x86/bugs: Fix handling when SRSO mitigation is disabled
authorDavid Kaplan <david.kaplan@amd.com>
Wed, 4 Sep 2024 15:07:11 +0000 (10:07 -0500)
committerBorislav Petkov (AMD) <bp@alien8.de>
Thu, 5 Sep 2024 09:20:50 +0000 (11:20 +0200)
When the SRSO mitigation is disabled, either via mitigations=off or
spec_rstack_overflow=off, the warning about the lack of IBPB-enhancing
microcode is printed anyway.

This is unnecessary since the user has turned off the mitigation.

  [ bp: Massage, drop SBPB rationale as it doesn't matter because when
    mitigations are disabled x86_pred_cmd is not being used anyway. ]

Signed-off-by: David Kaplan <david.kaplan@amd.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Acked-by: Josh Poimboeuf <jpoimboe@kernel.org>
Link: https://lore.kernel.org/r/20240904150711.193022-1-david.kaplan@amd.com
arch/x86/kernel/cpu/bugs.c

index 189840db2f8dc195c6b6e32a7bfcee4167a8dbda..d1915427b4ffcb1141452b0fe5bb8872ab2ae1da 100644 (file)
@@ -2557,10 +2557,9 @@ static void __init srso_select_mitigation(void)
 {
        bool has_microcode = boot_cpu_has(X86_FEATURE_IBPB_BRTYPE);
 
-       if (cpu_mitigations_off())
-               return;
-
-       if (!boot_cpu_has_bug(X86_BUG_SRSO)) {
+       if (!boot_cpu_has_bug(X86_BUG_SRSO) ||
+           cpu_mitigations_off() ||
+           srso_cmd == SRSO_CMD_OFF) {
                if (boot_cpu_has(X86_FEATURE_SBPB))
                        x86_pred_cmd = PRED_CMD_SBPB;
                return;
@@ -2591,11 +2590,6 @@ static void __init srso_select_mitigation(void)
        }
 
        switch (srso_cmd) {
-       case SRSO_CMD_OFF:
-               if (boot_cpu_has(X86_FEATURE_SBPB))
-                       x86_pred_cmd = PRED_CMD_SBPB;
-               return;
-
        case SRSO_CMD_MICROCODE:
                if (has_microcode) {
                        srso_mitigation = SRSO_MITIGATION_MICROCODE;
@@ -2649,6 +2643,8 @@ static void __init srso_select_mitigation(void)
                        pr_err("WARNING: kernel not compiled with MITIGATION_SRSO.\n");
                 }
                break;
+       default:
+               break;
        }
 
 out: