 25, 2018 at 12:36:46PM +0000, Michael Fothergill wrote:
> > > ​If I become sid and install the kernel correctly, could I go back to
> > being
> > > just buster (sounds like an energy drink) and carry on using the new
> > kernel?
> > 
> > No.
> > 
> > *******************
> > 
> > At that point I really did seem that:
> > 
> > 1. I had no choice but to become sid/unstable here.
> 
> I can only guess of course, I think probably they figured you would
> upgrade your system to Sid, then compile a kernel and then *downgrade*
> the system again to buster. The answer to that would clearly be "no". 
> But running a kernel compiled on a *different* Sid system on buster or
> stretch is an entirely different thing of course.

Yes, that's correct.  If you actually "become sid" (upgrade your whole
system to sid), there is no going back.

But you can set up a *separate* system (either an entirely new box,
or a chroot into which you debootstrap sid, or a virtual machine, or a
container, or whatever other fancy thing the kids are using these days),
build a kernel .deb package there, *copy* that package to your buster
system, and install it.

Or you can do what most of us are doing: wait for the Debian security
team (and, really, for the entire *world*) to figure out how best to
approach, mitigate, and/or solve the issues.

Meanwhile, I would recommend not letting random people get shell access
to your critical systems.  Near as I can tell, exploiting a Spectre-type
CPU vulnerability requires the ability to install and execute a program
of the attacker's creation on the target system.  If you don't have
users logging in and running commands, then you probably don't have to
worry so much about this.  Unless I'm completely missing something.

(If you have users issuing commands on your system through some other
vector, like a PHP web-app exploit, then that's a bigger issue you
should address directly.)

[toc] | [prev] | [next] | [standalone]


#191770

FromGene Heskett <gheskett@shentel.net>
Date2018-01-30 14:50 +0100
Message-ID<vdEsp-2zv-1@gated-at.bofh.it>
In reply to#191769
On Tuesday 30 January 2018 08:22:18 Greg Wooledge wrote:

> On Tue, Jan 30, 2018 at 12:13:47PM +0100, Michael Lange wrote:
> > Michael Fothergill <michael.fothergill@gmail.com> wrote:
> > > The response from Greg was the following:
> > >
> > > On Thu, Jan 25, 2018 at 12:36:46PM +0000, Michael Fothergill wrote:
> > > > ​If I become sid and install the kernel correctly, could I go
> > > > back to
> > >
> > > being
> > >
> > > > just buster (sounds like an energy drink) and carry on using the
> > > > new
> > >
> > > kernel?
> > >
> > > No.
> > >
> > > *******************
> > >
> > > At that point I really did seem that:
> > >
> > > 1. I had no choice but to become sid/unstable here.
> >
> > I can only guess of course, I think probably they figured you would
> > upgrade your system to Sid, then compile a kernel and then
> > *downgrade* the system again to buster. The answer to that would
> > clearly be "no". But running a kernel compiled on a *different* Sid
> > system on buster or stretch is an entirely different thing of
> > course.
>
> Yes, that's correct.  If you actually "become sid" (upgrade your whole
> system to sid), there is no going back.
>
> But you can set up a *separate* system (either an entirely new box,
> or a chroot into which you debootstrap sid, or a virtual machine, or a
> container, or whatever other fancy thing the kids are using these
> days), build a kernel .deb package there, *copy* that package to your
> buster system, and install it.
>
> Or you can do what most of us are doing: wait for the Debian security
> team (and, really, for the entire *world*) to figure out how best to
> approach, mitigate, and/or solve the issues.
>
> Meanwhile, I would recommend not letting random people get shell
> access to your critical systems.  Near as I can tell, exploiting a
> Spectre-type CPU vulnerability requires the ability to install and
> execute a program of the attacker's creation on the target system.  If
> you don't have users logging in and running commands, then you
> probably don't have to worry so much about this.  Unless I'm
> completely missing something.
>
> (If you have users issuing commands on your system through some other
> vector, like a PHP web-app exploit, then that's a bigger issue you
> should address directly.)

Running apache2 to serve up my web page, see sig, apache2 doesn't have 
access to a lot of its plugins, file browsing and pulling is all thats 
allowed, and thats only done via a NAT rule in dd-wrt to direct that 
port number only to this machine, should I be worried?

-- 
Cheers, Gene Heskett
--
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#191772

From"tv.debian@googlemail.com" <tv.debian@googlemail.com>
Date2018-01-30 16:40 +0100
Message-ID<vdGaR-3HO-1@gated-at.bofh.it>
In reply to#191769
On 30/01/2018 18:52, Greg Wooledge wrote:
> On Tue, Jan 30, 2018 at 12:13:47PM +0100, Michael Lange wrote:
>> Michael Fothergill <michael.fothergill@gmail.com> wrote:
>>> The response from Greg was the following:
>>>
>>> On Thu, Jan 25, 2018 at 12:36:46PM +0000, Michael Fothergill wrote:
>>>> ​If I become sid and install the kernel correctly, could I go back to
>>> being
>>>> just buster (sounds like an energy drink) and carry on using the new
>>> kernel?
>>>
>>> No.
>>>
>>> *******************
>>>
>>> At that point I really did seem that:
>>>
>>> 1. I had no choice but to become sid/unstable here.
>>
>> I can only guess of course, I think probably they figured you would
>> upgrade your system to Sid, then compile a kernel and then *downgrade*
>> the system again to buster. The answer to that would clearly be "no".
>> But running a kernel compiled on a *different* Sid system on buster or
>> stretch is an entirely different thing of course.
> 
> Yes, that's correct.  If you actually "become sid" (upgrade your whole
> system to sid), there is no going back.
> 
> But you can set up a *separate* system (either an entirely new box,
> or a chroot into which you debootstrap sid, or a virtual machine, or a
> container, or whatever other fancy thing the kids are using these days),
> build a kernel .deb package there, *copy* that package to your buster
> system, and install it.
> 
> Or you can do what most of us are doing: wait for the Debian security
> team (and, really, for the entire *world*) to figure out how best to
> approach, mitigate, and/or solve the issues.
> 
> Meanwhile, I would recommend not letting random people get shell access
> to your critical systems.  Near as I can tell, exploiting a Spectre-type
> CPU vulnerability requires the ability to install and execute a program
> of the attacker's creation on the target system.  If you don't have
> users logging in and running commands, then you probably don't have to
> worry so much about this.  Unless I'm completely missing something.
> 
> (If you have users issuing commands on your system through some other
> vector, like a PHP web-app exploit, then that's a bigger issue you
> should address directly.)
> 

It should be possible to exploit Spectre via javascript, the prominent 
web browsers (G.Chrome/Chromium and Firefox) have already applied 
mitigation for this scenario. For G.Chrome/Chromium you can also use an 
experimental flag do harden site isolation (at the cost of memory 
consumption). But you can be sure the clever kids in their basements, 
the mafia networks and the state sponsored rogue agencies are hard at 
work trying to find novelty use for these new pathways to our systems. 
So patch, update, and be careful what emailed link you click on (hint: 
none).
In Debian we are lucky as far as I can judge, Stable received a backport 
of the Kaiser/kpti patches, and Sid has retpolined kernel and patched 
gcc (but still vulnerable to Spectre 1 just as everybody else on the 
planet).
On Stable and Backport kernel you are covered for Meltdown (for Intel 
cpu) but still vulnerable to Spectre. That will be the case as long as 
the gcc patches are not backported, or the Debian deities decide to 
break the taboo and issue a kernel and gcc bump for Stable, unlikely.

In Testing you are following Sid, remember there is no official security 
support for Testing outside of the very end of the pre-stable release 
freeze period. So you can cherry-pick what you want from Sid, or wait 
for the migration to naturally happen (if it has not happened yet, I 
don't know).
The cpu microcode side of things is a lot murkier, Intel is going back 
and forth with crappy code that crashes some systems, and the decision 
to apply or not those microcode updates is a tricky one. As for board 
vendors they don't seem to scramble to send updates out...

In any case right now there is no cause for alarm for the general public 
(IMHO), that may change if a working javascript exploit surfaces but it 
isn't here yet. If you are hosting virtual systems for distrusted 
clients (aren't they all) then you need to weight your options 
seriously, keeping in mind that when an efficient exploit surfaces it 
will be too late to patch.

All of the above is just my attempt at offering a synthesis of my 
experience, I am not working for US-CERT and I am not a DD, so you can 
ignore all of the above and go find out for yourself (the best way®).

[toc] | [prev] | [next] | [standalone]


Page 2 of 5 — ← Prev page 1 [2] 3 4 5  Next page →

Back to top | Article view | linux.debian.user


csiph-web